Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
6Canonical DebianHp+3 more15Debian Linux Enterprise Linux DesktopEnterprise Linux Server+12 moreNov 21, 2024 Jan 18, 2018 N/A· v4 4.5 MEDIUM· v3 3.7 LOW· v2 Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: I18n). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151. Difficult to expl...Show more |
6Canonical DebianHp+3 more16Debian Linux Enterprise Linux DesktopEnterprise Linux Server+13 moreNov 21, 2024 Jan 18, 2018 N/A· v4 4.8 MEDIUM· v3 5.8 MEDIUM· v2 Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JNDI). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit:...Show more |
6Canonical DebianHp+3 more16Debian Linux Enterprise Linux DesktopEnterprise Linux Server+13 moreNov 21, 2024 Jan 18, 2018 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: LDAP). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit:...Show more |
6Canonical DebianHp+3 more13Debian Linux Enterprise Linux DesktopEnterprise Linux Server+10 moreNov 21, 2024 Jan 18, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are affected are Java SE: 8u152 and 9.0.1; Java SE Embedded: 8u151. Easily exploitable vulnerabi...Show more |
6Canonical DebianHp+3 more16Debian Linux Enterprise Linux DesktopEnterprise Linux Server+13 moreNov 21, 2024 Jan 18, 2018 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRo...Show more |
6Canonical DebianMariadb+3 more15Active Iq Unified Manager Debian LinuxEnterprise Linux Desktop+12 moreNov 21, 2024 Jan 18, 2018 N/A· v4 7.1 HIGH· v3 7.5 HIGH· v2 Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server : Partition). Supported versions that are affected are 5.5.58 and prior, 5.6.38 and prior and 5.7.19 and prior. Easily exploitable vulnera...Show more |
3Canonical DebianSamba3Debian Linux RsyncUbuntu LinuxJun 17, 2026 Jan 17, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The parse_arguments function in options.c in rsyncd in rsync before 3.1.3 does not prevent multiple --protect-args uses, which allows remote attackers to bypass an argument-sanitization protection mechanism. |
2Debian Long Range Zip Project2Debian Linux Long Range ZipJun 17, 2026 Jan 17, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in the ucompthread function (stream.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted lrz file. |
3Canonical DebianPhp3Debian Linux PhpUbuntu LinuxJun 17, 2026 Jan 16, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1. There is Reflected XSS on the PHAR 404 error page via the URI of a request for a .phar file. |
3Canonical DebianPhp3Debian Linux PhpUbuntu LinuxJun 17, 2026 Jan 16, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1, has an integer signedness error that leads to an infinite loop via a cra...Show more |
2Debian Openocd2Debian Linux Open On Chip DebuggerJun 17, 2026 Jan 16, 2018 N/A· v4 9.6 CRITICAL· v3 9.3 HIGH· v2 Open On-Chip Debugger (OpenOCD) 0.10.0 does not block attempts to use HTTP POST for sending data to 127.0.0.1 port 4444, which allows remote attackers to conduct cross-protocol scripting attacks, and consequently execute...Show more |
2Debian Transmissionbt2Debian Linux TransmissionJun 17, 2026 Jan 15, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Transmission through 2.92 relies on X-Transmission-Session-Id (which is not a forbidden header for Fetch) for access control, which allows remote attackers to execute arbitrary RPC commands, and consequently write to arb...Show more |
2Artifex Debian2Debian Linux MupdfJun 17, 2026 Jan 14, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In MuPDF 1.12.0, there is an infinite loop vulnerability and application hang in the pdf_parse_array function (pdf/pdf-parse.c) because EOF is not considered. Remote attackers could leverage this vulnerability to cause a...Show more |
2Debian Graphicsmagick2Debian Linux GraphicsmagickJun 17, 2026 Jan 14, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In GraphicsMagick 1.3.27, there is an infinite loop and application hang in the ReadBMPImage function (coders/bmp.c). Remote attackers could leverage this vulnerability to cause a denial of service via an image file with...Show more |
2Debian Shibboleth2Debian Linux Xmltooling CNov 21, 2024 Jan 13, 2018 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 Shibboleth XMLTooling-C before 1.6.3, as used in Shibboleth Service Provider before 2.6.0 on Windows and other products, mishandles digital signatures of user attribute data, which allows remote attackers to obtain sensi...Show more |
2Debian Google2Android Debian LinuxNov 21, 2024 Jan 12, 2018 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A vulnerability in the Android media framework (libvpx) related to odd frame width. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-64710201. |
5Canonical DebianFedoraproject+2 more10Debian Linux Enterprise Linux DesktopEnterprise Linux Server+7 moreNov 21, 2024 Jan 12, 2018 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A stack-based buffer overflow within GNOME gcab through 0.7.4 can be exploited by malicious attackers to cause a crash or, potentially, execute arbitrary code via a crafted .cab file. |
2Debian Wireshark2Debian Linux WiresharkNov 21, 2024 Jan 11, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark 2.4.0 to 2.4.3 and 2.2.0 to 2.2.11, the JSON, XML, NTP, XMPP, and GDB dissectors could crash. This was addressed in epan/tvbparse.c by limiting the recursion depth. |
2Debian Wireshark2Debian Linux WiresharkNov 21, 2024 Jan 11, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In Wireshark 2.4.0 to 2.4.3 and 2.2.0 to 2.2.11, the WCP dissector could crash. This was addressed in epan/dissectors/packet-wcp.c by validating the available buffer length. |
2Debian Wireshark2Debian Linux WiresharkNov 21, 2024 Jan 11, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In Wireshark 2.4.0 to 2.4.3 and 2.2.0 to 2.2.11, the IxVeriWave file parser could crash. This was addressed in wiretap/vwr.c by correcting the signature timestamp bounds checks. |