Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxNov 21, 2024 Jan 11, 2018 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 In the Linux kernel through 4.14.13, the rds_cmsg_atomic function in net/rds/rdma.c mishandles cases where page pinning fails or an invalid address is supplied, leading to an rds_atomic_free_op NULL pointer dereference. |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxNov 21, 2024 Jan 11, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 In the Linux kernel through 3.2, the rds_message_alloc_sgs() function does not validate a value that is used during DMA page allocation, leading to a heap-based out-of-bounds write (related to the rds_rdma_extra_size fun...Show more |
4Debian FasterxmlNetapp+1 more8Debian Linux E Series Santricity Os ControllerE Series Santricity Web Services Proxy+5 moreAug 27, 2025 Jan 10, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending malic...Show more |
2Debian Redmine2Debian Linux RedmineNov 21, 2024 Jan 10, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Redmine before 3.2.9, 3.3.x before 3.3.6, and 3.4.x before 3.4.4 does not block the --config and --debugger flags to the Mercurial hg program, which allows remote attackers to execute arbitrary commands (through the Merc...Show more |
2Debian Mono Project2Debian Linux MonoNov 21, 2024 Jan 8, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The TLS stack in Mono before 3.12.1 allows remote attackers to have unspecified impact via vectors related to client-side SSLv2 fallback. |
2Debian Mono Project2Debian Linux MonoNov 21, 2024 Jan 8, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequently impersonate clients by leveraging missing handshake state validation, aka a "SMACK SKIP-TLS" iss...Show more |
2Debian Libming2Debian Linux LibmingNov 21, 2024 Jan 8, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In libming 0.4.8, there is an integer overflow (caused by an out-of-range left shift) in the readUInt32 function (util/read.c). Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafte...Show more |
2Debian Opencv2Debian Linux OpencvNov 21, 2024 Jan 8, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In OpenCV 3.3.1, an assertion failure happens in cv::RBaseStream::setPos in modules/imgcodecs/src/bitstrm.cpp because of an incorrect integer cast. |
2Debian Opencv2Debian Linux OpencvNov 21, 2024 Jan 8, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In OpenCV 3.3.1, a heap-based buffer overflow happens in cv::Jpeg2KDecoder::readComponent8u in modules/imgcodecs/src/grfmt_jpeg2000.cpp when parsing a crafted image file. |
2Debian Irssi2Debian Linux IrssiNov 21, 2024 Jan 6, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Irssi before 1.0.6, a calculation error in the completion code could cause a heap buffer overflow when completing certain strings. |
When using an incomplete variable argument, Irssi before 1.0.6 may access data beyond the end of the string. |
2Debian Irssi2Debian Linux IrssiNov 21, 2024 Jan 6, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 When the channel topic is set without specifying a sender, Irssi before 1.0.6 may dereference a NULL pointer. |
3Canonical DebianIrssi3Debian Linux IrssiUbuntu LinuxNov 21, 2024 Jan 6, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 When using incomplete escape codes, Irssi before 1.0.6 may access data beyond the end of the string. |
2Debian Libming2Debian Linux LibmingNov 21, 2024 Jan 5, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In libming 0.4.8, there is an integer signedness error vulnerability (left shift of a negative value) in the readSBits function (util/read.c). Remote attackers can leverage this vulnerability to cause a denial of service...Show more |
3Canonical DebianImagemagick3Debian Linux ImagemagickUbuntu LinuxNov 21, 2024 Jan 5, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 In ImageMagick 7.0.7-17 Q16, there is a heap-based buffer over-read in coders/sixel.c in the ReadSIXELImage function, related to the sixel_decode function. |
2Debian Ibm2Debian Linux Security Key Lifecycle ManagerNov 21, 2024 Jan 4, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 133559. |
13Arm CanonicalDebian+10 more308Atom C Atom EAtom X3+305 moreMay 28, 2026 Jan 4, 2018 N/A· v4 5.6 MEDIUM· v3 4.7 MEDIUM· v2 Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis. |
7Arm CanonicalDebian+4 more220Atom C Atom EAtom X3+217 moreMay 6, 2025 Jan 4, 2018 N/A· v4 5.6 MEDIUM· v3 1.9 LOW· v2 Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis. |
2Codehaus Plexus Debian2Debian Linux Plexus UtilsNov 21, 2024 Jan 3, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Plexus-utils before 3.0.16 is vulnerable to command injection because it does not correctly process the contents of double quoted strings. |
2Debian Pocoproject2Debian Linux PocoNov 21, 2024 Jan 3, 2018 N/A· v4 6.5 MEDIUM· v3 5.8 MEDIUM· v2 The ZipCommon::isValidPath() function in Zip/src/ZipCommon.cpp in POCO C++ Libraries before 1.8 does not properly restrict the filename value in the ZIP header, which allows attackers to conduct absolute path traversal a...Show more |