Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical DebianLinux+1 more10Debian Linux Enterprise Linux DesktopEnterprise Linux Server+7 moreMay 13, 2026 Dec 11, 2017 N/A· v4 7.4 HIGH· v3 6.1 MEDIUM· v2 The Linux Kernel 2.6.32 and later are affected by a denial of service, by flooding the diagnostic port 0x80 an exception can be triggered leading to a kernel panic. |
3Canonical DebianImagemagick3Debian Linux ImagemagickUbuntu LinuxMay 13, 2026 Dec 11, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 ImageMagick before 7.0.7-12 has a coders/png.c Magick_png_read_raw_profile heap-based buffer over-read via a crafted file, related to ReadOneMNGImage. |
2Debian Graphicsmagick2Debian Linux GraphicsmagickMay 13, 2026 Dec 11, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 ReadGRAYImage in coders/gray.c in GraphicsMagick 1.3.26 has a magick/import.c ImportGrayQuantumType heap-based buffer over-read via a crafted file. |
2Debian Graphicsmagick2Debian Linux GraphicsmagickMay 13, 2026 Dec 11, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 ReadCMYKImage in coders/cmyk.c in GraphicsMagick 1.3.26 has a magick/import.c ImportCMYKQuantumType heap-based buffer over-read via a crafted file. |
2Debian Graphicsmagick2Debian Linux GraphicsmagickMay 13, 2026 Dec 11, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 WriteOnePNGImage in coders/png.c in GraphicsMagick 1.3.26 has a heap-based buffer over-read via a crafted file. |
2Debian Graphicsmagick2Debian Linux GraphicsmagickMay 13, 2026 Dec 11, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 ReadRGBImage in coders/rgb.c in GraphicsMagick 1.3.26 has a magick/import.c ImportRGBQuantumType heap-based buffer over-read via a crafted file. |
3Canonical DebianImagemagick3Debian Linux ImagemagickUbuntu LinuxMay 13, 2026 Dec 11, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 ImageMagick before 6.9.9-24 and 7.x before 7.0.7-12 has a use-after-free in Magick::Image::read in Magick++/lib/Image.cpp. |
3Canonical DebianUclouvain3Debian Linux OpenjpegUbuntu LinuxMay 13, 2026 Dec 8, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtovolume function in jp3d/convert.c. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly remot...Show more |
2Debian Otrs2Debian Linux OtrsMay 13, 2026 Dec 8, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In Open Ticket Request System (OTRS) through 3.3.20, 4 through 4.0.26, 5 through 5.0.24, and 6 through 6.0.1, an attacker who is logged in as a customer can use the ticket search form to disclose internal article informa...Show more |
In OTRS 6.0.x up to and including 6.0.1, OTRS 5.0.x up to and including 5.0.24, and OTRS 4.0.x up to and including 4.0.26, an attacker who is logged into OTRS as an agent can manipulate form parameters (related to PGP) a...Show more |
3Debian LinuxRedhat9Debian Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreMay 13, 2026 Dec 7, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Linux kernel version 3.3-rc1 and later is affected by a vulnerability lies in the processing of incoming L2CAP commands - ConfigRequest, and ConfigResponse messages. This info leak is a result of uninitialized stack...Show more |
2Debian Mercurial2Debian Linux MercurialMay 13, 2026 Dec 7, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 In Mercurial before 4.4.1, it is possible that a specially malformed repository can cause Git subrepositories to run arbitrary code in the form of a .git/hooks/post-update script checked into the repository. Typical use...Show more |
3Debian NodejsOpenssl3Debian Linux Node.jsOpensslMay 13, 2026 Dec 7, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 There is an overflow bug in the AVX2 Montgomery multiplication procedure used in exponentiation with 1024-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA as a result of this...Show more |
2Debian Openssl2Debian Linux OpensslMay 13, 2026 Dec 7, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 OpenSSL 1.0.2 (starting from version 1.0.2b) introduced an "error state" mechanism. The intent was that if a fatal error occurred during a handshake then OpenSSL would move into the error state and would immediately fail...Show more |
The Virtio Vring implementation in QEMU allows local OS guest users to cause a denial of service (divide-by-zero error and QEMU process crash) by unsetting vring alignment while updating Virtio rings. |
2Debian Heimdal Project2Debian Linux HeimdalMay 13, 2026 Dec 6, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Heimdal through 7.4, remote unauthenticated attackers are able to crash the KDC by sending a crafted UDP packet containing empty data fields for client name or realm. The parser would unconditionally dereference NULL...Show more |
2Debian Samba2Debian Linux RsyncMay 13, 2026 Dec 6, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, does not check for fnamecmp filenames in the daemon_filter_list data structure (in the recv_files function in receiver.c) and also does not apply the sa...Show more |
The recv_files function in receiver.c in the daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, proceeds with certain file metadata updates before checking for a filename in the daemon_filter_list data struc...Show more |
2Debian Openafs2Debian Linux OpenafsMay 13, 2026 Dec 6, 2017 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 OpenAFS 1.x before 1.6.22 does not properly validate Rx ack packets, which allows remote attackers to cause a denial of service (system crash or application crash) via crafted fields, as demonstrated by an integer underf...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxMay 13, 2026 Dec 5, 2017 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The bnep_add_connection function in net/bluetooth/bnep/core.c in the Linux kernel before 3.19 does not ensure that an l2cap socket is available, which allows local users to gain privileges via a crafted application. |