Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The pg_ctlcluster script in postgresql-common package in Debian wheezy before 134wheezy5, in Debian jessie before 165+deb8u2, in Debian unstable before 178, in Ubuntu 12.04 LTS before 129ubuntu1.2, in Ubuntu 14.04 LTS be...Show more |
5Debian FedoraprojectOpensuse+2 more6Debian Linux FedoraLeap+3 moreMay 13, 2026 Dec 5, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Tor before 0.2.8.12 might allow remote attackers to cause a denial of service (client crash) via a crafted hidden service descriptor. |
The most package in Debian wheezy before 5.0.0a-2.2, in Debian jessie before 5.0.0a-2.3+deb8u1, and in Debian unstable before 5.0.0a-3 allows remote attackers to execute arbitrary commands via shell metacharacters in the...Show more |
2Canonical Debian2Advanced Package Tool Ubuntu LinuxMay 13, 2026 Dec 5, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The apt package in Debian jessie before 1.0.9.8.4, in Debian unstable before 1.4~beta2, in Ubuntu 14.04 LTS before 1.0.1ubuntu2.17, in Ubuntu 16.04 LTS before 1.2.15ubuntu0.2, and in Ubuntu 16.10 before 1.3.2ubuntu0.1 al...Show more |
2Debian Tor Project2Debian Linux TorMay 13, 2026 Dec 3, 2017 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, there is a use-after-free in onion service v2 during intro-point expiration because the...Show more |
2Debian Tor Project2Debian Linux TorMay 13, 2026 Dec 3, 2017 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, relays (that have incompletely downloaded descriptors) can pick themselves in a circuit...Show more |
2Debian Tor Project2Debian Linux TorMay 13, 2026 Dec 3, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, an attacker can cause a denial of service (application hang) via crafted PEM input that...Show more |
2Debian Tor Project2Debian Linux TorMay 13, 2026 Dec 3, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, remote attackers can cause a denial of service (NULL pointer dereference and applicatio...Show more |
2Debian Tor Project2Debian Linux TorMay 13, 2026 Dec 3, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, the replay-cache protection mechanism is ineffective for v2 onion services, aka TROVE-2...Show more |
2Debian Wordpress2Debian Linux WordpressMay 13, 2026 Dec 2, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 wp-includes/feed.php in WordPress before 4.9.1 does not properly restrict enclosures in RSS and Atom fields, which might allow attackers to conduct XSS attacks via a crafted URL. |
2Debian Wordpress2Debian Linux WordpressMay 13, 2026 Dec 2, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 wp-includes/general-template.php in WordPress before 4.9.1 does not properly restrict the lang attribute of an HTML element, which might allow attackers to conduct XSS attacks via the language setting of a site. |
2Debian Wordpress2Debian Linux WordpressMay 13, 2026 Dec 2, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 wp-includes/functions.php in WordPress before 4.9.1 does not require the unfiltered_html capability for upload of .js files, which might allow remote attackers to conduct XSS attacks via a crafted file. |
3Canonical DebianX3Debian Linux LibxcursorUbuntu LinuxMay 13, 2026 Dec 1, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 libXcursor before 1.1.15 has various integer overflows that could lead to heap buffer overflows when processing malicious cursors, e.g., with programs like GIMP. It is also possible that an attack vector exists against t...Show more |
3Canonical DebianX3Debian Linux LibxfontUbuntu LinuxMay 13, 2026 Dec 1, 2017 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 In libXfont before 1.5.4 and libXfont2 before 2.0.3, a local attacker can open (but not read) files on the system as root, triggering tape rewinds, watchdogs, or similar mechanisms that can be triggered by opening files. |
3Canonical DebianVim3Debian Linux Ubuntu LinuxVimMay 13, 2026 Dec 1, 2017 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 fileio.c in Vim prior to 8.0.1263 sets the group ownership of a .swp file to the editor's primary group (which may be different from the group ownership of the original file), which allows local users to obtain sensitive...Show more |
2Debian Wireshark2Debian Linux WiresharkMay 13, 2026 Dec 1, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark 2.4.0 to 2.4.2 and 2.2.0 to 2.2.10, the CIP Safety dissector could crash. This was addressed in epan/dissectors/packet-cipsafety.c by validating the packet length. |
2Debian Wireshark2Debian Linux WiresharkMay 13, 2026 Dec 1, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark 2.4.0 to 2.4.2 and 2.2.0 to 2.2.10, the IWARP_MPA dissector could crash. This was addressed in epan/dissectors/packet-iwarp-mpa.c by validating a ULPDU length. |
2Debian Wireshark2Debian Linux WiresharkMay 13, 2026 Dec 1, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark 2.4.0 to 2.4.2 and 2.2.0 to 2.2.10, the NetBIOS dissector could crash. This was addressed in epan/dissectors/packet-netbios.c by ensuring that write operations are bounded by the beginning of a buffer. |
2Debian Haxx3Curl Debian LinuxLibcurlMay 13, 2026 Nov 29, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The FTP wildcard function in curl and libcurl before 7.57.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) or possibly have unspecified other impact via a string that ends...Show more |
2Debian Haxx3Curl Debian LinuxLibcurlMay 13, 2026 Nov 29, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The NTLM authentication feature in curl and libcurl before 7.57.0 on 32-bit platforms allows attackers to cause a denial of service (integer overflow and resultant buffer overflow, and application crash) or possibly have...Show more |