Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical DebianRedhat+1 more6Debian Linux Enterprise Linux DesktopEnterprise Linux Server+3 moreMay 13, 2026 Nov 27, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Samba before 4.7.3 might allow remote attackers to obtain sensitive information by leveraging failure of the server to clear allocated heap memory. |
4Canonical DebianRedhat+1 more6Debian Linux Enterprise Linux DesktopEnterprise Linux Server+3 moreMay 13, 2026 Nov 27, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Use-after-free vulnerability in Samba 4.x before 4.7.3 allows remote attackers to execute arbitrary code via a crafted SMB1 request. |
2Debian Pivotal Software2Debian Linux Spring LdapMay 13, 2026 Nov 27, 2017 N/A· v4 8.1 HIGH· v3 5.1 MEDIUM· v2 In Pivotal Spring-LDAP versions 1.3.0 - 2.3.1, when connected to some LDAP servers, when no additional attributes are bound, and when using LDAP BindAuthenticator with org.springframework.ldap.core.support.DefaultTlsDirC...Show more |
2Canonical Debian3Bazaar Debian LinuxUbuntu LinuxMay 13, 2026 Nov 27, 2017 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Bazaar through 2.7.0, when Subprocess SSH is used, allows remote attackers to execute arbitrary commands via a bzr+ssh URL with an initial dash character in the hostname, a related issue to CVE-2017-9800, CVE-2017-12836,...Show more |
The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to cause a denial of service (infinite loop and stack exhaustion) via vectors involving BDAT commands and an improper...Show more |
2Debian Exim2Debian Linux EximMay 13, 2026 Nov 25, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via vectors involving BDAT commands. |
2Debian Linux2Debian Linux Linux KernelMay 13, 2026 Nov 24, 2017 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The XFRM dump policy implementation in net/xfrm/xfrm_user.c in the Linux kernel before 4.13.11 allows local users to gain privileges or cause a denial of service (use-after-free) via a crafted SO_RCVBUF setsockopt system...Show more |
2Debian Neutrinolabs2Debian Linux XrdpMay 13, 2026 Nov 23, 2017 N/A· v4 8.4 HIGH· v3 7.2 HIGH· v2 The scp_v0s_accept function in sesman/libscp/libscp_v0.c in the session manager in xrdp through 0.9.4 uses an untrusted integer as a write length, which allows local users to cause a denial of service (buffer overflow an...Show more |
2Debian Postgresql2Debian Linux PostgresqlMay 13, 2026 Nov 22, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 INSERT ... ON CONFLICT DO UPDATE commands in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, and 9.5.x before 9.5.10 disclose table contents that the invoker lacks privilege to read. These exploits affect only tables wh...Show more |
2Debian Postgresql2Debian Linux PostgresqlMay 13, 2026 Nov 22, 2017 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 Invalid json_populate_recordset or jsonb_populate_recordset function calls in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, 9.5.x before 9.5.10, 9.4.x before 9.4.15, and 9.3.x before 9.3.20 can crash the server or dis...Show more |
Code injection exists in Kernel/System/Spelling.pm in Open Ticket Request System (OTRS) 5 before 5.0.24, 4 before 4.0.26, and 3.3 before 3.3.20. In the agent interface, an authenticated remote attacker can execute shell...Show more |
2Debian Openstack3Debian Linux SwauthSwiftMay 13, 2026 Nov 21, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in middleware.py in OpenStack Swauth through 1.2.0 when used with OpenStack Swift through 2.15.1. The Swift object store and proxy server are saving (unhashed) tokens retrieved from the Swauth mid...Show more |
2Debian Ffmpeg2Debian Linux FfmpegMay 13, 2026 Nov 21, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The VC-2 Video Compression encoder in FFmpeg 3.0 and 3.4 allows remote attackers to cause a denial of service (out-of-bounds read) because of incorrect buffer padding for non-Haar wavelets, related to libavcodec/vc2enc.c...Show more |
2Debian Libxls Project2Debian Linux LibxlsMay 13, 2026 Nov 20, 2017 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 An exploitable stack based buffer overflow vulnerability exists in the xls_getfcell function of libxls 1.3.4. A specially crafted XLS file can cause a memory corruption resulting in remote code execution. An attacker can...Show more |
2Debian Libxls Project2Debian Linux LibxlsMay 13, 2026 Nov 20, 2017 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 An exploitable out-of-bounds write vulnerability exists in the xls_mergedCells function of libxls 1.4. . A specially crafted XLS file can cause a memory corruption resulting in remote code execution. An attacker can send...Show more |
3Apache DebianRedhat8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreMay 13, 2026 Nov 20, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 By exploiting the way Apache OpenOffice before 4.1.4 renders embedded objects, an attacker could craft a document that allows reading in a file from the user's filesystem. Information could be retrieved by the attacker b...Show more |
2Apache Debian2Debian Linux OpenofficeMay 13, 2026 Nov 20, 2017 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A vulnerability in Apache OpenOffice Writer DOC file parser before 4.1.4, and specifically in ImportOldFormatStyles, allows attackers to craft malicious documents that cause denial of service (memory corruption and appli...Show more |
2Apache Debian2Debian Linux OpenofficeMay 13, 2026 Nov 20, 2017 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A vulnerability in OpenOffice's PPT file parser before 4.1.4, and specifically in PPTStyleSheet, allows attackers to craft malicious documents that cause denial of service (memory corruption and application crash) potent...Show more |
2Debian Xfig Project2Debian Linux XfigMay 13, 2026 Nov 20, 2017 N/A· v4 7.1 HIGH· v3 5.8 MEDIUM· v2 An array index error in the fig2dev program in Xfig 3.2.6a allows remote attackers to cause a denial-of-service attack or information disclosure with a maliciously crafted Fig format file, related to a negative font valu...Show more |
5Busybox CanonicalDebian+2 more6Busybox Debian LinuxEsxi+3 moreMay 13, 2026 Nov 20, 2017 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab autocomplete feature of the shell, used to get a list of filenames in a directory, does not sanitize filenames and results in executing any...Show more |