Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical DebianQemu3Debian Linux QemuUbuntu LinuxMay 13, 2026 Nov 17, 2017 N/A· v4 10.0 CRITICAL· v3 6.4 MEDIUM· v2 hw/input/ps2.c in Qemu does not validate 'rptr' and 'count' values during guest migration, leading to out-of-bounds access. |
2Debian Teluu2Debian Linux PjsipMay 13, 2026 Nov 17, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Teluu pjproject (pjlib and pjlib-util) in PJSIP before 2.7.1. Parsing the numeric header fields in a SIP message (like cseq, ttl, port, etc.) all had the potential to overflow, either causing u...Show more |
2Debian Optipng Project2Debian Linux OptipngMay 13, 2026 Nov 17, 2017 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Integer overflow bug in function minitiff_read_info() of optipng 0.7.6 allows an attacker to remotely execute code or cause denial of service. |
2Debian Python2Debian Linux PythonMay 13, 2026 Nov 17, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringobject.c, resulting in heap-based buffer overflow (and possible arbitrary code execution) |
2Debian Shibboleth2Debian Linux OpensamlMay 13, 2026 Nov 16, 2017 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 The DynamicMetadataProvider class in saml/saml2/metadata/impl/DynamicMetadataProvider.cpp in OpenSAML-C in OpenSAML before 2.6.1 fails to properly configure itself with the MetadataFilter plugins and does not perform cri...Show more |
2Debian Shibboleth2Debian Linux Service ProviderMay 13, 2026 Nov 16, 2017 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 shibsp/metadata/DynamicMetadataProvider.cpp in the Dynamic MetadataProvider plugin in Shibboleth Service Provider before 2.6.1 fails to properly configure itself with the MetadataFilter plugins and does not perform criti...Show more |
In the Agent Frontend in Open Ticket Request System (OTRS) 3.3.x through 3.3.18, with a crafted URL it is possible to gain information like database user and password. |
3Debian Varnish CacheVarnish Cache Project3Debian Linux VarnishVarnish CacheMay 13, 2026 Nov 16, 2017 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 vbf_stp_error in bin/varnishd/cache/cache_fetch.c in Varnish HTTP Cache 4.1.x before 4.1.9 and 5.x before 5.2.1 allows remote attackers to obtain sensitive information from process memory because a VFP_GetStorage buffer...Show more |
4Canonical DebianLinux+1 more4Debian Linux Linux Enterprise ServerLinux Kernel+1 moreMay 13, 2026 Nov 15, 2017 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The sctp_do_peeloff function in net/sctp/socket.c in the Linux kernel before 4.14 does not check whether the intended netns is used in a peel-off action, which allows local users to cause a denial of service (use-after-f...Show more |
2Debian Konversation2Debian Linux KonversationMay 13, 2026 Nov 15, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Konversation 1.4.x, 1.5.x, 1.6.x, and 1.7.x before 1.7.3 allow remote attackers to cause a denial of service (crash) via vectors related to parsing of IRC color formatting codes. |
2Debian Mediawiki2Debian Linux MediawikiMay 13, 2026 Nov 15, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The language converter in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows attribute injection attacks via glossary rules. |
2Debian Mediawiki2Debian Linux MediawikiMay 13, 2026 Nov 15, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The language converter in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows attackers to replace text inside tags via a rule definition followed by "a lot of junk." |
2Debian Mediawiki2Debian Linux MediawikiMay 13, 2026 Nov 15, 2017 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows remote attackers to inject > (greater than) characters via the id attribute of a headline. |
2Debian Mediawiki2Debian Linux MediawikiMay 13, 2026 Nov 15, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The implementation of raw message parameter expansion in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows HTML mangling attacks. |
2Debian Mediawiki2Debian Linux MediawikiMay 13, 2026 Nov 15, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2, when a private wiki is configured, provides different error messages for failed login attempts depending on whether the username exists, which allo...Show more |
2Debian Mediawiki2Debian Linux MediawikiMay 13, 2026 Nov 15, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 api.php in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 has a Reflected File Download vulnerability. |
2Debian Mediawiki2Debian Linux MediawikiMay 13, 2026 Nov 15, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 has XSS when the $wgShowExceptionDetails setting is false and the browser sends non-standard URL escaping. |
7Debian FujitsuNetapp+4 more45Adaptive Access Manager Application Testing SuiteClustered Data Ontap+42 moreMay 13, 2026 Nov 13, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use t...Show more |
2Debian Redmine2Debian Linux RedmineMay 13, 2026 Nov 13, 2017 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 In Redmine before 3.2.7 and 3.3.x before 3.3.4, the reminders function in app/models/mailer.rb does not check whether an issue is visible, which allows remote authenticated users to obtain sensitive information by readin...Show more |
2Debian Roundcube2Debian Linux WebmailApr 21, 2026 Nov 9, 2017 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, as exploited in the wild in November 2017...Show more |