Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian GoogleUclouvain3Debian Linux OpenjpegPdfiumMay 13, 2026 Oct 18, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Double free vulnerability in the j2k_read_ppm_v3 function in OpenJPEG before r2997, as used in PDFium in Google Chrome, allows remote attackers to cause a denial of service (process crash) via a crafted PDF. |
2Debian Redmine2Debian Linux RedmineMay 13, 2026 Oct 18, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles the rendering of wiki links, which allows remote attackers to obtain sensitive information. |
2Debian Redmine2Debian Linux RedmineMay 13, 2026 Oct 18, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles Time Entry rendering in activity views, which allows remote attackers to obtain sensitive information. |
2Debian Redmine2Debian Linux RedmineMay 13, 2026 Oct 18, 2017 N/A· v4 7.3 HIGH· v3 7.5 HIGH· v2 In Redmine before 3.2.6 and 3.3.x before 3.3.3, Redmine.pm lacks a check for whether the Repository module is enabled in a project's settings, which might allow remote attackers to obtain sensitive differences informatio...Show more |
2Debian Redmine2Debian Linux RedmineMay 13, 2026 Oct 18, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In Redmine before 3.2.6 and 3.3.x before 3.3.3, stored XSS is possible by using an SVG document as an attachment. |
2Debian Redmine2Debian Linux RedmineMay 13, 2026 Oct 18, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In Redmine before 3.2.6 and 3.3.x before 3.3.3, XSS exists because markup is mishandled in wiki content. |
2Debian Redmine2Debian Linux RedmineMay 13, 2026 Oct 18, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Redmine before 3.2.6 and 3.3.x before 3.3.3, remote attackers can obtain sensitive information (password reset tokens) by reading a Referer log, because account/lost_password does not use a redirect. |
2Debian Redmine2Debian Linux RedmineMay 13, 2026 Oct 18, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/views/issues/_list.html.erb via crafted column data. |
2Debian Redmine2Debian Linux RedmineMay 13, 2026 Oct 18, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/views/timelog/_list.html.erb via crafted column data. |
2Debian Redmine2Debian Linux RedmineMay 13, 2026 Oct 18, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/helpers/queries_helper.rb via a multi-value field with a crafted value that is mishandled during rendering of an issue list. |
2Debian Redmine2Debian Linux RedmineMay 13, 2026 Oct 18, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/helpers/application_helper.rb via a multi-value field with a crafted value that is mishandled during rendering of issue history. |
2Debian Freedesktop2Debian Linux PopplerMay 13, 2026 Oct 17, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 In Poppler 0.59.0, a NULL Pointer Dereference exists in the GfxImageColorMap::getGrayLine() function in GfxState.cc via a crafted PDF document. |
Debian ftpsync before 20171017 does not use the rsync --safe-links option, which allows remote attackers to conduct directory traversal attacks via a crafted upstream mirror. |
7Canonical DebianFreebsd+4 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Server+9 moreMay 13, 2026 Oct 17, 2017 N/A· v4 5.3 MEDIUM· v3 2.9 LOW· v2 Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Integrity Group Temporal Key (IGTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame, allowing an attac...Show more |
7Canonical DebianFreebsd+4 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Server+9 moreMay 13, 2026 Oct 17, 2017 N/A· v4 5.3 MEDIUM· v3 2.9 LOW· v2 Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Group Temporal Key (GTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame, allowing an attacker within...Show more |
7Canonical DebianFreebsd+4 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Server+9 moreMay 13, 2026 Oct 17, 2017 N/A· v4 6.8 MEDIUM· v3 5.4 MEDIUM· v2 Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Tunneled Direct-Link Setup (TDLS) Peer Key (TPK) during the TDLS handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames. |
7Canonical DebianFreebsd+4 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Server+9 moreMay 13, 2026 Oct 17, 2017 N/A· v4 6.8 MEDIUM· v3 5.4 MEDIUM· v2 Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Station-To-Station-Link (STSL) Transient Key (STK) during the PeerKey handshake, allowing an attacker within radio range to replay, decrypt, or spoof fra...Show more |
7Canonical DebianFreebsd+4 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Server+9 moreMay 13, 2026 Oct 17, 2017 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11r allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during the fast BSS transmission (FT) handshake, allowing an attacker within ra...Show more |
7Canonical DebianFreebsd+4 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Server+9 moreMay 13, 2026 Oct 17, 2017 N/A· v4 5.3 MEDIUM· v3 2.9 LOW· v2 Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the Integrity Group Temporal Key (IGTK) during the group key handshake, allowing an attacker within radio range to spoof frames fr...Show more |
7Canonical DebianFreebsd+4 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Server+9 moreMay 13, 2026 Oct 17, 2017 N/A· v4 5.3 MEDIUM· v3 2.9 LOW· v2 Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the group key handshake, allowing an attacker within radio range to replay frames from access points to clients. |