Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
7Canonical DebianFreebsd+4 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Server+9 moreMay 13, 2026 Oct 17, 2017 N/A· v4 5.3 MEDIUM· v3 2.9 LOW· v2 Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the Integrity Group Temporal Key (IGTK) during the four-way handshake, allowing an attacker within radio range to spoof frames fro...Show more |
7Canonical DebianFreebsd+4 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Server+9 moreMay 13, 2026 Oct 17, 2017 N/A· v4 5.3 MEDIUM· v3 2.9 LOW· v2 Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the four-way handshake, allowing an attacker within radio range to replay frames from access points to clients. |
7Canonical DebianFreebsd+4 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Server+9 moreMay 13, 2026 Oct 17, 2017 N/A· v4 6.8 MEDIUM· v3 5.4 MEDIUM· v2 Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during the four-way handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames...Show more |
3Debian QemuXen3Debian Linux QemuXenMay 13, 2026 Oct 16, 2017 N/A· v4 8.8 HIGH· v3 4.6 MEDIUM· v2 Heap-based buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU allows guest OS administrators to cause a denial of service (instance crash) or possibly execute arbitrary code via a series of packets i...Show more |
2Apache Debian2Debian Linux SubversionMay 13, 2026 Oct 16, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 through 1.9.4 are vulnerable to a denial-of-service attack caused by exponential XML entity expansion. The attack can cause the t...Show more |
2Debian Sound Exchange Project2Debian Linux Sound ExchangeMay 13, 2026 Oct 16, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 There is a stack-based buffer overflow in the lsx_ms_adpcm_block_expand_i function of adpcm.c in Sound eXchange (SoX) 14.4.2. A Crafted input will lead to a denial of service attack during conversion of an audio file. |
2Debian Sound Exchange Project2Debian Linux Sound ExchangeMay 13, 2026 Oct 16, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 There is a reachable assertion abort in the function sox_append_comment() in formats.c in Sound eXchange (SoX) 14.4.2. A Crafted input will lead to a denial of service attack during conversion of an audio file. |
2Debian Sound Exchange Project2Debian Linux Sound ExchangeMay 13, 2026 Oct 16, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 There is a heap-based buffer overflow in the ImaExpandS function of ima_rw.c in Sound eXchange (SoX) 14.4.2. A Crafted input will lead to a denial of service attack during conversion of an audio file. |
4Apache CanonicalDebian+1 more4Debian Linux Jboss Enterprise Application PlatformSolr+1 moreMay 13, 2026 Oct 14, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-listener command to reach the RunExecutableListener class. Elasticsearch,...Show more |
3Canonical DebianLibsdl3Debian Linux Simple Directmedia LayerUbuntu LinuxMay 13, 2026 Oct 11, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An exploitable integer overflow vulnerability exists when creating a new RGB Surface in SDL 2.0.5. A specially crafted file can cause an integer overflow resulting in too little memory being allocated which can lead to a...Show more |
2Debian Libsdl2Debian Linux Sdl ImageMay 13, 2026 Oct 11, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An exploitable buffer overflow vulnerability exists in the XCF property handling functionality of SDL_image 2.0.1. A specially crafted xcf file can cause a stack-based buffer overflow resulting in potential code executio...Show more |
4Canonical DebianRedhat+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreMay 13, 2026 Oct 11, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. YAML deserialization of gem specifications can bypass class white lists. Specially crafted serialized objects c...Show more |
2Debian Graphicsmagick2Debian Linux GraphicsmagickMay 13, 2026 Oct 11, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 ReadOneJNGImage in coders/png.c in GraphicsMagick 1.3.26 has a use-after-free issue when the height or width is zero, related to ReadJNGImage. |
2Debian Wireshark2Debian Linux WiresharkMay 13, 2026 Oct 10, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark 2.4.0 to 2.4.1, 2.2.0 to 2.2.9, and 2.0.0 to 2.0.15, the DMP dissector could crash. This was addressed in epan/dissectors/packet-dmp.c by validating a string length. |
2Apache Debian2Debian Linux ZookeeperMay 13, 2026 Oct 10, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Two four letter word commands "wchp/wchc" are CPU intensive and could cause spike of CPU utilization on Apache ZooKeeper server if abused, which leads to the server unable to serve legitimate client requests. Apache ZooK...Show more |
2Debian X.org2Debian Linux X ServerMay 13, 2026 Oct 10, 2017 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 In X.Org Server (aka xserver and xorg-server) before 1.19.4, a local attacker authenticated to the X server could overflow a global buffer, causing crashes of the X server or potentially other problems by injecting large...Show more |
2Debian X.org2Debian Linux X ServerMay 13, 2026 Oct 10, 2017 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 In X.Org Server (aka xserver and xorg-server) before 1.19.4, an attacker authenticated to an X server with the X shared memory extension enabled can cause aborts of the X server or replace shared memory segments of other...Show more |
3Debian GolangRedhat7Debian Linux Developer ToolsEnterprise Linux Eus+4 moreMay 13, 2026 Oct 5, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Go before 1.8.4 and 1.9.x before 1.9.1 allows "go get" remote command execution. Using custom domains, it is possible to arrange things so that example.com/pkg1 points to a Subversion repository but example.com/pkg1/pkg2...Show more |
3Debian MercurialRedhat8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreMay 13, 2026 Oct 5, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Mercurial prior to 4.3 did not adequately sanitize hostnames passed to ssh, leading to possible shell-injection attacks. |
3Debian MercurialRedhat8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreMay 13, 2026 Oct 5, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Mercurial prior to version 4.3 is vulnerable to a missing symlink check that can malicious repositories to modify files outside the repository |