Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Integer overflow in the load_multiboot function in hw/i386/multiboot.c in QEMU (aka Quick Emulator) allows local guest OS users to execute arbitrary code on the host via crafted multiboot header address values, which tri...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraLibgd+1 moreMay 13, 2026 Sep 7, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Double free vulnerability in the gdImagePngPtr function in libgd2 before 2.2.5 allows remote attackers to cause a denial of service via vectors related to a palette with no colors. |
3Canonical DebianImagemagick3Debian Linux ImagemagickUbuntu LinuxMay 13, 2026 Sep 7, 2017 N/A· v4 6.5 MEDIUM· v3 7.1 HIGH· v2 In coders/xbm.c in ImageMagick 7.0.6-1 Q16, a DoS in ReadXBMImage() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted XBM file, which claims large rows and columns fields in the h...Show more |
3Canonical DebianImagemagick3Debian Linux ImagemagickUbuntu LinuxMay 13, 2026 Sep 7, 2017 N/A· v4 6.5 MEDIUM· v3 7.1 HIGH· v2 In coders/psd.c in ImageMagick 7.0.7-0 Q16, a DoS in ReadPSDLayersInternal() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted PSD file, which claims a large "length" field in the...Show more |
3Canonical DebianImagemagick3Debian Linux ImagemagickUbuntu LinuxMay 13, 2026 Sep 7, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In the function ReadTXTImage() in coders/txt.c in ImageMagick 7.0.6-10, an integer overflow might occur for the addition operation "GetQuantumRange(depth)+1" when "depth" is large, producing a smaller value than expected...Show more |
3Canonical DebianImagemagick3Debian Linux ImagemagickUbuntu LinuxMay 13, 2026 Sep 7, 2017 N/A· v4 6.5 MEDIUM· v3 7.1 HIGH· v2 In coders/ps.c in ImageMagick 7.0.7-0 Q16, a DoS in ReadPSImage() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted PSD file, which claims a large "extent" field in the header but...Show more |
2Debian Ffmpeg2Debian Linux FfmpegMay 13, 2026 Sep 7, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 In the mxf_read_primer_pack function in libavformat/mxfdec.c in FFmpeg 3.3.3 -> 2.4, an integer signedness error might occur when a crafted file, which claims a large "item_num" field such as 0xffffffff, is provided. As...Show more |
3Canonical DebianLibarchive3Debian Linux LibarchiveUbuntu LinuxMay 13, 2026 Sep 6, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 libarchive 3.3.2 allows remote attackers to cause a denial of service (xml_data heap-based buffer over-read and application crash) via a crafted xar archive, related to the mishandling of empty strings in the atol8 funct...Show more |
2Debian Gnome2Debian Linux Gdk PixbufMay 13, 2026 Sep 5, 2017 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 An exploitable integer overflow vulnerability exists in the tiff_image_parse functionality of Gdk-Pixbuf 2.36.6 when compiled with Clang. A specially crafted tiff file can cause a heap-overflow resulting in remote code e...Show more |
2Debian Gnome2Debian Linux Gdk PixbufMay 13, 2026 Sep 5, 2017 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 An exploitable heap overflow vulnerability exists in the gdk_pixbuf__jpeg_image_load_increment functionality of Gdk-Pixbuf 2.36.6. A specially crafted jpeg file can cause a heap overflow resulting in remote code executio...Show more |
2Debian Uclouvain2Debian Linux OpenjpegMay 13, 2026 Sep 5, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A mishandled zero case was discovered in opj_j2k_set_cinema_parameters in lib/openjp2/j2k.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service (heap-based buffe...Show more |
2Debian Uclouvain2Debian Linux OpenjpegMay 13, 2026 Sep 5, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An off-by-one error was discovered in opj_tcd_code_block_enc_allocate_data in lib/openjp2/tcd.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service (heap-based b...Show more |
3Debian GnomeRedhat8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreMay 13, 2026 Sep 5, 2017 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to execute arbitrary commands via a .cbt file that is a TAR archive containing a filename beginning with...Show more |
2Debian Opencv2Debian Linux OpencvMay 13, 2026 Sep 4, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 OpenCV (Open Source Computer Vision Library) 3.3 has an out-of-bounds write error in the function FillColorRow1 in utils.cpp when reading an image file by using cv::imread. NOTE: this vulnerability exists because of an i...Show more |
2Debian Jasper Project2Debian Linux JasperMay 13, 2026 Sep 4, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20, 1.900.21, 1.900.22, 1.900.23, 1.900.24, 1.900.25, 1.900.26, 1.900.27, 1.900.28, 1.900...Show more |
2Debian Rarlab2Debian Linux UnrarMay 13, 2026 Sep 3, 2017 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a stack-based buffer over-read in unrarlib.c, related to ExtrFile and stricomp. |
2Debian Rarlab2Debian Linux UnrarMay 13, 2026 Sep 3, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The DecodeNumber function in unrarlib.c in unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a NULL pointer dereference flaw triggered by a crafted RAR archive. NOTE: this may be the same as one of the several test...Show more |
2Debian Rarlab2Debian Linux UnrarMay 13, 2026 Sep 3, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a directory traversal vulnerability for RAR v2 archives: pathnames of the form ../[filename] are unpacked into the upper directory. |
2Debian Simplesamlphp2Debian Linux Infocard ModuleMay 13, 2026 Sep 1, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The InfoCard module 1.0 for SimpleSAMLphp allows attackers to spoof XML messages by leveraging an incorrect check of return values in signature validation utilities. |
2Debian Simplesamlphp2Debian Linux SimplesamlphpMay 13, 2026 Sep 1, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SimpleSAMLphp 1.7.0 through 1.14.10 might allow attackers to obtain sensitive information, gain unauthorized access, or have unspecified other impacts by leveraging incorrect persistent NameID generation when an Identity...Show more |