Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Simplesamlphp2Debian Linux SimplesamlphpMay 13, 2026 Sep 1, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The (1) Htpasswd authentication source in the authcrypt module and (2) SimpleSAML_Session class in SimpleSAMLphp 1.14.11 and earlier allow remote attackers to conduct timing side-channel attacks by leveraging use of the...Show more |
2Debian Libzip2Debian Linux LibzipMay 13, 2026 Sep 1, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The _zip_read_eocd64 function in zip_open.c in libzip before 1.3.0 mishandles EOCD records, which allows remote attackers to cause a denial of service (memory allocation failure in _zip_cdir_grow in zip_dirent.c) via a c...Show more |
Use-after-free vulnerability in the sofree function in slirp/socket.c in QEMU (aka Quick Emulator) allows attackers to cause a denial of service (QEMU instance crash) by leveraging failure to properly clear ifq_so from p...Show more |
QEMU (aka Quick Emulator), when built with the VGA display emulator support, allows local guest OS privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) via vectors involving display u...Show more |
2Debian Simplesamlphp2Debian Linux SimplesamlphpMay 13, 2026 Sep 1, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The multiauth module in SimpleSAMLphp 1.14.13 and earlier allows remote attackers to bypass authentication context restrictions and use an authentication source defined in config/authsources.php via vectors related to im...Show more |
4Canonical DebianRedhat+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreMay 13, 2026 Aug 31, 2017 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 RubyGems version 2.6.12 and earlier is vulnerable to a DNS hijacking vulnerability that allows a MITM attacker to force the RubyGems client to download and install gems from a server that the attacker controls. |
4Canonical DebianRedhat+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreMay 13, 2026 Aug 31, 2017 N/A· v4 7.5 HIGH· v3 6.4 MEDIUM· v2 RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potentially overwrite any file on the filesystem. |
3Debian RedhatRubygems8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreMay 13, 2026 Aug 31, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications to cause a denial of service attack against RubyGems clients who have issued a `query` command. |
3Debian RedhatRubygems8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreMay 13, 2026 Aug 31, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters. Printing the gem specification would execute terminal escape sequences. |
2Debian Kohanaframework2Debian Linux KohanaMay 13, 2026 Aug 31, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in the Security component of Kohana before 3.3.6 allows remote attackers to inject arbitrary web script or HTML by bypassing the strip_image_tags protection mechanism in system/cl...Show more |
4Canonical DebianRedhat+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreMay 13, 2026 Aug 31, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Ruby through 2.2.7, 2.3.x through 2.3.4, and 2.4.x through 2.4.1 can expose arbitrary memory during a JSON.generate call. The issues lies in using strdup in ext/json/ext/generator/generator.c, which will stop after encou...Show more |
2Debian Gnu2Debian Linux Libidn2May 13, 2026 Aug 31, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Integer overflow in the decode_digit function in puny_decode.c in Libidn2 before 2.0.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact. |
2Debian Uclouvain2Debian Linux OpenjpegMay 13, 2026 Aug 30, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A stack-based buffer overflow was discovered in the pgxtoimage function in bin/jp2/convert.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly remo...Show more |
2Debian Uclouvain2Debian Linux OpenjpegMay 13, 2026 Aug 30, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An invalid write access was discovered in bin/jp2/convert.c in OpenJPEG 2.2.0, triggering a crash in the tgatoimage function. The vulnerability may lead to remote denial of service or possibly unspecified other impact. |
2Debian Uclouvain2Debian Linux OpenjpegMay 13, 2026 Aug 30, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A heap-based buffer overflow was discovered in the opj_t2_encode_packet function in lib/openjp2/t2.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possi...Show more |
2Debian Graphicsmagick2Debian Linux GraphicsmagickMay 13, 2026 Aug 30, 2017 N/A· v4 6.5 MEDIUM· v3 7.1 HIGH· v2 GraphicsMagick 1.3.26 has a denial of service issue in ReadXBMImage() in a coders/xbm.c "Read hex image data" version==10 case that results in the reader not returning; it would cause large amounts of CPU and memory cons...Show more |
2Debian Graphicsmagick2Debian Linux GraphicsmagickMay 13, 2026 Aug 30, 2017 N/A· v4 6.5 MEDIUM· v3 7.1 HIGH· v2 GraphicsMagick 1.3.26 has a denial of service issue in ReadXBMImage() in a coders/xbm.c "Read hex image data" version!=10 case that results in the reader not returning; it would cause large amounts of CPU and memory cons...Show more |
2Debian Graphicsmagick2Debian Linux GraphicsmagickMay 13, 2026 Aug 30, 2017 N/A· v4 6.5 MEDIUM· v3 7.1 HIGH· v2 GraphicsMagick 1.3.26 has a denial of service issue in ReadJNXImage() in coders/jnx.c whereby large amounts of CPU and memory resources may be consumed although the file itself does not support the requests. |
3Canonical DebianImagemagick3Debian Linux ImagemagickUbuntu LinuxMay 13, 2026 Aug 30, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The WriteTHUMBNAILImage function in coders/thumbnail.c in ImageMagick through 7.0.6-10 allows an attacker to cause a denial of service (buffer over-read) by sending a crafted JPEG file. |
3Canonical DebianImagemagick3Debian Linux ImagemagickUbuntu LinuxMay 13, 2026 Aug 30, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Null Pointer Dereference in the IdentifyImage function in MagickCore/identify.c in ImageMagick through 7.0.6-10 allows an attacker to perform denial of service by sending a crafted image file. |