Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Wireshark2Debian Linux WiresharkMay 13, 2026 Aug 30, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark 2.4.0, 2.2.0 to 2.2.8, and 2.0.0 to 2.0.14, the IrCOMM dissector has a buffer over-read and application crash. This was addressed in plugins/irda/packet-ircomm.c by adding length validation. |
2Debian Sleuthkit2Debian Linux The Sleuth KitMay 13, 2026 Aug 29, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In The Sleuth Kit (TSK) 4.4.2, fls hangs on a corrupt exfat image in tsk_img_read() in tsk/img/img_io.c in libtskimg.a. |
2Debian Sleuthkit2Debian Linux The Sleuth KitMay 13, 2026 Aug 29, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In The Sleuth Kit (TSK) 4.4.2, opening a crafted disk image triggers infinite recursion in dos_load_ext_table() in tsk/vs/dos.c in libtskvs.a, as demonstrated by mmls. |
2Debian Sleuthkit2Debian Linux The Sleuth KitMay 13, 2026 Aug 29, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In The Sleuth Kit (TSK) 4.4.2, opening a crafted ISO 9660 image triggers an out-of-bounds read in iso9660_proc_dir() in tsk/fs/iso9660_dent.c in libtskfs.a, as demonstrated by fls. |
2Debian Gnupg2Debian Linux LibgcryptMay 13, 2026 Aug 29, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Libgcrypt before 1.8.1 does not properly consider Curve25519 side-channel attacks, which makes it easier for attackers to discover a secret key, related to cipher/ecc.c and mpi/ec.c. |
2Debian Intel2Connman Debian LinuxMay 13, 2026 Aug 29, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Stack-based buffer overflow in "dnsproxy.c" in connman 1.34 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted response query string passed to the "name" vari...Show more |
3Debian FedoraprojectJasper Project3Debian Linux FedoraJasperMay 13, 2026 Aug 29, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 There are lots of memory leaks in JasPer 2.0.12, triggered in the function jas_strdup() in base/jas_string.c, that will lead to a remote denial of service attack. |
2Debian Graphicsmagick2Debian Linux GraphicsmagickMay 13, 2026 Aug 29, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 There is an invalid free in the MagickFree function in magick/memory.c in GraphicsMagick 1.3.26 that will lead to a remote denial of service attack. |
2Debian Openssl2Debian Linux OpensslMay 13, 2026 Aug 28, 2017 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 While parsing an IPAddressFamily extension in an X.509 certificate, it is possible to do a one-byte overread. This would result in an incorrect text display of the certificate. This bug has been present since 2006 and is...Show more |
3Canonical DebianImagemagick3Debian Linux ImagemagickUbuntu LinuxMay 13, 2026 Aug 28, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Use-after-free vulnerability in the DestroyImage function in image.c in ImageMagick before 7.0.6-6 allows remote attackers to cause a denial of service via a crafted file. |
Insecure use of temporary files in xbindkeys-config 0.1.3-2 allows remote attackers to execute arbitrary code. |
3Debian FedoraprojectNtp3Debian Linux FedoraNtpMay 13, 2026 Aug 24, 2017 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 ntpd in ntp before 4.2.8p3 with remote configuration enabled allows remote authenticated users with knowledge of the configuration password and access to a computer entrusted to perform remote configuration to cause a de...Show more |
2Debian Pyjwt Project2Debian Linux PyjwtMay 13, 2026 Aug 24, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In PyJWT 1.5.0 and below the `invalid_strings` check in `HMACAlgorithm.prepare_key` does not account for all PEM encoded public keys. Specifically, the PKCS1 PEM encoded format would be allowed because it is prefaced wit...Show more |
3Canonical DebianGnu3Cvs Debian LinuxUbuntu LinuxMay 13, 2026 Aug 24, 2017 N/A· v4 7.5 HIGH· v3 5.1 MEDIUM· v2 CVS 1.12.x, when configured to use SSH for remote repositories, might allow remote attackers to execute arbitrary code via a repository URL with a crafted hostname, as demonstrated by "-oProxyCommand=id;localhost:/bar." |
3Citrix DebianXen3Debian Linux XenXenserverMay 13, 2026 Aug 24, 2017 N/A· v4 8.8 HIGH· v3 7.2 HIGH· v2 arch/x86/mm.c in Xen allows local PV guest OS users to gain host OS privileges via vectors related to map_grant_ref. |
3Citrix DebianXen3Debian Linux XenXenserverMay 13, 2026 Aug 24, 2017 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 Race condition in the grant table code in Xen 4.6.x through 4.9.x allows local guest OS administrators to cause a denial of service (free list corruption and host crash) or gain privileges on the host via vectors involvi...Show more |
3Citrix DebianXen3Debian Linux XenXenserverMay 13, 2026 Aug 24, 2017 N/A· v4 8.8 HIGH· v3 4.6 MEDIUM· v2 Xen allows local OS guest users to cause a denial of service (crash) or possibly obtain sensitive information or gain privileges via vectors involving transitive grants. |
QEMU (aka Quick Emulator), when built with the IDE disk and CD/DVD-ROM Emulator support, allows local guest OS privileged users to cause a denial of service (NULL pointer dereference and QEMU process crash) by flushing a...Show more |
2Debian Newsbeuter2Debian Linux NewsbeuterMay 13, 2026 Aug 23, 2017 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Improper Neutralization of Special Elements used in an OS Command in bookmarking function of Newsbeuter versions 0.7 through 2.9 allows remote attackers to perform user-assisted code execution by crafting an RSS item tha...Show more |
4Debian FedoraprojectRedhat+1 more4Cloudforms Debian LinuxFedora+1 moreMay 13, 2026 Aug 23, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated users to execute arbitrary commands via a crafted XML-RPC request, related to nest...Show more |