Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Jython Project2Debian Linux JythonMay 13, 2026 Jul 6, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Jython before 2.7.1rc1 allows attackers to execute arbitrary code via a crafted serialized PyFunction object. |
2Debian Puppet2Debian Linux PuppetMay 13, 2026 Jul 5, 2017 N/A· v4 8.2 HIGH· v3 6.0 MEDIUM· v2 Versions of Puppet prior to 4.10.1 will deserialize data off the wire (from the agent to the server, in this case) with a attacker-specified format. This could be used to force YAML deserialization in an unsafe manner, w...Show more |
2Debian Linux2Debian Linux Linux KernelMay 13, 2026 Jul 4, 2017 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Memory leak in the virtio_gpu_object_create function in drivers/gpu/drm/virtio/virtgpu_object.c in the Linux kernel through 4.11.8 allows attackers to cause a denial of service (memory consumption) by triggering object-i...Show more |
2Debian Xml Libxml Project2Debian Linux Xml LibxmlMay 13, 2026 Jun 29, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Use-after-free in the XML-LibXML module through 2.0129 for Perl allows remote attackers to execute arbitrary code by controlling the arguments to a replaceChild call. |
2Debian Ffmpeg2Debian Linux FfmpegMay 13, 2026 Jun 28, 2017 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 libavcodec/webp.c in FFmpeg before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.3.1 does not ensure that pix_fmt is set, which allows remote attackers to cause a denial of servic...Show more |
2Debian Ffmpeg2Debian Linux FfmpegMay 13, 2026 Jun 28, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 FFmpeg before 2.8.12, 3.0.x and 3.1.x before 3.1.9, 3.2.x before 3.2.6, and 3.3.x before 3.3.2 does not properly restrict HTTP Live Streaming filename extensions and demuxer names, which allows attackers to read arbitrar...Show more |
2Debian Ffmpeg2Debian Linux FfmpegMay 13, 2026 Jun 28, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Heap-based buffer overflow in the decode_dds1 function in libavcodec/dfa.c in FFmpeg before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.3.1 allows remote attackers to cause a de...Show more |
2Debian Libming2Debian Linux LibmingMay 13, 2026 Jun 28, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 util/outputtxt.c in libming 0.4.8 mishandles memory allocation. A crafted input will lead to a remote denial of service (NULL pointer dereference) attack. |
2Debian Libming2Debian Linux LibmingMay 13, 2026 Jun 28, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The readEncUInt30 function in util/read.c in libming 0.4.8 mishandles memory allocation. A crafted input will lead to a remote denial of service (NULL pointer dereference) attack against parser.c. |
3Canonical DebianLibtiff3Debian Linux LibtiffUbuntu LinuxMay 13, 2026 Jun 26, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In LibTIFF 4.0.8, there is a memory leak in tif_jbig.c. A crafted TIFF document can lead to a memory leak resulting in a remote denial of service attack. |
3Canonical DebianLibtiff3Debian Linux LibtiffUbuntu LinuxMay 13, 2026 Jun 26, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 In LibTIFF 4.0.8, there is a heap-based buffer overflow in the t2p_write_pdf function in tools/tiff2pdf.c. This heap overflow could lead to different damages. For example, a crafted TIFF document can lead to an out-of-bo...Show more |
2Debian Long Range Zip Project2Debian Linux Long Range ZipMay 13, 2026 Jun 26, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In lrzip 0.631, a stack buffer overflow was found in the function get_fileinfo in lrzip.c:1074, which allows attackers to cause a denial of service via a crafted file. |
2Debian Long Range Zip Project2Debian Linux Long Range ZipMay 13, 2026 Jun 26, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In lrzip 0.631, a stack buffer overflow was found in the function get_fileinfo in lrzip.c:979, which allows attackers to cause a denial of service via a crafted file. |
2Debian Eclipse2Debian Linux MosquittoMay 13, 2026 Jun 25, 2017 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 In Mosquitto through 1.4.12, mosquitto.db (aka the persistence file) is world readable, which allows local users to obtain sensitive MQTT topic information. |
2Debian Freedesktop2Debian Linux PopplerMay 13, 2026 Jun 25, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The function GfxImageColorMap::getGray in GfxState.cc in Poppler 0.54.0 allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted PDF document, related to mis...Show more |
3Debian FreedesktopRedhat8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreMay 13, 2026 Jun 22, 2017 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Integer overflow leading to Heap buffer overflow in JBIG2Stream.cc in pdftocairo in Poppler before 0.56 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact v...Show more |
3Debian FreedesktopRedhat8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreMay 13, 2026 Jun 22, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Stack buffer overflow in GfxState.cc in pdftocairo in Poppler before 0.56 allows remote attackers to cause a denial of service (application crash) via a crafted PDF document. |
2Debian Flatpak2Debian Linux FlatpakMay 13, 2026 Jun 21, 2017 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 In Flatpak before 0.8.7, a third-party app repository could include malicious apps that contain files with inappropriate permissions, for example setuid or world-writable. The files are deployed with those permissions, w...Show more |
2Debian Wireshark2Debian Linux WiresharkMay 13, 2026 Jun 21, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark 2.2.7, PROFINET IO data with a high recursion depth allows remote attackers to cause a denial of service (stack exhaustion) in the dissect_IODWriteReq function in plugins/profinet/packet-dcerpc-pn-io.c. |
6Apache AppleDebian+3 more13Clustered Data Ontap Debian LinuxEnterprise Linux Desktop+10 moreMay 13, 2026 Jun 20, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token() to search past the end of its input string. By maliciously crafting a sequence...Show more |