Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian MercurialRedhat8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreMay 13, 2026 Jun 6, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 In Mercurial before 4.1.3, "hg serve --stdio" allows remote authenticated users to launch the Python debugger, and consequently execute arbitrary code, by using --debugger as a repository name. |
3Debian RedhatSamba8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreMay 13, 2026 Jun 6, 2017 N/A· v4 6.5 MEDIUM· v3 6.8 MEDIUM· v2 smbd in Samba before 4.4.10 and 4.5.x before 4.5.6 has a denial of service vulnerability (fd_open_atomic infinite loop with high CPU usage and memory consumption) due to wrongly handling dangling symlinks. |
2Debian Google2Chrome Debian LinuxMay 13, 2026 Jun 6, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Double-free vulnerability in libavformat/mov.c in FFMPEG in Google Chrome 41.0.2251.0 allows remote attackers to cause a denial of service (memory corruption and crash) via a crafted .m4a file. |
2Debian Freedesktop2Debian Linux PopplerMay 13, 2026 Jun 2, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In Poppler 0.54.0, a memory leak vulnerability was found in the function Object::initArray in Object.cc, which allows attackers to cause a denial of service via a crafted file. |
2Debian Freedesktop2Debian Linux PopplerMay 13, 2026 Jun 2, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In Poppler 0.54.0, a memory leak vulnerability was found in the function gmalloc in gmem.cc, which allows attackers to cause a denial of service via a crafted file. |
3Canonical DebianLibtiff3Debian Linux LibtiffUbuntu LinuxMay 13, 2026 Jun 2, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In LibTIFF 4.0.7, a memory leak vulnerability was found in the function OJPEGReadHeaderInfoSecTablesQTable in tif_ojpeg.c, which allows attackers to cause a denial of service via a crafted file. |
3Canonical DebianLibtiff3Debian Linux LibtiffUbuntu LinuxMay 13, 2026 Jun 2, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In LibTIFF 4.0.7, a memory leak vulnerability was found in the function TIFFReadDirEntryLong8Array in tif_dirread.c, which allows attackers to cause a denial of service via a crafted file. |
2Debian Wireshark2Debian Linux WiresharkMay 13, 2026 Jun 2, 2017 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the DICOM dissector has an infinite loop. This was addressed in epan/dissectors/packet-dcm.c by validating a length value. |
2Debian Wireshark2Debian Linux WiresharkMay 13, 2026 Jun 2, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the Bluetooth L2CAP dissector could divide by zero. This was addressed in epan/dissectors/packet-btl2cap.c by validating an interval value. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraGit Shell+2 moreMay 13, 2026 Jun 1, 2017 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 git-shell in git before 2.4.12, 2.5.x before 2.5.6, 2.6.x before 2.6.7, 2.7.x before 2.7.5, 2.8.x before 2.8.5, 2.9.x before 2.9.4, 2.10.x before 2.10.3, 2.11.x before 2.11.2, and 2.12.x before 2.12.3 might allow remote...Show more |
3Canonical DebianFile3\ Debian LinuxUbuntu LinuxMay 13, 2026 Jun 1, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Race condition in the rmtree and remove_tree functions in the File-Path module before 2.13 for Perl allows attackers to set the mode on arbitrary files via vectors involving directory-permission loosening logic. |
2Debian Samba2Debian Linux SambaApr 21, 2026 May 30, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share, and then cause the server to...Show more |
5Debian McafeeOpenldap+2 more10Blockchain Platform Debian LinuxEnterprise Linux Desktop+7 moreMay 13, 2026 May 29, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 servers/slapd/back-mdb/search.c in OpenLDAP through 2.4.44 is prone to a double free vulnerability. A user with access to search the directory can crash slapd by issuing a search including the Paged Results control with...Show more |
2Debian Vmware2Debian Linux Spring FrameworkMay 13, 2026 May 25, 2017 N/A· v4 9.6 CRITICAL· v3 9.3 HIGH· v2 Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to a Reflected File Download (RFD) attack. The attack involves a malicious user cra...Show more |
2Artifex Debian2Debian Linux Jbig2decMay 13, 2026 May 24, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 libjbig2dec.a in Artifex jbig2dec 0.13, as used in MuPDF and Ghostscript, has a NULL pointer dereference in the jbig2_huffman_get function in jbig2_huffman.c. For example, the jbig2dec utility will crash (segmentation fa...Show more |
2Debian Kodi2Debian Linux KodiMay 13, 2026 May 23, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Directory Traversal in Zip Extraction built-in function in Kodi 17.1 and earlier allows arbitrary file write on disk via a Zip file as subtitles. |
2Debian Videolan2Debian Linux Vlc Media PlayerMay 13, 2026 May 23, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Heap out-of-bound read in ParseJSS in VideoLAN VLC due to missing check of string length allows attackers to read heap uninitialized data via a crafted subtitles file. |
3Debian OpenvswitchRedhat5Debian Linux OpenstackOpenvswitch+2 moreMay 13, 2026 May 23, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Open vSwitch (OvS) 2.7.0, while parsing an OFPT_QUEUE_GET_CONFIG_REPLY type OFP 1.0 message, there is a buffer over-read that is caused by an unsigned integer underflow in the function `ofputil_pull_queue_get_config_r...Show more |
3Debian QemuRedhat3Debian Linux OpenstackQemuMay 13, 2026 May 23, 2017 N/A· v4 6.5 MEDIUM· v3 4.9 MEDIUM· v2 Memory leak in the keyboard input event handlers support in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption) by rapidly generating large keyboard eve...Show more |
3Debian QemuRedhat3Debian Linux OpenstackQemuMay 13, 2026 May 23, 2017 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Memory leak in the audio/audio.c in QEMU (aka Quick Emulator) allows remote attackers to cause a denial of service (memory consumption) by repeatedly starting and stopping audio capture. |