Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Libevent Project2Debian Linux LibeventMay 13, 2026 Mar 15, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The name_parse function in evdns.c in libevent before 2.1.6-beta allows remote attackers to have unspecified impact via vectors involving the label_len variable, which triggers an out-of-bounds stack read. |
2Debian Qemu2Debian Linux QemuMay 13, 2026 Mar 15, 2017 N/A· v4 6.0 MEDIUM· v3 4.9 MEDIUM· v2 Memory leak in hw/watchdog/wdt_i6300esb.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption and QEMU process crash) via a large number of device unp...Show more |
2Artifex Debian2Debian Linux MupdfMay 13, 2026 Mar 15, 2017 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Stack-based buffer overflow in jstest_main.c in mujstest in Artifex Software, Inc. MuPDF 1.10a allows remote attackers to have unspecified impact via a crafted image. |
4Debian OpensuseOpensuse Project+1 more4Debian Linux LeapLeap+1 moreMay 13, 2026 Mar 15, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in the nav_path function in lib/viewvc.py in ViewVC before 1.0.14 and 1.1.x before 1.1.26 allows remote attackers to inject arbitrary web script or HTML via the nav_data name. |
2Debian Wordpress2Debian Linux WordpressMay 13, 2026 Mar 12, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 In WordPress before 4.7.3 (wp-includes/embed.php), there is authenticated Cross-Site Scripting (XSS) in YouTube URL Embeds. |
2Debian Wordpress2Debian Linux WordpressMay 13, 2026 Mar 12, 2017 N/A· v4 4.9 MEDIUM· v3 5.5 MEDIUM· v2 In WordPress before 4.7.3 (wp-admin/plugins.php), unintended files can be deleted by administrators using the plugin deletion functionality. |
2Debian Wordpress2Debian Linux WordpressMay 13, 2026 Mar 12, 2017 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 In WordPress before 4.7.3 (wp-includes/pluggable.php), control characters can trick redirect URL validation. |
2Debian Wordpress2Debian Linux WordpressMay 13, 2026 Mar 12, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 In WordPress before 4.7.3, there is authenticated Cross-Site Scripting (XSS) via Media File Metadata. This is demonstrated by both (1) mishandling of the playlist shortcode in the wp_playlist_shortcode function in wp-inc...Show more |
2Debian Ytnef Project2Debian Linux YtnefMay 13, 2026 Mar 10, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in ytnef before 1.9.2. There is a potential heap-based buffer over-read on incoming Compressed RTF Streams, related to DecompressRTF() in libytnef. |
2Debian Ytnef Project2Debian Linux YtnefMay 13, 2026 Mar 10, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in ytnef before 1.9.2. There is a potential out-of-bounds access with fields of Size 0 in TNEFParse() in libytnef. |
2Debian Ytnef Project2Debian Linux YtnefMay 13, 2026 Mar 10, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in ytnef before 1.9.2. An invalid memory access (heap-based buffer over-read) can occur during handling of LONG data types, related to MAPIPrint() in libytnef. |
2Debian R Project2Debian Linux RMay 13, 2026 Mar 10, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An exploitable buffer overflow vulnerability exists in the LoadEncoding functionality of the R programming language version 3.3.0. A specially crafted R script can cause a buffer overflow resulting in a memory corruption...Show more |
3Debian FedoraprojectGnome3Debian Linux FedoraGdk PixbufMay 13, 2026 Mar 10, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The make_available_at_least function in io-tiff.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (infinite loop) via a large TIFF file. |
3Debian FedoraprojectGnome3Debian Linux FedoraGdk PixbufMay 13, 2026 Mar 10, 2017 N/A· v4 7.1 HIGH· v3 5.8 MEDIUM· v2 Integer underflow in the load_resources function in io-icns.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (out-of-bounds read and program crash) via a crafted image entry size in an ICO...Show more |
3Debian FedoraprojectGnome3Debian Linux FedoraGdk PixbufMay 13, 2026 Mar 10, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Integer overflow in io-ico.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (segmentation fault and application crash) via a crafted image entry offset in an ICO file, which triggers an out...Show more |
2Debian Linux2Debian Linux Linux KernelMay 13, 2026 Mar 7, 2017 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 Race condition in drivers/tty/n_hdlc.c in the Linux kernel through 4.10.1 allows local users to gain privileges or cause a denial of service (double free) by setting the HDLC line discipline. |
2Debian Libupnp Project2Debian Linux LibupnpMay 13, 2026 Mar 7, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Heap-based buffer overflow in the create_url_list function in gena/gena_device.c in Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary...Show more |
2Debian Libupnp Project2Debian Linux LibupnpMay 13, 2026 Mar 7, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attackers to write to arbitrary files in the webroot via a POST request without a registered handler. |
2Debian Libtiff2Debian Linux LibtiffMay 13, 2026 Mar 7, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The setByteArray function in tif_dir.c in libtiff 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tiff image. |
2Artifex Debian2Afpl Ghostscript Debian LinuxMay 13, 2026 Mar 7, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The getenv and filenameforall functions in Ghostscript 9.10 ignore the "-dSAFER" argument, which allows remote attackers to read data via a crafted postscript file. |