Debian
debian
10,145 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,145)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Debian FedoraprojectKde+1 more4Debian Linux FedoraKmail+1 moreMay 6, 2026 Dec 23, 2016 N/A· v4 7.3 HIGH· v3 7.5 HIGH· v2 Through a malicious URL that contained a quote character it was possible to inject HTML code in KMail's plaintext viewer. Due to the parser used on the URL it was not possible to include the equal sign (=) or a space int...Show more |
2Bottlepy Debian2Bottle Debian LinuxMay 6, 2026 Dec 16, 2016 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 redirect() in bottle.py in bottle 0.12.10 doesn't filter a "\r\n" sequence, which leads to a CRLF attack, as demonstrated by a redirect("233\r\nSet-Cookie: name=salt") call. |
2Debian Neutrinolabs2Debian Linux XrdpMay 6, 2026 Dec 16, 2016 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 An issue was discovered in xrdp before 0.9.1. When successfully logging in using RDP into an xrdp session, the file ~/.vnc/sesman_${username}_passwd is created. Its content is the equivalent of the user's cleartext passw...Show more |
3Canonical DebianGnupg4Debian Linux GnupgLibgcrypt+1 moreMay 6, 2026 Dec 13, 2016 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The mixing functions in the random number generator in Libgcrypt before 1.5.6, 1.6.x before 1.6.6, and 1.7.x before 1.7.3 and GnuPG before 1.4.21 make it easier for attackers to obtain the values of 160 bits by leveragin...Show more |
4Debian MariadbOracle+1 more4Debian Linux MariadbMysql+1 moreMay 6, 2026 Dec 13, 2016 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The C software implementation of AES Encryption and Decryption in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover AES keys by leveraging cache-bank timing differences. |
3Bdwgc Project DebianOpensuse4Bdwgc Debian LinuxLeap+1 moreMay 6, 2026 Dec 12, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Integer overflow vulnerability in bdwgc before 2016-09-27 allows attackers to cause client of bdwgc denial of service (heap buffer overflow crash) and possibly execute arbitrary code via huge allocation. |
The pvscsi_ring_pop_req_descr function in hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by leveraging failure t...Show more |
3Debian OpensuseQemu3Debian Linux LeapQemuMay 6, 2026 Dec 10, 2016 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 The vmsvga_fifo_run function in hw/display/vmware_vga.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) via vectors related to c...Show more |
The pvscsi_convert_sglist function in hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by leveraging an incorrect...Show more |
hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (out-of-bounds access or infinite loop, and QEMU process crash) via a crafted page count for descriptor...Show more |
Directory traversal vulnerability in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to access host files outside the export path via a .. (dot dot) in an unspecified string. |
3Debian QemuRedhat4Debian Linux OpenstackQemu+1 moreMay 6, 2026 Dec 10, 2016 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 Integer overflow in the net_tx_pkt_init function in hw/net/net_tx_pkt.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (QEMU process crash) via the maximum fragmentation co...Show more |
The vmxnet3_complete_packet function in hw/net/vmxnet3.c in QEMU (aka Quick Emulator) allows local guest OS administrators to obtain sensitive host memory information by leveraging failure to initialize the txcq_descr ob...Show more |
3Debian QemuRedhat3Debian Linux QemuVirtualizationMay 6, 2026 Dec 10, 2016 N/A· v4 6.0 MEDIUM· v3 2.1 LOW· v2 The vmxnet_tx_pkt_parse_headers function in hw/net/vmxnet_tx_pkt.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (buffer over-read) by leveraging failure to check IP heade...Show more |
The net_tx_pkt_do_sw_fragmentation function in hw/net/net_tx_pkt.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via a zero length f...Show more |
Use-after-free vulnerability in the vmxnet3_io_bar0_write function in hw/net/vmxnet3.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (QEMU instance crash) by leveraging fa...Show more |
2Debian Postgresql2Debian Linux PostgresqlMay 6, 2026 Dec 9, 2016 N/A· v4 7.1 HIGH· v3 4.6 MEDIUM· v2 PostgreSQL before 9.1.23, 9.2.x before 9.2.18, 9.3.x before 9.3.14, 9.4.x before 9.4.9, and 9.5.x before 9.5.4 might allow remote authenticated users with the CREATEDB or CREATEROLE role to gain superuser privileges via...Show more |
2Debian Postgresql2Debian Linux PostgresqlMay 6, 2026 Dec 9, 2016 N/A· v4 8.3 HIGH· v3 6.5 MEDIUM· v2 PostgreSQL before 9.1.23, 9.2.x before 9.2.18, 9.3.x before 9.3.14, 9.4.x before 9.4.9, and 9.5.x before 9.5.4 allow remote authenticated users to cause a denial of service (NULL pointer dereference and server crash), ob...Show more |
3Debian OpensuseQemu3Debian Linux LeapQemuMay 6, 2026 Dec 9, 2016 N/A· v4 6.0 MEDIUM· v3 2.1 LOW· v2 Memory leak in the v9fs_write function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption) by leveraging failure to free an IO vector. |
3Debian OpensuseQemu3Debian Linux LeapQemuMay 6, 2026 Dec 9, 2016 N/A· v4 6.0 MEDIUM· v3 2.1 LOW· v2 Memory leak in the v9fs_link function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption) via vectors involving a reference to the source fi...Show more |