Debian
debian
10,145 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,145)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Debian FedoraprojectRedhat+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+6 moreMay 6, 2026 Sep 21, 2016 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Integer overflow in the opj_pi_create_decode function in pi.c in OpenJPEG allows remote attackers to execute arbitrary code via a crafted JP2 file, which triggers an out-of-bounds read or write. |
2Charybdis Project Debian2Charybdis Debian LinuxMay 6, 2026 Sep 21, 2016 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 The m_authenticate function in modules/m_sasl.c in Charybdis before 3.5.3 allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a crafted AUTHENTICATE parameter. |
2Apache Debian2Debian Linux JackrabbitMay 6, 2026 Sep 21, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Cross-site request forgery (CSRF) vulnerability in the CSRF content-type check in Jackrabbit-Webdav in Apache Jackrabbit 2.4.x before 2.4.6, 2.6.x before 2.6.6, 2.8.x before 2.8.3, 2.10.x before 2.10.4, 2.12.x before 2.1...Show more |
2Debian Westes2Debian Linux FlexMay 6, 2026 Sep 21, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Heap-based buffer overflow in the yy_get_next_buffer function in Flex before 2.6.1 might allow context-dependent attackers to cause a denial of service or possibly execute arbitrary code via vectors involving num_to_read...Show more |
2Debian Uclouvain2Debian Linux OpenjpegMay 6, 2026 Sep 21, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Use-after-free vulnerability in the opj_j2k_write_mco function in j2k.c in OpenJPEG before 2.1.1 allows remote attackers to have unspecified impact via unknown vectors. |
5Debian MariadbOracle+2 more12Debian Linux Enterprise LinuxEnterprise Linux Desktop+9 moreMay 6, 2026 Sep 20, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5.51-38.1, 5.6.x before 5.6.32-78.0, and 5...Show more |
4Canonical DebianLibarchive+1 more6Debian Linux LibarchiveLinux Enterprise Desktop+3 moreMay 6, 2026 Sep 20, 2016 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The compress_bidder_init function in archive_read_support_filter_compress.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted tar file, which triggers an invalid left s...Show more |
4Canonical DebianLibarchive+1 more6Debian Linux LibarchiveLinux Enterprise Desktop+3 moreMay 6, 2026 Sep 20, 2016 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Multiple integer overflows in the (1) get_time_t_max and (2) get_time_t_min functions in archive_read_support_format_mtree.c in libarchive before 3.2.0 allow remote attackers to have unspecified impact via a crafted mtre...Show more |
3Canonical DebianLibarchive3Debian Linux LibarchiveUbuntu LinuxMay 6, 2026 Sep 20, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 bsdtar in libarchive before 3.2.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an invalid character in the name of a cab file. |
3Canonical DebianLibarchive3Debian Linux LibarchiveUbuntu LinuxMay 6, 2026 Sep 20, 2016 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 bsdtar in libarchive before 3.2.0 returns a success code without filling the entry when the header is a "split file in multivolume RAR," which allows remote attackers to cause a denial of service (NULL pointer dereferenc...Show more |
2Debian Drupal2Debian Linux DrupalMay 6, 2026 Sep 9, 2016 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The User module in Drupal 7.x before 7.44 allows remote authenticated users to gain privileges via vectors involving contributed or custom code that triggers a rebuild of the user profile form. |
2Debian Wireshark2Debian Linux WiresharkMay 6, 2026 Sep 9, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 epan/dissectors/packet-ipmi-trace.c in the IPMI trace dissector in Wireshark 2.x before 2.0.6 does not properly consider whether a string is constant, which allows remote attackers to cause a denial of service (use-after...Show more |
2Debian Wireshark2Debian Linux WiresharkMay 6, 2026 Sep 9, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Stack-based buffer overflow in epan/dissectors/packet-catapult-dct2000.c in the Catapult DCT2000 dissector in Wireshark 2.x before 2.0.6 allows remote attackers to cause a denial of service (application crash) via a craf...Show more |
2Debian Wireshark2Debian Linux WiresharkMay 6, 2026 Sep 9, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 epan/dissectors/packet-umts_fp.c in the UMTS FP dissector in Wireshark 2.x before 2.0.6 does not ensure that memory is allocated for certain data structures, which allows remote attackers to cause a denial of service (in...Show more |
2Debian Wireshark2Debian Linux WiresharkMay 6, 2026 Sep 9, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 epan/dissectors/packet-catapult-dct2000.c in the Catapult DCT2000 dissector in Wireshark 2.x before 2.0.6 does not restrict the number of channels, which allows remote attackers to cause a denial of service (buffer over-...Show more |
2Debian Wireshark2Debian Linux WiresharkMay 6, 2026 Sep 9, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 epan/dissectors/packet-h225.c in the H.225 dissector in Wireshark 2.x before 2.0.6 calls snprintf with one of its input buffers as the output buffer, which allows remote attackers to cause a denial of service (copy overl...Show more |
3Cracklib Project DebianOpensuse3Cracklib Debian LinuxLeapMay 6, 2026 Sep 7, 2016 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Stack-based buffer overflow in the FascistGecosUser function in lib/fascist.c in cracklib allows local users to cause a denial of service (application crash) or gain privileges via a long GECOS field, involving longbuffe...Show more |
2Debian Rubyonrails3Debian Linux RailsRuby On RailsMay 6, 2026 Sep 7, 2016 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in Action View in Ruby on Rails 3.x before 3.2.22.3, 4.x before 4.2.7.1, and 5.x before 5.0.0.1 might allow remote attackers to inject arbitrary web script or HTML via text declar...Show more |
3Canonical DebianQemu3Debian Linux QemuUbuntu LinuxMay 6, 2026 Sep 7, 2016 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 The esp_do_dma function in hw/scsi/esp.c in QEMU (aka Quick Emulator), when built with ESP/NCR53C9x controller emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds write and...Show more |
3Canonical DebianQemu3Debian Linux QemuUbuntu LinuxMay 6, 2026 Sep 2, 2016 N/A· v4 6.0 MEDIUM· v3 1.9 LOW· v2 The megasas_lookup_frame function in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds read and crash) via uns...Show more |