Debian
debian
10,145 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,145)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian OpenstackRedhat3Debian Linux HorizonOpenstackMay 6, 2026 Jul 12, 2016 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Cross-site scripting (XSS) vulnerability in OpenStack Dashboard (Horizon) 8.0.1 and earlier and 9.0.0 through 9.0.1 allows remote authenticated users to inject arbitrary web script or HTML by injecting an AngularJS templ...Show more |
2Apache Debian2Debian Linux Xerces C++May 6, 2026 Jul 8, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Stack-based buffer overflow in Apache Xerces-C++ before 3.1.4 allows context-dependent attackers to cause a denial of service via a deeply nested DTD. |
3Canonical DebianLibreoffice3Debian Linux LibreofficeUbuntu LinuxMay 6, 2026 Jul 8, 2016 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Use-after-free vulnerability in LibreOffice before 5.1.4 allows remote attackers to execute arbitrary code via a crafted RTF file, related to stylesheet and superscript tokens. |
4Apache CanonicalDebian+1 more6Commons Fileupload Debian LinuxIcewall Identity Manager+3 moreMay 6, 2026 Jul 4, 2016 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers...Show more |
2Debian Linux2Debian Linux Linux KernelMay 6, 2026 Jul 3, 2016 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 Race condition in the sclp_ctl_ioctl_sccb function in drivers/s390/char/sclp_ctl.c in the Linux kernel before 4.6 allows local users to obtain sensitive information from kernel memory by changing a certain length value,...Show more |
5Canonical DebianLinux+2 more11Debian Linux LinuxLinux Kernel+8 moreMay 6, 2026 Jul 3, 2016 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter subsystem in the Linux kernel before 4.6.3 allow local users to gain privileges or cause a denial of service (memory corru...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxMay 6, 2026 Jul 3, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The usbip_recv_xbuff function in drivers/usb/usbip/usbip_common.c in the Linux kernel before 4.5.3 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via...Show more |
4Canonical DebianLinux+1 more4Debian Linux Linux KernelSuse Linux Enterprise Real Time Extension+1 moreMay 6, 2026 Jun 27, 2016 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Multiple heap-based buffer overflows in the hiddev_ioctl_usage function in drivers/hid/usbhid/hiddev.c in the Linux kernel through 4.6.3 allow local users to cause a denial of service or possibly have unspecified other i...Show more |
4Canonical DebianLinux+1 more4Debian Linux Linux KernelSuse Linux Enterprise Real Time Extension+1 moreMay 6, 2026 Jun 27, 2016 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The start_thread function in arch/powerpc/kernel/process.c in the Linux kernel through 4.6.3 on powerpc platforms mishandles transactional state, which allows local users to cause a denial of service (invalid process sta...Show more |
2Debian Linux2Debian Linux Linux KernelMay 6, 2026 Jun 27, 2016 N/A· v4 6.3 MEDIUM· v3 5.4 MEDIUM· v2 Race condition in the vop_ioctl function in drivers/misc/mic/vop/vop_vringh.c in the MIC VOP driver in the Linux kernel before 4.6.1 allows local users to obtain sensitive information from kernel memory or cause a denial...Show more |
4Canonical DebianLinux+1 more10Debian Linux Linux KernelSuse Linux Enterprise Debuginfo+7 moreMay 6, 2026 Jun 27, 2016 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The ecryptfs_privileged_open function in fs/ecryptfs/kthread.c in the Linux kernel before 4.6.3 allows local users to gain privileges or cause a denial of service (stack memory consumption) via vectors involving crafted...Show more |
3Debian LinuxNovell3Debian Linux Linux KernelSuse Linux Enterprise Real Time ExtensionMay 6, 2026 Jun 27, 2016 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The snd_compress_check_input function in sound/core/compress_offload.c in the ALSA subsystem in the Linux kernel before 3.17 does not properly check for an integer overflow, which allows local users to cause a denial of...Show more |
6Canonical DebianNodejs+3 more7Debian Linux LinuxLinux Enterprise+4 moreMay 6, 2026 Jun 20, 2016 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of constant-time operations, which makes it easier for local users to discover a DSA private key via a timin...Show more |
4Canonical DebianGoogle+1 more4Android Debian LinuxLibexpat+1 moreMay 6, 2026 Jun 16, 2016 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 The XML parser in Expat does not use sufficient entropy for hash initialization, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted identifiers in an XML document. NOTE:...Show more |
4Debian FfmpegLibav+1 more4Debian Linux FfmpegLeap+1 moreMay 6, 2026 Jun 16, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The mov_read_dref function in libavformat/mov.c in Libav before 11.7 and FFmpeg before 0.11 allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via the entries value in a dr...Show more |
3Canonical DebianQemu3Debian Linux QemuUbuntu LinuxMay 6, 2026 Jun 16, 2016 N/A· v4 5.0 MEDIUM· v3 2.1 LOW· v2 The ohci_bus_start function in the USB OHCI emulation support (hw/usb/hcd-ohci.c) in QEMU allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via vectors re...Show more |
4Canonical DebianGoogle+1 more4Android Debian LinuxLibexpat+1 moreMay 6, 2026 Jun 16, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Expat, when used in a parser that has not called XML_SetHashSalt or passed it a seed of 0, makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms via vectors involving use of the sr...Show more |
3Canonical DebianQemu3Debian Linux QemuUbuntu LinuxMay 6, 2026 Jun 14, 2016 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 The (1) esp_reg_read and (2) esp_reg_write functions in hw/scsi/esp.c in QEMU allow local guest OS administrators to cause a denial of service (QEMU process crash) or execute arbitrary code on the QEMU host via vectors r...Show more |
3Canonical DebianQemu3Debian Linux QemuUbuntu LinuxMay 6, 2026 Jun 14, 2016 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The megasas_ctrl_get_info function in hw/scsi/megasas.c in QEMU allows local guest OS administrators to obtain sensitive host memory information via vectors related to reading device control information. |
3Canonical DebianQemu3Debian Linux QemuUbuntu LinuxMay 6, 2026 Jun 14, 2016 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 The get_cmd function in hw/scsi/esp.c in QEMU might allow local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) via vectors related to reading from the information transf...Show more |