Debian
debian
10,145 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,145)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Atheme DebianOpensuse4Atheme Debian LinuxLeap+1 moreMay 6, 2026 Jun 13, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Buffer overflow in the xmlrpc_char_encode function in modules/transport/xmlrpc/xmlrpclib.c in Atheme before 7.2.7 allows remote attackers to cause a denial of service via vectors related to XMLRPC response encoding. |
4Canonical DebianLibndp+1 more10Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+7 moreMay 6, 2026 Jun 13, 2016 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 libndp before 1.6, as used in NetworkManager, does not properly validate the origin of Neighbor Discovery Protocol (NDP) messages, which allows remote attackers to conduct man-in-the-middle attacks or cause a denial of s...Show more |
4Canonical DebianMozilla+1 more5Debian Linux FirefoxLeap+2 moreMay 6, 2026 Jun 13, 2016 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 do not ensure that the user approves the fullscreen and pointerlock settings, which allows remote attackers to cause a denial of service (UI outage), or conduc...Show more |
4Canonical DebianMozilla+1 more5Debian Linux FirefoxLeap+2 moreMay 6, 2026 Jun 13, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use-after-free vulnerability in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows remote attackers to execute arbitrary code via WebGL content that triggers texture access after destruction of the textu...Show more |
4Canonical DebianMozilla+1 more5Debian Linux FirefoxLeap+2 moreMay 6, 2026 Jun 13, 2016 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to spoof the address bar via a SELECT element with a persistent menu. |
4Canonical DebianMozilla+1 more5Debian Linux FirefoxLeap+2 moreMay 6, 2026 Jun 13, 2016 N/A· v4 7.5 HIGH· v3 6.8 MEDIUM· v2 Use-after-free vulnerability in the mozilla::dom::Element class in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2, when contenteditable mode is enabled, allows remote attackers to execute arbitrary code or...Show more |
4Canonical DebianMozilla+1 more5Debian Linux FirefoxLeap+2 moreMay 6, 2026 Jun 13, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Heap-based buffer overflow in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows remote attackers to execute arbitrary code via foreign-context HTML5 fragments, as demonstrated by fragments within an SVG...Show more |
6Canonical DebianMozilla+3 more21Debian Linux Enterprise Linux DesktopEnterprise Linux For Ibm Z Systems+18 moreMay 6, 2026 Jun 13, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or...Show more |
7Canonical DebianGraphicsmagick+4 more14Debian Linux GraphicsmagickImagemagick+11 moreMay 6, 2026 Jun 10, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename. |
3Canonical DebianXmlsoft3Debian Linux Libxml2Ubuntu LinuxMay 6, 2026 Jun 9, 2016 N/A· v4 7.1 HIGH· v3 5.8 MEDIUM· v2 XML external entity (XXE) vulnerability in the xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.4, when not in validating mode, allows context-dependent attackers to read arbitrary files or cause a d...Show more |
7Apple CanonicalDebian+4 more11Debian Linux Icewall Federation AgentIphone Os+8 moreMay 6, 2026 Jun 9, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The xmlParseElementDecl function in parser.c in libxml2 before 2.9.4 allows context-dependent attackers to cause a denial of service (heap-based buffer underread and application crash) via a crafted file, involving xmlPa...Show more |
4Debian OpensuseRedhat+1 more11Debian Linux Enterprise LinuxEnterprise Linux Desktop+8 moreMay 6, 2026 Jun 9, 2016 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface parameters, a similar issue to CVE-2015-5261. |
4Debian OpensuseRedhat+1 more11Debian Linux Enterprise LinuxEnterprise Linux Desktop+8 moreMay 6, 2026 Jun 9, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The smartcard interaction in SPICE allows remote attackers to cause a denial of service (QEMU-KVM process crash) or possibly execute arbitrary code via vectors related to connecting to a guest VM, which triggers a heap-b...Show more |
2Debian Videolan2Debian Linux Vlc Media PlayerMay 6, 2026 Jun 8, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Buffer overflow in the DecodeAdpcmImaQT function in modules/codec/adpcm.c in VideoLAN VLC media player before 2.2.4 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a cr...Show more |
3Canonical DebianF53Debian Linux NginxUbuntu LinuxMay 6, 2026 Jun 7, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 os/unix/ngx_files.c in nginx before 1.10.1 and 1.11.x before 1.11.1 allows remote attackers to cause a denial of service (NULL pointer dereference and worker process crash) via a crafted request, involving writing a clie...Show more |
37 Zip DebianOpensuse37 Zip Debian LinuxOpensuseMay 6, 2026 Jun 7, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The CInArchive::ReadFileItem method in Archive/Udf/UdfIn.cpp in 7zip 9.20 and 15.05 beta and p7zip allows remote attackers to cause a denial of service (out-of-bounds read) or execute arbitrary code via the PartitionRef...Show more |
2Debian Zend2Debian Linux Zend FrameworkMay 6, 2026 Jun 7, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The PDO adapters in Zend Framework before 1.12.16 do not filer null bytes in SQL statements, which allows remote attackers to execute arbitrary SQL commands via a crafted query. |
3Debian Doctrine ProjectZend10Annotations CacheCommon+7 moreMay 6, 2026 Jun 7, 2016 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Doctrine Annotations before 1.2.7, Cache before 1.3.2 and 1.4.x before 1.4.2, Common before 2.4.3 and 2.5.x before 2.5.1, ORM before 2.4.8 or 2.5.x before 2.5.1, MongoDB ODM before 1.0.2, and MongoDB ODM Bundle before 3....Show more |
4Canonical DebianRedhat+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+6 moreMay 6, 2026 Jun 7, 2016 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to read and write to arbitrary memory locations on the host via guest QXL commands related to surface creation. |
4Canonical DebianRedhat+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+6 moreMay 6, 2026 Jun 7, 2016 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host via QXL commands relat...Show more |