Debian
debian
10,145 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,145)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Botan Project Debian2Botan Debian LinuxMay 6, 2026 May 13, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Integer overflow in the PointGFp constructor in Botan before 1.10.11 and 1.11.x before 1.11.27 allows remote attackers to overwrite memory and possibly execute arbitrary code via a crafted ECC point, which triggers a hea...Show more |
2Botan Project Debian2Botan Debian LinuxMay 6, 2026 May 13, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The ressol function in Botan before 1.10.11 and 1.11.x before 1.11.27 allows remote attackers to cause a denial of service (infinite loop) via unspecified input to the OS2ECP function, related to a composite modulus. |
3Botan Project DebianFedoraproject3Botan Debian LinuxFedoraMay 6, 2026 May 13, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Botan before 1.10.13 and 1.11.x before 1.11.22 make it easier for remote attackers to conduct million-message attacks by measuring time differences, related to decoding of PKCS#1 padding. |
2Botan Project Debian2Botan Debian LinuxMay 6, 2026 May 13, 2016 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 The BER decoder in Botan 1.10.x before 1.10.10 and 1.11.x before 1.11.19 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors, related to a length field. |
2Botan Project Debian2Botan Debian LinuxMay 6, 2026 May 13, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The BER decoder in Botan 0.10.x before 1.10.10 and 1.11.x before 1.11.19 allows remote attackers to cause a denial of service (application crash) via an empty BIT STRING in ASN.1 data. |
6Canonical CitrixDebian+3 more11Debian Linux Enterprise Linux DesktopEnterprise Linux Server+8 moreMay 6, 2026 May 11, 2016 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Integer overflow in the VGA module in QEMU allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) by editing VGA registers in VBE mode. |
7Canonical CitrixDebian+4 more15Debian Linux Enterprise Linux DesktopEnterprise Linux Server+12 moreMay 6, 2026 May 11, 2016 N/A· v4 8.8 HIGH· v3 7.2 HIGH· v2 The VGA module in QEMU improperly performs bounds checking on banked access to video memory, which allows local guest OS administrators to execute arbitrary code on the host by changing access modes after setting the ban...Show more |
2Debian Websvn2Debian Linux WebsvnMay 6, 2026 May 11, 2016 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Multiple cross-site scripting (XSS) vulnerabilities in (1) revision.php, (2) log.php, (3) listing.php, and (4) comp.php in WebSVN allow context-dependent attackers to inject arbitrary web script or HTML via the name of a...Show more |
2Debian Ikiwiki2Debian Linux IkiwikiMay 6, 2026 May 10, 2016 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in the cgierror function in CGI.pm in ikiwiki before 3.20160506 might allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving an error mess...Show more |
2Debian Mercurial2Debian Linux MercurialMay 6, 2026 May 9, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The convert extension in Mercurial before 3.8 might allow context-dependent attackers to execute arbitrary code via a crafted git repository name. |
2Debian Libpam Sshauth Project2Debian Linux Libpam SshauthMay 6, 2026 May 6, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The pam_sm_authenticate function in pam_sshauth.c in libpam-sshauth might allow context-dependent attackers to bypass authentication or gain privileges via a system user account. |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraPoppler+1 moreMay 6, 2026 May 6, 2016 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 Heap-based buffer overflow in the ExponentialFunction::ExponentialFunction function in Poppler before 0.40.0 allows remote attackers to cause a denial of service (memory corruption and crash) or possibly execute arbitrar...Show more |
2Debian Tardiff Project2Debian Linux TardiffMay 6, 2026 May 6, 2016 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 Cool Projects TarDiff allows local users to write to arbitrary files via a symlink attack on a pathname in a /tmp/tardiff-$$ temporary directory. |
2Debian Tardiff Project2Debian Linux TardiffMay 6, 2026 May 6, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Cool Projects TarDiff allows remote attackers to execute arbitrary commands via shell metacharacters in the name of a (1) tar file or (2) file within a tar file. |
5Canonical DebianImagemagick+2 more6Debian Linux ImagemagickLeap+3 moreApr 21, 2026 May 5, 2016 N/A· v4 8.4 HIGH· v3 10.0 HIGH· v2 The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to execute arbitrary code via shell metacharact...Show more |
8Canonical DebianGoogle+5 more15Android Debian LinuxEnterprise Linux Desktop+12 moreMay 6, 2026 May 5, 2016 N/A· v4 5.9 MEDIUM· v3 2.6 LOW· v2 The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleartext information via a...Show more |
8Apple CanonicalDebian+5 more15Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+12 moreMay 6, 2026 May 5, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Integer overflow in the EVP_EncodeUpdate function in crypto/evp/encode.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (heap memory corruption) via a large amount o...Show more |
3Canonical DebianOpenbsd5Debian Linux OpensshUbuntu Core+2 moreMay 6, 2026 May 1, 2016 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The do_setup_env function in session.c in sshd in OpenSSH through 7.2p2, when the UseLogin feature is enabled and PAM is configured to read .pam_environment files in user home directories, allows local users to gain priv...Show more |
4Debian MozillaOpensuse+1 more5Debian Linux FirefoxLeap+2 moreMay 6, 2026 Apr 30, 2016 N/A· v4 8.8 HIGH· v3 10.0 HIGH· v2 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 46.0 and Firefox ESR 45.x before 45.1 allow remote attackers to cause a denial of service (memory corruption and application crash) or...Show more |
4Debian LinuxOracle+1 more4Debian Linux Enterprise LinuxLinux+1 moreMay 6, 2026 Apr 27, 2016 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 The fork implementation in the Linux kernel before 4.5 on s390 platforms mishandles the case of four page-table levels, which allows local users to cause a denial of service (system crash) or possibly have unspecified ot...Show more |