Debian
debian
10,145 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,145)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian FedoraprojectHorde3Debian Linux FedoraGroupwareMay 6, 2026 Apr 13, 2016 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in the _renderVarInput_number function in horde/framework/Core/lib/Horde/Core/Ui/VarRenderer/Html.php in Horde Groupware before 5.2.12 and Horde Groupware Webmail Edition before 5...Show more |
4Canonical DebianNovell+1 more5Debian Linux Suse Linux Enterprise DebuginfoSuse Linux Enterprise Real Time Extension+2 moreMay 6, 2026 Apr 13, 2016 N/A· v4 4.4 MEDIUM· v3 1.7 LOW· v2 The PCI backend driver in Xen, when running on an x86 system and using Linux 3.1.x through 4.3.x as the driver domain, allows local guest administrators to generate a continuous stream of WARN messages and cause a denial...Show more |
4Debian LinuxOpensuse+1 more8Debian Linux Linux Enterprise DesktopLinux Enterprise Real Time Extension+5 moreMay 6, 2026 Apr 13, 2016 N/A· v4 6.0 MEDIUM· v3 4.7 MEDIUM· v2 The PCI backend driver in Xen, when running on an x86 system and using Linux 3.1.x through 4.3.x as the driver domain, allows local guest administrators to hit BUG conditions and cause a denial of service (NULL pointer d...Show more |
4Debian OpensuseRedhat+1 more5Debian Linux LeapOpenstack+2 moreMay 6, 2026 Apr 13, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Integer overflow in the getnum function in lua_struct.c in Redis 2.8.x before 2.8.24 and 3.0.x before 3.0.6 allows context-dependent attackers with permission to run Lua code in a Redis session to cause a denial of servi...Show more |
2Debian Tryton2Debian Linux TrytondMay 6, 2026 Apr 13, 2016 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 model/modelstorage.py in trytond 3.2.x before 3.2.10, 3.4.x before 3.4.8, 3.6.x before 3.6.5, and 3.8.x before 3.8.1 allows remote authenticated users to bypass intended access restrictions and write to arbitrary fields...Show more |
2Debian Roundup Tracker2Debian Linux RoundupMay 6, 2026 Apr 13, 2016 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 schema.py in Roundup before 1.5.1 does not properly limit attributes included in default user permissions, which might allow remote authenticated users to obtain sensitive user information by viewing user details. |
3Canonical DebianSamba3Debian Linux SambaUbuntu LinuxMay 6, 2026 Apr 12, 2016 N/A· v4 7.5 HIGH· v3 6.8 MEDIUM· v2 The MS-SAMR and MS-LSAD protocol implementations in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 mishandle DCERPC connections, which allows man-in-the-middle attackers to perform protocol-d...Show more |
2Debian Drupal2Debian Linux DrupalMay 6, 2026 Apr 12, 2016 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Drupal 6.x before 6.38, when used with PHP before 5.4.45, 5.5.x before 5.5.29, or 5.6.x before 5.6.13, might allow remote attackers to execute arbitrary code via vectors related to session data truncation. |
2Debian Drupal2Debian Linux DrupalMay 6, 2026 Apr 12, 2016 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The "have you forgotten your password" links in the User module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allow remote attackers to obtain sensitive username information by leveraging a configuration that permits us...Show more |
2Debian Drupal2Debian Linux DrupalMay 6, 2026 Apr 12, 2016 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 The User module in Drupal 6.x before 6.38 and 7.x before 7.43 allows remote attackers to gain privileges by leveraging contributed or custom code that calls the user_save function with an explicit category and loads all...Show more |
2Debian Drupal2Debian Linux DrupalMay 6, 2026 Apr 12, 2016 N/A· v4 6.4 MEDIUM· v3 8.5 HIGH· v2 The System module in Drupal 6.x before 6.38 and 7.x before 7.43 might allow remote attackers to hijack the authentication of site administrators for requests that download and run files with arbitrary JSON-encoded conten...Show more |
2Debian Drupal2Debian Linux DrupalMay 6, 2026 Apr 12, 2016 N/A· v4 7.4 HIGH· v3 6.4 MEDIUM· v2 Open redirect vulnerability in the drupal_goto function in Drupal 6.x before 6.38, when used with PHP before 5.4.7, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a doub...Show more |
2Debian Drupal2Debian Linux DrupalMay 6, 2026 Apr 12, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 CRLF injection vulnerability in the drupal_set_header function in Drupal 6.x before 6.38, when used with PHP before 5.1.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting atta...Show more |
2Debian Drupal2Debian Linux DrupalMay 6, 2026 Apr 12, 2016 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 Drupal 6.x before 6.38, 7.x before 7.43, and 8.x before 8.0.4 might allow remote attackers to conduct open redirect attacks by leveraging (1) custom code or (2) a form shown on a 404 error page, related to path manipulat...Show more |
2Debian Drupal2Debian Linux DrupalMay 6, 2026 Apr 12, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The XML-RPC system in Drupal 6.x before 6.38 and 7.x before 7.43 might make it easier for remote attackers to conduct brute-force attacks via a large number of calls made at once to the same method. |
2Debian Drupal2Debian Linux DrupalMay 6, 2026 Apr 12, 2016 N/A· v4 8.1 HIGH· v3 6.5 MEDIUM· v2 The File module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allows remote authenticated users to bypass access restrictions and read, delete, or substitute a link to a file uploaded to an unprocessed form by leveragin...Show more |
2Debian Inspircd2Debian Linux InspircdMay 6, 2026 Apr 12, 2016 N/A· v4 8.6 HIGH· v3 7.8 HIGH· v2 The DNS::GetResult function in dns.cpp in InspIRCd before 2.0.19 allows remote DNS servers to cause a denial of service (netsplit) via an invalid character in a PTR response, as demonstrated by a "\032" (whitespace) char...Show more |
2Debian Redmine2Debian Linux RedmineMay 6, 2026 Apr 12, 2016 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 app/views/journals/index.builder in Redmine before 2.6.9, 3.0.x before 3.0.7, and 3.1.x before 3.1.3 allows remote attackers to obtain sensitive information by viewing an Atom feed. |
2Debian Redmine2Debian Linux RedmineMay 6, 2026 Apr 12, 2016 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 Open redirect vulnerability in the valid_back_url function in app/controllers/application_controller.rb in Redmine before 2.6.7, 3.0.x before 3.0.5, and 3.1.x before 3.1.1 allows remote attackers to redirect users to arb...Show more |
2Debian Redmine2Debian Linux RedmineMay 6, 2026 Apr 12, 2016 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 The Issues API in Redmine before 2.6.8, 3.0.x before 3.0.6, and 3.1.x before 3.1.2 allows remote authenticated users to obtain sensitive information in changeset messages by leveraging permission to read issues with rela...Show more |