Debian
debian
10,145 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,145)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical DebianGoogle+1 more4Chrome Debian LinuxOpensuse+1 moreMay 6, 2026 Mar 29, 2016 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Use-after-free vulnerability in the RenderWidgetHostImpl::Destroy function in content/browser/renderer_host/render_widget_host_impl.cc in the Navigation implementation in Google Chrome before 49.0.2623.108 allows remote...Show more |
6Canonical DebianGoogle+3 more10Chrome Debian LinuxEnterprise Linux Desktop+7 moreApr 21, 2026 Mar 29, 2016 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly consider element data types, which allows remote attackers to cause a denial of serv...Show more |
6Apple CanonicalDebian+3 more15Debian Linux Enterprise Linux DesktopEnterprise Linux Server+12 moreMay 6, 2026 Mar 24, 2016 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 The xmlNextChar function in libxml2 before 2.9.4 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document. |
The bgp_nlri_parse_vpnv4 function in bgp_mplsvpn.c in the VPNv4 NLRI parser in bgpd in Quagga before 1.0.20160309, when a certain VPNv4 configuration is used, relies on a Labeled-VPN SAFI routes-data length field during...Show more |
2Canonical Debian2Debian Linux Ubuntu LinuxMay 6, 2026 Mar 14, 2016 N/A· v4 8.4 HIGH· v3 7.2 HIGH· v2 pt_chown in the glibc package before 2.19-18+deb8u4 on Debian jessie; the elibc package before 2.15-0ubuntu10.14 on Ubuntu 12.04 LTS and before 2.19-0ubuntu6.8 on Ubuntu 14.04 LTS; and the glibc package before 2.21-0ubun...Show more |
3Debian GoogleOpensuse5Chrome Debian LinuxLeap+2 moreMay 6, 2026 Mar 13, 2016 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Multiple integer signedness errors in the opj_j2k_update_image_data function in j2k.c in OpenJPEG, as used in PDFium in Google Chrome before 49.0.2623.87, allow remote attackers to cause a denial of service (incorrect ca...Show more |
3Canonical DebianSamba3Debian Linux SambaUbuntu LinuxMay 6, 2026 Mar 13, 2016 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The SMB1 implementation in smbd in Samba 3.x and 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4 allows remote authenticated users to modify arbitrary ACLs by using a UNIX SMB1 call t...Show more |
7Canonical DebianFedoraproject+4 more14Bind Debian LinuxFedora+11 moreMay 6, 2026 Mar 9, 2016 N/A· v4 8.6 HIGH· v3 5.0 MEDIUM· v2 named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted signature record for a DNAME record, related to db....Show more |
7Canonical DebianFedoraproject+4 more14Bind Debian LinuxFedora+11 moreMay 6, 2026 Mar 9, 2016 N/A· v4 6.8 MEDIUM· v3 4.3 MEDIUM· v2 named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages, which allows remote attackers to cause a denial of service (assertion failure an...Show more |
3Canonical DebianIsc3Debian Linux DhcpUbuntu LinuxMay 6, 2026 Mar 9, 2016 N/A· v4 5.9 MEDIUM· v3 7.1 HIGH· v2 ISC DHCP 4.1.x before 4.1-ESV-R13 and 4.2.x and 4.3.x before 4.3.4 does not restrict the number of concurrent TCP sessions, which allows remote attackers to cause a denial of service (INSIST assertion failure or request-...Show more |
4Canonical DebianNodejs+1 more4Debian Linux Node.jsOpenssl+1 moreMay 6, 2026 Mar 3, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Multiple integer overflows in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g allow remote attackers to cause a denial of service (heap memory corruption or NULL pointer dereference) or possibly have unspecified othe...Show more |
5Canonical DebianGoogle+2 more5Android Debian LinuxMysql+2 moreMay 6, 2026 Mar 3, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Double free vulnerability in the dsa_priv_decode function in crypto/dsa/dsa_ameth.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g allows remote attackers to cause a denial of service (memory corruption) or possi...Show more |
4Canonical DebianNodejs+1 more4Debian Linux Node.jsOpenssl+1 moreMay 6, 2026 Mar 3, 2016 N/A· v4 5.1 MEDIUM· v3 1.9 LOW· v2 The MOD_EXP_CTIME_COPY_FROM_PREBUF function in crypto/bn/bn_exp.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g does not properly consider cache-bank access times during modular exponentiation, which makes it ea...Show more |
3Apache CanonicalDebian3Debian Linux TomcatUbuntu LinuxMay 6, 2026 Feb 25, 2016 N/A· v4 6.3 MEDIUM· v3 6.5 MEDIUM· v2 The setGlobalContext method in org/apache/naming/factory/ResourceLinkFactory.java in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M3 does not consider whether ResourceLinkFactory.setGlobalCont...Show more |
3Apache CanonicalDebian3Debian Linux TomcatUbuntu LinuxMay 6, 2026 Feb 25, 2016 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The session-persistence implementation in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 mishandles session attributes, which allows remote authenticated users to bypass in...Show more |
3Apache CanonicalDebian3Debian Linux TomcatUbuntu LinuxMay 6, 2026 Feb 25, 2016 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 does not place org.apache.catalina.manager.StatusManagerServlet on the org/apache/catalina/core/RestrictedServlets.properties...Show more |
3Apache CanonicalDebian3Debian Linux TomcatUbuntu LinuxMay 6, 2026 Feb 25, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The (1) Manager and (2) Host Manager applications in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 establish sessions and send CSRF tokens for arbitrary new requests, which allows remote att...Show more |
3Apache CanonicalDebian3Debian Linux TomcatUbuntu LinuxMay 6, 2026 Feb 25, 2016 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are used for deployments of multiple versions of the same web application, mi...Show more |
3Apache CanonicalDebian3Debian Linux TomcatUbuntu LinuxMay 6, 2026 Feb 25, 2016 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The Mapper component in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.30, and 9.x before 9.0.0.M2 processes redirects before considering security constraints and Filters, which allows remote attacker...Show more |
3Apache CanonicalDebian3Debian Linux TomcatUbuntu LinuxMay 6, 2026 Feb 25, 2016 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Directory traversal vulnerability in RequestUtil.java in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.65, and 8.x before 8.0.27 allows remote authenticated users to bypass intended SecurityManager restrictions and lis...Show more |