Debian
debian
10,145 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,145)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Debian FedoraprojectMozilla+1 more5Debian Linux FedoraFirefox+2 moreMay 6, 2026 Feb 13, 2016 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, mishandles a return value, which allows remote attackers to...Show more |
4Debian FedoraprojectMozilla+1 more5Debian Linux FedoraFirefox+2 moreMay 6, 2026 Feb 13, 2016 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Code.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not consider recursive load calls during a size check, which allows remote attackers to cause a...Show more |
4Debian FedoraprojectMozilla+1 more5Debian Linux FedoraFirefox+2 moreMay 6, 2026 Feb 13, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The directrun function in directmachine.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not validate a certain skip operation, which allows remote a...Show more |
5Debian MitOpensuse+2 more11Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+8 moreMay 6, 2026 Feb 13, 2016 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Multiple memory leaks in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x before 1.14.1 allow remote authenticated users to cause a denial of service (memory consumption) via...Show more |
5Debian MitOpensuse+2 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+9 moreMay 6, 2026 Feb 13, 2016 N/A· v4 5.3 MEDIUM· v3 2.1 LOW· v2 The xdr_nullstring function in lib/kadm5/kadm_rpc_xdr.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x before 1.14.1 does not verify whether '\0' characters exist as expected, which allows remote authen...Show more |
3Canonical DebianXmlsoft3Debian Linux Libxml2Ubuntu LinuxMay 6, 2026 Feb 12, 2016 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The htmlParseNameComplex function in HTMLparser.c in libxml2 allows attackers to cause a denial of service (out-of-bounds read) via a crafted XML document. |
3Canonical DebianFfmpeg3Debian Linux FfmpegUbuntu LinuxMay 6, 2026 Feb 12, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Integer overflow in the asf_write_packet function in libavformat/asfenc.c in FFmpeg before 2.8.5 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted PTS (aka prese...Show more |
5Canonical DebianGoogle+2 more5Android Debian LinuxLinux Kernel+2 moreMay 6, 2026 Feb 8, 2016 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object references in a certain error case, which allows local users to gain privileges or cause a denial of se...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxMay 6, 2026 Feb 8, 2016 N/A· v4 6.2 MEDIUM· v3 4.9 MEDIUM· v2 net/sctp/sm_sideeffect.c in the Linux kernel before 4.3 does not properly manage the relationship between a lock and a socket, which allows local users to cause a denial of service (deadlock) via a crafted sctp_accept ca...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraLinux Kernel+1 moreMay 6, 2026 Feb 8, 2016 N/A· v4 6.5 MEDIUM· v3 4.9 MEDIUM· v2 arch/x86/kvm/x86.c in the Linux kernel before 4.4 does not reset the PIT counter values during state restoration, which allows guest OS users to cause a denial of service (divide-by-zero error and host OS crash) via a ze...Show more |
2Debian Libtiff2Debian Linux LibtiffMay 6, 2026 Feb 1, 2016 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 tif_luv.c in libtiff allows attackers to cause a denial of service (out-of-bounds reads) via a crafted TIFF image. |
2Debian Libtiff2Debian Linux LibtiffMay 6, 2026 Feb 1, 2016 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 tif_luv.c in libtiff allows attackers to cause a denial of service (out-of-bounds writes) via a crafted TIFF image, a different vulnerability than CVE-2015-8781. |
2Debian Libtiff2Debian Linux LibtiffMay 6, 2026 Feb 1, 2016 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 tif_luv.c in libtiff allows attackers to cause a denial of service (out-of-bounds write) via an invalid number of samples per pixel in a LogL compressed TIFF image, a different vulnerability than CVE-2015-8782. |
3Canonical DebianHaxx3Curl Debian LinuxUbuntu LinuxMay 6, 2026 Jan 29, 2016 N/A· v4 7.3 HIGH· v3 5.0 MEDIUM· v2 The ConnectionExists function in lib/url.c in libcurl before 7.47.0 does not properly re-use NTLM-authenticated proxy connections, which might allow remote attackers to authenticate as other users via a request, a simila...Show more |
6Canonical DebianMariadb+3 more7Debian Linux Enterprise LinuxLeap+4 moreMay 6, 2026 Jan 27, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The ssl_verify_server_cert function in sql-common/client.c in MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10; Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier; and Perc...Show more |
An unspecified udev rule in the Debian fuse package in jessie before 2.9.3-15+deb8u2, in stretch before 2.9.5-1, and in sid before 2.9.5-1 sets world-writable permissions for the /dev/cuse character device, which allows...Show more |
4Debian NetappNtp+1 more6Clustered Data Ontap Debian LinuxNtp+3 moreMay 6, 2026 Jan 26, 2016 N/A· v4 7.7 HIGH· v3 4.0 MEDIUM· v2 NTP 4.x before 4.2.8p6 and 4.3.x before 4.3.90 do not verify peer associations of symmetric keys when authenticating packets, which might allow remote attackers to conduct impersonation attacks via an arbitrary trusted k...Show more |
5Canonical DebianEcryptfs+2 more6Debian Linux Ecryptfs UtilsFedora+3 moreMay 6, 2026 Jan 22, 2016 N/A· v4 8.4 HIGH· v3 4.6 MEDIUM· v2 mount.ecryptfs_private.c in eCryptfs-utils does not validate mount destination filesystem types, which allows local users to gain privileges by mounting over a nonstandard filesystem, as demonstrated by /proc/$pid. |
6Canonical DebianMariadb+3 more14Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+11 moreMay 6, 2026 Jan 21, 2016 N/A· v4 N/A· v3 4.0 MEDIUM· v2 Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via unknown vectors relate...Show more |
6Canonical DebianMariadb+3 more7Debian Linux Enterprise LinuxLeap+4 moreMay 6, 2026 Jan 21, 2016 N/A· v4 N/A· v3 3.5 LOW· v2 Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and MariaDB before 10.0.22 and 10.1.x before 10.1.9 allows remote authenticated users to affect availability via unknown vectors related to InnoDB. |