Debian
debian
10,145 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,145)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical DebianSamba3Debian Linux SambaUbuntu LinuxMay 6, 2026 Dec 29, 2015 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The shadow_copy2_get_shadow_copy_data function in modules/vfs_shadow_copy2.c in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not verify that the DIRECTORY_LIST access right has been gr...Show more |
3Canonical DebianSamba3Debian Linux SambaUbuntu LinuxMay 6, 2026 Dec 29, 2015 N/A· v4 5.4 MEDIUM· v3 4.3 MEDIUM· v2 Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 supports connections that are encrypted but unsigned, which allows man-in-the-middle attackers to conduct encrypted-to-unencrypted downgrade att...Show more |
3Canonical DebianSamba3Debian Linux SambaUbuntu LinuxMay 6, 2026 Dec 29, 2015 N/A· v4 7.2 HIGH· v3 5.0 MEDIUM· v2 vfs.c in smbd in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, when share names with certain substring relationships exist, allows remote attackers to bypass intended file-access restrictio...Show more |
4Canonical DebianLinuxfoundation+1 more9Cups Filters Debian LinuxEnterprise Linux Desktop+6 moreMay 6, 2026 Dec 17, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.2.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via ` (backtick) characters...Show more |
2Debian Phpmailer Project2Debian Linux PhpmailerMay 6, 2026 Dec 16, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Multiple CRLF injection vulnerabilities in PHPMailer before 5.2.14 allow attackers to inject arbitrary SMTP commands via CRLF sequences in an (1) email address to the validateAddress function in class.phpmailer.php or (2...Show more |
5Canonical DebianHp+2 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+6 moreMay 6, 2026 Dec 15, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The xmlParseXMLDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive information via an (1) unterminated encoding value or (2) incomplete XML declaration in XML data, wh...Show more |
5Canonical DebianHp+2 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+6 moreMay 6, 2026 Dec 15, 2015 N/A· v4 N/A· v3 6.4 MEDIUM· v2 The xmlNextChar function in libxml2 2.9.2 does not properly check the state, which allows context-dependent attackers to cause a denial of service (heap-based buffer over-read and application crash) or obtain sensitive i...Show more |
6Apple CanonicalDebian+3 more13Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+10 moreMay 6, 2026 Dec 15, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The xmlParseMisc function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (out-of-bounds heap read) via unspecified vectors related to incorrect entities boundaries and...Show more |
7Apple CanonicalDebian+4 more15Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+12 moreMay 6, 2026 Dec 15, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Heap-based buffer overflow in the xmlGROW function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive process memory information via unspecified vectors. |
5Canonical DebianHp+2 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+6 moreMay 6, 2026 Dec 15, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Heap-based buffer overflow in the xmlParseXmlDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service via unspecified vectors related to extracting errors after an...Show more |
5Canonical DebianHp+2 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+6 moreMay 6, 2026 Dec 15, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Heap-based buffer overflow in the xmlDictComputeFastQKey function in dict.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service via unspecified vectors. |
6Apple CanonicalDebian+3 more13Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+10 moreMay 6, 2026 Dec 15, 2015 N/A· v4 N/A· v3 7.1 HIGH· v2 The xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.3 does not properly prevent entity expansion, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted...Show more |
7Canonical DebianFedoraproject+4 more13Debian Linux Enterprise Linux DesktopEnterprise Linux Server+10 moreMay 6, 2026 Dec 6, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 ssl/s3_clnt.c in OpenSSL 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1p, and 1.0.2 before 1.0.2d, when used for a multi-threaded client, writes the PSK identity hint to an incorrect data structure, which allows remote servers...Show more |
9Apple CanonicalDebian+6 more25Api Gateway Communications Webrtc Session ControllerDebian Linux+22 moreMay 6, 2026 Dec 6, 2015 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1q, and 1.0.2 before 1.0.2e mishandles errors caused by malformed X509_ATTRIBUTE data, which...Show more |
4Canonical DebianNodejs+1 more4Debian Linux Node.jsOpenssl+1 moreMay 6, 2026 Dec 6, 2015 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 crypto/rsa/rsa_ameth.c in OpenSSL 1.0.1 before 1.0.1q and 1.0.2 before 1.0.2e allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an RSA PSS ASN.1 signature that lack...Show more |
3Debian GoogleNodejs3Chrome Debian LinuxNode.jsMay 6, 2026 Dec 6, 2015 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The BasicJsonStringifier::SerializeJSArray function in json-stringifier.h in the JSON stringifier in Google V8, as used in Google Chrome before 47.0.2526.73, improperly loads array elements, which allows remote attackers...Show more |
Off-by-one error in the extracthalf function in dpkg-deb/extract.c in the dpkg-deb component in Debian dpkg 1.16.x before 1.16.17 and 1.17.x before 1.17.26 allows remote attackers to execute arbitrary code via the archiv...Show more |
The Debian build procedure for the smokeping package in wheezy before 2.6.8-2+deb7u1 and jessie before 2.6.9-1+deb8u1 does not properly configure the way Apache httpd passes arguments to smokeping_cgi, which allows remot...Show more |
4Canonical DebianLibpng+1 more10Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+7 moreMay 6, 2026 Nov 24, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The png_convert_to_rfc1123 function in png.c in libpng 1.0.x before 1.0.64, 1.2.x before 1.2.54, and 1.4.x before 1.4.17 allows remote attackers to obtain sensitive process memory information via crafted tIME chunk data...Show more |
2Debian Horde3Debian Linux GroupwareHorde Application FrameworkMay 6, 2026 Nov 19, 2015 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Multiple cross-site request forgery (CSRF) vulnerabilities in Horde before 5.2.8, Horde Groupware before 5.2.11, and Horde Groupware Webmail Edition before 5.2.11 allow remote attackers to hijack the authentication of ad...Show more |