Debian
debian
10,145 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,145)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical DebianStrongswan4Debian Linux StrongswanStrongswan Vpn Client+1 moreMay 6, 2026 Jun 10, 2015 N/A· v4 N/A· v3 2.6 LOW· v2 strongSwan 4.3.0 through 5.x before 5.3.2 and strongSwan VPN Client before 1.4.6, when using EAP or pre-shared keys for authenticating an IKEv2 connection, does not enforce server authentication restrictions until the en...Show more |
Redis before 2.8.21 and 3.x before 3.0.2 allows remote attackers to execute arbitrary Lua bytecode via the eval command. |
The Expression Language (EL) implementation in Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.58, and 8.x before 8.0.16 does not properly consider the possibility of an accessible interface implemented by an inaccessibl...Show more |
6Canonical CitrixDebian+3 more8Debian Linux FedoraLinux Enterprise Desktop+5 moreMay 6, 2026 Jun 3, 2015 N/A· v4 N/A· v3 4.6 MEDIUM· v2 QEMU does not properly restrict write access to the PCI config space for certain PCI pass-through devices, which might allow local x86 HVM guests to gain privileges, cause a denial of service (host crash), obtain sensiti...Show more |
5Canonical DebianF5+2 more25Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+22 moreMay 6, 2026 May 29, 2015 N/A· v4 N/A· v3 7.8 HIGH· v2 racoon/gssapi.c in IPsec-Tools 0.8.2 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) via a series of crafted UDP requests. |
4Apple CanonicalDebian+1 more4Debian Linux Mac Os X ServerPostgresql+1 moreMay 6, 2026 May 28, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Double free vulnerability in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 allows remote attackers to cause a denial of service (crash) by closing an SSL s...Show more |
2Debian Linux2Debian Linux Linux KernelMay 6, 2026 May 27, 2015 N/A· v4 N/A· v3 6.2 MEDIUM· v2 Race condition in the prepare_binprm function in fs/exec.c in the Linux kernel before 3.19.6 allows local users to gain privileges by executing a setuid program at a time instant when a chown to root is in progress, and...Show more |
2Debian Linux2Debian Linux Linux KernelMay 6, 2026 May 27, 2015 N/A· v4 N/A· v3 4.9 MEDIUM· v2 A certain backport in the TCP Fast Open implementation for the Linux kernel before 3.18 does not properly maintain a count value, which allow local users to cause a denial of service (system crash) via the Fast Open feat...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxMay 6, 2026 May 27, 2015 N/A· v4 N/A· v3 9.3 HIGH· v2 The __driver_rfc4106_decrypt function in arch/x86/crypto/aesni-intel_glue.c in the Linux kernel before 3.19.3 does not properly determine the memory locations used for encrypted data, which allows context-dependent attac...Show more |
5Debian FedoraprojectLinux+2 more6Debian Linux Enterprise MrgFedora+3 moreMay 6, 2026 May 27, 2015 N/A· v4 N/A· v3 3.3 LOW· v2 The ndisc_router_discovery function in net/ipv6/ndisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in the Linux kernel before 3.19.6 allows remote attackers to reconfigure a hop-limit settin...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxMay 6, 2026 May 27, 2015 N/A· v4 N/A· v3 1.9 LOW· v2 arch/x86/kernel/entry_64.S in the Linux kernel before 3.19.2 does not prevent the TS_COMPAT flag from reaching a user-mode task, which might allow local users to bypass the seccomp or audit protection mechanism via a cra...Show more |
12Apple CanonicalDebian+9 more25Chrome Content ManagerDebian Linux+22 moreMay 27, 2026 May 21, 2015 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgra...Show more |
Multiple unspecified vulnerabilities in Google Chrome before 43.0.2357.65 allow attackers to cause a denial of service or possibly have other impact via unknown vectors. |
Cross-site scripting (XSS) vulnerability in Google Chrome before 43.0.2357.65 allows user-assisted remote attackers to inject arbitrary web script or HTML via crafted data that is improperly handled by the Bookmarks feat...Show more |
The Spellcheck API implementation in Google Chrome before 43.0.2357.65 does not use an HTTPS session for downloading a Hunspell dictionary, which allows man-in-the-middle attackers to deliver incorrect spelling suggestio...Show more |
platform/fonts/shaping/HarfBuzzShaper.cpp in Blink, as used in Google Chrome before 43.0.2357.65, does not initialize a certain width field, which allows remote attackers to cause a denial of service or possibly have uns...Show more |
android/java/src/org/chromium/chrome/browser/WebsiteSettingsPopup.java in Google Chrome before 43.0.2357.65 on Android does not properly restrict use of a URL's fragment identifier during construction of a page-info popu...Show more |
Multiple use-after-free vulnerabilities in content/renderer/media/user_media_client_impl.cc in the WebRTC implementation in Google Chrome before 43.0.2357.65 allow remote attackers to cause a denial of service or possibl...Show more |
PDFium, as used in Google Chrome before 43.0.2357.65, does not properly initialize memory, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors. |
Google Chrome before 43.0.2357.65 relies on libvpx code that was not built with an appropriate --size-limit value, which allows remote attackers to trigger a negative value for a size field, and consequently cause a deni...Show more |