Debian
debian
10,145 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,145)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Drupal 6.x before 6.35 and 7.x before 7.35 allows remote authenticated users to reset the password of other accounts by leveraging an account with the same password hash as another account and a crafted password reset UR...Show more |
6Canonical DebianDjangoproject+3 more6Debian Linux DjangoFedora+3 moreMay 6, 2026 Mar 25, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1 does not properly validate URLs, which allows remote attackers to conduct cross-site scr...Show more |
5Debian FedoraprojectOpensuse+2 more5Debian Linux FedoraOpensuse+2 moreMay 6, 2026 Mar 24, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 The force printer in tcpdump before 4.7.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors. |
3Apache DebianFedoraproject3Debian Linux FedoraXerces C++May 6, 2026 Mar 24, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 internal/XMLReader.cpp in Apache Xerces-C before 3.1.2 allows remote attackers to cause a denial of service (segmentation fault and crash) via crafted XML data. |
3Canonical DebianX3Debian Linux LibxfontUbuntu LinuxMay 6, 2026 Mar 20, 2015 N/A· v4 N/A· v3 8.5 HIGH· v2 The bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x before 1.5.1 does not properly handle character bitmaps it cannot read, which allows remote authenticated users to cause a denia...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxMay 6, 2026 Mar 16, 2015 N/A· v4 N/A· v3 10.0 HIGH· v2 Use-after-free vulnerability in the sctp_assoc_update function in net/sctp/associola.c in the Linux kernel before 3.18.8 allows remote attackers to cause a denial of service (slab corruption and panic) or possibly have u...Show more |
Race condition in the handle_to_path function in fs/fhandle.c in the Linux kernel through 3.19.1 allows local users to bypass intended size restrictions and trigger read operations on additional memory locations by chang...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxMay 6, 2026 Mar 16, 2015 N/A· v4 N/A· v3 6.9 MEDIUM· v2 The InfiniBand (IB) implementation in the Linux kernel package before 2.6.32-504.12.2 on Red Hat Enterprise Linux (RHEL) 6 does not properly restrict use of User Verbs for registration of memory regions, which allows loc...Show more |
3Debian FedoraprojectLibssh23Debian Linux FedoraLibssh2May 6, 2026 Mar 13, 2015 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The kex_agree_methods function in libssh2 before 1.5.0 allows remote servers to cause a denial of service (crash) or have other unspecified impact via crafted length values in an SSH_MSG_KEXINIT packet. |
3Debian FedoraprojectXen3Debian Linux FedoraXenMay 6, 2026 Mar 12, 2015 N/A· v4 N/A· v3 7.2 HIGH· v2 The x86 emulator in Xen 3.2.x through 4.5.x does not properly ignore segment overrides for instructions with register operands, which allows local guest users to obtain sensitive information, cause a denial of service (m...Show more |
3Debian FedoraprojectXen3Debian Linux FedoraXenMay 6, 2026 Mar 12, 2015 N/A· v4 N/A· v3 2.1 LOW· v2 The HYPERVISOR_xen_version hypercall in Xen 3.2.x through 4.5.x does not properly initialize data structures, which allows local guest users to obtain sensitive information via unspecified vectors. |
3Bestpractical DebianFedoraproject3Debian Linux FedoraRequest TrackerMay 6, 2026 Mar 9, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 RT (aka Request Tracker) 3.8.8 through 4.x before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to obtain sensitive RSS feed URLs and ticket data via unspecified vectors. |
3Bestpractical DebianFedoraproject3Debian Linux FedoraRequest TrackerMay 6, 2026 Mar 9, 2015 N/A· v4 N/A· v3 7.1 HIGH· v2 The email gateway in RT (aka Request Tracker) 3.0.0 through 4.x before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to cause a denial of service (CPU and disk consumption) via a crafted email. |
4Debian MageiaOpensuse+1 more4Debian Linux MageiaOpensuse+1 moreMay 6, 2026 Mar 8, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Integer overflow in the dissect_tnef function in epan/dissectors/packet-tnef.c in the TNEF dissector in Wireshark 1.10.x before 1.10.13 and 1.12.x before 1.12.4 allows remote attackers to cause a denial of service (infin...Show more |
5Debian MageiaOpensuse+2 more6Debian Linux LinuxMageia+3 moreMay 6, 2026 Mar 8, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Off-by-one error in the pcapng_read function in wiretap/pcapng.c in the pcapng file parser in Wireshark 1.10.x before 1.10.13 and 1.12.x before 1.12.4 allows remote attackers to cause a denial of service (out-of-bounds r...Show more |
5Debian MageiaOpensuse+2 more6Debian Linux LinuxMageia+3 moreMay 6, 2026 Mar 8, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 epan/dissectors/packet-wcp.c in the WCP dissector in Wireshark 1.10.x before 1.10.13 and 1.12.x before 1.12.4 does not properly initialize a data structure, which allows remote attackers to cause a denial of service (out...Show more |
5Canonical DebianLinux+2 more7Debian Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreMay 6, 2026 Mar 2, 2015 N/A· v4 N/A· v3 4.4 MEDIUM· v2 The em_sysenter function in arch/x86/kvm/emulate.c in the Linux kernel before 3.18.5, when the guest OS lacks SYSENTER MSR initialization, allows guest OS users to gain guest OS privileges or cause a denial of service (g...Show more |
4Canonical DebianLinux+1 more4Debian Linux LinuxLinux Kernel+1 moreMay 6, 2026 Mar 2, 2015 N/A· v4 N/A· v3 2.1 LOW· v2 The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a parenthesized module template expression in the salg_name field, as...Show more |
6Canonical DebianLinux+3 more15Debian Linux Enterprise Linux DesktopEnterprise Linux Server+12 moreMay 6, 2026 Mar 2, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 net/netfilter/nf_conntrack_proto_generic.c in the Linux kernel before 3.18 generates incorrect conntrack entries during handling of certain iptables rule sets for the SCTP, DCCP, GRE, and UDP-Lite protocols, which allows...Show more |
4Canonical DebianLinux+1 more4Debian Linux LinuxLinux Kernel+1 moreMay 6, 2026 Mar 2, 2015 N/A· v4 N/A· v3 2.1 LOW· v2 The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a module name in the salg_name field, a different vulnerability than C...Show more |