Debian
debian
10,145 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,145)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
APT before 1.0.9 does not verify downloaded files if they have been modified as indicated using the If-Modified-Since header, which has unspecified impact and attack vectors. |
5Canonical DebianOpensuse+2 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+9 moreMay 6, 2026 Nov 1, 2014 N/A· v4 N/A· v3 2.1 LOW· v2 The VGA emulator in QEMU allows local guest users to read host memory by setting the display to a high resolution. |
4Canonical DebianOpensuse+1 more4Debian Linux OpensusePidgin+1 moreMay 6, 2026 Oct 29, 2014 N/A· v4 N/A· v3 6.4 MEDIUM· v2 The (1) bundled GnuTLS SSL/TLS plugin and the (2) bundled OpenSSL SSL/TLS plugin in libpurple in Pidgin before 2.10.10 do not properly consider the Basic Constraints extension during verification of X.509 certificates fr...Show more |
3Cacti DebianOpensuse3Cacti Debian LinuxOpensuseMay 6, 2026 Oct 20, 2014 N/A· v4 N/A· v3 3.5 LOW· v2 Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote authenticated users with console access to inject arbitrary web script or HTML via a (1) Graph Tree Title in a delete or (2) edit action; (...Show more |
3Cacti DebianOpensuse3Cacti Debian LinuxOpensuseMay 6, 2026 Oct 20, 2014 N/A· v4 N/A· v3 3.5 LOW· v2 Cross-site scripting (XSS) vulnerability in data_sources.php in Cacti 0.8.8b allows remote authenticated users with console access to inject arbitrary web script or HTML via the name_cache parameter in a ds_edit action. |
3Canonical DebianGnu3Debian Linux GpgmeUbuntu LinuxMay 6, 2026 Oct 20, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Multiple heap-based buffer overflows in the status_handler function in (1) engine-gpgsm.c and (2) engine-uiserver.c in GPGME before 1.5.1 allow remote attackers to cause a denial of service (crash) and possibly execute a...Show more |
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array con...Show more |
3Canonical DebianW1.fi4Debian Linux HostapdUbuntu Linux+1 moreMay 6, 2026 Oct 16, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 wpa_supplicant and hostapd 0.7.2 through 2.2, when running with certain configurations and using wpa_cli or hostapd_cli with action scripts, allows remote attackers to execute arbitrary commands via a crafted frame. |
The changelog command in Apt before 1.0.9.2 allows local users to write to arbitrary files via a symlink attack on the changelog file. |
4Canonical DebianMageia+1 more4Debian Linux MageiaRequests+1 moreMay 6, 2026 Oct 15, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by reading the Authorization header in a redirected request. |
11Apple DebianFedoraproject+8 more20Aix DatabaseDebian Linux+17 moreMay 28, 2026 Oct 15, 2014 N/A· v4 3.4 LOW· v3 4.3 MEDIUM· v2 The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, a...Show more |
Libgcrypt before 1.5.4, as used in GnuPG and other products, does not properly perform ciphertext normalization and ciphertext randomization, which makes it easier for physically proximate attackers to conduct key-extrac...Show more |
3Canonical DebianMageia4Debian Linux Exuberant CtagsMageia+1 moreMay 6, 2026 Oct 7, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 jscript.c in Exuberant Ctags 5.8 allows remote attackers to cause a denial of service (infinite loop and CPU and disk consumption) via a crafted JavaScript file. |
Cross-site scripting (XSS) vulnerability in job.cc in apt-cacher-ng 0.7.26 allows remote attackers to inject arbitrary web script or HTML via a crafted URL. |
3Canonical DebianLibvncserver3Debian Linux LibvncserverUbuntu LinuxMay 6, 2026 Oct 6, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The rfbProcessClientNormalMessage function in libvncserver/rfbserver.c in LibVNCServer 0.9.9 and earlier allows remote attackers to cause a denial of service (divide-by-zero error and server crash) via a zero value in th...Show more |
4Debian FedoraprojectOpensuse+1 more4Debian Linux FedoraOpensuse+1 moreMay 6, 2026 Oct 2, 2014 N/A· v4 N/A· v3 5.8 MEDIUM· v2 The x86_emulate function in arch/x86/x86_emulate/x86_emulate.c in Xen 4.4.x and earlier does not properly check supervisor mode permissions, which allows local HVM users to cause a denial of service (guest crash) or gain...Show more |
4Debian FedoraprojectOpensuse+1 more4Debian Linux FedoraOpensuse+1 moreMay 6, 2026 Oct 2, 2014 N/A· v4 N/A· v3 6.1 MEDIUM· v2 Race condition in HVMOP_track_dirty_vram in Xen 4.0.0 through 4.4.x does not ensure possession of the guarding lock for dirty video RAM tracking, which allows certain local guest domains to cause a denial of service via...Show more |
4Debian FedoraprojectLibvncserver+1 more5Debian Linux Enterprise Linux Server AusEnterprise Linux Server Eus+2 moreMay 6, 2026 Sep 30, 2014 N/A· v4 N/A· v3 6.5 MEDIUM· v2 Multiple stack-based buffer overflows in the File Transfer feature in rfbserver.c in LibVNCServer 0.9.9 and earlier allow remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary cod...Show more |
5Debian FedoraprojectLibvncserver+2 more6Debian Linux Enterprise Linux Server AusEnterprise Linux Server Eus+3 moreMay 6, 2026 Sep 30, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 Integer overflow in the MallocFrameBuffer function in vncviewer.c in LibVNCServer 0.9.9 and earlier allows remote VNC servers to cause a denial of service (crash) and possibly execute arbitrary code via an advertisement...Show more |
Buffer overflow in the HTTP transport code in apt-get in APT 1.0.1 and earlier allows man-in-the-middle attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted URL. |