Debian
debian
10,145 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,145)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Debian File ProjectOpensuse+2 more5Debian Linux FileLinux+2 moreMay 6, 2026 Jul 9, 2014 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The cdf_count_chain function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, does not properly validate sector-count data, which allows remote attackers to ca...Show more |
5Debian File ProjectOpensuse+2 more5Debian Linux FileLinux+2 moreMay 6, 2026 Jul 9, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The cdf_check_stream_offset function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, relies on incorrect sector-size data, which allows remote attackers to ca...Show more |
5Christos Zoulas DebianOpensuse+2 more5Debian Linux FileLinux+2 moreMay 6, 2026 Jul 9, 2014 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The cdf_read_short_sector function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows remote attackers to cause a denial of service (assertion failure and...Show more |
The phpinfo implementation in ext/standard/info.c in PHP before 5.4.30 and 5.5.x before 5.5.14 does not ensure use of the string data type for the PHP_AUTH_PW, PHP_AUTH_TYPE, PHP_AUTH_USER, and PHP_SELF variables, which...Show more |
3Christos Zoulas DebianPhp3Debian Linux FilePhpMay 6, 2026 Jul 3, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 file before 5.19 does not properly restrict the amount of data read during a regex search, which allows remote attackers to cause a denial of service (CPU consumption) via a crafted file that triggers backtracking during...Show more |
4Canonical DebianLinux+1 more6Debian Linux Linux Enterprise DesktopLinux Enterprise Real Time Extension+3 moreMay 6, 2026 Jul 3, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The sctp_association_free function in net/sctp/associola.c in the Linux kernel before 3.15.2 does not properly manage a certain backlog value, which allows remote attackers to cause a denial of service (socket outage) vi...Show more |
3Debian GnupgOpensuse3Debian Linux GnupgOpensuseMay 6, 2026 Jun 25, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The do_uncompress function in g10/compress.c in GnuPG 1.x before 1.4.17 and 2.x before 2.0.24 allows context-dependent attackers to cause a denial of service (infinite loop) via malformed compressed packets, as demonstra...Show more |
3Debian OpensusePhp3Debian Linux OpensusePhpMay 6, 2026 Jun 18, 2014 N/A· v4 N/A· v3 5.1 MEDIUM· v2 Heap-based buffer overflow in the php_parserr function in ext/standard/dns.c in PHP 5.6.0beta4 and earlier allows remote servers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted DNS...Show more |
APT before 1.0.4 does not properly validate source packages, which allows man-in-the-middle attackers to download and install Trojan horse packages by removing the Release signature. |
4Debian GnuRedhat+1 more14Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+11 moreMay 6, 2026 Jun 5, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The (1) asn1_read_value_type and (2) asn1_read_value functions in GNU Libtasn1 before 3.6 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via a NULL value in an ivalue...Show more |
5Debian F5Gnu+2 more15Arx Firmware Debian LinuxEnterprise Linux Desktop+12 moreMay 6, 2026 Jun 5, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 The asn1_get_bit_der function in GNU Libtasn1 before 3.6 does not properly report an error when a negative bit length is identified, which allows context-dependent attackers to cause out-of-bounds access via crafted ASN....Show more |
5Debian F5Gnu+2 more15Arx Firmware Debian LinuxEnterprise Linux Desktop+12 moreMay 6, 2026 Jun 5, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Multiple unspecified vulnerabilities in the DER decoder in GNU Libtasn1 before 3.6, as used in GnuTLS, allow remote attackers to cause a denial of service (out-of-bounds read) via crafted ASN.1 data. |
The cdf_read_property_info function in cdf.c in the Fileinfo component in PHP before 5.4.29 and 5.5.x before 5.5.13 allows remote attackers to cause a denial of service (infinite loop or out-of-bounds memory access) via...Show more |
The cdf_unpack_summary_info function in cdf.c in the Fileinfo component in PHP before 5.4.29 and 5.5.x before 5.5.13 allows remote attackers to cause a denial of service (performance degradation) by triggering many file_...Show more |
Multiple directory traversal vulnerabilities in dpkg-source in dpkg-dev 1.3.0 allow remote attackers to modify files outside of the intended directories via a source package with a crafted Index: pseudo-header in conjunc...Show more |
Directory traversal vulnerability in dpkg-source in dpkg-dev 1.3.0 allows remote attackers to modify files outside of the intended directories via a crafted source package that lacks a --- header line. |
dpkg 1.15.9, 1.16.x before 1.16.14, and 1.17.x before 1.17.9 expect the patch program to be compliant with a need for the "C-style encoded filenames" feature, but is supported in environments with noncompliant patch prog...Show more |
4Canonical DebianDjangoproject+1 more4Debian Linux DjangoOpensuse+1 moreMay 6, 2026 May 16, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The django.util.http.is_safe_url function in Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly validate URLs, which allows remote attackers to conduct open redirect atta...Show more |
dpkg 1.15.9 on Debian squeeze introduces support for the "C-style encoded filenames" feature without recognizing that the squeeze patch program lacks this feature, which triggers an interaction error that allows remote a...Show more |
4Canonical DebianLinux+1 more4Debian Linux LinuxLinux Kernel+1 moreMay 6, 2026 May 11, 2014 N/A· v4 N/A· v3 4.9 MEDIUM· v2 The BPF_S_ANC_NLATTR_NEST extension implementation in the sk_run_filter function in net/core/filter.c in the Linux kernel through 3.14.3 uses the reverse order in a certain subtraction, which allows local users to cause...Show more |