Debian
debian
10,145 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,145)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The default configuration in cURL and libcurl 7.10.6 before 7.36.0 re-uses (1) SCP, (2) SFTP, (3) POP3, (4) POP3S, (5) IMAP, (6) IMAPS, (7) SMTP, (8) SMTPS, (9) LDAP, and (10) LDAPS connections, which might allow context...Show more |
2Debian Trustwave2Debian Linux ModsecurityMay 6, 2026 Apr 15, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 apache2/modsecurity.c in ModSecurity before 2.7.6 allows remote attackers to bypass rules by using chunked transfer coding with a capitalized Chunked value in the Transfer-Encoding HTTP header. |
2Debian Linux2Debian Linux Linux KernelMay 6, 2026 Apr 14, 2014 N/A· v4 N/A· v3 6.9 MEDIUM· v2 Integer overflow in the ping_init_sock function in net/ipv4/ping.c in the Linux kernel through 3.14.1 allows local users to cause a denial of service (use-after-free and system crash) or possibly gain privileges via a cr...Show more |
Buffer overflow in the GetStatistics64 remote procedure call (RPC) in OpenAFS 1.4.8 before 1.6.7 allows remote attackers to cause a denial of service (crash) via a crafted statsVersion argument. |
3Debian GoogleOpensuse3Chrome Debian LinuxOpensuseMay 6, 2026 Apr 9, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 Cross-site scripting (XSS) vulnerability in the Runtime_SetPrototype function in runtime.cc in Google V8, as used in Google Chrome before 34.0.1847.116, allows remote attackers to inject arbitrary web script or HTML via...Show more |
13Broadcom CanonicalDebian+10 more28Application Processing Engine Firmware Cp 1543 1 FirmwareDebian Linux+25 moreApr 21, 2026 Apr 7, 2014 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted pa...Show more |
4Cacti DebianFedoraproject+1 more4Cacti Debian LinuxFedora+1 moreMay 6, 2026 Mar 27, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in cdef.php in Cacti 0.8.7g, 0.8.8b, and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
3Christos Zoulas DebianPhp3Debian Linux FilePhpMay 6, 2026 Mar 24, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The BEGIN regular expression in the awk script detector in magic/Magdir/commands in file before 5.15 uses multiple wildcards with unlimited repetitions, which allows context-dependent attackers to cause a denial of servi...Show more |
6Canonical DebianOracle+3 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+9 moreMay 6, 2026 Mar 21, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The gdImageCreateFromXpm function in gdxpm.c in libgd, as used in PHP 5.4.26 and earlier, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted color table in...Show more |
Multiple SQL injection vulnerabilities in MantisBT before 1.2.16 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to the (1) mc_project_get_attachments function in api/soap/mc_project_a...Show more |
6Canonical DebianMozilla+3 more16Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+13 moreMay 6, 2026 Mar 19, 2014 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 vmtypedarrayobject.cpp in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 does not validate the length of the destination array before a copy operation, which...Show more |
6Canonical DebianMozilla+3 more16Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+13 moreMay 6, 2026 Mar 19, 2014 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 TypedArrayObject.cpp in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 does not prevent a zero-length transition during use of an ArrayBuffer object, which a...Show more |
6Canonical DebianMozilla+3 more16Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+13 moreMay 6, 2026 Mar 19, 2014 N/A· v4 N/A· v3 10.0 HIGH· v2 Use-after-free vulnerability in the TypeObject class in the JavaScript engine in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to ex...Show more |
6Canonical DebianMozilla+3 more16Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+13 moreMay 6, 2026 Mar 19, 2014 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to bypass the popup blocker via unspecified vectors. |
6Canonical DebianMozilla+3 more16Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+13 moreMay 6, 2026 Mar 19, 2014 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to execute arbitrary JavaScript code with chrome privile...Show more |
6Canonical DebianMozilla+3 more16Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+13 moreMay 6, 2026 Mar 19, 2014 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 The libxul.so!gfxContext::Polygon function in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive information from pro...Show more |
7Canonical DebianMozilla+4 more16Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+13 moreMay 6, 2026 Mar 19, 2014 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The SVG filter implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive displacement-correlation informat...Show more |
6Canonical DebianMozilla+3 more16Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+13 moreMay 6, 2026 Mar 19, 2014 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The mozilla::WaveReader::DecodeAudioData function in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive information f...Show more |
6Canonical DebianMozilla+3 more16Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+13 moreMay 6, 2026 Mar 19, 2014 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to cause a denial of serv...Show more |
SQL injection vulnerability in the mci_file_get function in api/soap/mc_file_api.php in MantisBT before 1.2.16 allows remote attackers to execute arbitrary SQL commands via a crafted envelope tag in a mc_issue_attachment...Show more |