Debian
debian
10,145 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,145)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical DebianMozilla+1 more7Debian Linux FirefoxOpensuse+4 moreApr 29, 2026 Feb 19, 2013 N/A· v4 N/A· v3 9.3 HIGH· v2 The Chrome Object Wrapper (COW) and System Only Wrapper (SOW) implementations in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey b...Show more |
3Debian FedoraprojectZend3Debian Linux FedoraZend FrameworkApr 29, 2026 Feb 13, 2013 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows remote attackers to read arbitrary files or create TCP connections via an external...Show more |
7Canonical DebianFedoraproject+4 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+9 moreApr 29, 2026 Feb 13, 2013 N/A· v4 N/A· v3 9.3 HIGH· v2 Buffer overflow in the e1000_receive function in the e1000 device driver (hw/e1000.c) in QEMU 1.3.0-rc2 and other versions, when the SBP and LPE flags are disabled, allows remote attackers to cause a denial of service (g...Show more |
2Debian Rubyonrails3Debian Linux RailsRuby On RailsApr 29, 2026 Jan 13, 2013 N/A· v4 N/A· v3 7.5 HIGH· v2 active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly restrict casts of string values, which allows remote attacke...Show more |
2Debian Rubyonrails3Debian Linux RailsRuby On RailsApr 29, 2026 Jan 13, 2013 N/A· v4 N/A· v3 6.4 MEDIUM· v2 Ruby on Rails 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows r...Show more |
The file upload feature in Drupal 6.x before 6.27 and 7.x before 7.18 allows remote authenticated users to bypass the protection mechanism and execute arbitrary PHP code via a null byte in a file name. |
Apt 0.8.16~exp5ubuntu13.x before 0.8.16~exp5ubuntu13.6, 0.8.16~exp12ubuntu10.x before 0.8.16~exp12ubuntu10.7, and 0.9.7.5ubuntu5.x before 0.9.7.5ubuntu5.2, as used in Ubuntu, uses world-readable permissions for /var/log/...Show more |
2Debian Mahara2Debian Linux MaharaApr 29, 2026 Nov 24, 2012 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Mahara 1.4.x before 1.4.4 and 1.5.x before 1.5.3 allows remote attackers to read arbitrary files or create TCP connections via an XML external entity (XXE) injection attack, as demonstrated by reading config.php. |
7Canonical DebianOpensuse+4 more13Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+10 moreApr 29, 2026 Nov 23, 2012 N/A· v4 N/A· v3 7.2 HIGH· v2 Qemu, as used in Xen 4.0, 4.1 and possibly other products, when emulating certain devices with a virtual console backend, allows local OS guest users to gain privileges via a crafted escape VT100 sequence that triggers t...Show more |
6Canonical DebianMozilla+3 more14Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+11 moreApr 29, 2026 Nov 21, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allow re...Show more |
6Canonical DebianMozilla+3 more14Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+11 moreApr 29, 2026 Nov 21, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 Heap-based buffer overflow in the nsWindow::OnExposeEvent function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14...Show more |
6Canonical DebianMozilla+3 more14Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+11 moreApr 29, 2026 Nov 21, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 Use-after-free vulnerability in the gfxFont::GetFontEntry function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14...Show more |
6Canonical DebianMozilla+3 more14Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+11 moreApr 29, 2026 Nov 21, 2012 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The HZ-GB-2312 character-set implementation in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 does not properly handl...Show more |
6Canonical DebianMozilla+3 more14Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+11 moreApr 29, 2026 Nov 21, 2012 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The evalInSandbox implementation in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 uses an incorrect context during t...Show more |
Cross-site scripting (XSS) vulnerability in the "extra" details in the DiffSource._get_row function in lib/viewvc.py in ViewVC 1.0.x before 1.0.13 and 1.1.x before 1.1.16 allows remote authenticated users with repository...Show more |
5Canonical DebianLibtiff+2 more8Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+5 moreApr 29, 2026 Nov 11, 2012 N/A· v4 N/A· v3 6.8 MEDIUM· v2 ppm2tiff does not check the return value of the TIFFScanlineSize function, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PPM image that triggers an i...Show more |
5Canonical DebianMariadb+2 more8Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+5 moreApr 29, 2026 Oct 17, 2012 N/A· v4 N/A· v3 3.5 LOW· v2 Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.64 and earlier, and 5.5.26 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Replicati...Show more |
5Canonical DebianMariadb+2 more8Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+5 moreApr 29, 2026 Oct 17, 2012 N/A· v4 N/A· v3 4.0 MEDIUM· v2 Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.65 and earlier, and 5.5.27 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer...Show more |
5Canonical DebianMariadb+2 more9Debian Linux Enterprise LinuxEnterprise Linux Desktop+6 moreApr 29, 2026 Oct 17, 2012 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.65 and earlier, and 5.5.27 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server. |
5Canonical DebianMariadb+2 more8Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+5 moreApr 29, 2026 Oct 17, 2012 N/A· v4 N/A· v3 4.0 MEDIUM· v2 Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.63 and earlier, and 5.5.25 and earlier, allows remote authenticated users to affect availability via unknown vectors related to InnoDB Plugin. |