Debian
debian
10,145 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,145)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian GoogleRedhat6Chrome Debian LinuxEnterprise Linux Desktop+3 moreApr 29, 2026 Dec 13, 2011 N/A· v4 N/A· v3 5.0 MEDIUM· v2 libxml2, as used in Google Chrome before 16.0.912.63, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors. |
3Canonical DebianIsc3Debian Linux DhcpUbuntu LinuxApr 29, 2026 Dec 8, 2011 N/A· v4 N/A· v3 5.0 MEDIUM· v2 dhcpd in ISC DHCP 4.x before 4.2.3-P1 and 4.1-ESV before 4.1-ESV-R4 does not properly handle regular expressions in dhcpd.conf, which allows remote attackers to cause a denial of service (daemon crash) via a crafted requ...Show more |
3Canonical DebianPhp3Debian Linux PhpUbuntu LinuxApr 29, 2026 Nov 29, 2011 N/A· v4 N/A· v3 6.4 MEDIUM· v2 Integer overflow in the exif_process_IFD_TAG function in exif.c in the exif extension in PHP 5.4.0beta2 on 32-bit platforms allows remote attackers to read the contents of arbitrary memory locations or cause a denial of...Show more |
3Debian FedoraprojectPhpmyadmin3Debian Linux FedoraPhpmyadminApr 29, 2026 Nov 17, 2011 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The simplexml_load_string function in the XML import plug-in (libraries/import/xml.php) in phpMyAdmin 3.4.x before 3.4.7.1 and 3.3.x before 3.3.10.5 allows remote authenticated users to read arbitrary files via XML data...Show more |
Heap-based buffer overflow in the Vorbis decoder in Google Chrome before 15.0.874.120 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted stream. |
Double free vulnerability in the Theora decoder in Google Chrome before 15.0.874.120 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted stream. |
4Canonical DebianLinux+1 more5Debian Linux Enterprise LinuxEnterprise Mrg+2 moreApr 29, 2026 Oct 10, 2011 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 net/core/net_namespace.c in the Linux kernel 2.6.32 and earlier does not properly handle a high rate of creation and cleanup of network namespaces, which makes it easier for remote attackers to cause a denial of service...Show more |
2Debian Fast Cgi Project2Debian Linux Fast CgiApr 29, 2026 Sep 23, 2011 N/A· v4 N/A· v3 7.5 HIGH· v2 The FCGI (aka Fast CGI) module 0.70 through 0.73 for Perl, as used by CGI::Fast, uses environment variable values from one request during processing of a later request, which allows remote attackers to bypass authenticat...Show more |
4Apple DebianGoogle+1 more8Chrome Debian LinuxEnterprise Linux Desktop+5 moreApr 29, 2026 Sep 19, 2011 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Double free vulnerability in libxml2, as used in Google Chrome before 14.0.835.163, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath handling. |
9Canonical DebianGoogle+6 more15Chrome CurlDebian Linux+12 moreApr 29, 2026 Sep 6, 2011 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initializa...Show more |
4Apple DebianGoogle+1 more8Chrome Debian LinuxEnterprise Linux Desktop+5 moreApr 29, 2026 Aug 29, 2011 N/A· v4 N/A· v3 7.5 HIGH· v2 Double free vulnerability in libxml2, as used in Google Chrome before 13.0.782.215, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted XPath expression. |
3Canonical DebianIsc3Debian Linux DhcpUbuntu LinuxApr 29, 2026 Aug 15, 2011 N/A· v4 N/A· v3 7.8 HIGH· v2 The server in ISC DHCP 3.x and 4.x before 4.2.2, 3.1-ESV before 3.1-ESV-R3, and 4.1-ESV before 4.1-ESV-R3 allows remote attackers to cause a denial of service (daemon exit) via a crafted BOOTP packet. |
3Canonical DebianIsc3Debian Linux DhcpUbuntu LinuxApr 29, 2026 Aug 15, 2011 N/A· v4 N/A· v3 7.8 HIGH· v2 The server in ISC DHCP 3.x and 4.x before 4.2.2, 3.1-ESV before 3.1-ESV-R3, and 4.1-ESV before 4.1-ESV-R3 allows remote attackers to cause a denial of service (daemon exit) via a crafted DHCP packet. |
3Apple DebianGoogle5Chrome Debian LinuxIphone Os+2 moreApr 29, 2026 Aug 3, 2011 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to display box rendering. |
3Apple DebianGoogle4Chrome Debian LinuxIphone Os+1 moreApr 29, 2026 Aug 3, 2011 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Google Chrome before 13.0.782.107 allows remote attackers to obtain potentially sensitive information about client-side redirect targets via a crafted web site. |
3Apple DebianGoogle5Chrome Debian LinuxIphone Os+2 moreApr 29, 2026 Aug 3, 2011 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Google Chrome before 13.0.782.107 does not properly track line boxes during rendering, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to...Show more |
3Canonical DebianSamba3Debian Linux SambaUbuntu LinuxApr 29, 2026 Jul 29, 2011 N/A· v4 N/A· v3 2.6 LOW· v2 Cross-site scripting (XSS) vulnerability in the chg_passwd function in web/swat.c in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allows remote authenticated administrators to inject arbitrary web...Show more |
3Canonical DebianSamba3Debian Linux SambaUbuntu LinuxApr 29, 2026 Jul 29, 2011 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Multiple cross-site request forgery (CSRF) vulnerabilities in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allow remote attackers to hijack the authentication of administrators for requests that (1...Show more |
2Debian Mod Authnz External Project2Debian Linux Mod Authnz ExternalApr 29, 2026 Jul 28, 2011 N/A· v4 N/A· v3 7.5 HIGH· v2 SQL injection vulnerability in mysql/mysql-auth.pl in the mod_authnz_external module 3.2.5 and earlier for the Apache HTTP Server allows remote attackers to execute arbitrary SQL commands via the user field. |
2Canonical Debian2Advanced Package Tool Ubuntu LinuxApr 29, 2026 Jul 27, 2011 N/A· v4 N/A· v3 4.3 MEDIUM· v2 APT before 0.8.15.2 does not properly validate inline GPG signatures, which allows man-in-the-middle attackers to install modified packages via vectors involving lack of an initial clearsigned message. |