Debian
debian
10,145 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,145)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraLibpng+1 moreApr 29, 2026 Jul 17, 2011 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The png_handle_sCAL function in pngrutil.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 does not properly handle invalid sCAL chunks, which allows remote attackers to cau...Show more |
3Debian FedoraprojectLibpng3Debian Linux FedoraLibpngApr 29, 2026 Jul 17, 2011 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The png_err function in pngerror.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 makes a function call using a NULL pointer argument instead of an empty-string argument, w...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraLibpng+1 moreApr 29, 2026 Jul 17, 2011 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Buffer overflow in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4, when used by an application that calls the png_rgb_to_gray function but not the png_set_expand function, all...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraLibpng+1 moreApr 29, 2026 Jul 17, 2011 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The png_format_buffer function in pngerror.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 allows remote attackers to cause a denial of service (application crash) via a c...Show more |
5Debian FedoraprojectMit+2 more7Debian Linux FedoraKrb5 Appl+4 moreApr 29, 2026 Jul 11, 2011 N/A· v4 N/A· v3 6.5 MEDIUM· v2 ftpd.c in the GSS-API FTP daemon in MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.1 and earlier does not check the krb5_setegid return value, which allows remote authenticated users to bypass intended group acc...Show more |
5Apple CanonicalDebian+2 more5Debian Linux FedoraLibcurl+2 moreApr 29, 2026 Jul 7, 2011 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The Curl_input_negotiate function in http_negotiate.c in libcurl 7.10.6 through 7.21.6, as used in curl and other products, always performs credential delegation during GSSAPI authentication, which allows remote servers...Show more |
5Apache AppleCanonical+2 more5Debian Linux FedoraMac Os X+2 moreApr 29, 2026 Jun 6, 2011 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit option is enabled, allows remote attackers to cause a denial of se...Show more |
5Apache AppleCanonical+2 more5Debian Linux FedoraMac Os X+2 moreApr 29, 2026 Jun 6, 2011 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.17, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request for a b...Show more |
Google Chrome before 11.0.696.68 does not properly perform casts of variables during interaction with the WebKit engine, which allows remote attackers to cause a denial of service or possibly have unspecified other impac...Show more |
9Apache AppleDebian+6 more10Android Debian LinuxFreebsd+7 moreApr 29, 2026 May 16, 2011 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apache HTTP Server before 2.2.18, and in fnmatch.c in libc in NetBSD 5.1, O...Show more |
Race condition in the sandbox launcher implementation in Google Chrome before 11.0.696.57 on Linux allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors. |
3Apple DebianGoogle4Chrome Debian LinuxItunes+1 moreApr 29, 2026 May 3, 2011 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Use-after-free vulnerability in Google Chrome before 11.0.696.57 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the ruby element and Cascading Style...Show more |
acl.c in Tinyproxy before 1.8.3, when an Allow configuration setting specifies a CIDR block, permits TCP connections from all IP addresses, which makes it easier for remote attackers to hide the origin of web traffic by...Show more |
3Canonical DebianIsc3Debian Linux DhcpUbuntu LinuxApr 29, 2026 Apr 8, 2011 N/A· v4 N/A· v3 7.5 HIGH· v2 dhclient in ISC DHCP 3.0.x through 4.2.x before 4.2.1-P1, 3.1-ESV before 3.1-ESV-R1, and 4.1-ESV before 4.1-ESV-R2 allows remote attackers to execute arbitrary commands via shell metacharacters in a hostname obtained fro...Show more |
2Debian Mpm Itk Project2Debian Linux Mpm ItkApr 29, 2026 Mar 29, 2011 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The configuration merger in itk.c in the Steinar H. Gunderson mpm-itk Multi-Processing Module 2.2.11-01 and 2.2.11-02 for the Apache HTTP Server does not properly handle certain configuration sections that specify NiceVa...Show more |
2Canonical Debian3Debian Linux Tex CommonUbuntu LinuxApr 29, 2026 Mar 25, 2011 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The default configuration of the shell_escape_commands directive in conf/texmf.d/95NonPath.cnf in the tex-common package before 2.08.1 in Debian GNU/Linux squeeze, Ubuntu 10.10 and 10.04 LTS, and possibly other operating...Show more |
3Apple DebianGoogle5Chrome Debian LinuxIphone Os+2 moreApr 29, 2026 Mar 25, 2011 N/A· v4 N/A· v3 7.5 HIGH· v2 Use-after-free vulnerability in the HTMLCollection implementation in Google Chrome before 10.0.648.204 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors. |
Use-after-free vulnerability in the frame-loader implementation in Google Chrome before 10.0.648.204 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors. |
6Canonical DebianFedoraproject+3 more6Debian Linux FedoraLinux Enterprise Server+3 moreApr 29, 2026 Mar 2, 2011 N/A· v4 N/A· v3 4.0 MEDIUM· v2 The vsf_filename_passes_filter function in ls.c in vsftpd before 2.3.3 allows remote authenticated users to cause a denial of service (CPU consumption and process slot exhaustion) via crafted glob expressions in STAT com...Show more |
5Avahi CanonicalDebian+2 more5Avahi Debian LinuxEnterprise Linux+2 moreApr 29, 2026 Feb 22, 2011 N/A· v4 N/A· v3 5.0 MEDIUM· v2 avahi-core/socket.c in avahi-daemon in Avahi before 0.6.29 allows remote attackers to cause a denial of service (infinite loop) via an empty mDNS (1) IPv4 or (2) IPv6 UDP packet to port 5353. NOTE: this vulnerability ex...Show more |