Debian
debian
10,145 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,145)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
libclamav in ClamAV before 0.94 allows attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors related to an out-of-memory condition. |
migrate_aliases.sh in Citadel Server 7.37 allows local users to overwrite arbitrary files via a symlink attack on a temporary file. |
test.sh in Honeyd 1.5c might allow local users to overwrite arbitrary files via a symlink attack on a temporary file. |
6Canonical DebianLinux+3 more7Debian Linux Linux DesktopLinux Kernel+4 moreApr 23, 2026 Sep 4, 2008 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 fs/direct-io.c in the dio subsystem in the Linux kernel before 2.6.23 does not properly zero out the dio struct, which allows local users to cause a denial of service (OOPS), as demonstrated by a certain fio test. |
7Apple CanonicalDebian+4 more11Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+8 moreApr 23, 2026 Aug 27, 2008 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafte...Show more |
4Canonical DebianLinux+1 more5Debian Linux Linux KernelSuse Linux Enterprise Desktop+2 moreApr 23, 2026 Aug 12, 2008 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 The (1) real_lookup and (2) __lookup_hash functions in fs/namei.c in the vfs implementation in the Linux kernel before 2.6.25.15 do not prevent creation of a child dentry for a deleted (aka S_DEAD) directory, which allow...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxApr 23, 2026 Aug 8, 2008 N/A· v4 N/A· v3 4.9 MEDIUM· v2 Off-by-one error in the iov_iter_advance function in mm/filemap.c in the Linux kernel before 2.6.27-rc2 allows local users to cause a denial of service (system crash) via a certain sequence of file I/O operations with re...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxApr 23, 2026 Aug 8, 2008 N/A· v4 N/A· v3 4.9 MEDIUM· v2 The shmem_delete_inode function in mm/shmem.c in the tmpfs implementation in the Linux kernel before 2.6.26.1 allows local users to cause a denial of service (system crash) via a certain sequence of file create, remove,...Show more |
6Canonical DebianOpensuse+3 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+6 moreApr 23, 2026 Aug 8, 2008 N/A· v4 N/A· v3 2.1 LOW· v2 QEMU 0.9.0 does not properly handle changes to removable media, which allows guest OS users to read arbitrary files on the host OS by using the diskformat: parameter in the -usbdevice option to modify the disk-image head...Show more |
4Canonical DebianLinux+1 more7Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+4 moreApr 23, 2026 Aug 8, 2008 N/A· v4 N/A· v3 2.1 LOW· v2 The snd_seq_oss_synth_make_info function in sound/core/seq/oss/seq_oss_synth.c in the sound subsystem in the Linux kernel before 2.6.27-rc2 does not verify that the device number is within the range defined by max_synthd...Show more |
3Canonical DebianPython3Debian Linux PythonUbuntu LinuxApr 23, 2026 Aug 1, 2008 N/A· v4 N/A· v3 7.5 HIGH· v2 Multiple buffer overflows in Python 2.5.2 and earlier on 32bit platforms allow context-dependent attackers to cause a denial of service (crash) or have unspecified other impact via a long string that leads to incorrect m...Show more |
Cross-site scripting (XSS) vulnerability in services/obrowser/index.php in Horde 3.2 and Turba 2.2 allows remote attackers to inject arbitrary web script or HTML via the contact name. |
Cross-site request forgery (CSRF) vulnerability in Moodle 1.6.x before 1.6.7 and 1.7.x before 1.7.5 allows remote attackers to modify profile settings and gain privileges as other users via a link or IMG tag to the user...Show more |
The save function in br/prefmanager.d in projectl 1.001 creates a projectL.prf file in the current working directory, which allows local users to overwrite arbitrary files via a symlink attack. |
5Canonical DebianLinux+2 more6Debian Linux Linux KernelOpensuse+3 moreApr 23, 2026 Jul 9, 2008 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The do_change_type function in fs/namespace.c in the Linux kernel before 2.6.22 does not verify that the caller has the CAP_SYS_ADMIN capability, which allows local users to gain privileges or cause a denial of service b...Show more |
7Avaya CanonicalDebian+4 more15Communication Manager Debian LinuxExpanded Meet Me Conferencing+12 moreApr 23, 2026 Jul 9, 2008 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The Linux kernel before 2.6.25.10 does not properly perform tty operations, which allows local users to cause a denial of service (system crash) or possibly gain privileges via vectors involving NULL pointer dereference...Show more |
6Canonical DebianFedoraproject+3 more6Debian Linux FedoraOpensuse+3 moreApr 23, 2026 Jul 7, 2008 N/A· v4 N/A· v3 7.5 HIGH· v2 Heap-based buffer overflow in pcre_compile.c in the Perl-Compatible Regular Expression (PCRE) library 7.7 allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a r...Show more |
4Canonical DebianLinux+1 more4Debian Linux Linux KernelOpensuse+1 moreApr 23, 2026 Jul 2, 2008 N/A· v4 N/A· v3 4.9 MEDIUM· v2 Integer overflow in the sctp_getsockopt_local_addrs_old function in net/sctp/socket.c in the Stream Control Transmission Protocol (sctp) functionality in the Linux kernel before 2.6.25.9 allows local users to cause a den...Show more |
3Canonical DebianRuby Lang3Debian Linux RubyUbuntu LinuxApr 23, 2026 Jun 24, 2008 N/A· v4 N/A· v3 7.8 HIGH· v2 Integer overflow in the (1) rb_ary_splice function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 before 1.8.7-p22, and 1.9.0 before 1.9.0-2; and (2) the rb_ary_replace function in 1.6...Show more |
3Canonical DebianRuby Lang3Debian Linux RubyUbuntu LinuxApr 23, 2026 Jun 24, 2008 N/A· v4 N/A· v3 7.8 HIGH· v2 Integer overflow in the (1) rb_ary_splice function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, and 1.8.7 before 1.8.7-p22; and (2) the rb_ary_replace function in 1.6.x allows context-depe...Show more |