Debian
debian
10,145 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,145)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical DebianRuby Lang3Debian Linux RubyUbuntu LinuxApr 23, 2026 Jun 24, 2008 N/A· v4 N/A· v3 7.8 HIGH· v2 The rb_str_format function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 before 1.8.7-p22, and 1.9.0 before 1.9.0-2 allows context-dependent attackers to trigger memory corruption via...Show more |
3Canonical DebianRuby Lang3Debian Linux RubyUbuntu LinuxApr 23, 2026 Jun 24, 2008 N/A· v4 N/A· v3 10.0 HIGH· v2 Multiple integer overflows in the rb_ary_store function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, and 1.8.7 before 1.8.7-p22 allow context-dependent attackers to execute arbitrary code...Show more |
3Canonical DebianRuby Lang3Debian Linux RubyUbuntu LinuxApr 23, 2026 Jun 24, 2008 N/A· v4 N/A· v3 10.0 HIGH· v2 Multiple integer overflows in the rb_str_buf_append function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 before 1.8.7-p22, and 1.9.0 before 1.9.0-2 allow context-dependent attackers...Show more |
2Debian Linux2Debian Linux Linux KernelApr 23, 2026 Jun 10, 2008 N/A· v4 N/A· v3 10.0 HIGH· v2 The asn1 implementation in (a) the Linux kernel 2.4 before 2.4.36.6 and 2.6 before 2.6.25.5, as used in the cifs and ip_nat_snmp_basic modules; and (b) the gxsnmp package; does not properly validate length values during...Show more |
2Debian Linux2Debian Linux Linux KernelApr 23, 2026 May 29, 2008 N/A· v4 N/A· v3 4.4 MEDIUM· v2 The (1) sparc_mmap_check function in arch/sparc/kernel/sys_sparc.c and the (2) sparc64_mmap_check function in arch/sparc64/kernel/sys_sparc.c, in the Linux kernel 2.4 before 2.4.36.5 and 2.6 before 2.6.25.3, omit some vi...Show more |
3Canonical DebianSamba3Debian Linux SambaUbuntu LinuxApr 23, 2026 May 29, 2008 N/A· v4 N/A· v3 7.5 HIGH· v2 Heap-based buffer overflow in the receive_smb_raw function in util/sock.c in Samba 3.0.0 through 3.0.29 allows remote attackers to execute arbitrary code via a crafted SMB response. |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxApr 23, 2026 May 16, 2008 N/A· v4 N/A· v3 7.8 HIGH· v2 Memory leak in the ipip6_rcv function in net/ipv6/sit.c in the Linux kernel 2.4 before 2.4.36.5 and 2.6 before 2.6.25.3 allows remote attackers to cause a denial of service (memory consumption) via network traffic to a S...Show more |
3Canonical DebianOpenssl3Debian Linux OpensslUbuntu LinuxApr 23, 2026 May 13, 2008 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that generates predictable numbers, which makes it easier for remote attackers to conduct brute force guess...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraPhp+1 moreApr 23, 2026 May 7, 2008 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The GENERATE_SEED macro in PHP 4.x before 4.4.8 and 5.x before 5.2.5, when running on 64-bit systems, performs a multiplication that generates a portion of zero bits during conversion due to insufficient precision, which...Show more |
4Canonical DebianMysql+1 more4Debian Linux MysqlMysql+1 moreApr 23, 2026 May 5, 2008 N/A· v4 N/A· v3 4.6 MEDIUM· v2 MySQL 4.1.x before 4.1.24, 5.0.x before 5.0.60, 5.1.x before 5.1.24, and 6.0.x before 6.0.5 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY...Show more |
6Canonical DebianFedoraproject+3 more8Debian Linux FedoraLinux Enterprise Desktop+5 moreApr 23, 2026 May 2, 2008 N/A· v4 N/A· v3 6.9 MEDIUM· v2 Race condition in the directory notification subsystem (dnotify) in Linux kernel 2.6.x before 2.6.24.6, and 2.6.25 before 2.6.25.1, allows local users to cause a denial of service (OOPS) and possibly gain privileges via...Show more |
The GUI for aptlinex before 0.91 does not sufficiently warn the user of potentially dangerous actions, which allows remote attackers to remove or modify packages via an apt:// URL. |
aptlinex before 0.91 allows local users to overwrite arbitrary files via a symlink attack on the gambas-apt.lock temporary file. |
3Canonical DebianPython3Debian Linux PythonUbuntu LinuxApr 23, 2026 Apr 18, 2008 N/A· v4 N/A· v3 9.3 HIGH· v2 Python 2.5.2 and earlier allows context-dependent attackers to execute arbitrary code via multiple vectors that cause a negative size value to be provided to the PyString_FromStringAndSize function, which allocates less...Show more |
tss 0.8.1 allows local users to read arbitrary files via the -a parameter, which is processed while tss is running with privileges. |
3Canonical DebianPython3Debian Linux PythonUbuntu LinuxApr 23, 2026 Apr 10, 2008 N/A· v4 N/A· v3 7.5 HIGH· v2 Integer signedness error in the zlib extension module in Python 2.5.2 and earlier allows remote attackers to execute arbitrary code via a negative signed integer, which triggers insufficient memory allocation and a buffe...Show more |
4Debian FedoraprojectOpensuse+1 more4Debian Linux FedoraOpensuse+1 moreApr 23, 2026 Mar 31, 2008 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secret key, in cleartext in a Session file under /tmp, which allows local users to obtain sensitive information. |
2Debian Lighttpd2Debian Linux LighttpdApr 23, 2026 Mar 27, 2008 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The connection_state_machine function (connections.c) in lighttpd 1.4.19 and earlier, and 1.5.x before 1.5.0, allows remote attackers to cause a denial of service (active SSL connection loss) by triggering an SSL error,...Show more |
7Apple CanonicalDebian+4 more11Debian Linux FedoraKerberos 5+8 moreApr 23, 2026 Mar 19, 2008 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, which might allow remote attackers to obtain sensitive information, aka "...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraKerberos 5+1 moreApr 23, 2026 Mar 19, 2008 N/A· v4 9.8 CRITICAL· v3 9.3 HIGH· v2 KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 message types, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted messages that...Show more |