Debian
debian
10,145 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,145)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Apple CanonicalDebian+1 more4Debian Linux Mac Os XUbuntu Linux+1 moreMay 1, 2025 Mar 17, 2008 N/A· v4 N/A· v3 9.3 HIGH· v2 The NEEDBITS macro in the inflate_dynamic function in inflate.c for unzip can be invoked using invalid buffers, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via u...Show more |
scponly 4.6 and earlier allows remote authenticated users to bypass intended restrictions and execute arbitrary code by invoking scp, as implemented by OpenSSH, with the -F and -o options. |
7Apple CanonicalDebian+4 more11Debian Linux FedoraLinux+8 moreApr 23, 2026 Jan 18, 2008 N/A· v4 N/A· v3 9.3 HIGH· v2 The XInput extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to execute arbitrary code via requests related to byte swapping and heap corruption within multiple functions, a different vulnerabili...Show more |
Untrusted search path vulnerability in apt-listchanges.py in apt-listchanges before 2.82 allows local users to execute arbitrary code via a malicious apt-listchanges program in the current working directory. |
3Debian MandrakesoftRedhat4Debian Linux FedoraMandrake Linux+1 moreApr 23, 2026 Jan 12, 2008 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The xmlCurrentChar function in libxml2 before 2.6.31 allows context-dependent attackers to cause a denial of service (infinite loop) via XML containing invalid UTF-8 sequences. |
6Apple CanonicalDebian+3 more6Debian Linux Mac Os XMysql+3 moreApr 23, 2026 Jan 10, 2008 N/A· v4 N/A· v3 7.5 HIGH· v2 Multiple buffer overflows in yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allow remote attackers to execute arbitrary code via (1) the ProcessOldClientHello function in handshake.cpp or (2) "inp...Show more |
3Debian FedoraprojectPostgresql3Debian Linux FedoraPostgresqlApr 23, 2026 Jan 9, 2008 N/A· v4 N/A· v3 7.2 HIGH· v2 The DBLink module in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, 7.4 before 7.4.19, and 7.3 before 7.3.21, when local trust or ident authentication is used, allows remote attackers to gain privileg...Show more |
4Canonical DebianPostgresql+1 more4Debian Linux PostgresqlTcl/tk+1 moreApr 23, 2026 Jan 9, 2008 N/A· v4 N/A· v3 4.0 MEDIUM· v2 The regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows context-dependent attackers to cause a denial of service (in...Show more |
Race condition in fileserver in OpenAFS 1.3.50 through 1.4.5 and 1.5.0 through 1.5.27 allows remote attackers to cause a denial of service (daemon crash) by simultaneously acquiring and giving back file callbacks, which...Show more |
unp 1.0.12, and other versions before 1.0.14, does not properly escape file names, which might allow context-dependent attackers to execute arbitrary commands via shell metacharacters in a filename argument. NOTE: this m...Show more |
3Canonical DebianExiv23Debian Linux Exiv2Ubuntu LinuxApr 23, 2026 Dec 20, 2007 N/A· v4 N/A· v3 7.5 HIGH· v2 Integer overflow in exif.cpp in exiv2 library allows context-dependent attackers to execute arbitrary code via a crafted EXIF file that triggers a heap-based buffer overflow. |
The libdspam7-drv-mysql cron job in Debian GNU/Linux includes the MySQL dspam database password in a command line argument, which might allow local users to read the password by listing the process and its arguments. |
6Canonical DebianLinux+3 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+9 moreApr 23, 2026 Dec 4, 2007 N/A· v4 N/A· v3 2.1 LOW· v2 The do_coredump function in fs/exec.c in Linux kernel 2.4.x and 2.6.x up to 2.6.24-rc3, and possibly other versions, does not change the UID of a core dump file if it exists before a root process creates a core dump in t...Show more |
SQL injection vulnerability in the Call Detail Record Postgres logging engine (cdr_pgsql) in Asterisk 1.4.x before 1.4.15, 1.2.x before 1.2.25, B.x before B.2.3.4, and C.x before C.1.0-beta6 allows remote authenticated u...Show more |
Heap-based buffer overflow in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to execute arbitrary code via crafted data in the "net socket listen" option, aka QEMU "net socket" heap overflow....Show more |
3Debian OpensuseQemu3Debian Linux OpensuseQemuApr 23, 2026 Oct 30, 2007 N/A· v4 N/A· v3 7.2 HIGH· v2 The NE2000 emulator in QEMU 0.8.2 allows local users to execute arbitrary code by writing Ethernet frames with a size larger than the MTU to the EN0_TCNT register, which triggers a heap-based buffer overflow in the slirp...Show more |
3Debian FedoraprojectQemu4Debian Linux FedoraFedora Core+1 moreApr 23, 2026 Oct 30, 2007 N/A· v4 N/A· v3 7.2 HIGH· v2 Integer signedness error in the NE2000 emulator in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to trigger a heap-based buffer overflow via certain register values that bypass sanity checks,...Show more |
5Debian OpenbsdRedhat+2 more7Debian Linux Enterprise LinuxLinux Advanced Workstation+4 moreApr 23, 2026 Oct 11, 2007 N/A· v4 N/A· v3 7.2 HIGH· v2 Stack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 through 4.2, and some other dhcpd implementations based on ISC dhcp-2, allows remote attackers to execute arbitrary code or ca...Show more |
guilt 0.27 allows local users to overwrite arbitrary files via a symlink attack on a guilt.log.[PID] temporary file. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLoop Aes Utils+2 moreApr 23, 2026 Oct 4, 2007 N/A· v4 N/A· v3 7.2 HIGH· v2 mount and umount in util-linux and loop-aes-utils call the setuid and setgid functions in the wrong order and do not check the return values, which might allow attackers to gain privileges via helpers such as mount.nfs. |