Debian
debian
10,145 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,145)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Apache CanonicalDebian+1 more5Debian Linux OpenofficeStaroffice+2 moreApr 23, 2026 Sep 18, 2007 N/A· v4 N/A· v3 9.3 HIGH· v2 Integer overflow in the TIFF parser in OpenOffice.org (OOo) before 2.3; and Sun StarOffice 6, 7, and 8 Office Suite (StarSuite); allows remote attackers to execute arbitrary code via a TIFF file with crafted values of un...Show more |
checkrestart in debian-goodies before 0.34 allows local users to gain privileges via shell metacharacters in the name of the executable file for a running process. |
reprepro 1.3.0 through 2.2.3 does not properly verify signatures when updating repositories, which allows remote attackers to construct and distribute an ostensibly valid Release.gpg file by signing it with an unknown ke...Show more |
3Canonical DebianGnu3Debian Linux TarUbuntu LinuxApr 23, 2026 Sep 5, 2007 N/A· v4 N/A· v3 7.5 HIGH· v2 Buffer overflow in the safer_name_suffix function in GNU tar has unspecified attack vectors and impact, resulting in a "crashing stack." |
3Canonical DebianPhp3Debian Linux PhpUbuntu LinuxApr 23, 2026 Sep 4, 2007 N/A· v4 N/A· v3 7.5 HIGH· v2 Multiple integer overflows in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, allow remote attackers to obtain sensitive information (memory contents) or cause a denial of service (thread crash) via a large len value to the...Show more |
3Canonical DebianPhp3Debian Linux PhpUbuntu LinuxApr 23, 2026 Sep 4, 2007 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The wordwrap function in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, does not properly use the breakcharlen variable, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash...Show more |
6Apple CanonicalDebian+3 more6Cups Debian LinuxGpdf+3 moreApr 23, 2026 Jul 30, 2007 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3.02, as used in (1) poppler before 0.5.91, (2) gpdf before 2.8.2, (3) kpdf, (4) kdegraphics, (5) CUPS, (6) PDFedit, and other products, might all...Show more |
6Apple CanonicalDebian+3 more7Debian Linux FreebsdMac Os X+4 moreApr 23, 2026 Jul 16, 2007 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via crafted TLVs in a BGP packet, related to an unchecked return value. |
gfax 0.4.2 and probably other versions creates temporary files insecurely, which allows local users to execute arbitrary commands via unknown vectors. |
3Canonical DebianMit3Debian Linux Kerberos 5Ubuntu LinuxApr 23, 2026 Jun 26, 2007 N/A· v4 N/A· v3 9.0 HIGH· v2 Stack-based buffer overflow in the rename_principal_2_svc function in kadmind for MIT Kerberos 1.5.3, 1.6.1, and other versions allows remote authenticated users to execute arbitrary code via a crafted request to rename...Show more |
3Canonical DebianMit3Debian Linux Kerberos 5Ubuntu LinuxApr 23, 2026 Jun 26, 2007 N/A· v4 N/A· v3 8.3 HIGH· v2 Integer signedness error in the gssrpc__svcauth_unix function in svc_auth_unix.c in the RPC library in MIT Kerberos 5 (krb5) 1.6.1 and earlier might allow remote attackers to execute arbitrary code via a negative length...Show more |
3Canonical DebianMit3Debian Linux Kerberos 5Ubuntu LinuxApr 23, 2026 Jun 26, 2007 N/A· v4 N/A· v3 10.0 HIGH· v2 The gssrpc__svcauth_gssapi function in the RPC library in MIT Kerberos 5 (krb5) 1.6.1 and earlier might allow remote attackers to execute arbitrary code via a zero-length RPC credential, which causes kadmind to free an u...Show more |
3Canonical DebianNet Dns3Debian Linux Net\Ubuntu LinuxApr 23, 2026 Jun 26, 2007 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 Net::DNS before 0.60, a Perl module, allows remote attackers to cause a denial of service (stack consumption) via a malformed compressed DNS packet with self-referencing pointers, which triggers an infinite loop. |
Emacs 21 allows user-assisted attackers to cause a denial of service (crash) via certain crafted images, as demonstrated via a GIF image in vm mode, related to image size calculation. |
2Debian Postgresql2Debian Linux PostgresqlApr 23, 2026 Jun 19, 2007 N/A· v4 N/A· v3 6.9 MEDIUM· v2 PostgreSQL 8.1 and probably later versions, when local trust authentication is enabled and the Database Link library (dblink) is installed, allows remote attackers to access arbitrary accounts and execute arbitrary SQL q...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxApr 23, 2026 Jun 11, 2007 N/A· v4 N/A· v3 2.1 LOW· v2 Integer underflow in the cpuset_tasks_read function in the Linux kernel before 2.6.20.13, and 2.6.21.x before 2.6.21.4, when the cpuset filesystem is mounted, allows local users to obtain kernel memory contents by using...Show more |
3Canonical DebianMysql3Debian Linux MysqlUbuntu LinuxApr 23, 2026 May 16, 2007 N/A· v4 N/A· v3 4.9 MEDIUM· v2 MySQL before 4.1.23, 5.0.x before 5.0.42, and 5.1.x before 5.1.18 does not require the DROP privilege for RENAME TABLE statements, which allows remote authenticated users to rename arbitrary tables. |
The OLE2 parser in Clam AntiVirus (ClamAV) allows remote attackers to cause a denial of service (resource consumption) via an OLE2 file with (1) a large property size or (2) a loop in the FAT file block chain that trigge...Show more |
3Canonical DebianSamba3Debian Linux SambaUbuntu LinuxApr 23, 2026 May 14, 2007 N/A· v4 N/A· v3 7.2 HIGH· v2 Logic error in the SID/Name translation functionality in smbd in Samba 3.0.23d through 3.0.25pre2 allows local users to gain temporary privileges and execute SMB/CIFS protocol operations via unspecified vectors that caus...Show more |
3Canonical DebianOracle3Debian Linux MysqlUbuntu LinuxApr 23, 2026 May 10, 2007 N/A· v4 N/A· v3 4.0 MEDIUM· v2 The in_decimal::set function in item_cmpfunc.cc in MySQL before 5.0.40, and 5.1 before 5.1.18-beta, allows context-dependent attackers to cause a denial of service (crash) via a crafted IF clause that results in a divide...Show more |