debian
10,149 tracked vulnerabilities.
CVE-2020-35965
HIGH
FFmpeg 4.3.1 - Out-of-bounds Write in libavcodec/exr.c decode_frame
Jan 04, 2021
CVSS 7.5
EPSS 0.02
CVE-2020-12658
CRITICAL
gssproxy < 0.8.3 - Denial of Service via Improper Mutex Handling
Dec 31, 2020
CVSS 9.8
EPSS 0.02
CVE-2020-26247
LOW
Nokogiri < 1.11.0 - XML External Entity Injection via Schema Parsing
Dec 30, 2020
CVSS 2.6
EPSS 0.01
CVE-2020-35730
MEDIUM
KEV
Roundcube Webmail <1.2.13, 1.3.x<1.3.16, 1.4.x<1.4.10 XSS via linkref_addindex
Dec 28, 2020
CVSS 6.1
EPSS 0.33
CVE-2020-35738
MEDIUM
WavPack 5.3.0 - Integer Overflow to Out-of-Bounds Write in WavpackPackSamples
Dec 28, 2020
CVSS 6.1
EPSS 0.01
CVE-2020-35728
HIGH
jackson-databind 2.9.0-2.9.10.7 - Deserialization of Untrusted Data via JNDIConnectionPool
Dec 27, 2020
CVSS 8.1
EPSS 0.13
CVE-2020-28169
HIGH
td-agent-builder < 2020-12-18 - Privilege Escalation via Writable bin Directory
Dec 24, 2020
CVSS 7.0
EPSS 0.01
CVE-2020-35605
CRITICAL
kitty < 0.19.3 - Remote Code Execution via Graphics Protocol Error Message
Dec 21, 2020
CVSS 9.8
EPSS 0.04
CVE-2020-35573
HIGH
PostSRSd < 1.10 - Denial of Service via Long Timestamp Tag in SRS Address
Dec 20, 2020
CVSS 7.5
EPSS 0.03
CVE-2020-35480
MEDIUM
MediaWiki < 1.35.1 - Information Disclosure of Hidden User Accounts
Dec 18, 2020
CVSS 5.3
EPSS 0.02
CVE-2020-35479
MEDIUM
MediaWiki 1.12.0-1.35.0 - Cross-Site Scripting via BlockLogFormatter.php
Dec 18, 2020
CVSS 6.1
EPSS 0.01
CVE-2020-35477
MEDIUM
MediaWiki <1.35.1 - Info Disclosure
Dec 18, 2020
CVSS 5.3
EPSS 0.02
CVE-2020-35475
HIGH
MediaWiki < 1.35.1 - Cross-Site Scripting in UserRights Special Page
Dec 18, 2020
CVSS 7.5
EPSS 0.02
CVE-2020-35491
HIGH
jackson-databind 2.0.0-2.9.10.7 - Deserialization of Untrusted Data via SharedPoolDataSource
Dec 17, 2020
CVSS 8.1
EPSS 0.09
CVE-2020-35490
HIGH
jackson-databind 2.0.0-2.9.10.7 - Deserialization of Untrusted Data
Dec 17, 2020
CVSS 8.1
EPSS 0.08
CVE-2020-29363
HIGH
p11-kit 0.23.6-0.23.21 - Heap-Based Buffer Overflow in RPC Protocol Deserialization
Dec 16, 2020
CVSS 7.5
EPSS 0.04
CVE-2020-29361
HIGH
p11-kit 0.21.1-0.23.21 - Integer Overflow in Array Allocations
Dec 16, 2020
CVSS 7.5
EPSS 0.03
CVE-2020-26259
MEDIUM
XStream <1.4.15 - File Deletion
Dec 16, 2020
CVSS 6.8
EPSS 0.82
CVE-2020-26258
MEDIUM
NUCLEI
XStream <1.4.15 - Server-Side Request Forgery via XML Unmarshalling
Dec 16, 2020
CVSS 6.3
EPSS 0.82
CVE-2020-29486
MEDIUM
Xen < 4.14.0 - Denial of Service via Xenstore Node Ownership Quota Manipulation
Dec 15, 2020
CVSS 6.0
EPSS 0.00
CVE-2020-29485
MEDIUM
Xen 4.6-4.14.x - Denial of Service via XS_RESET_WATCHES Memory Leak
Dec 15, 2020
CVSS 5.5
EPSS 0.00
CVE-2020-29484
MEDIUM
Xen < 4.14.0 - Denial of Service via Xenstore Watch Payload Length Overflow
Dec 15, 2020
CVSS 6.0
EPSS 0.00
CVE-2020-29483
MEDIUM
Xen < 4.14.0 - Use-After-Free in Xenstored via Guest Protocol Violation
Dec 15, 2020
CVSS 6.5
EPSS 0.00
CVE-2020-29482
MEDIUM
Xen < 4.14.0 - Denial of Service via Xenstore Path Length Limit Bypass
Dec 15, 2020
CVSS 6.0
EPSS 0.00
CVE-2020-29481
HIGH
Xen < 4.14.0 - Improper Privilege Management via Xenstore Node Access Rights
Dec 15, 2020
CVSS 8.8
EPSS 0.00
Products
debian_linux 9,999
advanced_package_tool 21
dpkg 14
shadow 8
lintian 6
apt 5
devscripts 3
horde 3
reportbug 3
apt-cacher 2
aptlinex 2
cifs-utils 2
debusine 2
dpkg-dev 2
fsp 2
horde_groupware 2
mime-support 2
netkit 2
python-apt 2
python-dns 2
qpopper 2
xsabre 2
yubiserver 2
FreedomBox 1
adequate 1
amaya 1
apache 1
apache2 1
apt-listchanges 1
apt-setup 1
Quick Filters