Vulnerabilities (CVE)

Vendor filter

Debian Subscribe

Product filter

Debian Linux Subscribe

Filter

3204 total CVE
CVE Vendors Products Updated CVSS
CVE-2019-7317 3 Libpng, Canonical, Debian 3 Libpng, Ubuntu Linux, Debian Linux 2019-05-25 2.6
png_image_free in png.c in libpng 1.6.36 has a use-after-free because png_image_free_function is called under png_safe_execute.
CVE-2019-12086 2 Fasterxml, Debian 2 Jackson-databind, Debian Linux 2019-05-25 5.0
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint, the service has the...
CVE-2018-19362 3 Fasterxml, Debian, Oracle 7 Jackson-databind, Debian Linux, Business Process Management Suite and 4 more 2019-05-25 7.5
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the jboss-common-core class from polymorphic deserialization.
CVE-2018-19361 3 Fasterxml, Debian, Oracle 7 Jackson-databind, Debian Linux, Business Process Management Suite and 4 more 2019-05-25 7.5
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the openjpa class from polymorphic deserialization.
CVE-2018-19360 3 Fasterxml, Debian, Oracle 7 Jackson-databind, Debian Linux, Business Process Management Suite and 4 more 2019-05-25 7.5
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the axis2-transport-jms class from polymorphic deserialization.
CVE-2018-14721 3 Fasterxml, Debian, Oracle 11 Jackson-databind, Debian Linux, Banking Platform and 8 more 2019-05-25 7.5
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure to block the axis2-jaxws class from polymorphic deserialization.
CVE-2018-14720 3 Fasterxml, Debian, Oracle 11 Jackson-databind, Debian Linux, Banking Platform and 8 more 2019-05-25 7.5
FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization.
CVE-2018-14719 3 Fasterxml, Debian, Oracle 10 Jackson-databind, Debian Linux, Banking Platform and 7 more 2019-05-25 7.5
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt and blaze-ds-core classes from polymorphic deserialization.
CVE-2018-14718 3 Fasterxml, Debian, Oracle 10 Jackson-databind, Debian Linux, Banking Platform and 7 more 2019-05-25 7.5
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class from polymorphic deserialization.
CVE-2019-0201 2 Apache, Debian 2 Zookeeper, Debian Linux 2019-05-24 4.3
An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper?s getACL() command doesn?t check any permission when retrieves the ACLs of the requested node and returns all information contained in the ACL Id...
CVE-2019-3839 2 Artifex, Debian 2 Ghostscript, Debian Linux 2019-05-24 6.8
It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system...
CVE-2019-12046 2 Lemonldap-ng, Debian 2 Lemonldap%3a%3a, Debian Linux 2019-05-24 7.5
LemonLDAP::NG -2.0.3 has Incorrect Access Control.
CVE-2019-2422 6 Oracle, Netapp, Canonical and 3 more 15 Jdk, Jre, Oncommand Unified Manager and 12 more 2019-05-23 4.3
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 7u201, 8u192 and 11.0.1; Java SE Embedded: 8u191. Difficult to exploit vulnerability allows unauthenticated...
CVE-2018-3639 9 Arm, Intel, Mitel and 6 more 50 Cortex-a, Atom C, Atom E and 47 more 2019-05-23 4.9
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user...
CVE-2018-11212 7 Ijg, Netapp, Oracle and 4 more 13 Libjpeg, Oncommand Unified Manager, Oncommand Workflow Automation and 10 more 2019-05-23 4.3
An issue was discovered in libjpeg 9a. The alloc_sarray function in jmemmgr.c allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted file.
CVE-2003-0367 5 Turbolinux, Openpkg, Mandrakesoft and 2 more 9 Mandrake Multi Network Firewall, Turbolinux Advanced Server, Mandrake Linux Corporate Server and 6 more 2019-05-23 2.1
znew in the gzip package allows local users to overwrite arbitrary files via a symlink attack on temporary files.
CVE-2019-11009 3 Graphicsmagick, Debian, Opensuse 3 Graphicsmagick, Debian Linux, Leap 2019-05-23 5.8
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the function ReadXWDImage of coders/xwd.c, which allows attackers to cause a denial of service or information disclosure via a crafted image file.
CVE-2019-11008 3 Graphicsmagick, Debian, Opensuse 3 Graphicsmagick, Debian Linux, Leap 2019-05-23 6.8
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer overflow in the function WriteXWDImage of coders/xwd.c, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other...
CVE-2007-1864 4 Php, Canonical, Debian and 1 more 5 Php, Ubuntu Linux, Debian Linux and 2 more 2019-05-22 7.5
Buffer overflow in the bundled libxmlrpc library in PHP before 4.4.7, and 5.x before 5.2.2, has unknown impact and remote attack vectors.
CVE-2017-3329 2 Oracle, Debian 2 Mysql, Debian Linux 2019-05-22 5.0
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Thread Pooling). Supported versions that are affected are 5.5.54 and earlier, 5.6.35 and earlier and 5.7.17 and earlier. Easily "exploitable" vulnerability allows...