Vulnerabilities > Debian > Debian Linux

DATE CVE VULNERABILITY TITLE RISK
2018-09-17 CVE-2017-15705 Improper Input Validation vulnerability in multiple products
A denial of service vulnerability was identified that exists in Apache SpamAssassin before 3.4.2.
network
low complexity
apache redhat debian canonical CWE-20
5.3
2018-09-16 CVE-2018-17101 Out-of-bounds Write vulnerability in multiple products
An issue was discovered in LibTIFF 4.0.9.
6.8
2018-09-16 CVE-2018-17100 Integer Overflow or Wraparound vulnerability in multiple products
An issue was discovered in LibTIFF 4.0.9.
6.8
2018-09-16 CVE-2018-17082 Cross-site Scripting vulnerability in PHP
The Apache2 component in PHP before 5.6.38, 7.0.x before 7.0.32, 7.1.x before 7.1.22, and 7.2.x before 7.2.10 allows XSS via the body of a "Transfer-Encoding: chunked" request, because the bucket brigade is mishandled in the php_handler function in sapi/apache2handler/sapi_apache2.c.
4.3
2018-09-14 CVE-2018-12086 Out-of-bounds Write vulnerability in multiple products
Buffer overflow in OPC UA applications allows remote attackers to trigger a stack overflow with carefully structured requests.
network
low complexity
opcfoundation debian CWE-787
5.0
2018-09-13 CVE-2018-17000 NULL Pointer Dereference vulnerability in multiple products
A NULL pointer dereference in the function _TIFFmemcmp at tif_unix.c (called from TIFFWriteDirectoryTagTransferfunction) in LibTIFF 4.0.9 allows an attacker to cause a denial-of-service through a crafted tiff file.
4.3
2018-09-13 CVE-2018-16741 OS Command Injection vulnerability in multiple products
An issue was discovered in mgetty before 1.2.1.
local
low complexity
mgetty-project debian CWE-78
7.2
2018-09-12 CVE-2018-16981 Out-of-bounds Write vulnerability in multiple products
stb stb_image.h 2.19, as used in catimg, Emscripten, and other products, has a heap-based buffer overflow in the stbi__out_gif_code function.
network
low complexity
nothings debian CWE-787
8.8
2018-09-12 CVE-2018-16949 Resource Exhaustion vulnerability in multiple products
An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2.
network
low complexity
openafs debian CWE-400
5.0
2018-09-12 CVE-2018-16948 Information Exposure vulnerability in multiple products
An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2.
network
low complexity
openafs debian CWE-200
5.0