Vulnerabilities > Debian > Debian Linux > High

DATE CVE VULNERABILITY TITLE RISK
2019-08-25 CVE-2019-15538 Resource Exhaustion vulnerability in multiple products
An issue was discovered in xfs_setattr_nonsize in fs/xfs/xfs_iops.c in the Linux kernel through 5.2.9.
7.5
2019-08-21 CVE-2019-15296 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8.
local
low complexity
audiocoding debian CWE-119
7.8
2019-08-20 CVE-2019-10086 Deserialization of Untrusted Data vulnerability in multiple products
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects.
7.3
2019-08-20 CVE-2019-15239 Use After Free vulnerability in multiple products
In the Linux kernel, a certain net/ipv4/tcp_output.c change, which was properly incorporated into 4.16.12, was incorrectly backported to the earlier longterm kernels, introducing a new vulnerability that was potentially more severe than the issue that was intended to be fixed by backporting.
local
low complexity
linux debian CWE-416
7.8
2019-08-15 CVE-2019-9852 Path Traversal vulnerability in multiple products
LibreOffice has a feature where documents can specify that pre-installed macros can be executed on various script events such as mouse-over, document-open etc.
7.8
2019-08-15 CVE-2019-10081 Out-of-bounds Write vulnerability in multiple products
HTTP/2 (2.4.20 through 2.4.39) very early pushes, for example configured with "H2PushResource", could lead to an overwrite of memory in the pushing request's pool, leading to crashes.
network
low complexity
apache debian CWE-787
7.5
2019-08-15 CVE-2019-13222 Out-of-bounds Read vulnerability in multiple products
An out-of-bounds read of a global buffer in the draw_line function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service or disclose sensitive information by opening a crafted Ogg Vorbis file.
local
low complexity
stb-vorbis-project debian CWE-125
7.1
2019-08-15 CVE-2019-13221 Out-of-bounds Write vulnerability in multiple products
A stack buffer overflow in the compute_codewords function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service or execute arbitrary code by opening a crafted Ogg Vorbis file.
local
low complexity
stb-vorbis-project debian CWE-787
7.8
2019-08-15 CVE-2019-13220 Use of Uninitialized Resource vulnerability in multiple products
Use of uninitialized stack variables in the start_decoder function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service or disclose sensitive information by opening a crafted Ogg Vorbis file.
local
low complexity
stb-vorbis-project debian CWE-908
7.1
2019-08-15 CVE-2019-13217 Out-of-bounds Write vulnerability in multiple products
A heap buffer overflow in the start_decoder function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service or execute arbitrary code by opening a crafted Ogg Vorbis file.
local
low complexity
stb-vorbis-project debian CWE-787
7.8