Vulnerabilities > Debian

DATE CVE VULNERABILITY TITLE RISK
2017-04-24 CVE-2017-3308 Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML).
network
low complexity
oracle debian mariadb redhat
7.7
2017-04-24 CVE-2017-3305 Cleartext Transmission of Sensitive Information vulnerability in multiple products
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: C API).
network
high complexity
oracle debian CWE-319
5.3
2017-04-24 CVE-2017-8105 Out-of-bounds Write vulnerability in multiple products
FreeType 2 before 2017-03-24 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_decoder_parse_charstrings function in psaux/t1decode.c.
network
low complexity
freetype debian CWE-787
critical
9.8
2017-04-23 CVE-2017-8073 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
WeeChat before 1.7.1 allows a remote crash by sending a filename via DCC to the IRC plugin.
network
low complexity
weechat debian CWE-119
7.5
2017-04-23 CVE-2017-8064 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
drivers/media/usb/dvb-usb-v2/dvb_usb_core.c in the Linux kernel 4.9.x and 4.10.x before 4.10.12 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memory corruption) or possibly have unspecified other impact by leveraging use of more than one virtual page for a DMA scatterlist.
local
low complexity
linux debian CWE-119
7.8
2017-04-21 CVE-2016-2347 Integer Overflow or Wraparound vulnerability in multiple products
Integer underflow in the decode_level3_header function in lib/lha_file_header.c in Lhasa before 0.3.1 allows remote attackers to execute arbitrary code via a crafted archive.
local
low complexity
opensuse debian lhasa-project CWE-190
7.8
2017-04-20 CVE-2017-7718 Out-of-bounds Read vulnerability in multiple products
hw/display/cirrus_vga_rop.h in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) via vectors related to copying VGA data via the cirrus_bitblt_rop_fwd_transp_ and cirrus_bitblt_rop_fwd_ functions.
local
low complexity
qemu debian CWE-125
5.5
2017-04-18 CVE-2017-7943 Missing Release of Resource after Effective Lifetime vulnerability in multiple products
The ReadSVGImage function in svg.c in ImageMagick 7.0.5-4 allows remote attackers to consume an amount of available memory via a crafted file.
network
low complexity
imagemagick debian CWE-772
6.5
2017-04-18 CVE-2017-7941 Missing Release of Resource after Effective Lifetime vulnerability in multiple products
The ReadSGIImage function in sgi.c in ImageMagick 7.0.5-4 allows remote attackers to consume an amount of available memory via a crafted file.
network
low complexity
imagemagick debian CWE-772
6.5
2017-04-18 CVE-2017-7645 Improper Input Validation vulnerability in multiple products
The NFSv2/NFSv3 server in the nfsd subsystem in the Linux kernel through 4.10.11 allows remote attackers to cause a denial of service (system crash) via a long RPC reply, related to net/sunrpc/svc.c, fs/nfsd/nfs3xdr.c, and fs/nfsd/nfsxdr.c.
network
low complexity
linux debian canonical CWE-20
7.5