← Back

Debian Linux

debian_linux

Vendor: Debian • 10,000 CVEs

CVEs (10,000)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Debian
LinuxRedhat
3Debian Linux
Enterprise LinuxLinux Kernel
Jun 17, 2026
Sep 9, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An out-of-bounds memory read flaw was found in the Linux kernel's BPF subsystem in how a user calls the bpf_tail_call function with a key larger than the max_entries of the map. This flaw allows a local user to gain unau...Show more
An out-of-bounds memory read flaw was found in the Linux kernel's BPF subsystem in how a user calls the bpf_tail_call function with a key larger than the max_entries of the map. This flaw allows a local user to gain unauthorized access to data.Show less
2Debian
Linux
2Debian Linux
Linux Kernel
Jun 17, 2026
Sep 9, 2022
N/A· v4
4.7 MEDIUM· v3
N/A· v2
An issue was discovered in the Linux kernel through 5.19.8. drivers/firmware/efi/capsule-loader.c has a race condition with a resultant use-after-free.
2Debian
Sqlalchemy
2Debian Linux
Mako
Jun 17, 2026
Sep 7, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Sqlalchemy mako before 1.2.2 is vulnerable to Regular expression Denial of Service when using the Lexer class to parse. This also affects babelplugin and linguaplugin.
2Debian
Vim
2Debian Linux
Vim
Jun 17, 2026
Sep 6, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Use After Free in GitHub repository vim/vim prior to 9.0.0389.
2Clusterlabs
Debian
2Debian Linux
Pcs
Jun 17, 2026
Sep 6, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
A vulnerability was found in the PCS project. This issue occurs due to incorrect permissions on a Unix socket used for internal communication between PCS daemons. A privilege escalation could happen by obtaining an authe...Show more
A vulnerability was found in the PCS project. This issue occurs due to incorrect permissions on a Unix socket used for internal communication between PCS daemons. A privilege escalation could happen by obtaining an authentication token for a hacluster user. With the "hacluster" token, this flaw allows an attacker to have complete control over the cluster managed by PCS.Show less
2Debian
Snakeyaml Project
2Debian Linux
Snakeyaml
Jun 17, 2026
Sep 5, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack...Show more
Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow.Show less
2Debian
Snakeyaml Project
2Debian Linux
Snakeyaml
Jun 17, 2026
Sep 5, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack...Show more
Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow.Show less
2Debian
Snakeyaml Project
2Debian Linux
Snakeyaml
Jun 17, 2026
Sep 5, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack...Show more
Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow.Show less
2Debian
Tinygltf Project
2Debian Linux
Tinygltf
Jun 17, 2026
Sep 5, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
The tinygltf library uses the C library function wordexp() to perform file path expansion on untrusted paths that are provided from the input file. This function allows for command injection by using backticks. An attack...Show more
The tinygltf library uses the C library function wordexp() to perform file path expansion on untrusted paths that are provided from the input file. This function allows for command injection by using backticks. An attacker could craft an untrusted path input that would result in a path expansion. We recommend upgrading to 2.6.0 or past commit 52ff00a38447f06a17eab1caa2cf0730a119c751Show less
2Debian
Linux
2Debian Linux
Linux Kernel
Jun 17, 2026
Sep 5, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An issue was discovered in the Linux kernel before 5.19. In pxa3xx_gcu_write in drivers/video/fbdev/pxa3xx-gcu.c, the count parameter has a type conflict of size_t versus int, causing an integer overflow and bypassing th...Show more
An issue was discovered in the Linux kernel before 5.19. In pxa3xx_gcu_write in drivers/video/fbdev/pxa3xx-gcu.c, the count parameter has a type conflict of size_t versus int, causing an integer overflow and bypassing the size check. After that, because it is used as the third argument to copy_from_user(), a heap overflow may occur. NOTE: the original discoverer disputes that the overflow can actually happen.Show less
3Debian
FedoraprojectVim
3Debian Linux
FedoraVim
Jun 17, 2026
Sep 3, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Use After Free in GitHub repository vim/vim prior to 9.0.0360.
2Debian
Libvncserver Project
2Debian Linux
Libvncserver
Jun 17, 2026
Sep 2, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
libvncclient v0.9.13 was discovered to contain a memory leak via the function rfbClientCleanup().
2Debian
Owasp
2Debian Linux
Owasp Modsecurity Core Rule Set
Jun 17, 2026
Sep 2, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability. Attackers can use the comment characters and variable assignments in the SQL syntax to bypass Modsecurity WAF prot...Show more
Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability. Attackers can use the comment characters and variable assignments in the SQL syntax to bypass Modsecurity WAF protection and implement SQL injection attacks on Web applications.Show less
2Debian
Linux
2Debian Linux
Linux Kernel
Jun 17, 2026
Sep 2, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An issue was discovered in net/netfilter/nf_tables_api.c in the Linux kernel before 5.19.6. A denial of service can occur upon binding to an already bound chain.
2Debian
Linux
2Debian Linux
Linux Kernel
Jun 17, 2026
Sep 2, 2022
N/A· v4
4.7 MEDIUM· v3
N/A· v2
An issue was discovered in include/asm-generic/tlb.h in the Linux kernel before 5.19. Because of a race condition (unmap_mapping_range versus munmap), a device driver can free a page while it still has stale TLB entries....Show more
An issue was discovered in include/asm-generic/tlb.h in the Linux kernel before 5.19. Because of a race condition (unmap_mapping_range versus munmap), a device driver can free a page while it still has stale TLB entries. This only occurs in situations with VM_PFNMAP VMAs.Show less
3Bluez
CanonicalDebian
3Bluez
Debian LinuxUbuntu Linux
Jun 17, 2026
Sep 2, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
BlueZ before 5.59 allows physically proximate attackers to cause a denial of service because malformed and invalid capabilities can be processed in profiles/audio/avdtp.c.
3Bluez
CanonicalDebian
3Bluez
Debian LinuxUbuntu Linux
Jun 17, 2026
Sep 2, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
BlueZ before 5.59 allows physically proximate attackers to obtain sensitive information because profiles/audio/avrcp.c does not validate params_len.
2Debian
Linux
2Debian Linux
Linux Kernel
Jun 17, 2026
Sep 1, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An issue was found in the Linux kernel in nf_conntrack_irc where the message handling can be confused and incorrectly matches the message. A firewall may be able to be bypassed when users are using unencrypted IRC with n...Show more
An issue was found in the Linux kernel in nf_conntrack_irc where the message handling can be confused and incorrectly matches the message. A firewall may be able to be bypassed when users are using unencrypted IRC with nf_conntrack_irc configured.Show less
2Debian
Linux
2Debian Linux
Linux Kernel
Jun 17, 2026
Sep 1, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Found Linux Kernel flaw in the i740 driver. The Userspace program could pass any values to the driver through ioctl() interface. The driver doesn't check the value of 'pixclock', so it may cause a divide by zero error.
2Debian
Python Scciclient Project
2Debian Linux
Python Scciclient
Jun 17, 2026
Sep 1, 2022
N/A· v4
7.4 HIGH· v3
N/A· v2
A flaw was found in the python-scciclient when making an HTTPS connection to a server where the server's certificate would not be verified. This issue opens up the connection to possible Man-in-the-middle (MITM) attacks.