← Back

Debian Linux

debian_linux

Vendor: Debian • 10,001 CVEs

CVEs (10,001)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Debian
Linux
2Debian Linux
Linux Kernel
Jun 17, 2026
Jul 18, 2022
N/A· v4
6.7 MEDIUM· v3
N/A· v2
When sending malicous data to kernel by ioctl cmd FBIOPUT_VSCREENINFO,kernel will write memory out of bounds.
2Debian
Lemonldap Ng
2Debian Linux
Lemonldap\
Jun 17, 2026
Jul 18, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue was discovered in LemonLDAP::NG (aka lemonldap-ng) 2.0.13. When using the RESTServer plug-in to operate a REST password validation service (for another LemonLDAP::NG instance, for example) and using the Kerberos...Show more
An issue was discovered in LemonLDAP::NG (aka lemonldap-ng) 2.0.13. When using the RESTServer plug-in to operate a REST password validation service (for another LemonLDAP::NG instance, for example) and using the Kerberos authentication method combined with another method with the Combination authentication plug-in, any password will be recognized as valid for an existing user.Show less
2Debian
Lemonldap Ng
2Debian Linux
Lemonldap\
Jun 17, 2026
Jul 18, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
In LemonLDAP::NG (aka lemonldap-ng) through 2.0.8, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl...Show more
In LemonLDAP::NG (aka lemonldap-ng) through 2.0.8, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used.Show less
2Debian
Squid Cache
2Debian Linux
Squid
Jun 17, 2026
Jul 17, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In Squid 3.x through 3.5.28, 4.x through 4.17, and 5.x before 5.6, due to improper buffer management, a Denial of Service can occur when processing long Gopher server responses.
2Debian
Dovecot
2Debian Linux
Dovecot
Jun 17, 2026
Jul 17, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before 2.3.20. When two passdb configuration entries exist with the same driver and args settings, incorrect username_filter and mechanism settings can...Show more
An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before 2.3.20. When two passdb configuration entries exist with the same driver and args settings, incorrect username_filter and mechanism settings can be applied to passdb definitions. These incorrectly applied settings can lead to an unintended security configuration and can permit privilege escalation in certain configurations. The documentation does not advise against the use of passdb definitions that have the same driver and args settings. One such configuration would be where an administrator wishes to use the same PAM configuration or passwd file for both normal and master users but use the username_filter setting to restrict which of the users is able to be a master user.Show less
3Arm
DebianTrustedfirmware
3Debian Linux
Mbed TlsMbed Tls
Jun 17, 2026
Jul 15, 2022
N/A· v4
9.1 CRITICAL· v3
N/A· v2
An issue was discovered in Mbed TLS before 2.28.1 and 3.x before 3.2.0. In some configurations, an unauthenticated attacker can send an invalid ClientHello message to a DTLS server that causes a heap-based buffer over-re...Show more
An issue was discovered in Mbed TLS before 2.28.1 and 3.x before 3.2.0. In some configurations, an unauthenticated attacker can send an invalid ClientHello message to a DTLS server that causes a heap-based buffer over-read of up to 255 bytes. This can cause a server crash or possibly information disclosure based on error responses. Affected configurations have MBEDTLS_SSL_DTLS_CLIENT_PORT_REUSE enabled and MBEDTLS_SSL_IN_CONTENT_LEN less than a threshold that depends on the configuration: 258 bytes if using mbedtls_ssl_cookie_check, and possibly up to 571 bytes with a custom cookie check function.Show less
4Amd
DebianFedoraproject+1 more
126A10 9600p Firmware
A10 9630p FirmwareA12 9700p Firmware+123 more
Jun 17, 2026
Jul 14, 2022
N/A· v4
6.5 MEDIUM· v3
2.1 LOW· v2
Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure.
6Debian
FedoraprojectLlhttp+3 more
6Debian Linux
FedoraLlhttp+3 more
Jun 17, 2026
Jul 14, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding headers. This can lead to HTTP Request Smuggling (HRS).
4Debian
LlhttpNodejs+1 more
4Debian Linux
LlhttpNode.js+1 more
Jun 17, 2026
Jul 14, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS).
6Debian
FedoraprojectLlhttp+3 more
6Debian Linux
FedoraLlhttp+3 more
Jun 17, 2026
Jul 14, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding headers and can lead to HTTP Request Smuggling (HRS).
4Debian
FedoraprojectNodejs+1 more
4Debian Linux
FedoraNode.js+1 more
Jun 17, 2026
Jul 14, 2022
N/A· v4
8.1 HIGH· v3
N/A· v2
A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.20.0, <18.5.0 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP addr...Show more
A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.20.0, <18.5.0 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding attacks.Show less
4Apple
DebianFedoraproject+1 more
4Debian Linux
FedoraGit+1 more
Jun 17, 2026
Jul 12, 2022
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
Git is a distributed revision control system. Git prior to versions 2.37.1, 2.36.2, 2.35.4, 2.34.4, 2.33.4, 2.32.3, 2.31.4, and 2.30.5, is vulnerable to privilege escalation in all platforms. An unsuspecting user could s...Show more
Git is a distributed revision control system. Git prior to versions 2.37.1, 2.36.2, 2.35.4, 2.34.4, 2.33.4, 2.32.3, 2.31.4, and 2.30.5, is vulnerable to privilege escalation in all platforms. An unsuspecting user could still be affected by the issue reported in CVE-2022-24765, for example when navigating as root into a shared tmp directory that is owned by them, but where an attacker could create a git repository. Versions 2.37.1, 2.36.2, 2.35.4, 2.34.4, 2.33.4, 2.32.3, 2.31.4, and 2.30.5 contain a patch for this issue. The simplest way to avoid being affected by the exploit described in the example is to avoid running git as root (or an Administrator in Windows), and if needed to reduce its use to a minimum. While a generic workaround is not possible, a system could be hardened from the exploit described in the example by removing any such repository if it exists already and creating one as root to block any future attacks.Show less
5Debian
FedoraprojectIntel+2 more
129Core I3 6100 Firmware
Core I3 6100e FirmwareCore I3 6100h Firmware+126 more
Jun 17, 2026
Jul 12, 2022
N/A· v4
6.5 MEDIUM· v3
1.9 LOW· v2
Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass their retpoline mitigation in the kernel to leak arbitrary data. An attacker with unprivileged user access can hijack r...Show more
Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass their retpoline mitigation in the kernel to leak arbitrary data. An attacker with unprivileged user access can hijack return instructions to achieve arbitrary speculative code execution under certain microarchitecture-dependent conditions.Show less
4Amd
DebianFedoraproject+1 more
126A10 9600p Firmware
A10 9630p FirmwareA12 9700p Firmware+123 more
Jun 17, 2026
Jul 12, 2022
N/A· v4
6.5 MEDIUM· v3
2.1 LOW· v2
Mis-trained branch predictions for return instructions may allow arbitrary speculative code execution under certain microarchitecture-dependent conditions.
2Debian
Qemu
2Debian Linux
Qemu
Jun 17, 2026
Jul 11, 2022
N/A· v4
8.8 HIGH· v3
6.1 MEDIUM· v2
softmmu/physmem.c in QEMU through 7.0.0 can perform an uninitialized read on the translate_fail path, leading to an io_readx or io_writex crash. NOTE: a third party states that the Non-virtualization Use Case in the qemu...Show more
softmmu/physmem.c in QEMU through 7.0.0 can perform an uninitialized read on the translate_fail path, leading to an io_readx or io_writex crash. NOTE: a third party states that the Non-virtualization Use Case in the qemu.org reference applies here, i.e., "Bugs affecting the non-virtualization use case are not considered security bugs at this time.Show less
20xacab
Debian
2Debian Linux
Mat2
Jun 17, 2026
Jul 8, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
mat2 (aka metadata anonymisation toolkit) before 0.13.0 allows ../ directory traversal during the ZIP archive cleaning process. This primarily affects mat2 web instances, in which clients could obtain sensitive informati...Show more
mat2 (aka metadata anonymisation toolkit) before 0.13.0 allows ../ directory traversal during the ZIP archive cleaning process. This primarily affects mat2 web instances, in which clients could obtain sensitive information via a crafted archive.Show less
4Debian
EclipseJenkins+1 more
8Debian Linux
Element Plug In For Vcenter ServerHci Compute Node+5 more
Jun 17, 2026
Jul 7, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug that can wind up not properly cleaning up the active connections and associated resources. This can...Show more
In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug that can wind up not properly cleaning up the active connections and associated resources. This can lead to a Denial of Service scenario where there are no enough resources left to process good requests.Show less
3Debian
EclipseNetapp
7Debian Linux
Element Plug In For Vcenter ServerHci Compute Node+4 more
Jun 17, 2026
Jul 7, 2022
N/A· v4
2.7 LOW· v3
4.0 MEDIUM· v2
In Eclipse Jetty versions 9.4.0 thru 9.4.46, and 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, the parsing of the authority segment of an http scheme URI, the Jetty HttpURI class improperly detects an invalid inpu...Show more
In Eclipse Jetty versions 9.4.0 thru 9.4.46, and 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, the parsing of the authority segment of an http scheme URI, the Jetty HttpURI class improperly detects an invalid input as a hostname. This can lead to failures in a Proxy scenario.Show less
6Apple
DebianFedoraproject+3 more
14Bootstrap Os
Clustered Data OntapCurl+11 more
Jun 17, 2026
Jul 7, 2022
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
When curl < 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed and even allows it to inject data to the...Show more
When curl < 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed and even allows it to inject data to the client.Show less
6Apple
DebianFedoraproject+3 more
14Bootstrap Os
Clustered Data OntapCurl+11 more
Jun 17, 2026
Jul 7, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation...Show more
When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file accessible to more users than intended.Show less