← Back

Debian Linux

debian_linux

Vendor: Debian • 10,001 CVEs

CVEs (10,001)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Debian
Intel
2Connection Manager
Debian Linux
Jun 17, 2026
Jun 9, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ConnMan (aka Connection Manager) 1.30 through 1.39 has a stack-based buffer overflow in uncompress in dnsproxy.c via NAME, RDATA, or RDLENGTH (for A or AAAA).
4Ckeditor
DebianDrupal+1 more
4Ckeditor
Debian LinuxDrupal+1 more
Jun 17, 2026
Jun 9, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor 4 4.14.0 through 4.16.x before 4.16.1 allows remote attackers to inject executable JavaScript code through a crafted comment because --!>...Show more
A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor 4 4.14.0 through 4.16.x before 4.16.1 allows remote attackers to inject executable JavaScript code through a crafted comment because --!> is mishandled.Show less
5Arm
BroadcomDebian+2 more
8Bcm2711
Core I7 10700kCore I7 7700k+5 more
Jun 17, 2026
Jun 9, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Potential speculative code store bypass in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution of overwritten instructions, may cause an incorrect speculation and co...Show more
Potential speculative code store bypass in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution of overwritten instructions, may cause an incorrect speculation and could result in data leakage.Show less
4Debian
EclipseNetapp+1 more
8Active Iq Unified Manager
Communications Cloud Native Core PolicyDebian Linux+5 more
Jun 17, 2026
Jun 9, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to access protected resources within the WEB-INF directory. For example a request to...Show more
For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to access protected resources within the WEB-INF directory. For example a request to `/concat?/%2557EB-INF/web.xml` can retrieve the web.xml file. This can reveal sensitive information regarding the implementation of a web application.Show less
3Debian
FedoraprojectLinux
3Debian Linux
FedoraLinux Kernel
Jun 17, 2026
Jun 8, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A flaw double-free memory corruption in the Linux kernel HCI device initialization subsystem was found in the way user attach malicious HCI TTY Bluetooth device. A local user could use this flaw to crash the system. This...Show more
A flaw double-free memory corruption in the Linux kernel HCI device initialization subsystem was found in the way user attach malicious HCI TTY Bluetooth device. A local user could use this flaw to crash the system. This flaw affects all the Linux kernel versions starting from 3.13.Show less
3Debian
FedoraprojectOpenexr
3Debian Linux
FedoraOpenexr
Jun 17, 2026
Jun 8, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR. This is a different...Show more
An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR. This is a different flaw from CVE-2021-23215.Show less
3Debian
FedoraprojectOpenexr
3Debian Linux
FedoraOpenexr
Jun 17, 2026
Jun 8, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR.
2Debian
Vmware
2Debian Linux
Rabbitmq
Jun 17, 2026
Jun 8, 2021
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
RabbitMQ all versions prior to 3.8.16 are prone to a denial of service vulnerability due to improper input validation in AMQP 1.0 client connection endpoint. A malicious user can exploit the vulnerability by sending mali...Show more
RabbitMQ all versions prior to 3.8.16 are prone to a denial of service vulnerability due to improper input validation in AMQP 1.0 client connection endpoint. A malicious user can exploit the vulnerability by sending malicious AMQP messages to the target RabbitMQ instance having the AMQP 1.0 plugin enabled.Show less
4Debian
FedoraprojectGnupg+1 more
8Communications Cloud Native Core Binding Support Function
Communications Cloud Native Core Network Function Cloud Native EnvironmentCommunications Cloud Native Core Network Repository Function+5 more
Jun 17, 2026
Jun 8, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm, and the window size is not chosen appropriately. This, for...Show more
Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm, and the window size is not chosen appropriately. This, for example, affects use of ElGamal in OpenPGP.Show less
3Debian
OracleWireshark
5Debian Linux
Enterprise Manager Ops CenterInstantis Enterprisetrack+2 more
Jun 17, 2026
Jun 7, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Infinite loop in DVB-S2-BB dissector in Wireshark 3.4.0 to 3.4.5 allows denial of service via packet injection or crafted capture file
2Debian
F5
2Debian Linux
Nginx
Dec 5, 2025
Jun 6, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
NGINX before 1.13.6 has a buffer overflow for years that exceed four digits, as demonstrated by a file with a modification date in 1969 that causes an integer overflow (or a false modification date far in the future), wh...Show more
NGINX before 1.13.6 has a buffer overflow for years that exceed four digits, as demonstrated by a file with a modification date in 1969 that causes an integer overflow (or a false modification date far in the future), when encountered by the autoindex module.Show less
2Debian
Inverse
2Debian Linux
Sogo
Jun 17, 2026
Jun 4, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
SOGo 2.x before 2.4.1 and 3.x through 5.x before 5.1.1 does not validate the signatures of any SAML assertions it receives. Any actor with network access to the deployment could impersonate users when SAML is the authent...Show more
SOGo 2.x before 2.4.1 and 3.x through 5.x before 5.1.1 does not validate the signatures of any SAML assertions it receives. Any actor with network access to the deployment could impersonate users when SAML is the authentication method. (Only versions after 2.0.5a are affected.)Show less
3Debian
EntrouvertFedoraproject
3Debian Linux
FedoraLasso
Jun 17, 2026
Jun 4, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature.
2Debian
Ffmpeg
2Debian Linux
Ffmpeg
Jun 17, 2026
Jun 2, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the av_dict_set function in dict.c.
2Debian
Freedesktop
2Debian Linux
Xdg Utils
Nov 21, 2024
Jun 2, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The open_generic_xdg_mime function in xdg-open in xdg-utils 1.1.0 rc1 in Debian, when using dash, does not properly handle local variables, which allows remote attackers to execute arbitrary commands via a crafted file.
2Avahi
Debian
2Avahi
Debian Linux
Jun 17, 2026
Jun 2, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the client connection on the avahi Unix socket is not correctly handled in the client_work function, allowing a local attac...Show more
A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the client connection on the avahi Unix socket is not correctly handled in the client_work function, allowing a local attacker to trigger an infinite loop. The highest threat from this vulnerability is to the availability of the avahi service, which becomes unresponsive after this flaw is triggered.Show less
2Debian
Ffmpeg
2Debian Linux
Ffmpeg
Jun 17, 2026
Jun 2, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the wtvfile_open_sector function in wtvdec.c.
2Debian
Ffmpeg
2Debian Linux
Ffmpeg
Jun 17, 2026
Jun 2, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the ff_frame_pool_get function in framepool.c.
2Debian
Ffmpeg
2Debian Linux
Ffmpeg
Jun 17, 2026
Jun 2, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the avpriv_float_dsp_allocl function in libavutil/float_dsp.c.
4Debian
FedoraprojectQemu+1 more
5Debian Linux
Enterprise LinuxFedora+2 more
Jun 17, 2026
Jun 2, 2021
N/A· v4
6.5 MEDIUM· v3
2.1 LOW· v2
The ahci_commit_buf function in ide/ahci.c in QEMU allows attackers to cause a denial of service (NULL dereference) when the command header 'ad->cur_cmd' is null.