← Back

Debian Linux

debian_linux

Vendor: Debian • 10,001 CVEs

CVEs (10,001)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
4Debian
FedoraprojectOpensuse+1 more
5Backports Sle
Debian LinuxFedora+2 more
Jun 17, 2026
May 19, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue has been found in PowerDNS Recursor 4.1.0 through 4.3.0 where records in the answer section of a NXDOMAIN response lacking an SOA were not properly validated in SyncRes::processAnswer, allowing an attacker to by...Show more
An issue has been found in PowerDNS Recursor 4.1.0 through 4.3.0 where records in the answer section of a NXDOMAIN response lacking an SOA were not properly validated in SyncRes::processAnswer, allowing an attacker to bypass DNSSEC validation.Show less
5Canonical
DebianLinux+2 more
24A700s Firmware
Active Iq Unified ManagerBootstrap Os+21 more
Jun 17, 2026
May 18, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
gadget_dev_desc_UDC_store in drivers/usb/gadget/configfs.c in the Linux kernel 3.16 through 5.6.13 relies on kstrdup without considering the possibility of an internal '\0' value, which allows attackers to trigger an out...Show more
gadget_dev_desc_UDC_store in drivers/usb/gadget/configfs.c in the Linux kernel 3.16 through 5.6.13 relies on kstrdup without considering the possibility of an internal '\0' value, which allows attackers to trigger an out-of-bounds read, aka CID-15753588bcd4.Show less
6Canonical
DebianFedoraproject+3 more
25A700s Firmware
Active Iq Unified ManagerBootstrap Os+22 more
Jun 17, 2026
May 15, 2020
N/A· v4
5.3 MEDIUM· v3
4.7 MEDIUM· v2
The VFIO PCI driver in the Linux kernel through 5.6.13 mishandles attempts to access disabled memory space.
4Canonical
DebianFreerdp+1 more
4Debian Linux
FreerdpLeap+1 more
Jun 17, 2026
May 15, 2020
N/A· v4
2.2 LOW· v3
3.5 LOW· v2
libfreerdp/core/update.c in FreeRDP versions > 1.1 through 2.0.0-rc4 has an Out-of-bounds Read.
4Canonical
DebianFreerdp+1 more
4Debian Linux
FreerdpLeap+1 more
Jun 17, 2026
May 15, 2020
N/A· v4
2.2 LOW· v3
3.5 LOW· v2
libfreerdp/cache/bitmap.c in FreeRDP versions > 1.0 through 2.0.0-rc4 has an Out of bounds read.
4Canonical
DebianFreerdp+1 more
4Debian Linux
FreerdpLeap+1 more
Jun 17, 2026
May 15, 2020
N/A· v4
6.6 MEDIUM· v3
6.0 MEDIUM· v2
libfreerdp/gdi/region.c in FreeRDP versions > 1.0 through 2.0.0-rc4 has an Integer Overflow.
4Canonical
DebianFreerdp+1 more
4Debian Linux
FreerdpLeap+1 more
Jun 17, 2026
May 15, 2020
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
libfreerdp/gdi/gdi.c in FreeRDP > 1.0 through 2.0.0-rc4 has an Out-of-bounds Read.
4Canonical
DebianFreerdp+1 more
4Debian Linux
FreerdpLeap+1 more
Jun 17, 2026
May 15, 2020
N/A· v4
6.6 MEDIUM· v3
6.0 MEDIUM· v2
libfreerdp/codec/planar.c in FreeRDP version > 1.0 through 2.0.0-rc4 has an Out-of-bounds Write.
3Debian
FedoraprojectTransmissionbt
3Debian Linux
FedoraTransmission
Nov 21, 2024
May 15, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Use-after-free in libtransmission/variant.c in Transmission before 3.00 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted torrent file.
3Canonical
DebianFedoraproject
4Apt
Debian LinuxFedora+1 more
Jun 17, 2026
May 15, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Missing input validation in the ar/tar implementations of APT before version 2.1.2 could result in denial of service when processing specially crafted deb files.
5Canonical
DebianGoogle+2 more
5Android
Debian LinuxLeap+2 more
Jun 17, 2026
May 14, 2020
N/A· v4
5.0 MEDIUM· v3
1.9 LOW· v2
In exif_data_save_data_entry of exif-data.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User inte...Show more
In exif_data_save_data_entry of exif-data.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-148705132Show less
2Debian
Opensuse
2Debian Linux
Open Build Service
Jun 17, 2026
May 13, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A Improper Neutralization of Input During Web Page Generation vulnerability in open-build-service allows remote attackers to store arbitrary JS code to cause XSS. This issue affects: openSUSE open-build-service versions...Show more
A Improper Neutralization of Input During Web Page Generation vulnerability in open-build-service allows remote attackers to store arbitrary JS code to cause XSS. This issue affects: openSUSE open-build-service versions prior to 7cc32c8e2ff7290698e101d9a80a9dc29a5500fb.Show less
4Canonical
CiscoDebian+1 more
4Clam Antivirus
Debian LinuxFedora+1 more
Jun 17, 2026
May 13, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability in the PDF archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.101 - 0.102.2 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device....Show more
A vulnerability in the PDF archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.101 - 0.102.2 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to a stack buffer overflow read. An attacker could exploit this vulnerability by sending a crafted PDF file to an affected device. An exploit could allow the attacker to cause the ClamAV scanning process crash, resulting in a denial of service condition.Show less
4Canonical
CiscoDebian+1 more
4Clam Antivirus
Debian LinuxFedora+1 more
Jun 17, 2026
May 13, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability in the ARJ archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.102.2 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vul...Show more
A vulnerability in the ARJ archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.102.2 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to a heap buffer overflow read. An attacker could exploit this vulnerability by sending a crafted ARJ file to an affected device. An exploit could allow the attacker to cause the ClamAV scanning process crash, resulting in a denial of service condition.Show less
3Canonical
DebianFreerdp
3Debian Linux
FreerdpUbuntu Linux
Jun 17, 2026
May 12, 2020
N/A· v4
2.2 LOW· v3
3.5 LOW· v2
In FreeRDP after 1.1 and before 2.0.0, a stream out-of-bounds seek in rdp_read_font_capability_set could lead to a later out-of-bounds read. As a result, a manipulated client or server might force a disconnect due to an...Show more
In FreeRDP after 1.1 and before 2.0.0, a stream out-of-bounds seek in rdp_read_font_capability_set could lead to a later out-of-bounds read. As a result, a manipulated client or server might force a disconnect due to an invalid data read. This has been fixed in 2.0.0.Show less
2Debian
Redhat
3Ansible Engine
Ansible TowerDebian Linux
Jun 17, 2026
May 12, 2020
N/A· v4
5.0 MEDIUM· v3
1.9 LOW· v2
A flaw was found in the Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and 2.9.x before 2.9.7 as well as Ansible Tower before and including versions 3.4.5 and 3.5.5 and 3.6.3...Show more
A flaw was found in the Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and 2.9.x before 2.9.7 as well as Ansible Tower before and including versions 3.4.5 and 3.5.5 and 3.6.3 when the ldap_attr and ldap_entry community modules are used. The issue discloses the LDAP bind password to stdout or a log file if a playbook task is written using the bind_pw in the parameters field. The highest threat from this vulnerability is data confidentiality.Show less
4Debian
FedoraprojectInfradead+1 more
4Debian Linux
FedoraLeap+1 more
Jun 17, 2026
May 12, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
OpenConnect 8.09 has a buffer overflow, causing a denial of service (application crash) or possibly unspecified other impact, via crafted certificate data to get_cert_name in gnutls.c.
2Debian
Rubyonrails
2Actionpack Page Caching
Debian Linux
Jun 17, 2026
May 12, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
There is a vulnerability in actionpack_page-caching gem < v1.2.1 that allows an attacker to write arbitrary files to a web server, potentially resulting in remote code execution if the attacker can write unescaped ERB to...Show more
There is a vulnerability in actionpack_page-caching gem < v1.2.1 that allows an attacker to write arbitrary files to a web server, potentially resulting in remote code execution if the attacker can write unescaped ERB to a view.Show less
4Canonical
DebianExim+1 more
4Debian Linux
EximFedora+1 more
Jun 17, 2026
May 11, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Exim through 4.93 has an out-of-bounds read in the SPA authenticator that could result in SPA/NTLM authentication bypass in auths/spa.c and auths/auth-spa.c.
2Debian
Redhat
6Ansible Engine
Ansible TowerCeph Storage+3 more
Jun 17, 2026
May 11, 2020
N/A· v4
5.5 MEDIUM· v3
1.9 LOW· v2
A flaw was found in Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and 2.9.x before 2.9.7 as well as Ansible Tower before and including versions 3.4.5 and 3.5.5 and 3.6.3 whe...Show more
A flaw was found in Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and 2.9.x before 2.9.7 as well as Ansible Tower before and including versions 3.4.5 and 3.5.5 and 3.6.3 when using modules which decrypts vault files such as assemble, script, unarchive, win_copy, aws_s3 or copy modules. The temporary directory is created in /tmp leaves the s ts unencrypted. On Operating Systems which /tmp is not a tmpfs but part of the root partition, the directory is only cleared on boot and the decryp emains when the host is switched off. The system will be vulnerable when the system is not running. So decrypted data must be cleared as soon as possible and the data which normally is encrypted ble.Show less