← Back

Debian Linux

debian_linux

Vendor: Debian • 10,001 CVEs

CVEs (10,001)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Debian
FedoraprojectRedhat
4Debian Linux
Enterprise LinuxFedora+1 more
Nov 21, 2024
Dec 3, 2019
N/A· v4
4.7 MEDIUM· v3
3.3 LOW· v2
shadow: TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees
2Debian
Stanford
2Debian Linux
Webauth
Nov 21, 2024
Dec 3, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
webauth before 4.6.1 has authentication credential disclosure
2Debian
Freebsd
2Debian Linux
Freebsd
Nov 21, 2024
Dec 2, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
FreeBSD: Input Validation Flaw allows local users to gain elevated privileges
4Canonical
DebianFedoraproject+1 more
4Debian Linux
FedoraOpenslp+1 more
Nov 21, 2024
Dec 2, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
openslp: SLPIntersectStringList()' Function has a DoS vulnerability
3Debian
FedoraprojectOpensc Project
3Debian Linux
FedoraOpensc
Jun 17, 2026
Dec 1, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An issue was discovered in OpenSC through 0.19.0 and 0.20.x through 0.20.0-rc3. libopensc/card-setcos.c has an incorrect read operation during parsing of a SETCOS file attribute.
4Canonical
DebianFedoraproject+1 more
4Debian Linux
FedoraRabbitmq C+1 more
Jun 17, 2026
Dec 1, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in amqp_handle_input in amqp_connection.c in rabbitmq-c 0.9.0. There is an integer overflow that leads to heap memory corruption in the handling of CONNECTION_STATE_HEADER. A rogue server could re...Show more
An issue was discovered in amqp_handle_input in amqp_connection.c in rabbitmq-c 0.9.0. There is an integer overflow that leads to heap memory corruption in the handling of CONNECTION_STATE_HEADER. A rogue server could return a malicious frame header that leads to a smaller target_size value than needed. This condition is then carried on to a memcpy function that copies too much data into a heap buffer.Show less
3Debian
FedoraprojectProftpd
3Debian Linux
FedoraProftpd
Jun 17, 2026
Nov 30, 2019
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. A dereference of a NULL pointer may occur. This pointer is returned by the OpenSSL sk_X509_REVOKED_value() function when encountering an empty CRL inst...Show more
An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. A dereference of a NULL pointer may occur. This pointer is returned by the OpenSSL sk_X509_REVOKED_value() function when encountering an empty CRL installed by a system administrator. The dereference occurs when validating the certificate of a client connecting to the server in a TLS client/server mutual-authentication setup.Show less
5Canonical
DebianLinux+2 more
9Active Iq Unified Manager
Debian LinuxHci Compute Node+6 more
Jun 17, 2026
Nov 30, 2019
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
relay_open in kernel/relay.c in the Linux kernel through 5.4.1 allows local users to cause a denial of service (such as relay blockage) by triggering a NULL alloc_percpu result.
2Debian
Gnupg
3Debian Linux
GnupgLibgcrypt
Nov 21, 2024
Nov 29, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The mpi_powm function in Libgcrypt before 1.6.3 and GnuPG before 1.4.19 allows attackers to obtain sensitive information by leveraging timing differences when accessing a pre-computed table during modular exponentiation,...Show more
The mpi_powm function in Libgcrypt before 1.6.3 and GnuPG before 1.4.19 allows attackers to obtain sensitive information by leveraging timing differences when accessing a pre-computed table during modular exponentiation, related to a "Last-Level Cache Side-Channel Attack."Show less
2Debian
Gnupg
3Debian Linux
GnupgLibgcrypt
Nov 21, 2024
Nov 29, 2019
N/A· v4
4.2 MEDIUM· v3
1.9 LOW· v2
Libgcrypt before 1.6.3 and GnuPG before 1.4.19 does not implement ciphertext blinding for Elgamal decryption, which allows physically proximate attackers to obtain the server's private key by determining factors using cr...Show more
Libgcrypt before 1.6.3 and GnuPG before 1.4.19 does not implement ciphertext blinding for Elgamal decryption, which allows physically proximate attackers to obtain the server's private key by determining factors using crafted ciphertext and the fluctuations in the electromagnetic field during multiplication.Show less
3Debian
PuppetRuby Lang
5Debian Linux
Puppet AgentPuppet Enterprise+2 more
Nov 21, 2024
Nov 29, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
verify_certificate_identity in the OpenSSL extension in Ruby before 2.0.0 patchlevel 645, 2.1.x before 2.1.6, and 2.2.x before 2.2.2 does not properly validate hostnames, which allows remote attackers to spoof servers vi...Show more
verify_certificate_identity in the OpenSSL extension in Ruby before 2.0.0 patchlevel 645, 2.1.x before 2.1.6, and 2.2.x before 2.2.2 does not properly validate hostnames, which allows remote attackers to spoof servers via vectors related to (1) multiple wildcards, (1) wildcards in IDNA names, (3) case sensitivity, and (4) non-ASCII characters.Show less
4Canonical
DebianFedoraproject+1 more
4Debian Linux
FedoraLinux Kernel+1 more
Jun 17, 2026
Nov 29, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A heap overflow flaw was found in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The vulnerability allows a remote attacker to cause a system crash, resulting in a denial of se...Show more
A heap overflow flaw was found in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The vulnerability allows a remote attacker to cause a system crash, resulting in a denial of service, or execute arbitrary code. The highest threat with this vulnerability is with the availability of the system. If code execution occurs, the code will run with the permissions of root. This will affect both confidentiality and integrity of files on the system.Show less
3Canonical
DebianLinux
3Debian Linux
Linux KernelUbuntu Linux
Jun 17, 2026
Nov 29, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A stack-based buffer overflow was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip driver. An attacker is able to cause a denial of service (system crash) or, possibly execute arbitrary code, when a...Show more
A stack-based buffer overflow was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip driver. An attacker is able to cause a denial of service (system crash) or, possibly execute arbitrary code, when a STA works in IBSS mode (allows connecting stations together without the use of an AP) and connects to another STA.Show less
5Canonical
DebianFedoraproject+2 more
5Debian Linux
FedoraLeap+2 more
Jun 17, 2026
Nov 29, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A heap-based buffer overflow was discovered in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The flaw could occur when the station attempts a connection negotiation during the...Show more
A heap-based buffer overflow was discovered in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The flaw could occur when the station attempts a connection negotiation during the handling of the remote devices country settings. This could allow the remote device to cause a denial of service (system crash) or possibly execute arbitrary code.Show less
5Canonical
DebianLinux+2 more
14Active Iq Unified Manager
Aff A400 FirmwareAff A700s Firmware+11 more
Jun 17, 2026
Nov 28, 2019
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
In the Linux kernel 5.3.11, mounting a crafted btrfs image twice can cause an rwsem_down_write_slowpath use-after-free because (in rwsem_can_spin_on_owner in kernel/locking/rwsem.c) rwsem_owner_flags returns an already f...Show more
In the Linux kernel 5.3.11, mounting a crafted btrfs image twice can cause an rwsem_down_write_slowpath use-after-free because (in rwsem_can_spin_on_owner in kernel/locking/rwsem.c) rwsem_owner_flags returns an already freed pointer,Show less
2Debian
Vsftpd Project
2Debian Linux
Vsftpd
Nov 21, 2024
Nov 27, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
3Debian
Packagekit ProjectRedhat
3Debian Linux
Enterprise Linux ServerPackagekit
Nov 21, 2024
Nov 27, 2019
N/A· v4
5.3 MEDIUM· v3
4.6 MEDIUM· v2
PackageKit 0.6.17 allows installation of unsigned RPM packages as though they were signed which may allow installation of non-trusted packages and execution of arbitrary code.
3Debian
OpensuseOtrs
5Debian Linux
FaqOpensuse+2 more
Nov 21, 2024
Nov 27, 2019
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
An Access Bypass issue exists in OTRS Help Desk before 3.2.4, 3.1.14, and 3.0.19, OTRS ITSM before 3.2.3, 3.1.8, and 3.0.7, and FAQ before 2.2.3, 2.1.4, and 2.0.8. Access rights by the object linking mechanism is not ver...Show more
An Access Bypass issue exists in OTRS Help Desk before 3.2.4, 3.1.14, and 3.0.19, OTRS ITSM before 3.2.3, 3.1.8, and 3.0.7, and FAQ before 2.2.3, 2.1.4, and 2.0.8. Access rights by the object linking mechanism is not verifiedShow less
3Debian
GnupgRedhat
3Debian Linux
Enterprise LinuxGnupg
Nov 21, 2024
Nov 27, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
dirmngr before 2.1.0 improperly handles certain system calls, which allows remote attackers to cause a denial of service (DOS) via a specially-crafted certificate.
4Accountsservice Project
DebianOpensuse+1 more
4Accountsservice
Debian LinuxEnterprise Linux+1 more
Nov 21, 2024
Nov 27, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
An issue exists AccountService 0.6.37 in the user_change_password_authorized_cb() function in user.c which could let a local users obtain encrypted passwords.