← Back

Debian Linux

debian_linux

Vendor: Debian • 10,001 CVEs

CVEs (10,001)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Debian
Hardlink ProjectRedhat
3Debian Linux
Enterprise LinuxHardlink
Nov 21, 2024
Nov 26, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Hardlink before 0.1.2 has multiple integer overflows leading to heap-based buffer overflows because of the way string lengths concatenation is done in the calculation of the required memory space to be used. A remote att...Show more
Hardlink before 0.1.2 has multiple integer overflows leading to heap-based buffer overflows because of the way string lengths concatenation is done in the calculation of the required memory space to be used. A remote attacker could provide a specially-crafted directory tree and trick the local user into consolidating it, leading to hardlink executable crash or potentially arbitrary code execution with user privileges.Show less
3Debian
Hardlink ProjectRedhat
3Debian Linux
Enterprise LinuxHardlink
Nov 21, 2024
Nov 26, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Hardlink before 0.1.2 suffer from multiple stack-based buffer overflow flaws because of the way directory trees with deeply nested directories are processed. A remote attacker could provide a specially-crafted directory...Show more
Hardlink before 0.1.2 suffer from multiple stack-based buffer overflow flaws because of the way directory trees with deeply nested directories are processed. A remote attacker could provide a specially-crafted directory tree, and trick the local user into consolidating it, leading to hardlink executable crash, or, potentially arbitrary code execution with the privileges of the user running the hardlink executable.Show less
2Debian
Tahoe Lafs
2Debian Linux
Tahoe Lafs
Nov 21, 2024
Nov 26, 2019
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
Tahoe-LAFS v1.3.0 through v1.8.2 could allow unauthorized users to delete immutable files in some cases.
2Debian
Polipo Project
2Debian Linux
Polipo
Nov 21, 2024
Nov 26, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Polipo before 1.0.4.1 suffers from a DoD vulnerability via specially-crafted HTTP POST / PUT request.
1Debian
2Advanced Package Tool
Debian Linux
Nov 21, 2024
Nov 26, 2019
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
It was found that apt-key in apt, all versions, do not correctly validate gpg keys with the master keyring, leading to a potential man-in-the-middle attack.
3Canonical
DebianSuse
3Cloud Init
Debian LinuxLinux Enterprise Server
Nov 21, 2024
Nov 25, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
An privilege elevation vulnerability exists in Cloud-init before 0.7.0 when requests to an untrusted system are submitted for EC2 instance data.
5Canonical
DebianFedoraproject+2 more
5Debian Linux
FedoraOniguruma+2 more
Jun 17, 2026
Nov 25, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Oniguruma through 6.9.3, as used in PHP 7.3.x and other products, has a heap-based buffer over-read in str_lower_case_match in regexec.c.
2Debian
Gnu
2Debian Linux
Patch
Nov 21, 2024
Nov 25, 2019
N/A· v4
7.5 HIGH· v3
6.4 MEDIUM· v2
A Directory Traversal vulnerability exists in the GNU patch before 2.7.4. A remote attacker can write to arbitrary files via a symlink attack in a patch file. NOTE: this issue exists because of an incomplete fix for CVE-...Show more
A Directory Traversal vulnerability exists in the GNU patch before 2.7.4. A remote attacker can write to arbitrary files via a symlink attack in a patch file. NOTE: this issue exists because of an incomplete fix for CVE-2015-1196.Show less
4Debian
FedoraprojectLibuser Project+1 more
4Debian Linux
Enterprise LinuxFedora+1 more
Jan 23, 2026
Nov 25, 2019
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
libuser has information disclosure when moving user's home directory
3Debian
QuaggaRedhat
3Debian Linux
Enterprise LinuxQuagga
Nov 21, 2024
Nov 25, 2019
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
quagga (ospf6d) 0.99.21 has a DoS flaw in the way the ospf6d daemon performs routes removal
5Broadcom
DebianFedoraproject+2 more
5Debian Linux
FedoraOpenstack+2 more
Jun 17, 2026
Nov 23, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain a web management plugin that is v...Show more
Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain a web management plugin that is vulnerable to a denial of service attack. The "X-Reason" HTTP Header can be leveraged to insert a malicious Erlang format string that will expand and consume the heap, resulting in the server crashing.Show less
2Debian
Vanderbilt
2Adaptive Communication Environment
Debian Linux
Nov 21, 2024
Nov 22, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
generate_doygen.pl in ace before 6.2.7+dfsg-2 creates predictable file names in the /tmp directory which allows attackers to gain elevated privileges.
2Call Cc
Debian
2Chicken
Debian Linux
Nov 21, 2024
Nov 22, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Buffer overflow in CHICKEN 4.9.0 and 4.9.0.1 may allow remote attackers to execute arbitrary code via the 'select' function.
2Debian
Digium
3Asterisk
Certified AsteriskDebian Linux
Jun 17, 2026
Nov 22, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
An issue was discovered in manager.c in Sangoma Asterisk through 13.x, 16.x, 17.x and Certified Asterisk 13.21 through 13.21-cert4. A remote authenticated Asterisk Manager Interface (AMI) user without system authorizatio...Show more
An issue was discovered in manager.c in Sangoma Asterisk through 13.x, 16.x, 17.x and Certified Asterisk 13.21 through 13.21-cert4. A remote authenticated Asterisk Manager Interface (AMI) user without system authorization could use a specially crafted Originate AMI request to execute arbitrary system commands.Show less
2Debian
Digium
3Asterisk
Certified AsteriskDebian Linux
Jun 17, 2026
Nov 22, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in res_pjsip_t38.c in Sangoma Asterisk through 13.x and Certified Asterisk through 13.21-x. If it receives a re-invite initiating T.38 faxing and has a port of 0 and no c line in the SDP, a NULL p...Show more
An issue was discovered in res_pjsip_t38.c in Sangoma Asterisk through 13.x and Certified Asterisk through 13.21-x. If it receives a re-invite initiating T.38 faxing and has a port of 0 and no c line in the SDP, a NULL pointer dereference and crash will occur. This is different from CVE-2019-18940.Show less
2Debian
Digium
3Asterisk
Certified AsteriskDebian Linux
Jun 17, 2026
Nov 22, 2019
N/A· v4
6.5 MEDIUM· v3
5.8 MEDIUM· v2
An issue was discovered in channels/chan_sip.c in Sangoma Asterisk 13.x before 13.29.2, 16.x before 16.6.2, and 17.x before 17.0.1, and Certified Asterisk 13.21 before cert5. A SIP request can be sent to Asterisk that ca...Show more
An issue was discovered in channels/chan_sip.c in Sangoma Asterisk 13.x before 13.29.2, 16.x before 16.6.2, and 17.x before 17.0.1, and Certified Asterisk 13.21 before cert5. A SIP request can be sent to Asterisk that can change a SIP peer's IP address. A REGISTER does not need to occur, and calls can be hijacked as a result. The only thing that needs to be known is the peer's name; authentication details such as passwords do not need to be known. This vulnerability is only exploitable when the nat option is set to the default, or auto_force_rport.Show less
2Debian
Postfix Admin Project
2Debian Linux
Postfix Admin
Nov 21, 2024
Nov 22, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
PostfixAdmin 2.3.4 has multiple XSS vulnerabilities
4Debian
FedoraprojectRedhat+1 more
4Debian Linux
Enterprise LinuxFedora+1 more
Nov 21, 2024
Nov 22, 2019
N/A· v4
4.7 MEDIUM· v3
3.3 LOW· v2
libbluray MountManager class has a time-of-check time-of-use (TOCTOU) race when expanding JAR files
3Debian
OpenstackRedhat
3Debian Linux
DesignateEnterprise Linux Openstack Platform
Nov 21, 2024
Nov 22, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Designate does not enforce the DNS protocol limit concerning record set sizes
3Debian
OpensuseRedhat
4Ansible
Backports SleDebian Linux+1 more
Jun 17, 2026
Nov 22, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, prompt passwords by expanding them from templates as they could contain special characters....Show more
ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, prompt passwords by expanding them from templates as they could contain special characters. Passwords should be wrapped to prevent templates trigger and exposing them.Show less