← Back

Debian Linux

debian_linux

Vendor: Debian • 10,002 CVEs

CVEs (10,002)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
4Debian
FedoraprojectOniguruma Project+1 more
4Debian Linux
Enterprise LinuxFedora+1 more
Jun 17, 2026
Nov 17, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An integer overflow in the search_in_range function in regexec.c in Oniguruma 6.x before 6.9.4_rc2 leads to an out-of-bounds read, in which the offset of this read is under the control of an attacker. (This only affects...Show more
An integer overflow in the search_in_range function in regexec.c in Oniguruma 6.x before 6.9.4_rc2 leads to an out-of-bounds read, in which the offset of this read is under the control of an attacker. (This only affects the 32-bit compiled version). Remote attackers can cause a denial-of-service or information disclosure, or possibly have unspecified other impact, via a crafted regular expression.Show less
2Debian
Linux Ax25
2Ax25 Tools
Debian Linux
Nov 21, 2024
Nov 15, 2019
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
The AX.25 daemon (ax25d) in ax25-tools before 0.0.8-13 does not check the return value of a setuid call. The setuid call is responsible for dropping privileges but if the call fails the daemon would continue to run with...Show more
The AX.25 daemon (ax25d) in ax25-tools before 0.0.8-13 does not check the return value of a setuid call. The setuid call is responsible for dropping privileges but if the call fails the daemon would continue to run with root privileges which can allow possible privilege escalation.Show less
4Debian
DrupalFedoraproject+1 more
4Debian Linux
DrupalEnterprise Linux+1 more
Nov 21, 2024
Nov 15, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type in the system or has the ability to point individual File upload fields...Show more
An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type in the system or has the ability to point individual File upload fields to the private file directory in comments, and the parent node is denied access, non-privileged users can still download the file attached to the comment if they know or guess its direct URL.Show less
2Debian
Gksu Polkit Project
2Debian Linux
Gksu Polkit
Nov 21, 2024
Nov 15, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In gksu-polkit before 0.0.3, the source file for xauth may contain arbitrary commands that may allow an attacker to overtake an administrator X11 session.
5Avaya
DebianMozilla+2 more
27Aura Application Enablement Services
Aura Application Server 5300Aura Communication Manager+24 more
Nov 21, 2024
Nov 15, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a...Show more
A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a Denial of Service.Show less
3Chrony Project
DebianFedoraproject
3Chrony
Debian LinuxFedora
Nov 21, 2024
Nov 15, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Chrony before 1.29.1 has traffic amplification in cmdmon protocol
3Clamav
DebianFedoraproject
3Clamav
Debian LinuxFedora
Nov 21, 2024
Nov 15, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
ClamAV before 0.97.7: dbg_printhex possible information leak
3Clamav
DebianFedoraproject
3Clamav
Debian LinuxFedora
Nov 21, 2024
Nov 15, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ClamAV before 0.97.7 has buffer overflow in the libclamav component
3Clamav
DebianFedoraproject
3Clamav
Debian LinuxFedora
Nov 21, 2024
Nov 15, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ClamAV before 0.97.7 has WWPack corrupt heap memory
2Debian
Horms
2Debian Linux
Perdition
Nov 21, 2024
Nov 15, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Perdition before 2.2 may have weak security when handling outbound connections, caused by an error in the STARTTLS IMAP and POP server. ssl_outgoing_ciphers not being applied to STARTTLS connections
3Cyrus
DebianFedoraproject
3Debian Linux
FedoraImap
Jun 17, 2026
Nov 15, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connec...Show more
Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection.Show less
3Canonical
DebianRack Cors Project
3Debian Linux
Rack CorsUbuntu Linux
Jun 17, 2026
Nov 14, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in the rack-cors (aka Rack CORS Middleware) gem before 1.0.4 for Ruby. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in...Show more
An issue was discovered in the rack-cors (aka Rack CORS Middleware) gem before 1.0.4 for Ruby. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format.Show less
8Canonical
DebianF5+5 more
778Big Ip Access Policy Manager
Big Ip Advanced Firewall ManagerBig Ip Analytics+775 more
Nov 21, 2024
Nov 14, 2019
N/A· v4
6.5 MEDIUM· v3
4.9 MEDIUM· v2
Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to potentially enable denial of service of the host system via local acces...Show more
Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to potentially enable denial of service of the host system via local access.Show less
3Debian
IntelOpensuse
59Debian Linux
LeapXeon 3104 Firmware+56 more
Jun 17, 2026
Nov 14, 2019
N/A· v4
6.0 MEDIUM· v3
2.1 LOW· v2
Improper conditions check in the voltage modulation interface for some Intel(R) Xeon(R) Scalable Processors may allow a privileged user to potentially enable denial of service via local access.
9Canonical
DebianFedoraproject+6 more
160Apollo 2000 Firmware
Apollo 4200 FirmwareCeleron 5305u Firmware+157 more
Jun 17, 2026
Nov 14, 2019
N/A· v4
6.5 MEDIUM· v3
2.1 LOW· v2
TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access.
4Debian
FedoraprojectMoodle+1 more
4Debian Linux
Enterprise LinuxFedora+1 more
Nov 21, 2024
Nov 14, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from groups the user does not belong to
2Debian
Klibc Project
2Debian Linux
Klibc
Nov 21, 2024
Nov 14, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
In klibc 1.5.20 and 1.5.21, the DHCP options written by ipconfig to /tmp/net-$DEVICE.conf are not properly escaped. This may allow a remote attacker to send a specially crafted DHCP reply which could execute arbitrary co...Show more
In klibc 1.5.20 and 1.5.21, the DHCP options written by ipconfig to /tmp/net-$DEVICE.conf are not properly escaped. This may allow a remote attacker to send a specially crafted DHCP reply which could execute arbitrary code with the privileges of any process which sources DHCP options.Show less
3Debian
OpensuseXfce
3Debian Linux
OpensuseThunar
Nov 21, 2024
Nov 14, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Thunar before 1.3.1 could crash when copy and pasting a file name with % format characters due to a format string error.
3Debian
OpensuseRsyslog
3Debian Linux
OpensuseRsyslog
Nov 21, 2024
Nov 14, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when multiple rulesets were used and some output batches contained messages belonging to more than one ruleset. A local...Show more
A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when multiple rulesets were used and some output batches contained messages belonging to more than one ruleset. A local attacker could cause denial of the rsyslogd daemon service via a log message belonging to more than one rulesetShow less
3Debian
OpensuseRsyslog
3Debian Linux
OpensuseRsyslog
Nov 21, 2024
Nov 14, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages were logged when multiple rulesets were used and some output batches contained messages belonging to more than one ruleset. A local...Show more
A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages were logged when multiple rulesets were used and some output batches contained messages belonging to more than one ruleset. A local attacker could cause denial of the rsyslogd daemon service via a log message belonging to more than one ruleset.Show less