← Back

Debian Linux

debian_linux

Vendor: Debian • 10,002 CVEs

CVEs (10,002)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Cor Entertainment
DebianFedoraproject
3Alien Arena
Debian LinuxFedora
Nov 21, 2024
Nov 12, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
It is possible to cause a DoS condition by causing the server to crash in alien-arena 7.33 by supplying various invalid parameters to the download command.
3Debian
FedoraprojectLibpoe Component Irc Perl Project
3Debian Linux
FedoraLibpoe Component Irc Perl
Nov 21, 2024
Nov 12, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
libpoe-component-irc-perl before v6.32 does not remove carriage returns and line feeds. This can be used to execute arbitrary IRC commands by passing an argument such as "some text\rQUIT" to the 'privmsg' handler, which...Show more
libpoe-component-irc-perl before v6.32 does not remove carriage returns and line feeds. This can be used to execute arbitrary IRC commands by passing an argument such as "some text\rQUIT" to the 'privmsg' handler, which would cause the client to disconnect from the server.Show less
2Debian
Gargoyle Project
2Debian Linux
Gargoyle
Nov 21, 2024
Nov 12, 2019
N/A· v4
4.8 MEDIUM· v3
4.4 MEDIUM· v2
If LD_LIBRARY_PATH is undefined in gargoyle-free before 2009-08-25, the variable will point to the current directory. This can allow a local user to trick another user into running gargoyle in a directory with a cracked...Show more
If LD_LIBRARY_PATH is undefined in gargoyle-free before 2009-08-25, the variable will point to the current directory. This can allow a local user to trick another user into running gargoyle in a directory with a cracked libgarglk.so and gain access to the user's account.Show less
2Debian
Openstack
2Debian Linux
Keystone
Nov 21, 2024
Nov 12, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
OpenStack Keystone: extremely long passwords can crash Keystone by exhausting stack space
2Debian
Json Jwt Project
2Debian Linux
Json Jwt
Jun 17, 2026
Nov 12, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string.
2Atop Project
Debian
2Atop
Debian Linux
Nov 21, 2024
Nov 12, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
atop: symlink attack possible due to insecure tempfile handling
3Debian
GnomeRedhat
3Debian Linux
Enterprise LinuxGdk Pixbuf
Nov 21, 2024
Nov 12, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
gdk-pixbuf through 2.31.1 has GIF loader buffer overflow when initializing decompression tables due to an input validation flaw
4Canonical
DebianFedoraproject+1 more
4Debian Linux
FedoraTnef+1 more
Jun 17, 2026
Nov 11, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In tnef before 1.4.18, an attacker may be able to write to the victim's .ssh/authorized_keys file via an e-mail message with a crafted winmail.dat application/ms-tnef attachment, because of a heap-based buffer over-read...Show more
In tnef before 1.4.18, an attacker may be able to write to the victim's .ssh/authorized_keys file via an e-mail message with a crafted winmail.dat application/ms-tnef attachment, because of a heap-based buffer over-read involving strdup.Show less
2Debian
Noping
2Debian Linux
Liboping
Nov 21, 2024
Nov 9, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
liboping 1.3.2 allows users reading arbitrary files upon the local system.
3Debian
FedoraprojectRedhat
3389 Directory Server
Debian LinuxEnterprise Linux
Jun 17, 2026
Nov 8, 2019
N/A· v4
6.5 MEDIUM· v3
3.5 LOW· v2
A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes,...Show more
A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.Show less
2Debian
Gri Project
2Debian Linux
Gri
Nov 21, 2024
Nov 8, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
gri before 2.12.18 generates temporary files in an insecure way.
2Debian
Mantisbt
2Debian Linux
Mantisbt
Nov 21, 2024
Nov 7, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
An access control issue in MantisBT before 1.2.13 allows users with "Reporter" permissions to change any issue to "New".
2Debian
Gambas Project
2Debian Linux
Gambas
Nov 21, 2024
Nov 7, 2019
N/A· v4
7.5 HIGH· v3
6.4 MEDIUM· v2
Gambas before 3.4.0 allows remote attackers to move or manipulate directory contents or perform symlink attacks due to the creation of insecure temporary directories.
2Clamav
Debian
2Clamav
Debian Linux
Nov 21, 2024
Nov 7, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
clamav 0.91.2 suffers from a floating point exception when using ScanOLE2.
2Canonical
Debian
3Debian Linux
LintianUbuntu Linux
Nov 21, 2024
Nov 7, 2019
N/A· v4
6.3 MEDIUM· v3
4.3 MEDIUM· v2
Lintian before 2.5.12 allows remote attackers to gather information about the "host" system using crafted symlinks.
2Debian
Viewvc
2Debian Linux
Viewvc
Nov 21, 2024
Nov 7, 2019
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
viewvc 1.0.3 allows improper access control to files in a repository when using the "forbidden" configuration option.
2Debian
Ldap Git Backup Project
2Debian Linux
Ldap Git Backup
Nov 21, 2024
Nov 7, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
ldap-git-backup before 1.0.4 exposes password hashes due to incorrect directory permissions.
2Debian
Shibboleth
2Debian Linux
Service Provider
Nov 21, 2024
Nov 7, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which is placed in sp-key.pm. It relies on the root umask (default 22) instead of chmod...Show more
The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which is placed in sp-key.pm. It relies on the root umask (default 22) instead of chmoding the resulting file itself, so the generated private key is world readable by default.Show less
3Debian
SimplesamlphpXmlseclibs Project
3Debian Linux
SimplesamlphpXmlseclibs
Jun 17, 2026
Nov 7, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Rob Richards XmlSecLibs, all versions prior to v3.0.3, as used for example by SimpleSAMLphp, performed incorrect validation of cryptographic signatures in XML messages, allowing an authenticated attacker to impersonate o...Show more
Rob Richards XmlSecLibs, all versions prior to v3.0.3, as used for example by SimpleSAMLphp, performed incorrect validation of cryptographic signatures in XML messages, allowing an authenticated attacker to impersonate others or elevate privileges by creating a crafted XML message.Show less
2Debian
Tahoe Lafs
2Debian Linux
Tahoe Lafs
Nov 21, 2024
Nov 7, 2019
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
Tahoe-LAFS 1.9.0 fails to ensure integrity which allows remote attackers to corrupt mutable files or directories upon retrieval.