← Back

Debian Linux

debian_linux

Vendor: Debian • 10,002 CVEs

CVEs (10,002)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
5Canonical
DebianIcoutils Project+2 more
11Debian Linux
Enterprise LinuxEnterprise Linux Desktop+8 more
Nov 21, 2024
Nov 4, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Integer overflow in the extract_group_icon_cursor_resource function in b/wrestool/extract.c in icoutils before 0.31.1 allows local users to cause a denial of service (process crash) or execute arbitrary code via a crafte...Show more
Integer overflow in the extract_group_icon_cursor_resource function in b/wrestool/extract.c in icoutils before 0.31.1 allows local users to cause a denial of service (process crash) or execute arbitrary code via a crafted executable file.Show less
5Canonical
DebianIcoutils Project+2 more
11Debian Linux
Enterprise LinuxEnterprise Linux Desktop+8 more
Nov 21, 2024
Nov 4, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The extract_group_icon_cursor_resource in wrestool/extract.c in icoutils before 0.31.1 can access unallocated memory, which allows local users to cause a denial of service (process crash) and execute arbitrary code via a...Show more
The extract_group_icon_cursor_resource in wrestool/extract.c in icoutils before 0.31.1 can access unallocated memory, which allows local users to cause a denial of service (process crash) and execute arbitrary code via a crafted executable.Show less
4Canonical
DebianIcoutils Project+1 more
5Debian Linux
IcoutilsLeap+2 more
Nov 21, 2024
Nov 4, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Integer overflow in the check_offset function in b/wrestool/fileread.c in icoutils before 0.31.1 allows local users to cause a denial of service (process crash) and execute arbitrary code via a crafted executable.
4Debian
FedoraprojectRedhat+1 more
4Debian Linux
Enterprise LinuxFedora+1 more
Nov 21, 2024
Nov 4, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
The scipy.weave component in SciPy before 0.12.1 creates insecure temporary directories.
3Debian
RedhatSudo Project
4Debian Linux
Enterprise LinuxShadow+1 more
Nov 21, 2024
Nov 4, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program". The user session can be escaped to the parent session by using the TIOCSTI ioctl to push characters into...Show more
There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program". The user session can be escaped to the parent session by using the TIOCSTI ioctl to push characters into the input buffer to be read by the next process.Show less
6Broadcom
CanonicalDebian+3 more
188300 Firmware
8700 FirmwareA400 Firmware+15 more
Jun 17, 2026
Nov 4, 2019
N/A· v4
7.0 HIGH· v3
6.9 MEDIUM· v2
An issue was discovered in drivers/media/platform/vivid in the Linux kernel through 5.3.8. It is exploitable for privilege escalation on some Linux distributions where local users have /dev/video0 access, but only if the...Show more
An issue was discovered in drivers/media/platform/vivid in the Linux kernel through 5.3.8. It is exploitable for privilege escalation on some Linux distributions where local users have /dev/video0 access, but only if the driver happens to be loaded. There are multiple race conditions during streaming stopping in this driver (part of the V4L2 subsystem). These issues are caused by wrong mutex locking in vivid_stop_generating_vid_cap(), vivid_stop_generating_vid_out(), sdr_cap_stop_streaming(), and the corresponding kthreads. At least one of these race conditions leads to a use-after-free.Show less
2Berlios
Debian
2Debian Linux
Slim
Nov 21, 2024
Nov 4, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
slim has NULL pointer dereference when using crypt() method from glibc 2.17
3Debian
FedoraprojectSmokeping
3Debian Linux
FedoraSmokeping
Nov 21, 2024
Nov 1, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in SmokePing 2.6.9 in the start and end time fields.
3Debian
OpenstackRedhat
4Compute
Debian LinuxKeystone+1 more
Nov 21, 2024
Nov 1, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to validate server-side SSL certificates.
2Debian
Mutt
2Debian Linux
Mutt
Nov 20, 2024
Nov 1, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Mutt before 1.5.20 patch 7 allows an attacker to cause a denial of service via a series of requests to mutt temporary files.
2Debian
Glpi Project
2Debian Linux
Glpi
Nov 21, 2024
Nov 1, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
GLPI 0.83.7 has Local File Inclusion in common.tabs.php.
4Debian
GnomeOpensuse+1 more
4Debian Linux
Enterprise LinuxEvince+1 more
Nov 21, 2024
Nov 1, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
evince is missing a check on number of pages which can lead to a segmentation fault
2Debian
Readymedia Project
2Debian Linux
Readymedia
Nov 21, 2024
Nov 1, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
MiniDLNA has heap-based buffer overflow
2Debian
Miniupnp Project
2Debian Linux
Miniupnpd
Nov 21, 2024
Nov 1, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
MiniUPnPd has information disclosure use of snprintf()
4Debian
OpensusePython+1 more
7Debian Linux
Enterprise LinuxEnterprise Linux Eus+4 more
Jun 17, 2026
Oct 31, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org Python 2.7.11 / 3.6.6. A specially crafted X509 certificate can cause a NULL pointer dereference, resulting in a denial o...Show more
An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org Python 2.7.11 / 3.6.6. A specially crafted X509 certificate can cause a NULL pointer dereference, resulting in a denial of service. An attacker can initiate or accept TLS connections using crafted certificates to trigger this vulnerability.Show less
2Call Cc
Debian
2Chicken
Debian Linux
Nov 21, 2024
Oct 31, 2019
N/A· v4
6.5 MEDIUM· v3
5.0 MEDIUM· v2
Chicken before 4.8.0 does not properly handle NUL bytes in certain strings, which allows an attacker to conduct "poisoned NUL byte attack."
2Call Cc
Debian
2Chicken
Debian Linux
Nov 21, 2024
Oct 31, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
OS command injection vulnerability in the "qs" procedure from the "utils" module in Chicken before 4.9.0.
2Autojump Project
Debian
2Autojump
Debian Linux
Nov 21, 2024
Oct 31, 2019
N/A· v4
7.3 HIGH· v3
4.4 MEDIUM· v2
autojump before 21.5.8 allows local users to gain privileges via a Trojan horse custom_install directory in the current working directory.
2Debian
Mediawiki
2Debian Linux
Mediawiki
Nov 21, 2024
Oct 31, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.5 and 1.20.x before 1.20.4 and allows remote attackers to inject arbitrary web script or HTML via Lua function names.
2Debian
Mantisbt
2Debian Linux
Mantisbt
Nov 21, 2024
Oct 31, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A cross-site scripting (XSS) vulnerability in the configuration report page (adm_config_report.php) in MantisBT 1.2.0rc1 before 1.2.14 allows remote authenticated users to inject arbitrary web script or HTML via a comple...Show more
A cross-site scripting (XSS) vulnerability in the configuration report page (adm_config_report.php) in MantisBT 1.2.0rc1 before 1.2.14 allows remote authenticated users to inject arbitrary web script or HTML via a complex value.Show less