← Back

Debian Linux

debian_linux

Vendor: Debian • 10,002 CVEs

CVEs (10,002)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Canonical
DebianSpip
3Debian Linux
SpipUbuntu Linux
Jun 17, 2026
Sep 17, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
SPIP before 3.1.11 and 3.2 before 3.2.5 allows authenticated visitors to modify any published content and execute other modifications in the database. This is related to ecrire/inc/meta.php and ecrire/inc/securiser_actio...Show more
SPIP before 3.1.11 and 3.2 before 3.2.5 allows authenticated visitors to modify any published content and execute other modifications in the database. This is related to ecrire/inc/meta.php and ecrire/inc/securiser_action.php.Show less
8Canonical
DebianFedoraproject+5 more
34Aff A700s Firmware
Data Availability ServicesDebian Linux+31 more
Jun 17, 2026
Sep 17, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged gu...Show more
A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged guest user able to pass descriptors with invalid length to the host when migration is underway, could use this flaw to increase their privileges on the host.Show less
4Canonical
DebianFedoraproject+1 more
4Debian Linux
FedoraOpendmarc+1 more
Jun 17, 2026
Sep 17, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 is prone to a signature-bypass vulnerability with multiple From: addresses, which might affect applications that consider a domain name to be relevant to the origin o...Show more
OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 is prone to a signature-bypass vulnerability with multiple From: addresses, which might affect applications that consider a domain name to be relevant to the origin of an e-mail message.Show less
5Canonical
DebianFedoraproject+2 more
5Debian Linux
FedoraLeap+2 more
Jun 17, 2026
Sep 17, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
process_http_response in OpenConnect before 8.05 has a Buffer Overflow when a malicious server uses HTTP chunked encoding with crafted chunk sizes.
6Debian
FedoraprojectHaxx+3 more
17Cloud Backup
Communications Operations MonitorCommunications Session Border Controller+14 more
Jun 17, 2026
Sep 16, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Heap buffer overflow in the TFTP protocol handler in cURL 7.19.4 to 7.65.3.
6Debian
FedoraprojectHaxx+3 more
12Cloud Backup
Communications Operations MonitorCommunications Session Border Controller+9 more
Jun 17, 2026
Sep 16, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.
2Debian
Gpac
2Debian Linux
Gpac
Nov 21, 2024
Sep 16, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
audio_sample_entry_AddBox() at isomedia/box_code_base.c in GPAC 0.7.1 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.
2Debian
Gpac
2Debian Linux
Gpac
Nov 21, 2024
Sep 16, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
AVC_DuplicateConfig() at isomedia/avc_ext.c in GPAC 0.7.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file. There is "cfg_new->AVCLevelIndication =...Show more
AVC_DuplicateConfig() at isomedia/avc_ext.c in GPAC 0.7.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file. There is "cfg_new->AVCLevelIndication = cfg->AVCLevelIndication;" but cfg could be NULL.Show less
6Debian
FasterxmlFedoraproject+3 more
17Banking Platform
Customer Management And Segmentation FoundationDebian Linux+14 more
Jun 17, 2026
Sep 15, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariDataSource. This is a different vulnerability than CVE-2019-14540.
6Debian
FasterxmlFedoraproject+3 more
19Banking Platform
Customer Management And Segmentation FoundationDebian Linux+16 more
Jun 17, 2026
Sep 15, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariConfig.
3Debian
OpensuseWireshark
3Debian Linux
LeapWireshark
Jun 17, 2026
Sep 15, 2019
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
In Wireshark 3.0.0 to 3.0.3 and 2.6.0 to 2.6.10, the Gryphon dissector could go into an infinite loop. This was addressed in plugins/epan/gryphon/packet-gryphon.c by checking for a message length of zero.
3Canonical
DebianW1.fi
4Debian Linux
HostapdUbuntu Linux+1 more
Jun 17, 2026
Sep 12, 2019
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
hostapd before 2.10 and wpa_supplicant before 2.10 allow an incorrect indication of disconnection in certain situations because source address validation is mishandled. This is a denial of service that should have been p...Show more
hostapd before 2.10 and wpa_supplicant before 2.10 allow an incorrect indication of disconnection in certain situations because source address validation is mishandled. This is a denial of service that should have been prevented by PMF (aka management frame protection). The attacker must send a crafted 802.11 frame from a location that is within the 802.11 communications range.Show less
4Canonical
DebianDino+1 more
4Debian Linux
DinoFedora+1 more
Jun 17, 2026
Sep 11, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Dino before 2019-09-10 does not properly check the source of an MAM message in module/xep/0313_message_archive_management.vala.
4Canonical
DebianDino+1 more
4Debian Linux
DinoFedora+1 more
Jun 17, 2026
Sep 11, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Dino before 2019-09-10 does not check roster push authorization in module/roster/module.vala.
4Canonical
DebianDino+1 more
4Debian Linux
DinoFedora+1 more
Jun 17, 2026
Sep 11, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Dino before 2019-09-10 does not properly check the source of a carbons message in module/xep/0280_message_carbons.vala.
2Debian
Wordpress
2Debian Linux
Wordpress
Jun 17, 2026
Sep 11, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
WordPress before 5.2.3 allows XSS in post previews by authenticated users.
2Debian
Wordpress
2Debian Linux
Wordpress
Jun 17, 2026
Sep 11, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
WordPress before 5.2.3 has an issue with URL sanitization in wp_kses_bad_protocol_once in wp-includes/kses.php that can lead to cross-site scripting (XSS) attacks.
2Debian
Wordpress
2Debian Linux
Wordpress
Jun 17, 2026
Sep 11, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
WordPress before 5.2.3 allows reflected XSS in the dashboard.
2Debian
Wordpress
2Debian Linux
Wordpress
Jun 17, 2026
Sep 11, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
In WordPress before 5.2.3, validation and sanitization of a URL in wp_validate_redirect in wp-includes/pluggable.php could lead to an open redirect if a provided URL path does not start with a forward slash.
2Debian
Wordpress
2Debian Linux
Wordpress
Jun 17, 2026
Sep 11, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
WordPress before 5.2.3 allows XSS in shortcode previews.