← Back

Debian Linux

debian_linux

Vendor: Debian • 10,002 CVEs

CVEs (10,002)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
5Artifex
DebianFedoraproject+2 more
5Debian Linux
FedoraGhostscript+2 more
Jun 17, 2026
Sep 3, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A flaw was found in, ghostscript versions prior to 9.50, in the .pdfexectoken and other procedures where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially cra...Show more
A flaw was found in, ghostscript versions prior to 9.50, in the .pdfexectoken and other procedures where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.Show less
5Artifex
DebianFedoraproject+2 more
5Debian Linux
FedoraGhostscript+2 more
Jun 17, 2026
Sep 3, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafte...Show more
A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.Show less
3Canonical
DebianSamba
3Debian Linux
SambaUbuntu Linux
Jun 17, 2026
Sep 3, 2019
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
A flaw was found in samba versions 4.9.x up to 4.9.13, samba 4.10.x up to 4.10.8 and samba 4.11.x up to 4.11.0rc3, when certain parameters were set in the samba configuration file. An unauthenticated attacker could use t...Show more
A flaw was found in samba versions 4.9.x up to 4.9.13, samba 4.10.x up to 4.10.8 and samba 4.11.x up to 4.11.0rc3, when certain parameters were set in the samba configuration file. An unauthenticated attacker could use this flaw to escape the shared directory and access the contents of directories outside the share.Show less
3Canonical
DebianFreetype
3Debian Linux
FreetypeUbuntu Linux
Nov 21, 2024
Sep 3, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
FreeType before 2.6.2 has a heap-based buffer over-read in tt_cmap14_validate in sfnt/ttcmap.c.
2Debian
Freetype
2Debian Linux
Freetype
Nov 21, 2024
Sep 3, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
FreeType before 2.6.1 has a buffer over-read in skip_comment in psaux/psobjs.c because ps_parser_skip_PS_token is mishandled in an FT_New_Memory_Face operation.
2Debian
Freetype
2Debian Linux
Freetype
Nov 21, 2024
Sep 3, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
FreeType before 2.6.1 has a heap-based buffer over-read in T1_Get_Private_Dict in type1/t1parse.c.
2Debian
Videolan
2Debian Linux
Vlc Media Player
Jun 17, 2026
Aug 29, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A vulnerability in mkv::event_thread_t in VideoLAN VLC media player 3.0.7.1 allows remote attackers to trigger a heap-based buffer overflow via a crafted .mkv file.
2Debian
Videolan
2Debian Linux
Vlc Media Player
Jun 17, 2026
Aug 29, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The mkv::virtual_segment_c::seek method of demux/mkv/virtual_segment.cpp in VideoLAN VLC media player 3.0.7.1 has a use-after-free.
2Debian
Videolan
2Debian Linux
Vlc Media Player
Jun 17, 2026
Aug 29, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The Control function of demux/mkv/mkv.cpp in VideoLAN VLC media player 3.0.7.1 has a use-after-free.
2Debian
Videolan
2Debian Linux
Vlc Media Player
Jun 17, 2026
Aug 29, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A heap-based buffer over-read exists in DemuxInit() in demux/asf/asf.c in VideoLAN VLC media player 3.0.7.1 via a crafted .mkv file.
2Debian
Videolan
2Debian Linux
Vlc Media Player
Jun 17, 2026
Aug 29, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In VideoLAN VLC media player 3.0.7.1, there is a NULL pointer dereference at the function SeekPercent of demux/asf/asf.c that will lead to a denial of service attack.
2Debian
Videolan
2Debian Linux
Vlc Media Player
Jun 17, 2026
Aug 29, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The Control function of demux/asf/asf.c in VideoLAN VLC media player 3.0.7.1 has a use-after-free.
3Debian
LinuxRedhat
3Debian Linux
Enterprise LinuxLinux Kernel
Jun 17, 2026
Aug 29, 2019
N/A· v4
4.7 MEDIUM· v3
4.7 MEDIUM· v2
In the Linux kernel before 5.1.13, there is a memory leak in drivers/scsi/libsas/sas_expander.c when SAS expander discovery fails. This will cause a BUG and denial of service.
2Debian
Videolan
2Debian Linux
Vlc Media Player
Jun 17, 2026
Aug 29, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A divide-by-zero error exists in the SeekIndex function of demux/asf/asf.c in VideoLAN VLC media player 3.0.7.1. As a result, an FPE can be triggered via a crafted WMV file.
2Debian
Videolan
2Debian Linux
Vlc Media Player
Jun 17, 2026
Aug 29, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A divide-by-zero error exists in the Control function of demux/caf.c in VideoLAN VLC media player 3.0.7.1. As a result, an FPE can be triggered via a crafted CAF file.
2Debian
Videolan
2Debian Linux
Vlc Media Player
Jun 17, 2026
Aug 29, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A heap-based buffer over-read in xiph_PackHeaders() in modules/demux/xiph.h in VideoLAN VLC media player 3.0.7.1 allows remote attackers to trigger a heap-based buffer over-read via a crafted .ogg file.
2Debian
Videolan
2Debian Linux
Vlc Media Player
Jun 17, 2026
Aug 29, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The xiph_SplitHeaders function in modules/demux/xiph.h in VideoLAN VLC media player 3.0.7.1 does not check array bounds properly. As a result, a heap-based buffer over-read can be triggered via a crafted .ogg file.
3Debian
DovecotFedoraproject
4Debian Linux
DovecotFedora+1 more
Jun 17, 2026
Aug 29, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for quoted strings. This occurs because '\0' characters are mishandled, and can lead to out-of-bounds writ...Show more
In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for quoted strings. This occurs because '\0' characters are mishandled, and can lead to out-of-bounds writes and remote code execution.Show less
2Debian
Xymon
2Debian Linux
Xymon
Jun 17, 2026
Aug 27, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Xymon through 4.3.28, a stack-based buffer overflow exists in the status-log viewer component because of   expansion in svcstatus.c.
2Debian
Xymon
2Debian Linux
Xymon
Jun 17, 2026
Aug 27, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Xymon through 4.3.28, a stack-based buffer overflow vulnerability exists in the history viewer component via a long hostname or service parameter to history.c.