← Back

Debian Linux

debian_linux

Vendor: Debian • 10,002 CVEs

CVEs (10,002)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Debian
Unzip Project
2Debian Linux
Unzip
Jun 17, 2026
Jul 4, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Info-ZIP UnZip 6.0 mishandles the overlapping of files inside a ZIP container, leading to denial of service (resource consumption), aka a "better zip bomb" issue.
4Canonical
DebianLibsdl+1 more
5Backports Sle
Debian LinuxLeap+2 more
Jun 17, 2026
Jul 3, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An exploitable integer overflow vulnerability exists when loading a PCX file in SDL2_image 2.0.4. A specially crafted file can cause an integer overflow, resulting in too little memory being allocated, which can lead to...Show more
An exploitable integer overflow vulnerability exists when loading a PCX file in SDL2_image 2.0.4. A specially crafted file can cause an integer overflow, resulting in too little memory being allocated, which can lead to a buffer overflow and potential code execution. An attacker can provide a specially crafted image file to trigger this vulnerability.Show less
4Canonical
DebianLibsdl+1 more
5Backports Sle
Debian LinuxLeap+2 more
Jun 17, 2026
Jul 3, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An exploitable heap-based buffer overflow vulnerability exists when loading a PCX file in SDL2_image, version 2.0.4. A missing error handler can lead to a buffer overflow and potential code execution. An attacker can pro...Show more
An exploitable heap-based buffer overflow vulnerability exists when loading a PCX file in SDL2_image, version 2.0.4. A missing error handler can lead to a buffer overflow and potential code execution. An attacker can provide a specially crafted image file to trigger this vulnerability.Show less
3Debian
DosboxFedoraproject
3Debian Linux
DosboxFedora
Jun 17, 2026
Jul 3, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A buffer overflow in DOSBox 0.74-2 allows attackers to execute arbitrary code.
4Canonical
DebianOpensuse+1 more
4Debian Linux
LeapQemu+1 more
Jun 17, 2026
Jul 3, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
qemu-bridge-helper.c in QEMU 3.1 and 4.0.0 does not ensure that a network interface name (obtained from bridge.conf or a --br=bridge option) is limited to the IFNAMSIZ size, which can lead to an ACL bypass.
2Debian
Dosbox
2Debian Linux
Dosbox
Jun 17, 2026
Jul 2, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
DOSBox 0.74-2 has Incorrect Access Control.
2Audiofile
Debian
2Audiofile
Debian Linux
Jun 17, 2026
Jul 2, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In Audio File Library (aka audiofile) 0.3.6, there exists one NULL pointer dereference bug in ulaw2linear_buf in G711.cpp in libmodules.a that allows an attacker to cause a denial of service via a crafted file.
3Canonical
DebianImagemagick
3Debian Linux
ImagemagickUbuntu Linux
Jun 17, 2026
Jul 1, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
ImageMagick before 7.0.8-50 has a memory leak vulnerability in the function ReadPSImage in coders/ps.c.
4Canonical
DebianF5+1 more
5Big Ip Application Acceleration Manager
Big Ip WebacceleratorDebian Linux+2 more
Jun 17, 2026
Jul 1, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
ImageMagick before 7.0.8-50 has a "use of uninitialized value" vulnerability in the function ReadCUTImage in coders/cut.c.
3Canonical
DebianDjangoproject
3Debian Linux
DjangoUbuntu Linux
Jun 17, 2026
Jul 1, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in Django 1.11 before 1.11.22, 2.1 before 2.1.10, and 2.2 before 2.2.3. An HTTP request is not redirected to HTTPS when the SECURE_PROXY_SSL_HEADER and SECURE_SSL_REDIRECT settings are used, and t...Show more
An issue was discovered in Django 1.11 before 1.11.22, 2.1 before 2.1.10, and 2.2 before 2.2.3. An HTTP request is not redirected to HTTPS when the SECURE_PROXY_SSL_HEADER and SECURE_SSL_REDIRECT settings are used, and the proxy connects to Django via HTTPS. In other words, django.http.HttpRequest.scheme has incorrect behavior when a client uses HTTP.Show less
6Canonical
DebianFedoraproject+3 more
6Debian Linux
FedoraLeap+3 more
Jun 17, 2026
Jul 1, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte on the stack contains...Show more
In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte on the stack contains the characters A, a, I, i, or 0, or any other character.Show less
4Canonical
DebianExiv2+1 more
4Debian Linux
Exiv2Fedora+1 more
Jun 17, 2026
Jun 30, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
http.c in Exiv2 through 0.27.1 allows a malicious http server to cause a denial of service (crash due to a NULL pointer dereference) by returning a crafted response that lacks a space character.
4Canonical
DebianExiv2+1 more
4Debian Linux
Exiv2Fedora+1 more
Jun 17, 2026
Jun 30, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A PngChunk::parseChunkContent uncontrolled memory allocation in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (crash due to an std::bad_alloc exception) via a crafted PNG image file.
4Canonical
DebianExiv2+1 more
4Debian Linux
Exiv2Fedora+1 more
Jun 17, 2026
Jun 30, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A CiffDirectory::readDirectory integer overflow and out-of-bounds read in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV) via a crafted CRW image file.
2Debian
Lemonldap Ng
2Debian Linux
Lemonldap\
Jun 17, 2026
Jun 28, 2019
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
LemonLDAP::NG before 1.9.20 has an XML External Entity (XXE) issue when submitting a notification to the notification server. By default, the notification server is not enabled and has a "deny all" rule.
4Debian
FedoraprojectGoogle+1 more
5Backports
ChromeDebian Linux+2 more
Jun 17, 2026
Jun 27, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Incorrect security UI in popup blocker in Google Chrome on iOS prior to 75.0.3770.80 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
4Debian
FedoraprojectGoogle+1 more
5Backports
ChromeDebian Linux+2 more
Jun 17, 2026
Jun 27, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Excessive data validation in URL parser in Google Chrome prior to 75.0.3770.80 allowed a remote attacker who convinced a user to input a URL to bypass website URL validation via a crafted URL.
4Debian
FedoraprojectGoogle+1 more
5Backports
ChromeDebian Linux+2 more
Jun 17, 2026
Jun 27, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient policy enforcement in extensions API in Google Chrome prior to 75.0.3770.80 allowed an attacker who convinced a user to install a malicious extension to bypass restrictions on file URIs via a crafted Chrome...Show more
Insufficient policy enforcement in extensions API in Google Chrome prior to 75.0.3770.80 allowed an attacker who convinced a user to install a malicious extension to bypass restrictions on file URIs via a crafted Chrome Extension.Show less
4Debian
FedoraprojectGoogle+1 more
5Backports
ChromeDebian Linux+2 more
Jun 17, 2026
Jun 27, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Resource size information leakage in Blink in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
4Debian
FedoraprojectGoogle+1 more
5Backports
ChromeDebian Linux+2 more
Jun 17, 2026
Jun 27, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Heap buffer overflow in ANGLE in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.