← Back

Debian Linux

debian_linux

Vendor: Debian • 10,001 CVEs

CVEs (10,001)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
5Canonical
DebianHaxx+2 more
9Communications Webrtc Session Controller
CurlDebian Linux+6 more
Apr 15, 2026
May 24, 2018
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
curl version curl 7.20.0 to and including curl 7.59.0 contains a CWE-126: Buffer Over-read vulnerability in denial of service that can result in curl can be tricked into reading data beyond the end of a heap based buffer...Show more
curl version curl 7.20.0 to and including curl 7.59.0 contains a CWE-126: Buffer Over-read vulnerability in denial of service that can result in curl can be tricked into reading data beyond the end of a heap based buffer used to store downloaded RTSP content.. This vulnerability appears to have been fixed in curl < 7.20.0 and curl >= 7.60.0.Show less
4Canonical
DebianLinux+1 more
10Debian Linux
Enterprise LinuxEnterprise Linux Desktop+7 more
Nov 21, 2024
May 24, 2018
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
The Linux Kernel version 3.18 contains a dangerous feature vulnerability in modify_user_hw_breakpoint() that can result in crash and possibly memory corruption. This attack appear to be exploitable via local code executi...Show more
The Linux Kernel version 3.18 contains a dangerous feature vulnerability in modify_user_hw_breakpoint() that can result in crash and possibly memory corruption. This attack appear to be exploitable via local code execution and the ability to use ptrace. This vulnerability appears to have been fixed in git commit f67b15037a7a50c57f72e69a6d59941ad90a0f0f.Show less
2Artifex
Debian
2Debian Linux
Mupdf
Nov 21, 2024
May 24, 2018
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In Artifex MuPDF 1.12.0 and earlier, multiple use of uninitialized value bugs in the PDF parser could allow an attacker to cause a denial of service (crash) or influence program flow via a crafted file.
2Artifex
Debian
2Debian Linux
Mupdf
Nov 21, 2024
May 24, 2018
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In Artifex MuPDF 1.12.0 and earlier, multiple reachable assertions in the PDF parser allow an attacker to cause a denial of service (assert crash) via a crafted file.
2Artifex
Debian
2Debian Linux
Mupdf
Nov 21, 2024
May 24, 2018
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In Artifex MuPDF 1.12.0 and earlier, multiple memory leaks in the PDF parser allow an attacker to cause a denial of service (memory leak) via a crafted file.
4Canonical
DebianOpensuse+1 more
4Debian Linux
LeapProcps Ng+1 more
Dec 17, 2025
May 23, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
procps-ng before version 3.3.15 is vulnerable to a stack buffer overflow in pgrep. This vulnerability is mitigated by FORTIFY, as it involves strncat() to a stack-allocated string. When pgrep is compiled with FORTIFY (as...Show more
procps-ng before version 3.3.15 is vulnerable to a stack buffer overflow in pgrep. This vulnerability is mitigated by FORTIFY, as it involves strncat() to a stack-allocated string. When pgrep is compiled with FORTIFY (as on Red Hat Enterprise Linux and Fedora), the impact is limited to a crash.Show less
3Canonical
DebianProcps Ng Project
3Debian Linux
Procps NgUbuntu Linux
Nov 21, 2024
May 23, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
procps-ng before version 3.3.15 is vulnerable to a denial of service in ps via mmap buffer overflow. Inbuilt protection in ps maps a guard page at the end of the overflowed buffer, ensuring that the impact of this flaw i...Show more
procps-ng before version 3.3.15 is vulnerable to a denial of service in ps via mmap buffer overflow. Inbuilt protection in ps maps a guard page at the end of the overflowed buffer, ensuring that the impact of this flaw is limited to a crash (temporary denial of service).Show less
3Canonical
DebianProcps Ng Project
3Debian Linux
Procps NgUbuntu Linux
Nov 21, 2024
May 23, 2018
N/A· v4
7.0 HIGH· v3
4.4 MEDIUM· v2
procps-ng before version 3.3.15 is vulnerable to a local privilege escalation in top. If a user runs top with HOME unset in an attacker-controlled directory, the attacker could achieve privilege escalation by exploiting...Show more
procps-ng before version 3.3.15 is vulnerable to a local privilege escalation in top. If a user runs top with HOME unset in an attacker-controlled directory, the attacker could achieve privilege escalation by exploiting one of several vulnerabilities in the config_file() function.Show less
5Canonical
DebianProcps Ng Project+2 more
10Debian Linux
Enterprise LinuxEnterprise Linux Desktop+7 more
Nov 21, 2024
May 23, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
procps-ng before version 3.3.15 is vulnerable to an incorrect integer size in proc/alloc.* leading to truncation/integer overflow issues. This flaw is related to CVE-2018-1124.
6Canonical
DebianOpensuse+3 more
9Debian Linux
Enterprise LinuxEnterprise Linux Desktop+6 more
Nov 21, 2024
May 23, 2018
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
procps-ng before version 3.3.15 is vulnerable to multiple integer overflows leading to a heap corruption in file2strvec function. This allows a privilege escalation for a local attacker who can create entries in procfs b...Show more
procps-ng before version 3.3.15 is vulnerable to multiple integer overflows leading to a heap corruption in file2strvec function. This allows a privilege escalation for a local attacker who can create entries in procfs by starting processes, which could result in crashes or arbitrary code execution in proc utilities run by other users.Show less
2Debian
Wireshark
2Debian Linux
Wireshark
Nov 21, 2024
May 22, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the LDSS dissector could crash. This was addressed in epan/dissectors/packet-ldss.c by avoiding a buffer over-read upon encountering a missing '\0' character.
2Debian
Wireshark
2Debian Linux
Wireshark
Nov 21, 2024
May 22, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the GSM A DTAP dissector could crash. This was addressed in epan/dissectors/packet-gsm_a_dtap.c by fixing an off-by-one error that caused a buffer overflow.
2Debian
Wireshark
2Debian Linux
Wireshark
Nov 21, 2024
May 22, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the RRC dissector and other dissectors could crash. This was addressed in epan/proto.c by avoiding a NULL pointer dereference.
2Debian
Wireshark
2Debian Linux
Wireshark
Nov 21, 2024
May 22, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the Q.931 dissector could crash. This was addressed in epan/dissectors/packet-q931.c by avoiding a use-after-free after a malformed packet prevented certain cleanu...Show more
In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the Q.931 dissector could crash. This was addressed in epan/dissectors/packet-q931.c by avoiding a use-after-free after a malformed packet prevented certain cleanup.Show less
2Debian
Wireshark
2Debian Linux
Wireshark
Nov 21, 2024
May 22, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the LTP dissector and other dissectors could consume excessive memory. This was addressed in epan/tvbuff.c by rejecting negative lengths.
2Debian
Wireshark
2Debian Linux
Wireshark
Nov 21, 2024
May 22, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the DNS dissector could crash. This was addressed in epan/dissectors/packet-dns.c by avoiding a NULL pointer dereference for an empty name in an SRV record.
12Arm
CanonicalDebian+9 more
282Atom C
Atom EAtom X5 E3930+279 more
May 29, 2026
May 22, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an atta...Show more
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB), Variant 4.Show less
3Canonical
DebianLinux
3Debian Linux
Linux KernelUbuntu Linux
Nov 21, 2024
May 21, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
kernel drivers before version 4.17-rc1 are vulnerable to a weakness in the Linux kernel's implementation of random seed data. Programs, early in the boot sequence, could use the data allocated for the seed before it was...Show more
kernel drivers before version 4.17-rc1 are vulnerable to a weakness in the Linux kernel's implementation of random seed data. Programs, early in the boot sequence, could use the data allocated for the seed before it was sufficiently generated.Show less
3Apache
DebianOracle
3Debian Linux
Goldengate Stream AnalyticsZookeeper
Jun 17, 2026
May 21, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, and 3.5.0-alpha through 3.5.3-beta. As a result an arbitrary end point could join the cluster and beg...Show more
No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, and 3.5.0-alpha through 3.5.3-beta. As a result an arbitrary end point could join the cluster and begin propagating counterfeit changes to the leader.Show less
2Debian
Syntastic Project
2Debian Linux
Syntastic
Nov 21, 2024
May 20, 2018
N/A· v4
7.5 HIGH· v3
8.5 HIGH· v2
Syntastic (aka vim-syntastic) through 3.9.0 does not properly handle searches for configuration files (it searches the current directory up to potentially the root). This improper handling might be exploited for arbitrar...Show more
Syntastic (aka vim-syntastic) through 3.9.0 does not properly handle searches for configuration files (it searches the current directory up to potentially the root). This improper handling might be exploited for arbitrary code execution via a malicious gcc plugin, if an attacker has write access to a directory that is a parent of the base directory of the project being checked. NOTE: exploitation is more difficult after 3.8.0 because filename prediction may be needed.Show less