← Back

Debian Linux

debian_linux

Vendor: Debian • 10,001 CVEs

CVEs (10,001)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Canonical
DebianRuby Lang
3Debian Linux
RubyUbuntu Linux
Jun 17, 2026
Apr 3, 2018
N/A· v4
9.1 CRITICAL· v3
7.5 HIGH· v2
In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, the Dir.open, Dir.new, Dir.entries and Dir.empty? methods do not check NULL characters. When using the corresponding...Show more
In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, the Dir.open, Dir.new, Dir.entries and Dir.empty? methods do not check NULL characters. When using the corresponding method, unintentional directory traversal may be performed.Show less
3Canonical
DebianRuby Lang
3Debian Linux
RubyUbuntu Linux
Jun 17, 2026
Apr 3, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, the UNIXServer.open and UNIXSocket.open methods are not checked for null characters. It may be connected to an uninte...Show more
In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, the UNIXServer.open and UNIXSocket.open methods are not checked for null characters. It may be connected to an unintended socket.Show less
4Canonical
DebianRedhat+1 more
4Debian Linux
Enterprise LinuxRuby+1 more
Jun 17, 2026
Apr 3, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, an attacker controlling the unpacking format (similar to format string vulnerabilities) can trigger a buffer under-re...Show more
In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, an attacker controlling the unpacking format (similar to format string vulnerabilities) can trigger a buffer under-read in the String#unpack method, resulting in a massive and controlled information disclosure.Show less
4Canonical
DebianRedhat+1 more
4Debian Linux
Enterprise LinuxRuby+1 more
Jun 17, 2026
Apr 3, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, an attacker can pass a large HTTP request with a crafted header to WEBrick server or a crafted body to WEBrick server...Show more
In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, an attacker can pass a large HTTP request with a crafted header to WEBrick server or a crafted body to WEBrick server/handler and cause a denial of service (memory consumption).Show less
4Canonical
DebianRedhat+1 more
4Debian Linux
Enterprise LinuxRuby+1 more
Jun 17, 2026
Apr 3, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in the Dir.mktmpdir method in the tmpdir library in Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1 might allow attackers to create arb...Show more
Directory traversal vulnerability in the Dir.mktmpdir method in the tmpdir library in Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1 might allow attackers to create arbitrary directories or files via a .. (dot dot) in the prefix argument.Show less
2Debian
Ruby Lang
2Debian Linux
Ruby
Nov 21, 2024
Apr 3, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1 allows an HTTP Response Splitting attack. An attacker can inject a crafted key and value into an HTTP response for the HT...Show more
Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1 allows an HTTP Response Splitting attack. An attacker can inject a crafted key and value into an HTTP response for the HTTP server of WEBrick.Show less
2Debian
Eyrie
2Debian Linux
Remctl
Nov 21, 2024
Apr 3, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
remctld in remctl before 3.14, when an attacker is authorized to execute a command that uses the sudo option, has a use-after-free that leads to a daemon crash, memory corruption, or arbitrary command execution.
2Beep Project
Debian
2Beep
Debian Linux
Nov 21, 2024
Apr 3, 2018
N/A· v4
7.0 HIGH· v3
4.4 MEDIUM· v2
Johnathan Nightingale beep through 1.3.4, if setuid, has a race condition that allows local privilege escalation.
5Apple
CanonicalDebian+2 more
11Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+8 more
Nov 21, 2024
Apr 3, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. watchOS before 4.3 is...Show more
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. watchOS before 4.3 is affected. The issue involves the fetch API in the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.Show less
4Apple
ChromiumDebian+1 more
7Chromium
Debian LinuxEnterprise Linux Desktop+4 more
Nov 21, 2024
Apr 3, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The issue involves the "SQLite" component. It allows remote attackers to execute arbitrary code or cause...Show more
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The issue involves the "SQLite" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.Show less
6Canonical
DebianLinux+3 more
12Communications Eagle Application Processor
Debian LinuxEnterprise Linux Desktop+9 more
Jun 17, 2026
Mar 30, 2018
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
The Linux kernel 4.15 has a Buffer Overflow via an SNDRV_SEQ_IOCTL_SET_CLIENT_POOL ioctl write operation to /dev/snd/seq by a local user.
2Debian
Libming
2Debian Linux
Libming
Jun 17, 2026
Mar 30, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
libming 0.4.8 has a NULL pointer dereference in the getInt function of the decompile.c file. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted swf file.
2Debian
Drupal
2Debian Linux
Drupal
Jun 17, 2026
Mar 29, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configura...Show more
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations.Show less
2Debian
Redhat
2Debian Linux
Libvirt
Nov 21, 2024
Mar 28, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
libvirt version before 4.2.0-rc1 is vulnerable to a resource exhaustion as a result of an incomplete fix for CVE-2018-5748 that affects QEMU monitor but now also triggered via QEMU guest agent.
2Debian
Firebirdsql
2Debian Linux
Firebird
Nov 21, 2024
Mar 28, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
An authenticated remote attacker can execute arbitrary code in Firebird SQL Server versions 2.5.7 and 3.0.2 by executing a malformed SQL statement.
4Canonical
DebianRedhat+1 more
6Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+3 more
Nov 21, 2024
Mar 28, 2018
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Zsh before version 5.4.2-test-1 is vulnerable to a buffer overflow in the shell autocomplete functionality. A local unprivileged user can create a specially crafted directory path which leads to code execution in the con...Show more
Zsh before version 5.4.2-test-1 is vulnerable to a buffer overflow in the shell autocomplete functionality. A local unprivileged user can create a specially crafted directory path which leads to code execution in the context of the user who tries to use autocomplete to traverse the before mentioned path. If the user affected is privileged, this leads to privilege escalation.Show less
3Canonical
DebianOpenssl
3Debian Linux
OpensslUbuntu Linux
Nov 21, 2024
Mar 27, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Constructed ASN.1 types with a recursive definition (such as can be found in PKCS7) could eventually exceed the stack given malicious input with excessive recursion. This could result in a Denial Of Service attack. There...Show more
Constructed ASN.1 types with a recursive definition (such as can be found in PKCS7) could eventually exceed the stack given malicious input with excessive recursion. This could result in a Denial Of Service attack. There are no such structures used within SSL/TLS that come from untrusted sources so this is considered safe. Fixed in OpenSSL 1.1.0h (Affected 1.1.0-1.1.0g). Fixed in OpenSSL 1.0.2o (Affected 1.0.2b-1.0.2n).Show less
2Debian
Loofah Project
2Debian Linux
Loofah
Jun 17, 2026
Mar 27, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In the Loofah gem through 2.2.0 for Ruby, non-whitelisted HTML attributes may occur in sanitized output by republishing a crafted HTML fragment.
2Debian
Ldap Account Manager
2Debian Linux
Ldap Account Manager
Jun 17, 2026
Mar 27, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 places a CSRF token in the sec_token parameter of a URI, which makes it easier for remote attackers to defeat a CSRF protection mechanism by leveraging lo...Show more
Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 places a CSRF token in the sec_token parameter of a URI, which makes it easier for remote attackers to defeat a CSRF protection mechanism by leveraging logging.Show less
2Debian
Ldap Account Manager
2Debian Linux
Ldap Account Manager
Jun 17, 2026
Mar 27, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 has XSS via the dn parameter to the templates/3rdParty/pla/htdocs/cmd.php URI or the template parameter to the templates/3rdParty/pla/htdocs/cmd.php?cmd=r...Show more
Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 has XSS via the dn parameter to the templates/3rdParty/pla/htdocs/cmd.php URI or the template parameter to the templates/3rdParty/pla/htdocs/cmd.php?cmd=rename_form URI.Show less