← Back

Debian Linux

debian_linux

Vendor: Debian • 10,001 CVEs

CVEs (10,001)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Debian
X.org
2Debian Linux
X Server
Aug 29, 2025
Jan 24, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
xorg-x11-server before 1.19.5 was missing length validation in RENDER extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
2Debian
X.org
2Debian Linux
X Server
Aug 29, 2025
Jan 24, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
xorg-x11-server before 1.19.5 was missing length validation in X-Resource extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
2Debian
X.org
2Debian Linux
X Server
Aug 29, 2025
Jan 24, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
xorg-x11-server before 1.19.5 was missing length validation in MIT-SCREEN-SAVER extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
2Debian
X.org
2Debian Linux
X Server
Aug 29, 2025
Jan 24, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
xorg-x11-server before 1.19.5 was missing length validation in XINERAMA extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
2Debian
X.org
2Debian Linux
X Server
Aug 29, 2025
Jan 24, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
xorg-x11-server before 1.19.5 was missing length validation in XFIXES extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
2Debian
X.org
2Debian Linux
X Server
Aug 29, 2025
Jan 24, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
xorg-x11-server before 1.19.5 was missing length validation in XFree86 DRI extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
2Debian
X.org
2Debian Linux
X Server
Aug 29, 2025
Jan 24, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
xorg-x11-server before 1.19.5 was missing length validation in XFree86 DGA extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
2Debian
X.org
2Debian Linux
X Server
Aug 29, 2025
Jan 24, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
xorg-x11-server before 1.19.5 was missing length validation in XFree86 VidModeExtension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
2Debian
X.org
2Debian Linux
X Server
Aug 29, 2025
Jan 24, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
xorg-x11-server before 1.19.5 was vulnerable to integer overflow in (S)ProcXIBarrierReleasePointer functions allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
2Debian
X.org
2Debian Linux
X Server
Aug 29, 2025
Jan 24, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
xorg-x11-server before 1.19.5 had wrong extra length check in ProcXIChangeHierarchy function allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
2Debian
X.org
2Debian Linux
X Server
Aug 29, 2025
Jan 24, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
xorg-x11-server before 1.19.5 was vulnerable to integer overflow in ProcDbeGetVisualInfo function allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
2Debian
X.org
2Debian Linux
X Server
Aug 29, 2025
Jan 24, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
xorg-x11-server before 1.19.5 was missing extra length validation in ProcEstablishConnection function allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
2Artifex
Debian
2Debian Linux
Mupdf
Jun 17, 2026
Jan 24, 2018
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In Artifex MuPDF 1.12.0, there is a heap-based buffer overflow vulnerability in the do_pdf_save_document function in the pdf/pdf-write.c file. Remote attackers could leverage the vulnerability to cause a denial of servic...Show more
In Artifex MuPDF 1.12.0, there is a heap-based buffer overflow vulnerability in the do_pdf_save_document function in the pdf/pdf-write.c file. Remote attackers could leverage the vulnerability to cause a denial of service via a crafted pdf file.Show less
4Canonical
DebianQemu+1 more
9Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+6 more
Jun 17, 2026
Jan 23, 2018
N/A· v4
6.0 MEDIUM· v3
2.1 LOW· v2
The vga_draw_text function in Qemu allows local OS guest privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) by leveraging improper memory address validation.
2Debian
Qemu
2Debian Linux
Qemu
Nov 21, 2024
Jan 23, 2018
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
The cirrus_invalidate_region function in hw/display/cirrus_vga.c in Qemu allows local OS guest privileged users to cause a denial of service (out-of-bounds array access and QEMU process crash) via vectors related to nega...Show more
The cirrus_invalidate_region function in hw/display/cirrus_vga.c in Qemu allows local OS guest privileged users to cause a denial of service (out-of-bounds array access and QEMU process crash) via vectors related to negative pitch.Show less
4Canonical
DebianGnu+1 more
9Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+6 more
Jun 17, 2026
Jan 23, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the web UI in Mailman before 2.1.26 allows remote attackers to inject arbitrary web script or HTML via a user-options URL.
3Canonical
DebianNlnetlabs
3Debian Linux
Ubuntu LinuxUnbound
Nov 21, 2024
Jan 23, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A flaw was found in the way unbound before 1.6.8 validated wildcard-synthesized NSEC records. An improperly validated wildcard NSEC record could be used to prove the non-existence (NXDOMAIN answer) of an existing wildcar...Show more
A flaw was found in the way unbound before 1.6.8 validated wildcard-synthesized NSEC records. An improperly validated wildcard NSEC record could be used to prove the non-existence (NXDOMAIN answer) of an existing wildcard record, or trick unbound into accepting a NODATA proof.Show less
3Debian
FedoraprojectGnu
3Debian Linux
FedoraLibtasn1
Jun 17, 2026
Jan 22, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in the _asn1_decode_simple_ber function in decoding.c in GNU Libtasn1 before 4.13. Unlimited recursion in the BER decoder leads to stack exhaustion and DoS.
4Debian
FasterxmlNetapp+1 more
9Debian Linux
E Series Santricity Os ControllerE Series Santricity Web Services Proxy+6 more
Jun 17, 2026
Jan 22, 2018
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 and CVE-2017-17485 deserialization flaws. This is exploita...Show more
FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 and CVE-2017-17485 deserialization flaws. This is exploitable via two different gadgets that bypass a blacklist.Show less
4Canonical
DebianNetapp+1 more
12Cloud Backup
Clustered Data OntapData Ontap+9 more
Apr 29, 2026
Jan 21, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
sshd in OpenSSH before 7.4 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence NEWKEYS message, as demonstrated by Honggfuzz, related to kex.c and packe...Show more
sshd in OpenSSH before 7.4 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence NEWKEYS message, as demonstrated by Honggfuzz, related to kex.c and packet.c.Show less