← Back

Debian Linux

debian_linux

Vendor: Debian • 10,001 CVEs

CVEs (10,001)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Debian
Shibboleth
2Debian Linux
Opensaml
May 13, 2026
Nov 16, 2017
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
The DynamicMetadataProvider class in saml/saml2/metadata/impl/DynamicMetadataProvider.cpp in OpenSAML-C in OpenSAML before 2.6.1 fails to properly configure itself with the MetadataFilter plugins and does not perform cri...Show more
The DynamicMetadataProvider class in saml/saml2/metadata/impl/DynamicMetadataProvider.cpp in OpenSAML-C in OpenSAML before 2.6.1 fails to properly configure itself with the MetadataFilter plugins and does not perform critical security checks such as signature verification, enforcement of validity periods, and other checks specific to deployments, aka CPPOST-105.Show less
2Debian
Shibboleth
2Debian Linux
Service Provider
May 13, 2026
Nov 16, 2017
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
shibsp/metadata/DynamicMetadataProvider.cpp in the Dynamic MetadataProvider plugin in Shibboleth Service Provider before 2.6.1 fails to properly configure itself with the MetadataFilter plugins and does not perform criti...Show more
shibsp/metadata/DynamicMetadataProvider.cpp in the Dynamic MetadataProvider plugin in Shibboleth Service Provider before 2.6.1 fails to properly configure itself with the MetadataFilter plugins and does not perform critical security checks such as signature verification, enforcement of validity periods, and other checks specific to deployments, aka SSPCPP-763.Show less
2Debian
Otrs
2Debian Linux
Otrs
May 13, 2026
Nov 16, 2017
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
In the Agent Frontend in Open Ticket Request System (OTRS) 3.3.x through 3.3.18, with a crafted URL it is possible to gain information like database user and password.
3Debian
Varnish CacheVarnish Cache Project
3Debian Linux
VarnishVarnish Cache
May 13, 2026
Nov 16, 2017
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
vbf_stp_error in bin/varnishd/cache/cache_fetch.c in Varnish HTTP Cache 4.1.x before 4.1.9 and 5.x before 5.2.1 allows remote attackers to obtain sensitive information from process memory because a VFP_GetStorage buffer...Show more
vbf_stp_error in bin/varnishd/cache/cache_fetch.c in Varnish HTTP Cache 4.1.x before 4.1.9 and 5.x before 5.2.1 allows remote attackers to obtain sensitive information from process memory because a VFP_GetStorage buffer is larger than intended in certain circumstances involving -sfile Stevedore transient objects.Show less
4Canonical
DebianLinux+1 more
4Debian Linux
Linux Enterprise ServerLinux Kernel+1 more
May 13, 2026
Nov 15, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The sctp_do_peeloff function in net/sctp/socket.c in the Linux kernel before 4.14 does not check whether the intended netns is used in a peel-off action, which allows local users to cause a denial of service (use-after-f...Show more
The sctp_do_peeloff function in net/sctp/socket.c in the Linux kernel before 4.14 does not check whether the intended netns is used in a peel-off action, which allows local users to cause a denial of service (use-after-free and system crash) or possibly have unspecified other impact via crafted system calls.Show less
2Debian
Konversation
2Debian Linux
Konversation
May 13, 2026
Nov 15, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Konversation 1.4.x, 1.5.x, 1.6.x, and 1.7.x before 1.7.3 allow remote attackers to cause a denial of service (crash) via vectors related to parsing of IRC color formatting codes.
2Debian
Mediawiki
2Debian Linux
Mediawiki
May 13, 2026
Nov 15, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The language converter in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows attribute injection attacks via glossary rules.
2Debian
Mediawiki
2Debian Linux
Mediawiki
May 13, 2026
Nov 15, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The language converter in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows attackers to replace text inside tags via a rule definition followed by "a lot of junk."
2Debian
Mediawiki
2Debian Linux
Mediawiki
May 13, 2026
Nov 15, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows remote attackers to inject > (greater than) characters via the id attribute of a headline.
2Debian
Mediawiki
2Debian Linux
Mediawiki
May 13, 2026
Nov 15, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The implementation of raw message parameter expansion in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows HTML mangling attacks.
2Debian
Mediawiki
2Debian Linux
Mediawiki
May 13, 2026
Nov 15, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2, when a private wiki is configured, provides different error messages for failed login attempts depending on whether the username exists, which allo...Show more
MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2, when a private wiki is configured, provides different error messages for failed login attempts depending on whether the username exists, which allows remote attackers to enumerate account names and conduct brute-force attacks via a series of requests.Show less
2Debian
Mediawiki
2Debian Linux
Mediawiki
May 13, 2026
Nov 15, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
api.php in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 has a Reflected File Download vulnerability.
2Debian
Mediawiki
2Debian Linux
Mediawiki
May 13, 2026
Nov 15, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 has XSS when the $wgShowExceptionDetails setting is false and the browser sends non-standard URL escaping.
7Debian
FujitsuNetapp+4 more
45Adaptive Access Manager
Application Testing SuiteClustered Data Ontap+42 more
May 13, 2026
Nov 13, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use t...Show more
A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use this flaw to make a TLS/SSL server consume an excessive amount of CPU and fail to accept connections from other clients.Show less
2Debian
Redmine
2Debian Linux
Redmine
May 13, 2026
Nov 13, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
In Redmine before 3.2.7 and 3.3.x before 3.3.4, the reminders function in app/models/mailer.rb does not check whether an issue is visible, which allows remote authenticated users to obtain sensitive information by readin...Show more
In Redmine before 3.2.7 and 3.3.x before 3.3.4, the reminders function in app/models/mailer.rb does not check whether an issue is visible, which allows remote authenticated users to obtain sensitive information by reading e-mail reminder messages.Show less
2Debian
Roundcube
2Debian Linux
Webmail
Apr 21, 2026
Nov 9, 2017
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, as exploited in the wild in November 2017...Show more
Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, as exploited in the wild in November 2017. The attacker must be able to authenticate at the target system with a valid username/password as the attack requires an active session. The issue is related to file-based attachment plugins and _task=settings&_action=upload-display&_from=timezone requests.Show less
2Debian
Graphicsmagick
2Debian Linux
Graphicsmagick
May 13, 2026
Nov 9, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
coders/wpg.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file, related to the A...Show more
coders/wpg.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file, related to the AcquireCacheNexus function in magick/pixel_cache.c.Show less
4Canonical
DebianNetapp+1 more
5Clustered Data Ontap
Debian LinuxPhp+2 more
May 13, 2026
Nov 7, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In PHP before 5.6.32, 7.x before 7.0.25, and 7.1.x before 7.1.11, an error in the date extension's timelib_meridian handling of 'front of' and 'back of' directives could be used by attackers able to supply date strings t...Show more
In PHP before 5.6.32, 7.x before 7.0.25, and 7.1.x before 7.1.11, an error in the date extension's timelib_meridian handling of 'front of' and 'back of' directives could be used by attackers able to supply date strings to leak information from the interpreter, related to ext/date/lib/parse_date.c out-of-bounds reads affecting the php_parse_date function. NOTE: this is a different issue than CVE-2017-11145.Show less
2Debian
Ffmpeg
2Debian Linux
Ffmpeg
May 13, 2026
Nov 6, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The read_header function in libavcodec/ffv1dec.c in FFmpeg 2.4 and 3.3.4 and possibly earlier allows remote attackers to have unspecified impact via a crafted MP4 file, which triggers an out-of-bounds read.
3Canonical
DebianSamba
3Debian Linux
RsyncUbuntu Linux
May 13, 2026
Nov 6, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The receive_xattr function in xattrs.c in rsync 3.1.2 and 3.1.3-development does not check for a trailing '\0' character in an xattr name, which allows remote attackers to cause a denial of service (heap-based buffer ove...Show more
The receive_xattr function in xattrs.c in rsync 3.1.2 and 3.1.3-development does not check for a trailing '\0' character in an xattr name, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact by sending crafted data to the daemon.Show less