← Back

Debian Linux

debian_linux

Vendor: Debian • 10,001 CVEs

CVEs (10,001)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Debian
LibgdOpensuse
3Debian Linux
LeapLibgd
May 6, 2026
Aug 12, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
gd_tga.c in the GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TGA file.
4Debian
LibgdOpensuse+1 more
4Debian Linux
LeapLibgd+1 more
May 6, 2026
Aug 12, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Integer overflow in the _gdContributionsAlloc function in gd_interpolation.c in GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds memory write or memory cons...Show more
Integer overflow in the _gdContributionsAlloc function in gd_interpolation.c in GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds memory write or memory consumption) via unspecified vectors.Show less
3Debian
LibgdOpensuse
3Debian Linux
LeapLibgd
May 6, 2026
Aug 12, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The output function in gd_gif_out.c in the GD Graphics Library (aka libgd) allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted image.
3Debian
LibgdOpensuse
3Debian Linux
LeapLibgd
May 6, 2026
Aug 12, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The gdImageCreateFromTgaCtx function in the GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TGA file.
5Canonical
DebianFedoraproject+2 more
6Debian Linux
FedoraLeap+3 more
May 6, 2026
Aug 10, 2016
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Use-after-free vulnerability in libcurl before 7.50.1 allows attackers to control which connection is used or possibly have unspecified other impact via unknown vectors.
3Debian
HaxxOpensuse
3Debian Linux
LeapLibcurl
May 6, 2026
Aug 10, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
curl and libcurl before 7.50.1 do not check the client certificate when choosing the TLS connection to reuse, which might allow remote attackers to hijack the authentication of the connection by leveraging a previously c...Show more
curl and libcurl before 7.50.1 do not check the client certificate when choosing the TLS connection to reuse, which might allow remote attackers to hijack the authentication of the connection by leveraging a previously created connection with a different client certificate.Show less
3Debian
HaxxOpensuse
3Debian Linux
LeapLibcurl
May 6, 2026
Aug 10, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
curl and libcurl before 7.50.1 do not prevent TLS session resumption when the client certificate has changed, which allows remote attackers to bypass intended restrictions by resuming a session.
2Debian
Redislabs
2Debian Linux
Redis
May 6, 2026
Aug 10, 2016
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
linenoise, as used in Redis before 3.2.3, uses world-readable permissions for .rediscli_history, which allows local users to obtain sensitive information by reading the file.
2Debian
Wordpress
2Debian Linux
Wordpress
May 6, 2026
Aug 7, 2016
N/A· v4
8.6 HIGH· v3
5.0 MEDIUM· v2
WordPress before 4.5 does not consider octal and hexadecimal IP address formats when determining an intranet address, which allows remote attackers to bypass an intended SSRF protection mechanism via a crafted address.
4Canonical
DebianLibgd+1 more
4Debian Linux
LeapLibgd+1 more
May 6, 2026
Aug 7, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The gdImageCropThreshold function in gd_crop.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 7.0.9, allows remote attackers to cause a denial of service (application crash) via an invalid col...Show more
The gdImageCropThreshold function in gd_crop.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 7.0.9, allows remote attackers to cause a denial of service (application crash) via an invalid color index.Show less
4Debian
OpensusePhp+1 more
7Debian Linux
LeapLinux Enterprise Debuginfo+4 more
May 6, 2026
Aug 7, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Double free vulnerability in the php_wddx_process_data function in wddx.c in the WDDX extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8 allows remote attackers to cause a denial of service (applic...Show more
Double free vulnerability in the php_wddx_process_data function in wddx.c in the WDDX extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted XML data that is mishandled in a wddx_deserialize call.Show less
3Debian
OpensusePhp
4Debian Linux
LeapOpensuse+1 more
May 6, 2026
Aug 7, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
spl_array.c in the SPL extension in PHP before 5.5.37 and 5.6.x before 5.6.23 improperly interacts with the unserialize implementation and garbage collection, which allows remote attackers to execute arbitrary code or ca...Show more
spl_array.c in the SPL extension in PHP before 5.5.37 and 5.6.x before 5.6.23 improperly interacts with the unserialize implementation and garbage collection, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and application crash) via crafted serialized data.Show less
3Debian
OpensusePhp
4Debian Linux
LeapOpensuse+1 more
May 6, 2026
Aug 7, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Integer overflow in the SplFileObject::fread function in spl_directory.c in the SPL extension in PHP before 5.5.37 and 5.6.x before 5.6.23 allows remote attackers to cause a denial of service or possibly have unspecified...Show more
Integer overflow in the SplFileObject::fread function in spl_directory.c in the SPL extension in PHP before 5.5.37 and 5.6.x before 5.6.23 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large integer argument, a related issue to CVE-2016-5096.Show less
5Debian
FedoraprojectFreebsd+2 more
6Debian Linux
Enterprise LinuxFedora+3 more
May 6, 2026
Aug 7, 2016
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Integer overflow in the _gd2GetHeader function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8, allows remote attackers to cause a...Show more
Integer overflow in the _gd2GetHeader function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8, allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via crafted chunk dimensions in an image.Show less
3Debian
LibgdOpensuse
3Debian Linux
LeapLibgd
May 6, 2026
Aug 7, 2016
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
gd_xbm.c in the GD Graphics Library (aka libgd) before 2.2.0, as used in certain custom PHP 5.5.x configurations, allows context-dependent attackers to obtain sensitive information from process memory or cause a denial o...Show more
gd_xbm.c in the GD Graphics Library (aka libgd) before 2.2.0, as used in certain custom PHP 5.5.x configurations, allows context-dependent attackers to obtain sensitive information from process memory or cause a denial of service (stack-based buffer under-read and application crash) via a long name.Show less
2Debian
Linux
2Debian Linux
Linux Kernel
May 6, 2026
Aug 6, 2016
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
The trace_writeback_dirty_page implementation in include/trace/events/writeback.h in the Linux kernel before 4.4 improperly interacts with mm/migrate.c, which allows local users to cause a denial of service (NULL pointer...Show more
The trace_writeback_dirty_page implementation in include/trace/events/writeback.h in the Linux kernel before 4.4 improperly interacts with mm/migrate.c, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by triggering a certain page move.Show less
2Debian
Google
2Android
Debian Linux
May 6, 2026
Aug 5, 2016
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
exif.c in Matthias Wandel jhead 2.87, as used in libjhead in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01, allows remote attackers to execute arbitrary code or cause a denia...Show more
exif.c in Matthias Wandel jhead 2.87, as used in libjhead in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01, allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds access) via crafted EXIF data, aka internal bug 28868315.Show less
2Debian
Djangoproject
2Debian Linux
Django
May 6, 2026
Aug 5, 2016
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the dismissChangeRelatedObjectPopup function in contrib/admin/static/admin/js/admin/RelatedObjectLookups.js in Django before 1.8.14, 1.9.x before 1.9.8, and 1.10.x before 1.10r...Show more
Cross-site scripting (XSS) vulnerability in the dismissChangeRelatedObjectPopup function in contrib/admin/static/admin/js/admin/RelatedObjectLookups.js in Django before 1.8.14, 1.9.x before 1.9.8, and 1.10.x before 1.10rc1 allows remote attackers to inject arbitrary web script or HTML via vectors involving unsafe usage of Element.innerHTML.Show less
5Canonical
DebianOracle+2 more
13Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+10 more
May 6, 2026
Aug 2, 2016
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
The virtqueue_pop function in hw/virtio/virtio.c in QEMU allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by submitting requests without waiting for completion...Show more
The virtqueue_pop function in hw/virtio/virtio.c in QEMU allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by submitting requests without waiting for completion.Show less
5Canonical
DebianFedoraproject+2 more
5Debian Linux
FedoraPerl+2 more
May 6, 2026
Aug 2, 2016
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
The XSLoader::load method in XSLoader in Perl does not properly locate .so files when called in a string eval, which might allow local users to execute arbitrary code via a Trojan horse library under the current working...Show more
The XSLoader::load method in XSLoader in Perl does not properly locate .so files when called in a string eval, which might allow local users to execute arbitrary code via a Trojan horse library under the current working directory.Show less