← Back

Debian Linux

debian_linux

Vendor: Debian • 10,001 CVEs

CVEs (10,001)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Debian
GoogleOpensuse
3Chrome
Debian LinuxOpensuse
May 6, 2026
May 14, 2016
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The TreeScope::adoptIfNeeded function in WebKit/Source/core/dom/TreeScope.cpp in the DOM implementation in Blink, as used in Google Chrome before 50.0.2661.102, does not prevent script execution during node-adoption oper...Show more
The TreeScope::adoptIfNeeded function in WebKit/Source/core/dom/TreeScope.cpp in the DOM implementation in Blink, as used in Google Chrome before 50.0.2661.102, does not prevent script execution during node-adoption operations, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.Show less
3Debian
EnlightenmentOpensuse
3Debian Linux
Imlib2Opensuse
May 6, 2026
May 13, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Integer overflow in imlib2 before 1.4.9 on 32-bit platforms allows remote attackers to execute arbitrary code via large dimensions in an image, which triggers an out-of-bounds heap memory write operation.
2Debian
Enlightenment
2Debian Linux
Imlib2
May 6, 2026
May 13, 2016
N/A· v4
8.2 HIGH· v3
6.4 MEDIUM· v2
The GIF loader in imlib2 before 1.4.9 allows remote attackers to cause a denial of service (application crash) or obtain sensitive information via a crafted image, which triggers an out-of-bounds read.
2Debian
Enlightenment
2Debian Linux
Imlib2
May 6, 2026
May 13, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Off-by-one error in the __imlib_MergeUpdate function in lib/updates.c in imlib2 before 1.4.9 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via crafted coordinates.
2Debian
Openafs
2Debian Linux
Openafs
May 6, 2026
May 13, 2016
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The newEntry function in ptserver/ptprocs.c in OpenAFS before 1.6.17 allows remote authenticated users from foreign Kerberos realms to bypass intended access restrictions and create arbitrary groups as administrators by...Show more
The newEntry function in ptserver/ptprocs.c in OpenAFS before 1.6.17 allows remote authenticated users from foreign Kerberos realms to bypass intended access restrictions and create arbitrary groups as administrators by leveraging mishandling of the creator ID.Show less
2Debian
Openafs
2Debian Linux
Openafs
May 6, 2026
May 13, 2016
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Off-by-one error in afs_pioctl.c in OpenAFS before 1.6.16 might allow local users to cause a denial of service (memory overwrite and system crash) via a pioctl with an input buffer size of 4096 bytes.
2Debian
Enlightenment
2Debian Linux
Imlib2
May 6, 2026
May 13, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Integer overflow in imlib2 before 1.4.7 allows remote attackers to cause a denial of service (memory consumption or application crash) via a crafted image, which triggers an invalid read operation.
2Debian
Enlightenment
2Debian Linux
Imlib2
May 6, 2026
May 13, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
imlib2 before 1.4.7 allows remote attackers to cause a denial of service (segmentation fault) via a crafted GIF file.
2Debian
Enlightenment
2Debian Linux
Imlib2
May 6, 2026
May 13, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
imlib2 before 1.4.7 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted PNM file.
2Debian
Enlightenment
2Debian Linux
Imlib2
May 6, 2026
May 13, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
imlib2 before 1.4.7 allows remote attackers to cause a denial of service (segmentation fault) via a GIF image without a colormap.
2Debian
Enlightenment
2Debian Linux
Imlib2
May 6, 2026
May 13, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
imlib2 before 1.4.9 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) by drawing a 2x1 ellipse.
3Botan Project
DebianFedoraproject
3Botan
Debian LinuxFedora
May 6, 2026
May 13, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Botan before 1.10.13 and 1.11.x before 1.11.29 do not use a constant-time algorithm to perform a modular inverse on the signature nonce k, which might allow remote attackers to obtain ECDSA secret keys via a timing side-...Show more
Botan before 1.10.13 and 1.11.x before 1.11.29 do not use a constant-time algorithm to perform a modular inverse on the signature nonce k, which might allow remote attackers to obtain ECDSA secret keys via a timing side-channel attack.Show less
2Botan Project
Debian
2Botan
Debian Linux
May 6, 2026
May 13, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Integer overflow in the PointGFp constructor in Botan before 1.10.11 and 1.11.x before 1.11.27 allows remote attackers to overwrite memory and possibly execute arbitrary code via a crafted ECC point, which triggers a hea...Show more
Integer overflow in the PointGFp constructor in Botan before 1.10.11 and 1.11.x before 1.11.27 allows remote attackers to overwrite memory and possibly execute arbitrary code via a crafted ECC point, which triggers a heap-based buffer overflow.Show less
2Botan Project
Debian
2Botan
Debian Linux
May 6, 2026
May 13, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The ressol function in Botan before 1.10.11 and 1.11.x before 1.11.27 allows remote attackers to cause a denial of service (infinite loop) via unspecified input to the OS2ECP function, related to a composite modulus.
3Botan Project
DebianFedoraproject
3Botan
Debian LinuxFedora
May 6, 2026
May 13, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Botan before 1.10.13 and 1.11.x before 1.11.22 make it easier for remote attackers to conduct million-message attacks by measuring time differences, related to decoding of PKCS#1 padding.
2Botan Project
Debian
2Botan
Debian Linux
May 6, 2026
May 13, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
The BER decoder in Botan 1.10.x before 1.10.10 and 1.11.x before 1.11.19 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors, related to a length field.
2Botan Project
Debian
2Botan
Debian Linux
May 6, 2026
May 13, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The BER decoder in Botan 0.10.x before 1.10.10 and 1.11.x before 1.11.19 allows remote attackers to cause a denial of service (application crash) via an empty BIT STRING in ASN.1 data.
6Canonical
CitrixDebian+3 more
11Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+8 more
May 6, 2026
May 11, 2016
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Integer overflow in the VGA module in QEMU allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) by editing VGA registers in VBE mode.
7Canonical
CitrixDebian+4 more
15Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+12 more
May 6, 2026
May 11, 2016
N/A· v4
8.8 HIGH· v3
7.2 HIGH· v2
The VGA module in QEMU improperly performs bounds checking on banked access to video memory, which allows local guest OS administrators to execute arbitrary code on the host by changing access modes after setting the ban...Show more
The VGA module in QEMU improperly performs bounds checking on banked access to video memory, which allows local guest OS administrators to execute arbitrary code on the host by changing access modes after setting the bank register, aka the "Dark Portal" issue.Show less
2Debian
Websvn
2Debian Linux
Websvn
May 6, 2026
May 11, 2016
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in (1) revision.php, (2) log.php, (3) listing.php, and (4) comp.php in WebSVN allow context-dependent attackers to inject arbitrary web script or HTML via the name of a...Show more
Multiple cross-site scripting (XSS) vulnerabilities in (1) revision.php, (2) log.php, (3) listing.php, and (4) comp.php in WebSVN allow context-dependent attackers to inject arbitrary web script or HTML via the name of a (a) file or (b) directory in a repository.Show less