← Back

Debian Linux

debian_linux

Vendor: Debian • 10,001 CVEs

CVEs (10,001)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Debian
Drupal
2Debian Linux
Drupal
May 6, 2026
Apr 12, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The "have you forgotten your password" links in the User module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allow remote attackers to obtain sensitive username information by leveraging a configuration that permits us...Show more
The "have you forgotten your password" links in the User module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allow remote attackers to obtain sensitive username information by leveraging a configuration that permits using an email address to login and a module that permits logging in.Show less
2Debian
Drupal
2Debian Linux
Drupal
May 6, 2026
Apr 12, 2016
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
The User module in Drupal 6.x before 6.38 and 7.x before 7.43 allows remote attackers to gain privileges by leveraging contributed or custom code that calls the user_save function with an explicit category and loads all...Show more
The User module in Drupal 6.x before 6.38 and 7.x before 7.43 allows remote attackers to gain privileges by leveraging contributed or custom code that calls the user_save function with an explicit category and loads all roles into the array.Show less
2Debian
Drupal
2Debian Linux
Drupal
May 6, 2026
Apr 12, 2016
N/A· v4
6.4 MEDIUM· v3
8.5 HIGH· v2
The System module in Drupal 6.x before 6.38 and 7.x before 7.43 might allow remote attackers to hijack the authentication of site administrators for requests that download and run files with arbitrary JSON-encoded conten...Show more
The System module in Drupal 6.x before 6.38 and 7.x before 7.43 might allow remote attackers to hijack the authentication of site administrators for requests that download and run files with arbitrary JSON-encoded content, aka a "reflected file download vulnerability."Show less
2Debian
Drupal
2Debian Linux
Drupal
May 6, 2026
Apr 12, 2016
N/A· v4
7.4 HIGH· v3
6.4 MEDIUM· v2
Open redirect vulnerability in the drupal_goto function in Drupal 6.x before 6.38, when used with PHP before 5.4.7, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a doub...Show more
Open redirect vulnerability in the drupal_goto function in Drupal 6.x before 6.38, when used with PHP before 5.4.7, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a double-encoded URL in the "destination" parameter.Show less
2Debian
Drupal
2Debian Linux
Drupal
May 6, 2026
Apr 12, 2016
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
CRLF injection vulnerability in the drupal_set_header function in Drupal 6.x before 6.38, when used with PHP before 5.1.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting atta...Show more
CRLF injection vulnerability in the drupal_set_header function in Drupal 6.x before 6.38, when used with PHP before 5.1.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks by leveraging a module that allows user-submitted data to appear in HTTP headers.Show less
2Debian
Drupal
2Debian Linux
Drupal
May 6, 2026
Apr 12, 2016
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
Drupal 6.x before 6.38, 7.x before 7.43, and 8.x before 8.0.4 might allow remote attackers to conduct open redirect attacks by leveraging (1) custom code or (2) a form shown on a 404 error page, related to path manipulat...Show more
Drupal 6.x before 6.38, 7.x before 7.43, and 8.x before 8.0.4 might allow remote attackers to conduct open redirect attacks by leveraging (1) custom code or (2) a form shown on a 404 error page, related to path manipulation.Show less
2Debian
Drupal
2Debian Linux
Drupal
May 6, 2026
Apr 12, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The XML-RPC system in Drupal 6.x before 6.38 and 7.x before 7.43 might make it easier for remote attackers to conduct brute-force attacks via a large number of calls made at once to the same method.
2Debian
Drupal
2Debian Linux
Drupal
May 6, 2026
Apr 12, 2016
N/A· v4
8.1 HIGH· v3
6.5 MEDIUM· v2
The File module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allows remote authenticated users to bypass access restrictions and read, delete, or substitute a link to a file uploaded to an unprocessed form by leveragin...Show more
The File module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allows remote authenticated users to bypass access restrictions and read, delete, or substitute a link to a file uploaded to an unprocessed form by leveraging permission to create content or comment and upload files.Show less
2Debian
Inspircd
2Debian Linux
Inspircd
May 6, 2026
Apr 12, 2016
N/A· v4
8.6 HIGH· v3
7.8 HIGH· v2
The DNS::GetResult function in dns.cpp in InspIRCd before 2.0.19 allows remote DNS servers to cause a denial of service (netsplit) via an invalid character in a PTR response, as demonstrated by a "\032" (whitespace) char...Show more
The DNS::GetResult function in dns.cpp in InspIRCd before 2.0.19 allows remote DNS servers to cause a denial of service (netsplit) via an invalid character in a PTR response, as demonstrated by a "\032" (whitespace) character in a hostname.Show less
2Debian
Redmine
2Debian Linux
Redmine
May 6, 2026
Apr 12, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
app/views/journals/index.builder in Redmine before 2.6.9, 3.0.x before 3.0.7, and 3.1.x before 3.1.3 allows remote attackers to obtain sensitive information by viewing an Atom feed.
2Debian
Redmine
2Debian Linux
Redmine
May 6, 2026
Apr 12, 2016
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
Open redirect vulnerability in the valid_back_url function in app/controllers/application_controller.rb in Redmine before 2.6.7, 3.0.x before 3.0.5, and 3.1.x before 3.1.1 allows remote attackers to redirect users to arb...Show more
Open redirect vulnerability in the valid_back_url function in app/controllers/application_controller.rb in Redmine before 2.6.7, 3.0.x before 3.0.5, and 3.1.x before 3.1.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted back_url parameter, as demonstrated by "@attacker.com," a different vulnerability than CVE-2014-1985.Show less
2Debian
Redmine
2Debian Linux
Redmine
May 6, 2026
Apr 12, 2016
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The Issues API in Redmine before 2.6.8, 3.0.x before 3.0.6, and 3.1.x before 3.1.2 allows remote authenticated users to obtain sensitive information in changeset messages by leveraging permission to read issues with rela...Show more
The Issues API in Redmine before 2.6.8, 3.0.x before 3.0.6, and 3.1.x before 3.1.2 allows remote authenticated users to obtain sensitive information in changeset messages by leveraging permission to read issues with related changesets from other projects.Show less
2Debian
Redmine
2Debian Linux
Redmine
May 6, 2026
Apr 12, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
app/views/timelog/_form.html.erb in Redmine before 2.6.8, 3.0.x before 3.0.6, and 3.1.x before 3.1.2 allows remote attackers to obtain sensitive information about subjects of issues by viewing the time logging form.
4Canonical
DebianQemu+1 more
11Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+8 more
May 6, 2026
Apr 12, 2016
N/A· v4
8.4 HIGH· v3
3.6 LOW· v2
The net_checksum_calculate function in net/checksum.c in QEMU allows local guest OS users to cause a denial of service (out-of-bounds heap read and crash) via the payload length in a crafted packet.
3Debian
QemuRedhat
4Debian Linux
OpenstackQemu+1 more
May 6, 2026
Apr 12, 2016
N/A· v4
8.8 HIGH· v3
6.9 MEDIUM· v2
Use-after-free vulnerability in hw/ide/ahci.c in QEMU, when built with IDE AHCI Emulation support, allows guest OS users to cause a denial of service (instance crash) or possibly execute arbitrary code via an invalid AHC...Show more
Use-after-free vulnerability in hw/ide/ahci.c in QEMU, when built with IDE AHCI Emulation support, allows guest OS users to cause a denial of service (instance crash) or possibly execute arbitrary code via an invalid AHCI Native Command Queuing (NCQ) AIO command.Show less
2Debian
Xmlsoft
2Debian Linux
Libxml2
May 6, 2026
Apr 11, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The htmlParseComment function in HTMLparser.c in libxml2 allows attackers to obtain sensitive information, cause a denial of service (out-of-bounds heap memory access and application crash), or possibly have unspecified...Show more
The htmlParseComment function in HTMLparser.c in libxml2 allows attackers to obtain sensitive information, cause a denial of service (out-of-bounds heap memory access and application crash), or possibly have unspecified other impact via an unclosed HTML comment.Show less
2Debian
Kamailio
2Debian Linux
Kamailio
May 6, 2026
Apr 11, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Heap-based buffer overflow in the encode_msg function in encode_msg.c in the SEAS module in Kamailio (formerly OpenSER and SER) before 4.3.5 allows remote attackers to cause a denial of service (memory corruption and pro...Show more
Heap-based buffer overflow in the encode_msg function in encode_msg.c in the SEAS module in Kamailio (formerly OpenSER and SER) before 4.3.5 allows remote attackers to cause a denial of service (memory corruption and process crash) or possibly execute arbitrary code via a large SIP packet.Show less
2Debian
Oar Project
2Debian Linux
Oar
May 6, 2026
Apr 11, 2016
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
The oarsh script in OAR before 2.5.7 allows remote authenticated users of a cluster to obtain sensitive information and possibly gain privileges via vectors related to OpenSSH options.
2Debian
Dhcpcd Project
2Debian Linux
Dhcpcd
May 6, 2026
Apr 11, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The decode_search function in dhcp.c in dhcpcd 3.x does not properly free allocated memory, which allows remote DHCP servers to cause a denial of service via a crafted response.
2Debian
Dhcpcd Project
2Debian Linux
Dhcpcd
May 6, 2026
Apr 11, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The decode_search function in dhcp.c in dhcpcd 3.x allows remote DHCP servers to cause a denial of service (out-of-bounds read) via a crafted response.