← Back

Debian Linux

debian_linux

Vendor: Debian • 10,001 CVEs

CVEs (10,001)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
4Debian
MozillaNovell+1 more
7Debian Linux
Network Security ServicesSolaris+4 more
May 6, 2026
Jul 6, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Mozilla Network Security Services (NSS) before 3.19.1, as used in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and other products, does not properly perform Elliptical Curve Cryptograph...Show more
Mozilla Network Security Services (NSS) before 3.19.1, as used in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and other products, does not properly perform Elliptical Curve Cryptography (ECC) multiplications, which makes it easier for remote attackers to spoof ECDSA signatures via unspecified vectors.Show less
5Canonical
DebianMozilla+2 more
9Debian Linux
FirefoxFirefox Esr+6 more
May 6, 2026
Jul 6, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 allow remote attackers to cause a denial of servic...Show more
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.Show less
5Canonical
DebianMozilla+2 more
8Debian Linux
Network Security ServicesSolaris+5 more
May 6, 2026
Jul 6, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Mozilla Network Security Services (NSS) before 3.19, as used in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, Thunderbird before 38.1, and other products, does not properly determine sta...Show more
Mozilla Network Security Services (NSS) before 3.19, as used in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, Thunderbird before 38.1, and other products, does not properly determine state transitions for the TLS state machine, which allows man-in-the-middle attackers to defeat cryptographic protection mechanisms by blocking messages, as demonstrated by removing a forward-secrecy property by blocking a ServerKeyExchange message, aka a "SMACK SKIP-TLS" issue.Show less
2Debian
Fuse Project
2Debian Linux
Fuse
May 6, 2026
Jul 2, 2015
N/A· v4
N/A· v3
3.6 LOW· v2
fusermount in FUSE before 2.9.3-15 does not properly clear the environment before invoking (1) mount or (2) umount as root, which allows local users to write to arbitrary files via a crafted LIBMOUNT_MTAB environment var...Show more
fusermount in FUSE before 2.9.3-15 does not properly clear the environment before invoking (1) mount or (2) umount as root, which allows local users to write to arbitrary files via a crafted LIBMOUNT_MTAB environment variable that is used by mount's debugging feature.Show less
2Debian
Drupal
2Debian Linux
Drupal
May 6, 2026
Jun 22, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The OpenID module in Drupal 6.x before 6.36 and 7.x before 7.38 allows remote attackers to log into other users' accounts by leveraging an OpenID identity from certain providers, as demonstrated by the Verisign, LiveJour...Show more
The OpenID module in Drupal 6.x before 6.36 and 7.x before 7.38 allows remote attackers to log into other users' accounts by leveraging an OpenID identity from certain providers, as demonstrated by the Verisign, LiveJournal, and StackExchange providers.Show less
2Debian
Drupal
2Debian Linux
Drupal
May 6, 2026
Jun 22, 2015
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Open redirect vulnerability in the Field UI module in Drupal 7.x before 7.38 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destinations parameter.
2Debian
Drupal
2Debian Linux
Drupal
May 6, 2026
Jun 22, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The Render cache system in Drupal 7.x before 7.38, when used to cache content by user role, allows remote authenticated users to obtain private content viewed by user 1 by reading the cache.
2Automattic
Debian
2Debian Linux
Genericons
May 6, 2026
Jun 17, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in example.html in Genericons before 3.3.1, as used in WordPress before 4.2.2, allows remote attackers to inject arbitrary web script or HTML via a fragment identifier.
8Arista
CanonicalDebian+5 more
18Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+15 more
May 6, 2026
Jun 15, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending a packet with TXSTATUS_STARTPACKET set and then a crafted packet with TXSTATUS_DEVICEOWNS set.
3Canonical
DebianStrongswan
4Debian Linux
StrongswanStrongswan Vpn Client+1 more
May 6, 2026
Jun 10, 2015
N/A· v4
N/A· v3
2.6 LOW· v2
strongSwan 4.3.0 through 5.x before 5.3.2 and strongSwan VPN Client before 1.4.6, when using EAP or pre-shared keys for authenticating an IKEv2 connection, does not enforce server authentication restrictions until the en...Show more
strongSwan 4.3.0 through 5.x before 5.3.2 and strongSwan VPN Client before 1.4.6, when using EAP or pre-shared keys for authenticating an IKEv2 connection, does not enforce server authentication restrictions until the entire authentication process is complete, which allows remote servers to obtain credentials by using a valid certificate and then reading the responses.Show less
2Debian
Redislabs
2Debian Linux
Redis
May 6, 2026
Jun 9, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
Redis before 2.8.21 and 3.x before 3.0.2 allows remote attackers to execute arbitrary Lua bytecode via the eval command.
2Apache
Debian
2Debian Linux
Tomcat
May 6, 2026
Jun 7, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Expression Language (EL) implementation in Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.58, and 8.x before 8.0.16 does not properly consider the possibility of an accessible interface implemented by an inaccessibl...Show more
The Expression Language (EL) implementation in Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.58, and 8.x before 8.0.16 does not properly consider the possibility of an accessible interface implemented by an inaccessible class, which allows attackers to bypass a SecurityManager protection mechanism via a web application that leverages use of incorrect privileges during EL evaluation.Show less
6Canonical
CitrixDebian+3 more
8Debian Linux
FedoraLinux Enterprise Desktop+5 more
May 6, 2026
Jun 3, 2015
N/A· v4
N/A· v3
4.6 MEDIUM· v2
QEMU does not properly restrict write access to the PCI config space for certain PCI pass-through devices, which might allow local x86 HVM guests to gain privileges, cause a denial of service (host crash), obtain sensiti...Show more
QEMU does not properly restrict write access to the PCI config space for certain PCI pass-through devices, which might allow local x86 HVM guests to gain privileges, cause a denial of service (host crash), obtain sensitive information, or possibly have other unspecified impact via unknown vectors.Show less
5Canonical
DebianF5+2 more
25Big Ip Access Policy Manager
Big Ip Advanced Firewall ManagerBig Ip Analytics+22 more
May 6, 2026
May 29, 2015
N/A· v4
N/A· v3
7.8 HIGH· v2
racoon/gssapi.c in IPsec-Tools 0.8.2 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) via a series of crafted UDP requests.
4Apple
CanonicalDebian+1 more
4Debian Linux
Mac Os X ServerPostgresql+1 more
May 6, 2026
May 28, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Double free vulnerability in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 allows remote attackers to cause a denial of service (crash) by closing an SSL s...Show more
Double free vulnerability in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 allows remote attackers to cause a denial of service (crash) by closing an SSL session at a time when the authentication timeout will expire during the session shutdown sequence.Show less
2Debian
Linux
2Debian Linux
Linux Kernel
May 6, 2026
May 27, 2015
N/A· v4
N/A· v3
6.2 MEDIUM· v2
Race condition in the prepare_binprm function in fs/exec.c in the Linux kernel before 3.19.6 allows local users to gain privileges by executing a setuid program at a time instant when a chown to root is in progress, and...Show more
Race condition in the prepare_binprm function in fs/exec.c in the Linux kernel before 3.19.6 allows local users to gain privileges by executing a setuid program at a time instant when a chown to root is in progress, and the ownership is changed but the setuid bit is not yet stripped.Show less
2Debian
Linux
2Debian Linux
Linux Kernel
May 6, 2026
May 27, 2015
N/A· v4
N/A· v3
4.9 MEDIUM· v2
A certain backport in the TCP Fast Open implementation for the Linux kernel before 3.18 does not properly maintain a count value, which allow local users to cause a denial of service (system crash) via the Fast Open feat...Show more
A certain backport in the TCP Fast Open implementation for the Linux kernel before 3.18 does not properly maintain a count value, which allow local users to cause a denial of service (system crash) via the Fast Open feature, as demonstrated by visiting the chrome://flags/#enable-tcp-fast-open URL when using certain 3.10.x through 3.16.x kernel builds, including longterm-maintenance releases and ckt (aka Canonical Kernel Team) builds.Show less
3Canonical
DebianLinux
3Debian Linux
Linux KernelUbuntu Linux
May 6, 2026
May 27, 2015
N/A· v4
N/A· v3
9.3 HIGH· v2
The __driver_rfc4106_decrypt function in arch/x86/crypto/aesni-intel_glue.c in the Linux kernel before 3.19.3 does not properly determine the memory locations used for encrypted data, which allows context-dependent attac...Show more
The __driver_rfc4106_decrypt function in arch/x86/crypto/aesni-intel_glue.c in the Linux kernel before 3.19.3 does not properly determine the memory locations used for encrypted data, which allows context-dependent attackers to cause a denial of service (buffer overflow and system crash) or possibly execute arbitrary code by triggering a crypto API call, as demonstrated by use of a libkcapi test program with an AF_ALG(aead) socket.Show less
5Debian
FedoraprojectLinux+2 more
6Debian Linux
Enterprise MrgFedora+3 more
May 6, 2026
May 27, 2015
N/A· v4
N/A· v3
3.3 LOW· v2
The ndisc_router_discovery function in net/ipv6/ndisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in the Linux kernel before 3.19.6 allows remote attackers to reconfigure a hop-limit settin...Show more
The ndisc_router_discovery function in net/ipv6/ndisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in the Linux kernel before 3.19.6 allows remote attackers to reconfigure a hop-limit setting via a small hop_limit value in a Router Advertisement (RA) message.Show less
3Canonical
DebianLinux
3Debian Linux
Linux KernelUbuntu Linux
May 6, 2026
May 27, 2015
N/A· v4
N/A· v3
1.9 LOW· v2
arch/x86/kernel/entry_64.S in the Linux kernel before 3.19.2 does not prevent the TS_COMPAT flag from reaching a user-mode task, which might allow local users to bypass the seccomp or audit protection mechanism via a cra...Show more
arch/x86/kernel/entry_64.S in the Linux kernel before 3.19.2 does not prevent the TS_COMPAT flag from reaching a user-mode task, which might allow local users to bypass the seccomp or audit protection mechanism via a crafted application that uses the (1) fork or (2) close system call, as demonstrated by an attack against seccomp before 3.16.Show less