← Back

Debian Linux

debian_linux

Vendor: Debian • 10,000 CVEs

CVEs (10,000)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
7Canonical
DebianJuniper+4 more
14Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+11 more
May 6, 2026
Apr 16, 2015
N/A· v4
N/A· v3
5.7 MEDIUM· v2
Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier, and 5.6.23 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Compiling.
6Canonical
DebianMariadb+3 more
14Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+11 more
May 6, 2026
Apr 16, 2015
N/A· v4
N/A· v3
3.5 LOW· v2
Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier, and 5.6.23 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Federated.
6Canonical
DebianMariadb+3 more
13Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+10 more
May 6, 2026
Apr 16, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Security : Encryption.
6Canonical
DebianMariadb+3 more
15Communications Policy Management
Debian LinuxEnterprise Linux Desktop+12 more
May 6, 2026
Apr 16, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows remote authenticated users to affect availability via vectors related to InnoDB : DML.
2Debian
Tuxfamily
2Chrony
Debian Linux
May 6, 2026
Apr 16, 2015
N/A· v4
N/A· v3
6.5 MEDIUM· v2
chrony before 1.31.1 does not initialize the last "next" pointer when saving unacknowledged replies to command requests, which allows remote authenticated users to cause a denial of service (uninitialized pointer derefer...Show more
chrony before 1.31.1 does not initialize the last "next" pointer when saving unacknowledged replies to command requests, which allows remote authenticated users to cause a denial of service (uninitialized pointer dereference and daemon crash) or possibly execute arbitrary code via a large number of command requests.Show less
2Debian
Tuxfamily
2Chrony
Debian Linux
May 6, 2026
Apr 16, 2015
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Heap-based buffer overflow in chrony before 1.31.1 allows remote authenticated users to cause a denial of service (chronyd crash) or possibly execute arbitrary code by configuring the (1) NTP or (2) cmdmon access with a...Show more
Heap-based buffer overflow in chrony before 1.31.1 allows remote authenticated users to cause a denial of service (chronyd crash) or possibly execute arbitrary code by configuring the (1) NTP or (2) cmdmon access with a subnet size that is indivisible by four and an address with a nonzero bit in the subnet remainder.Show less
3Canonical
DebianX.org
4Debian Linux
Libx11Ubuntu Linux+1 more
May 6, 2026
Apr 16, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple off-by-one errors in the (1) MakeBigReq and (2) SetReqLen macros in include/X11/Xlibint.h in X11R6.x and libX11 before 1.6.0 allow remote attackers to have unspecified impact via a crafted request, which trigger...Show more
Multiple off-by-one errors in the (1) MakeBigReq and (2) SetReqLen macros in include/X11/Xlibint.h in X11R6.x and libX11 before 1.6.0 allow remote attackers to have unspecified impact via a crafted request, which triggers a buffer overflow.Show less
1Debian
2Dbd Firebird
Debian Linux
May 6, 2026
Apr 14, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple stack-based buffer overflows in the ib_fill_isqlda function in dbdimp.c in DBD-Firebird before 1.19 allow remote attackers to have unspecified impact via unknown vectors that trigger an error condition, related...Show more
Multiple stack-based buffer overflows in the ib_fill_isqlda function in dbdimp.c in DBD-Firebird before 1.19 allow remote attackers to have unspecified impact via unknown vectors that trigger an error condition, related to binding octets to columns.Show less
4Canonical
DebianGnu+1 more
4Debian Linux
Enterprise LinuxMailman+1 more
May 6, 2026
Apr 13, 2015
N/A· v4
N/A· v3
7.6 HIGH· v2
Directory traversal vulnerability in GNU Mailman before 2.1.20, when not using a static alias, allows remote attackers to execute arbitrary files via a .. (dot dot) in a list name.
4Canonical
DebianFedoraproject+1 more
4Debian Linux
FedoraLibtasn1+1 more
May 6, 2026
Apr 10, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
Stack-based buffer overflow in asn1_der_decoding in libtasn1 before 4.4 allows remote attackers to have unspecified impact via unknown vectors.
3Arj Software
DebianFedoraproject
3Arj Archiver
Debian LinuxFedora
May 6, 2026
Apr 8, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in Open-source ARJ archiver 3.10.22 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted ARJ archive.
4Canonical
DebianFedoraproject+1 more
4Debian Linux
FedoraUbuntu Linux+1 more
May 6, 2026
Apr 1, 2015
N/A· v4
N/A· v3
4.9 MEDIUM· v2
QEMU, as used in Xen 3.3.x through 4.5.x, does not properly restrict access to PCI command registers, which might allow local HVM guest users to cause a denial of service (non-maskable interrupt and host crash) by disabl...Show more
QEMU, as used in Xen 3.3.x through 4.5.x, does not properly restrict access to PCI command registers, which might allow local HVM guest users to cause a denial of service (non-maskable interrupt and host crash) by disabling the (1) memory or (2) I/O decoding for a PCI Express device and then accessing the device, which triggers an Unsupported Request (UR) response.Show less
2Debian
Openldap
2Debian Linux
Openldap
May 6, 2026
Apr 1, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The default slapd configuration in the Debian openldap package 2.4.23-3 through 2.4.39-1.1 allows remote authenticated users to modify the user's permissions and other user attributes via unspecified vectors.
9Canonical
DebianFujitsu+6 more
619700 Firmware
Cognos Metrics ManagerCommunications Application Session Controller+58 more
May 28, 2026
Apr 1, 2015
N/A· v4
3.7 LOW· v3
5.0 MEDIUM· v2
The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recover...Show more
The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recovery attacks against the initial bytes of a stream by sniffing network traffic that occasionally relies on keys affected by the Invariance Weakness, and then using a brute-force approach involving LSB values, aka the "Bar Mitzvah" issue.Show less
2Debian
Gaia Gis
2Debian Linux
Freexl
May 6, 2026
Mar 31, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The parse_SST function in FreeXL before 1.0.0i allows remote attackers to cause a denial of service (memory consumption) via a crafted shared strings table in a workbook.
2Debian
Gaia Gis
2Debian Linux
Freexl
May 6, 2026
Mar 31, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
FreeXL before 1.0.0i allows remote attackers to cause a denial of service (stack corruption) and possibly execute arbitrary code via a crafted workbook, related to a "premature EOF."
2Debian
Gaia Gis
2Debian Linux
Freexl
May 6, 2026
Mar 31, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
FreeXL before 1.0.0i allows remote attackers to cause a denial of service (stack corruption) or possibly execute arbitrary code via a crafted sector in a workbook.
2Debian
Shibboleth
2Debian Linux
Service Provider
May 6, 2026
Mar 31, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Shibboleth Service Provider (SP) before 2.5.4 allows remote authenticated users to cause a denial of service (crash) via a crafted SAML message.
2Debian
Dulwich Project
2Debian Linux
Dulwich
May 6, 2026
Mar 31, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in the C implementation of the apply_delta function in _pack.c in Dulwich before 0.9.9 allows remote attackers to execute arbitrary code via a crafted pack file.
2Debian
Dulwich Project
2Debian Linux
Dulwich
May 6, 2026
Mar 31, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
The build_index_from_tree function in index.py in Dulwich before 0.9.9 allows remote attackers to execute arbitrary code via a commit with a directory path starting with .git/, which is not properly handled when checking...Show more
The build_index_from_tree function in index.py in Dulwich before 0.9.9 allows remote attackers to execute arbitrary code via a commit with a directory path starting with .git/, which is not properly handled when checking out a working tree.Show less