← Back

Debian Linux

debian_linux

Vendor: Debian • 10,000 CVEs

CVEs (10,000)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Debian
FedoraprojectLsyncd Project
3Debian Linux
FedoraLsyncd
May 6, 2026
Dec 5, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
default-rsyncssh.lua in Lsyncd 2.1.5 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a filename.
3Canonical
DebianGnu
3Debian Linux
GlibcUbuntu Linux
May 6, 2026
Dec 5, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
iconvdata/ibm930.c in GNU C Library (aka glibc) before 2.16 allows context-dependent attackers to cause a denial of service (out-of-bounds read) via a multibyte character value of "0xffff" to the iconv function when conv...Show more
iconvdata/ibm930.c in GNU C Library (aka glibc) before 2.16 allows context-dependent attackers to cause a denial of service (out-of-bounds read) via a multibyte character value of "0xffff" to the iconv function when converting IBM930 encoded data to UTF-8.Show less
2Debian
Graphviz
2Debian Linux
Graphviz
May 6, 2026
Dec 3, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Format string vulnerability in the yyerror function in lib/cgraph/scan.l in Graphviz allows remote attackers to have unspecified impact via format string specifiers in unknown vectors, which are not properly handled in a...Show more
Format string vulnerability in the yyerror function in lib/cgraph/scan.l in Graphviz allows remote attackers to have unspecified impact via format string specifiers in unknown vectors, which are not properly handled in an error string.Show less
5Canonical
DebianMageia+2 more
6Debian Linux
MageiaOpensuse+3 more
May 6, 2026
Dec 3, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
OpenVPN 2.x before 2.0.11, 2.1.x, 2.2.x before 2.2.3, and 2.3.x before 2.3.6 allows remote authenticated users to cause a denial of service (server crash) via a small control channel packet.
4Debian
MageiaMutt+1 more
5Debian Linux
Linux Enterprise DesktopMageia+2 more
May 6, 2026
Dec 2, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The write_one_header function in mutt 1.5.23 does not properly handle newline characters at the beginning of a header, which allows remote attackers to cause a denial of service (crash) via a header with an empty body, w...Show more
The write_one_header function in mutt 1.5.23 does not properly handle newline characters at the beginning of a header, which allows remote attackers to cause a denial of service (crash) via a header with an empty body, which triggers a heap-based buffer overflow in the mutt_substrdup function.Show less
2Debian
Gnu
2Cpio
Debian Linux
May 6, 2026
Dec 2, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Heap-based buffer overflow in the process_copy_in function in GNU Cpio 2.11 allows remote attackers to cause a denial of service via a large block value in a cpio archive.
4Canonical
DebianGnupg+1 more
5Debian Linux
GnupgLibksba+2 more
May 6, 2026
Dec 1, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Integer underflow in the ksba_oid_to_str function in Libksba before 1.3.2, as used in GnuPG, allows remote attackers to cause a denial of service (crash) via a crafted OID in a (1) S/MIME message or (2) ECC based OpenPGP...Show more
Integer underflow in the ksba_oid_to_str function in Libksba before 1.3.2, as used in GnuPG, allows remote attackers to cause a denial of service (crash) via a crafted OID in a (1) S/MIME message or (2) ECC based OpenPGP data, which triggers a buffer overflow.Show less
4Debian
OpensuseRedhat+1 more
5Debian Linux
Enterprise LinuxEnterprise Linux Desktop+2 more
May 6, 2026
Dec 1, 2014
N/A· v4
N/A· v3
4.9 MEDIUM· v2
The acceleration support for the "REP MOVS" instruction in Xen 4.4.x, 3.2.x, and earlier lacks properly bounds checking for memory mapped I/O (MMIO) emulated in the hypervisor, which allows local HVM guests to cause a de...Show more
The acceleration support for the "REP MOVS" instruction in Xen 4.4.x, 3.2.x, and earlier lacks properly bounds checking for memory mapped I/O (MMIO) emulated in the hypervisor, which allows local HVM guests to cause a denial of service (host crash) via unspecified vectors.Show less
3Debian
OpensuseXen
3Debian Linux
OpensuseXen
May 6, 2026
Dec 1, 2014
N/A· v4
N/A· v3
4.7 MEDIUM· v2
The compatibility mode hypercall argument translation in Xen 3.3.x through 4.4.x, when running on a 64-bit hypervisor, allows local 32-bit HVM guests to cause a denial of service (host crash) via vectors involving alteri...Show more
The compatibility mode hypercall argument translation in Xen 3.3.x through 4.4.x, when running on a 64-bit hypervisor, allows local 32-bit HVM guests to cause a denial of service (host crash) via vectors involving altering the high halves of registers while in 64-bit mode.Show less
2Debian
Mantisbt
2Debian Linux
Mantisbt
May 6, 2026
Nov 28, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in view_all_bug_page.php in MantisBT before 1.2.18 allow remote attackers to execute arbitrary SQL commands via the (1) sort or (2) dir parameter to view_all_set.php.
4Canonical
DebianFedoraproject+1 more
4Debian Linux
FedoraLibreoffice+1 more
May 6, 2026
Nov 26, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
LibreOffice before 4.3.5 allows remote attackers to cause a denial of service (invalid write operation and crash) and possibly execute arbitrary code via a crafted RTF file.
3Debian
Mageia ProjectWordpress
3Debian Linux
MageiaWordpress
May 6, 2026
Nov 25, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
wp-login.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to reset passwords by leveraging access to an e-mail account that received a password-rese...Show more
wp-login.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to reset passwords by leveraging access to an e-mail account that received a password-reset message.Show less
3Debian
Mageia ProjectWordpress
3Debian Linux
MageiaWordpress
May 6, 2026
Nov 25, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to obtain access to an account idle since 2008 by leveraging an improper PHP dynamic type comparison for a...Show more
WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to obtain access to an account idle since 2008 by leveraging an improper PHP dynamic type comparison for an MD5 hash.Show less
2Debian
Wordpress
2Debian Linux
Wordpress
May 6, 2026
Nov 25, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted Cascading Styl...Show more
Cross-site scripting (XSS) vulnerability in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted Cascading Style Sheets (CSS) token sequence in a post.Show less
2Debian
Wordpress
2Debian Linux
Wordpress
May 6, 2026
Nov 25, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Press This in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecifie...Show more
Cross-site scripting (XSS) vulnerability in Press This in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.Show less
6Apache
DebianDrupal+3 more
6Debian Linux
DrillDrupal+3 more
May 6, 2026
Nov 24, 2014
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in jquery.ui.dialog.js in the Dialog widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title option.
3Debian
OpensuseXen
3Debian Linux
OpensuseXen
May 6, 2026
Nov 24, 2014
N/A· v4
N/A· v3
7.1 HIGH· v2
The do_mmu_update function in arch/x86/mm.c in Xen 3.2.x through 4.4.x does not properly manage page references, which allows remote domains to cause a denial of service by leveraging control over an HVM guest and a craf...Show more
The do_mmu_update function in arch/x86/mm.c in Xen 3.2.x through 4.4.x does not properly manage page references, which allows remote domains to cause a denial of service by leveraging control over an HVM guest and a crafted MMU_MACHPHYS_UPDATE.Show less
3Debian
DrupalSecure Password Hashes Project
3Debian Linux
DrupalSecure Passwords Hashes
May 6, 2026
Nov 24, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal allows remote attackers to cause a denial of service (CPU and memory consumption) vi...Show more
The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted request.Show less
2Debian
Drupal
2Debian Linux
Drupal
May 6, 2026
Nov 24, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack sessions via a crafted request, as demonstrated by a crafted request to a server that supports both HTTP and HTTPS sessions.
4Canonical
DebianGnu+1 more
4Debian Linux
GlibcOpensuse+1 more
May 6, 2026
Nov 24, 2014
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The wordexp function in GNU C Library (aka glibc) 2.21 does not enforce the WRDE_NOCMD flag, which allows context-dependent attackers to execute arbitrary commands, as demonstrated by input containing "$((`...`))".