← Back

Debian Linux

debian_linux

Vendor: Debian • 10,000 CVEs

CVEs (10,000)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Apache
DebianRedhat
3Debian Linux
Http ServerJboss Enterprise Application Platform
May 6, 2026
Jul 20, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The deflate_in_filter function in mod_deflate.c in the mod_deflate module in the Apache HTTP Server before 2.4.10, when request body decompression is enabled, allows remote attackers to cause a denial of service (resourc...Show more
The deflate_in_filter function in mod_deflate.c in the mod_deflate module in the Apache HTTP Server before 2.4.10, when request body decompression is enabled, allows remote attackers to cause a denial of service (resource consumption) via crafted request data that decompresses to a much larger size.Show less
5Debian
LinuxOpensuse+2 more
6Debian Linux
Enterprise Linux Server AusLinux Enterprise Desktop+3 more
May 6, 2026
Jul 19, 2014
N/A· v4
N/A· v3
6.9 MEDIUM· v2
The PPPoL2TP feature in net/l2tp/l2tp_ppp.c in the Linux kernel through 3.15.6 allows local users to gain privileges by leveraging data-structure differences between an l2tp socket and an inet socket.
4Debian
FreedesktopMageia Project+1 more
4Dbus
Debian LinuxMageia+1 more
May 6, 2026
Jul 19, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6 allows local users to cause a denial of service (disconnect) via a certain sequence of crafted messages that cause the dbus-daemon to forward a message containing an invali...Show more
dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6 allows local users to cause a denial of service (disconnect) via a certain sequence of crafted messages that cause the dbus-daemon to forward a message containing an invalid file descriptor.Show less
5Debian
FreedesktopMageia+2 more
5Dbus
Debian LinuxMageia+2 more
May 6, 2026
Jul 19, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6, when running on Linux 2.6.37-rc4 or later, allows local users to cause a denial of service (system-bus disconnect of other services or applications) by sending a message c...Show more
dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6, when running on Linux 2.6.37-rc4 or later, allows local users to cause a denial of service (system-bus disconnect of other services or applications) by sending a message containing a file descriptor, then exceeding the maximum recursion depth before the initial message is forwarded.Show less
4Debian
MariadbOracle+1 more
8Debian Linux
Linux Enterprise DesktopLinux Enterprise Server+5 more
May 6, 2026
Jul 17, 2014
N/A· v4
N/A· v3
5.5 MEDIUM· v2
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier, and 5.6.17 and earlier, allows remote authenticated users to affect integrity and availability via vectors related to SRCHAR.
6Debian
MariadbOpensuse Project+3 more
12Debian Linux
Linux Enterprise DesktopLinux Enterprise Server+9 more
May 6, 2026
Jul 17, 2014
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier and 5.6.17 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via vectors relat...Show more
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier and 5.6.17 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to SRINFOSC.Show less
4Debian
MariadbOracle+1 more
7Debian Linux
Linux Enterprise DesktopLinux Enterprise Server+4 more
May 6, 2026
Jul 17, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier allows remote authenticated users to affect availability via vectors related to SROPTZR.
4Debian
MariadbOracle+1 more
7Debian Linux
Linux Enterprise DesktopLinux Enterprise Server+4 more
May 6, 2026
Jul 17, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier allows remote authenticated users to affect availability via vectors related to ENARC.
3Debian
HpOracle
4Debian Linux
Hp UxJdk+1 more
May 6, 2026
Jul 17, 2014
N/A· v4
N/A· v3
9.3 HIGH· v2
Unspecified vulnerability in the Java SE component in Oracle Java SE 7u60 and SE 8u5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.
3Debian
OracleRedhat
5Debian Linux
Enterprise LinuxJdk+2 more
May 6, 2026
Jul 17, 2014
N/A· v4
N/A· v3
9.3 HIGH· v2
Unspecified vulnerability in the Java SE component in Oracle Java SE Java SE 7u60 and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a d...Show more
Unspecified vulnerability in the Java SE component in Oracle Java SE Java SE 7u60 and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2014-4223. NOTE: the previous information is from the July 2014 CPU. Oracle has not commented on another vendor's claim that the issue is related to improper restriction of the "use of privileged annotations."Show less
3Canonical
DebianLinux
3Debian Linux
Linux KernelUbuntu Linux
May 6, 2026
Jul 9, 2014
N/A· v4
N/A· v3
6.9 MEDIUM· v2
The Linux kernel before 3.15.4 on Intel processors does not properly restrict use of a non-canonical value for the saved RIP address in the case of a system call that does not use IRET, which allows local users to levera...Show more
The Linux kernel before 3.15.4 on Intel processors does not properly restrict use of a non-canonical value for the saved RIP address in the case of a system call that does not use IRET, which allows local users to leverage a race condition and gain privileges, or cause a denial of service (double fault), via a crafted application that makes ptrace and fork system calls.Show less
2Debian
Php
2Debian Linux
Php
May 6, 2026
Jul 9, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
The SPL component in PHP before 5.4.30 and 5.5.x before 5.5.14 incorrectly anticipates that certain data structures will have the array data type after unserialization, which allows remote attackers to execute arbitrary...Show more
The SPL component in PHP before 5.4.30 and 5.5.x before 5.5.14 incorrectly anticipates that certain data structures will have the array data type after unserialization, which allows remote attackers to execute arbitrary code via a crafted string that triggers use of a Hashtable destructor, related to "type confusion" issues in (1) ArrayObject and (2) SPLObjectStorage.Show less
5Debian
File ProjectOpensuse+2 more
5Debian Linux
FileLinux+2 more
May 6, 2026
Jul 9, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The cdf_read_property_info function in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, does not properly validate a stream offset, which allows remote attackers to cause...Show more
The cdf_read_property_info function in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, does not properly validate a stream offset, which allows remote attackers to cause a denial of service (application crash) via a crafted CDF file.Show less
5Debian
File ProjectOpensuse+2 more
5Debian Linux
FileLinux+2 more
May 6, 2026
Jul 9, 2014
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The cdf_count_chain function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, does not properly validate sector-count data, which allows remote attackers to ca...Show more
The cdf_count_chain function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, does not properly validate sector-count data, which allows remote attackers to cause a denial of service (application crash) via a crafted CDF file.Show less
5Debian
File ProjectOpensuse+2 more
5Debian Linux
FileLinux+2 more
May 6, 2026
Jul 9, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The cdf_check_stream_offset function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, relies on incorrect sector-size data, which allows remote attackers to ca...Show more
The cdf_check_stream_offset function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, relies on incorrect sector-size data, which allows remote attackers to cause a denial of service (application crash) via a crafted stream offset in a CDF file.Show less
5Christos Zoulas
DebianOpensuse+2 more
5Debian Linux
FileLinux+2 more
May 6, 2026
Jul 9, 2014
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The cdf_read_short_sector function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows remote attackers to cause a denial of service (assertion failure and...Show more
The cdf_read_short_sector function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted CDF file.Show less
2Debian
Php
2Debian Linux
Php
May 6, 2026
Jul 6, 2014
N/A· v4
N/A· v3
2.6 LOW· v2
The phpinfo implementation in ext/standard/info.c in PHP before 5.4.30 and 5.5.x before 5.5.14 does not ensure use of the string data type for the PHP_AUTH_PW, PHP_AUTH_TYPE, PHP_AUTH_USER, and PHP_SELF variables, which...Show more
The phpinfo implementation in ext/standard/info.c in PHP before 5.4.30 and 5.5.x before 5.5.14 does not ensure use of the string data type for the PHP_AUTH_PW, PHP_AUTH_TYPE, PHP_AUTH_USER, and PHP_SELF variables, which might allow context-dependent attackers to obtain sensitive information from process memory by using the integer data type with crafted values, related to a "type confusion" vulnerability, as demonstrated by reading a private SSL key in an Apache HTTP Server web-hosting environment with mod_ssl and a PHP 5.3.x mod_php.Show less
3Christos Zoulas
DebianPhp
3Debian Linux
FilePhp
May 6, 2026
Jul 3, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
file before 5.19 does not properly restrict the amount of data read during a regex search, which allows remote attackers to cause a denial of service (CPU consumption) via a crafted file that triggers backtracking during...Show more
file before 5.19 does not properly restrict the amount of data read during a regex search, which allows remote attackers to cause a denial of service (CPU consumption) via a crafted file that triggers backtracking during processing of an awk rule. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7345.Show less
4Canonical
DebianLinux+1 more
6Debian Linux
Linux Enterprise DesktopLinux Enterprise Real Time Extension+3 more
May 6, 2026
Jul 3, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The sctp_association_free function in net/sctp/associola.c in the Linux kernel before 3.15.2 does not properly manage a certain backlog value, which allows remote attackers to cause a denial of service (socket outage) vi...Show more
The sctp_association_free function in net/sctp/associola.c in the Linux kernel before 3.15.2 does not properly manage a certain backlog value, which allows remote attackers to cause a denial of service (socket outage) via a crafted SCTP packet.Show less
3Debian
GnupgOpensuse
3Debian Linux
GnupgOpensuse
May 6, 2026
Jun 25, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The do_uncompress function in g10/compress.c in GnuPG 1.x before 1.4.17 and 2.x before 2.0.24 allows context-dependent attackers to cause a denial of service (infinite loop) via malformed compressed packets, as demonstra...Show more
The do_uncompress function in g10/compress.c in GnuPG 1.x before 1.4.17 and 2.x before 2.0.24 allows context-dependent attackers to cause a denial of service (infinite loop) via malformed compressed packets, as demonstrated by an a3 01 5b ff byte sequence.Show less