← Back

Debian Linux

debian_linux

Vendor: Debian • 10,000 CVEs

CVEs (10,000)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Debian
Xen
2Debian Linux
Xen
Apr 29, 2026
Nov 2, 2013
N/A· v4
N/A· v3
5.2 MEDIUM· v2
Xen before 4.1.x, 4.2.x, and 4.3.x does not take the page_alloc_lock and grant_table.lock in the same order, which allows local guest administrators with access to multiple vcpus to cause a denial of service (host deadlo...Show more
Xen before 4.1.x, 4.2.x, and 4.3.x does not take the page_alloc_lock and grant_table.lock in the same order, which allows local guest administrators with access to multiple vcpus to cause a denial of service (host deadlock) via unspecified vectors.Show less
2Debian
Systemd Project
2Debian Linux
Systemd
Apr 29, 2026
Oct 28, 2013
N/A· v4
N/A· v3
5.9 MEDIUM· v2
The SetX11Keyboard function in systemd, when PolicyKit Local Authority (PKLA) is used to change the group permissions on the X Keyboard Extension (XKB) layouts description, allows local users in the group to modify the X...Show more
The SetX11Keyboard function in systemd, when PolicyKit Local Authority (PKLA) is used to change the group permissions on the X Keyboard Extension (XKB) layouts description, allows local users in the group to modify the Xorg X11 Server configuration file and possibly gain privileges via vectors involving "special and control characters."Show less
2Debian
Systemd Project
2Debian Linux
Systemd
Apr 29, 2026
Oct 28, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Integer overflow in the valid_user_field function in journal/journald-native.c in systemd allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large journal data field, w...Show more
Integer overflow in the valid_user_field function in journal/journald-native.c in systemd allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large journal data field, which triggers a heap-based buffer overflow.Show less
4Apache
DebianOpensuse+1 more
5Cloud
Debian LinuxLinux Enterprise Software Development Kit+2 more
Apr 29, 2026
Oct 17, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Heap-based buffer overflow in the fcgid_header_bucket_read function in fcgid_bucket.c in the mod_fcgid module before 2.3.9 for the Apache HTTP Server allows remote attackers to have an unspecified impact via unknown vect...Show more
Heap-based buffer overflow in the fcgid_header_bucket_read function in fcgid_bucket.c in the mod_fcgid module before 2.3.9 for the Apache HTTP Server allows remote attackers to have an unspecified impact via unknown vectors.Show less
3Debian
OpensuseRubyonrails
3Debian Linux
OpensuseRails
Apr 29, 2026
Oct 17, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple format string vulnerabilities in log_subscriber.rb files in the log subscriber component in Action Mailer in Ruby on Rails 3.x before 3.2.15 allow remote attackers to cause a denial of service via a crafted e-ma...Show more
Multiple format string vulnerabilities in log_subscriber.rb files in the log subscriber component in Action Mailer in Ruby on Rails 3.x before 3.2.15 allow remote attackers to cause a denial of service via a crafted e-mail address that is improperly handled during construction of a log message.Show less
3Debian
GoogleOpensuse
3Chrome
Debian LinuxOpensuse
Apr 29, 2026
Oct 16, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Use-after-free vulnerability in the HTMLFormElement::prepareForSubmission function in core/html/HTMLFormElement.cpp in Blink, as used in Google Chrome before 30.0.1599.101, allows remote attackers to cause a denial of se...Show more
Use-after-free vulnerability in the HTMLFormElement::prepareForSubmission function in core/html/HTMLFormElement.cpp in Blink, as used in Google Chrome before 30.0.1599.101, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to submission for FORM elements.Show less
5Canonical
DebianMariadb+2 more
7Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+4 more
Apr 29, 2026
Oct 16, 2013
N/A· v4
N/A· v3
4.9 MEDIUM· v2
Unspecified vulnerability in Oracle MySQL Server 5.5.x through 5.5.32 and 5.6.x through 5.6.12 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Replication.
5Canonical
DebianMariadb+2 more
7Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+4 more
Apr 29, 2026
Oct 16, 2013
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.70 and earlier, 5.5.32 and earlier, and 5.6.12 and earlier allows remote authenticated users to affect availability via unknown vectors related...Show more
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.70 and earlier, 5.5.32 and earlier, and 5.6.12 and earlier allows remote authenticated users to affect availability via unknown vectors related to Optimizer.Show less
3Canonical
DebianSystemd Project
3Debian Linux
SystemdUbuntu Linux
Apr 29, 2026
Oct 3, 2013
N/A· v4
N/A· v3
6.9 MEDIUM· v2
systemd does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setu...Show more
systemd does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.Show less
3Debian
GoogleOpensuse
3Chrome
Debian LinuxOpensuse
Apr 29, 2026
Oct 2, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Google V8, as used in Google Chrome before 30.0.1599.66, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
2Debian
Konstanty Bialkowski
2Debian Linux
Libmodplug
Apr 29, 2026
Sep 16, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple heap-based buffer overflows in the (1) abc_MIDI_drum and (2) abc_MIDI_gchord functions in load_abc.cpp in libmodplug 0.8.8.4 and earlier allow remote attackers to cause a denial of service (memory corruption and...Show more
Multiple heap-based buffer overflows in the (1) abc_MIDI_drum and (2) abc_MIDI_gchord functions in load_abc.cpp in libmodplug 0.8.8.4 and earlier allow remote attackers to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via a crafted ABC.Show less
2Debian
Konstanty Bialkowski
2Debian Linux
Libmodplug
Apr 29, 2026
Sep 16, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Integer overflow in the abc_set_parts function in load_abc.cpp in libmodplug 0.8.8.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted P header in an ABC f...Show more
Integer overflow in the abc_set_parts function in load_abc.cpp in libmodplug 0.8.8.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted P header in an ABC file, which triggers a heap-based buffer overflow.Show less
2Debian
Libtiff
2Debian Linux
Libtiff
Apr 29, 2026
Sep 10, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Heap-based buffer overflow in the readgifimage function in the gif2tiff tool in libtiff 4.0.3 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted hei...Show more
Heap-based buffer overflow in the readgifimage function in the gif2tiff tool in libtiff 4.0.3 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted height and width values in a GIF image.Show less
2Debian
Libtiff
2Debian Linux
Libtiff
Apr 29, 2026
Sep 10, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Use-after-free vulnerability in the t2p_readwrite_pdf_image function in tools/tiff2pdf.c in libtiff 4.0.3 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted TIFF...Show more
Use-after-free vulnerability in the t2p_readwrite_pdf_image function in tools/tiff2pdf.c in libtiff 4.0.3 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted TIFF image.Show less
3Cacti
DebianOpensuse
3Cacti
Debian LinuxOpensuse
Apr 29, 2026
Aug 29, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in cacti/host.php in Cacti 0.8.8b and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
2Debian
Xen
2Debian Linux
Xen
Apr 29, 2026
Aug 28, 2013
N/A· v4
N/A· v3
7.4 HIGH· v2
Buffer overflow in the Python bindings for the xc_vcpu_setaffinity call in Xen 4.0.x, 4.1.x, and 4.2.x allows local administrators with permissions to configure VCPU affinity to cause a denial of service (memory corrupti...Show more
Buffer overflow in the Python bindings for the xc_vcpu_setaffinity call in Xen 4.0.x, 4.1.x, and 4.2.x allows local administrators with permissions to configure VCPU affinity to cause a denial of service (memory corruption and xend toolstack crash) and possibly gain privileges via a crafted cpumap.Show less
2Debian
Google
2Chrome
Debian Linux
Apr 29, 2026
Aug 21, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The SharedMemory::Create function in memory/shared_memory_posix.cc in Google Chrome before 29.0.1547.57 uses weak permissions under /dev/shm/, which allows attackers to obtain sensitive information via direct access to a...Show more
The SharedMemory::Create function in memory/shared_memory_posix.cc in Google Chrome before 29.0.1547.57 uses weak permissions under /dev/shm/, which allows attackers to obtain sensitive information via direct access to a POSIX shared-memory file.Show less
2Debian
Google
2Chrome
Debian Linux
Apr 29, 2026
Aug 21, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Use-after-free vulnerability in the Document::finishedParsing function in core/dom/Document.cpp in Blink, as used in Google Chrome before 29.0.1547.57, allows remote attackers to cause a denial of service or possibly hav...Show more
Use-after-free vulnerability in the Document::finishedParsing function in core/dom/Document.cpp in Blink, as used in Google Chrome before 29.0.1547.57, allows remote attackers to cause a denial of service or possibly have unspecified other impact via an onload event that changes an IFRAME element so that its src attribute is no longer an XML document, leading to unintended garbage collection of this document.Show less
2Debian
Google
2Chrome
Debian Linux
Apr 29, 2026
Aug 21, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Use-after-free vulnerability in the HTMLMediaElement::didMoveToNewDocument function in core/html/HTMLMediaElement.cpp in Blink, as used in Google Chrome before 29.0.1547.57, allows remote attackers to cause a denial of s...Show more
Use-after-free vulnerability in the HTMLMediaElement::didMoveToNewDocument function in core/html/HTMLMediaElement.cpp in Blink, as used in Google Chrome before 29.0.1547.57, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving moving a (1) AUDIO or (2) VIDEO element between documents.Show less
2Debian
Google
2Chrome
Debian Linux
Apr 29, 2026
Aug 21, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Use-after-free vulnerability in the XSLT ProcessingInstruction implementation in Blink, as used in Google Chrome before 29.0.1547.57, allows remote attackers to cause a denial of service or possibly have unspecified othe...Show more
Use-after-free vulnerability in the XSLT ProcessingInstruction implementation in Blink, as used in Google Chrome before 29.0.1547.57, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to an applyXSLTransform call involving (1) an HTML document or (2) an xsl:processing-instruction element that is still in the process of loading.Show less