← Back

Debian Linux

debian_linux

Vendor: Debian • 10,000 CVEs

CVEs (10,000)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Debian
Google
2Chrome
Debian Linux
Apr 29, 2026
Jul 10, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Use-after-free vulnerability in Google Chrome before 28.0.1500.71 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a 404 HTTP status code during the loa...Show more
Use-after-free vulnerability in Google Chrome before 28.0.1500.71 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a 404 HTTP status code during the loading of resources.Show less
2Debian
Google
2Chrome
Debian Linux
Apr 29, 2026
Jul 10, 2013
N/A· v4
N/A· v3
9.3 HIGH· v2
Use-after-free vulnerability in Google Chrome before 28.0.1500.71 allows remote servers to execute arbitrary code via crafted response traffic after a URL request.
2Debian
Google
2Chrome
Debian Linux
Apr 29, 2026
Jul 10, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Google Chrome before 28.0.1500.71 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted JPEG2000 image.
2Debian
Google
2Chrome
Debian Linux
Apr 29, 2026
Jul 10, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
common/extensions/sync_helper.cc in Google Chrome before 28.0.1500.71 proceeds with sync operations for NPAPI extensions without checking for a certain plugin permission setting, which might allow remote attackers to tri...Show more
common/extensions/sync_helper.cc in Google Chrome before 28.0.1500.71 proceeds with sync operations for NPAPI extensions without checking for a certain plugin permission setting, which might allow remote attackers to trigger unwanted extension changes via unspecified vectors.Show less
2Debian
Google
2Chrome
Debian Linux
Apr 29, 2026
Jul 10, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Google Chrome before 28.0.1500.71 does not properly prevent pop-under windows, which allows remote attackers to have an unspecified impact via a crafted web site.
6Canonical
DebianMozilla+3 more
15Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+12 more
Apr 22, 2026
Jun 26, 2013
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadystatechange events in conjunction with page reloading, which al...Show more
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted web site that triggers an attempt to execute data at an unmapped memory location.Show less
6Canonical
DebianFedoraproject+3 more
6Debian Linux
FedoraLibxcb+3 more
Apr 29, 2026
Jun 15, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Integer overflow in X.org libxcb 1.9 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the read_packet function.
3Debian
OpensuseWireshark
3Debian Linux
OpensuseWireshark
Apr 29, 2026
Jun 9, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The vwr_read function in wiretap/vwr.c in the Ixia IxVeriWave file parser in Wireshark 1.8.x before 1.8.8 does not validate the relationship between a record length and a trailer length, which allows remote attackers to...Show more
The vwr_read function in wiretap/vwr.c in the Ixia IxVeriWave file parser in Wireshark 1.8.x before 1.8.8 does not validate the relationship between a record length and a trailer length, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) via a crafted packet.Show less
3Debian
OpensuseWireshark
3Debian Linux
OpensuseWireshark
Apr 29, 2026
Jun 9, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The http_payload_subdissector function in epan/dissectors/packet-http.c in the HTTP dissector in Wireshark 1.6.x before 1.6.16 and 1.8.x before 1.8.8 does not properly determine when to use a recursive approach, which al...Show more
The http_payload_subdissector function in epan/dissectors/packet-http.c in the HTTP dissector in Wireshark 1.6.x before 1.6.16 and 1.8.x before 1.8.8 does not properly determine when to use a recursive approach, which allows remote attackers to cause a denial of service (stack consumption) via a crafted packet.Show less
3Debian
OpensuseWireshark
3Debian Linux
OpensuseWireshark
Apr 29, 2026
Jun 9, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
epan/dissectors/packet-rdp.c in the RDP dissector in Wireshark 1.8.x before 1.8.8 does not validate return values during checks for data availability, which allows remote attackers to cause a denial of service (applicati...Show more
epan/dissectors/packet-rdp.c in the RDP dissector in Wireshark 1.8.x before 1.8.8 does not validate return values during checks for data availability, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.Show less
3Debian
OpensuseWireshark
3Debian Linux
OpensuseWireshark
Apr 29, 2026
Jun 9, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Array index error in the NBAP dissector in Wireshark 1.8.x before 1.8.8 allows remote attackers to cause a denial of service (application crash) via a crafted packet, related to nbap.cnf and packet-nbap.c.
3Debian
OpensuseWireshark
3Debian Linux
OpensuseWireshark
Apr 29, 2026
Jun 9, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Buffer overflow in the dissect_iphc_crtp_fh function in epan/dissectors/packet-ppp.c in the PPP dissector in Wireshark 1.8.x before 1.8.8 allows remote attackers to cause a denial of service (application crash) via a cra...Show more
Buffer overflow in the dissect_iphc_crtp_fh function in epan/dissectors/packet-ppp.c in the PPP dissector in Wireshark 1.8.x before 1.8.8 allows remote attackers to cause a denial of service (application crash) via a crafted packet.Show less
3Debian
OpensuseWireshark
3Debian Linux
OpensuseWireshark
Apr 29, 2026
Jun 9, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
epan/dissectors/packet-gmr1_bcch.c in the GMR-1 BCCH dissector in Wireshark 1.8.x before 1.8.8 does not properly initialize memory, which allows remote attackers to cause a denial of service (application crash) via a cra...Show more
epan/dissectors/packet-gmr1_bcch.c in the GMR-1 BCCH dissector in Wireshark 1.8.x before 1.8.8 does not properly initialize memory, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.Show less
3Debian
OpensuseWireshark
3Debian Linux
OpensuseWireshark
Apr 29, 2026
Jun 9, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The dissect_capwap_data function in epan/dissectors/packet-capwap.c in the CAPWAP dissector in Wireshark 1.6.x before 1.6.16 and 1.8.x before 1.8.8 incorrectly uses a -1 data value to represent an error condition, which...Show more
The dissect_capwap_data function in epan/dissectors/packet-capwap.c in the CAPWAP dissector in Wireshark 1.6.x before 1.6.16 and 1.8.x before 1.8.8 incorrectly uses a -1 data value to represent an error condition, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.Show less
3Canonical
DebianLinux
3Debian Linux
Linux KernelUbuntu Linux
Apr 29, 2026
Jun 7, 2013
N/A· v4
N/A· v3
6.9 MEDIUM· v2
Format string vulnerability in the b43_request_firmware function in drivers/net/wireless/b43/main.c in the Broadcom B43 wireless driver in the Linux kernel through 3.9.4 allows local users to gain privileges by leveragin...Show more
Format string vulnerability in the b43_request_firmware function in drivers/net/wireless/b43/main.c in the Broadcom B43 wireless driver in the Linux kernel through 3.9.4 allows local users to gain privileges by leveraging root access and including format string specifiers in an fwpostfix modprobe parameter, leading to improper construction of an error message.Show less
2Debian
Google
2Chrome
Debian Linux
Apr 29, 2026
Jun 5, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple unspecified vulnerabilities in Google Chrome before 27.0.1453.110 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
2Debian
Google
2Chrome
Debian Linux
Apr 29, 2026
Jun 5, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
Google Chrome before 27.0.1453.110 does not properly handle SSL sockets, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
2Debian
Google
2Chrome
Debian Linux
Apr 29, 2026
Jun 5, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Skia, as used in Google Chrome before 27.0.1453.110, does not properly handle GPU acceleration, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via...Show more
Skia, as used in Google Chrome before 27.0.1453.110, does not properly handle GPU acceleration, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.Show less
2Debian
Google
2Chrome
Debian Linux
Apr 29, 2026
Jun 5, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Use-after-free vulnerability in the SVG implementation in Google Chrome before 27.0.1453.110 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
2Debian
Google
2Chrome
Debian Linux
Apr 29, 2026
Jun 5, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Use-after-free vulnerability in Google Chrome before 27.0.1453.110 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving access to a database API by a worker...Show more
Use-after-free vulnerability in Google Chrome before 27.0.1453.110 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving access to a database API by a worker process.Show less