← Back

Debian Linux

debian_linux

Vendor: Debian • 10,000 CVEs

CVEs (10,000)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
7Canonical
DebianOpensuse+4 more
13Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+10 more
Apr 29, 2026
Nov 23, 2012
N/A· v4
N/A· v3
7.2 HIGH· v2
Qemu, as used in Xen 4.0, 4.1 and possibly other products, when emulating certain devices with a virtual console backend, allows local OS guest users to gain privileges via a crafted escape VT100 sequence that triggers t...Show more
Qemu, as used in Xen 4.0, 4.1 and possibly other products, when emulating certain devices with a virtual console backend, allows local OS guest users to gain privileges via a crafted escape VT100 sequence that triggers the overwrite of a "device model's address space."Show less
6Canonical
DebianMozilla+3 more
14Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+11 more
Apr 29, 2026
Nov 21, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allow re...Show more
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.Show less
6Canonical
DebianMozilla+3 more
14Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+11 more
Apr 29, 2026
Nov 21, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
Heap-based buffer overflow in the nsWindow::OnExposeEvent function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14...Show more
Heap-based buffer overflow in the nsWindow::OnExposeEvent function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code via unspecified vectors.Show less
6Canonical
DebianMozilla+3 more
14Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+11 more
Apr 29, 2026
Nov 21, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
Use-after-free vulnerability in the gfxFont::GetFontEntry function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14...Show more
Use-after-free vulnerability in the gfxFont::GetFontEntry function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.Show less
6Canonical
DebianMozilla+3 more
14Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+11 more
Apr 29, 2026
Nov 21, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The HZ-GB-2312 character-set implementation in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 does not properly handl...Show more
The HZ-GB-2312 character-set implementation in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 does not properly handle a ~ (tilde) character in proximity to a chunk delimiter, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted document.Show less
6Canonical
DebianMozilla+3 more
14Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+11 more
Apr 29, 2026
Nov 21, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The evalInSandbox implementation in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 uses an incorrect context during t...Show more
The evalInSandbox implementation in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 uses an incorrect context during the handling of JavaScript code that sets the location.href property, which allows remote attackers to conduct cross-site scripting (XSS) attacks or read arbitrary files by leveraging a sandboxed add-on.Show less
2Debian
Viewvc
2Debian Linux
Viewvc
Apr 29, 2026
Nov 19, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the "extra" details in the DiffSource._get_row function in lib/viewvc.py in ViewVC 1.0.x before 1.0.13 and 1.1.x before 1.1.16 allows remote authenticated users with repository...Show more
Cross-site scripting (XSS) vulnerability in the "extra" details in the DiffSource._get_row function in lib/viewvc.py in ViewVC 1.0.x before 1.0.13 and 1.1.x before 1.1.16 allows remote authenticated users with repository commit access to inject arbitrary web script or HTML via the "function name" line.Show less
5Canonical
DebianLibtiff+2 more
8Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+5 more
Apr 29, 2026
Nov 11, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
ppm2tiff does not check the return value of the TIFFScanlineSize function, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PPM image that triggers an i...Show more
ppm2tiff does not check the return value of the TIFFScanlineSize function, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PPM image that triggers an integer overflow, a zero-memory allocation, and a heap-based buffer overflow.Show less
5Canonical
DebianMariadb+2 more
8Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+5 more
Apr 29, 2026
Oct 17, 2012
N/A· v4
N/A· v3
3.5 LOW· v2
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.64 and earlier, and 5.5.26 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Replicati...Show more
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.64 and earlier, and 5.5.26 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Replication.Show less
5Canonical
DebianMariadb+2 more
8Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+5 more
Apr 29, 2026
Oct 17, 2012
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.65 and earlier, and 5.5.27 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer...Show more
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.65 and earlier, and 5.5.27 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.Show less
5Canonical
DebianMariadb+2 more
9Debian Linux
Enterprise LinuxEnterprise Linux Desktop+6 more
Apr 29, 2026
Oct 17, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.65 and earlier, and 5.5.27 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server.
5Canonical
DebianMariadb+2 more
8Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+5 more
Apr 29, 2026
Oct 17, 2012
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.63 and earlier, and 5.5.25 and earlier, allows remote authenticated users to affect availability via unknown vectors related to InnoDB Plugin.
5Canonical
DebianMariadb+2 more
8Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+5 more
Apr 29, 2026
Oct 17, 2012
N/A· v4
N/A· v3
3.5 LOW· v2
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.63 and earlier, and 5.5.25 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Full Text...Show more
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.63 and earlier, and 5.5.25 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Full Text Search.Show less
5Canonical
DebianMariadb+2 more
9Debian Linux
Enterprise LinuxEnterprise Linux Desktop+6 more
Apr 29, 2026
Oct 17, 2012
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.63 and earlier, and 5.5.25 and earlier, allows remote authenticated users to affect availability via unknown vectors related to InnoDB.
6Canonical
DebianF5+3 more
21Big Ip Access Policy Manager
Big Ip Advanced Firewall ManagerBig Ip Analytics+18 more
Apr 29, 2026
Oct 17, 2012
N/A· v4
N/A· v3
9.0 HIGH· v2
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.64 and earlier, and 5.5.26 and earlier, allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vec...Show more
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.64 and earlier, and 5.5.26 and earlier, allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Information Schema.Show less
5Canonical
DebianMariadb+2 more
8Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+5 more
Apr 29, 2026
Oct 16, 2012
N/A· v4
N/A· v3
2.1 LOW· v2
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.65 and earlier, and 5.5.27 and earlier, allows local users to affect confidentiality via unknown vectors related to Server Installation.
5Canonical
DebianMariadb+2 more
8Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+5 more
Apr 29, 2026
Oct 16, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.64 and earlier, and 5.5.26 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors relat...Show more
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.64 and earlier, and 5.5.26 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Protocol.Show less
5Canonical
DebianMariadb+2 more
8Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+5 more
Apr 29, 2026
Oct 16, 2012
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.64 and earlier, and 5.5.26 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer...Show more
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.64 and earlier, and 5.5.26 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.Show less
2Bacula
Debian
2Bacula
Debian Linux
Apr 29, 2026
Oct 10, 2012
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The dump_resource function in dird/dird_conf.c in Bacula before 5.2.11 does not properly enforce ACL rules, which allows remote authenticated users to obtain resource dump information via unspecified vectors.
5Canonical
DebianMozilla+2 more
13Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+10 more
Apr 29, 2026
Oct 10, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
Heap-based buffer overflow in the Convolve3x3 function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote...Show more
Heap-based buffer overflow in the Convolve3x3 function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code via unspecified vectors.Show less