← Back

Debian Linux

debian_linux

Vendor: Debian • 10,000 CVEs

CVEs (10,000)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Debian
Mediawiki
2Debian Linux
Mediawiki
Apr 29, 2026
Jan 8, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
MediaWiki before 1.17.1 allows remote attackers to obtain the page titles of all restricted pages via a series of requests involving the (1) curid or (2) oldid parameter.
5Apple
DebianGoogle+2 more
9Chrome
Debian LinuxEnterprise Linux Desktop+6 more
Apr 29, 2026
Jan 7, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Heap-based buffer overflow in libxml2, as used in Google Chrome before 16.0.912.75, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
8Debian
FedoraprojectFreebsd+5 more
10Debian Linux
FedoraFreebsd+7 more
Apr 29, 2026
Dec 25, 2011
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU inetutils, and possibly other products a...Show more
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU inetutils, and possibly other products allows remote attackers to execute arbitrary code via a long encryption key, as exploited in the wild in December 2011.Show less
2Debian
Lighttpd
2Debian Linux
Lighttpd
Apr 29, 2026
Dec 24, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Integer signedness error in the base64_decode function in the HTTP authentication functionality (http_auth.c) in lighttpd 1.4 before 1.4.30 and 1.5 before SVN revision 2806 allows remote attackers to cause a denial of se...Show more
Integer signedness error in the base64_decode function in the HTTP authentication functionality (http_auth.c) in lighttpd 1.4 before 1.4.30 and 1.5 before SVN revision 2806 allows remote attackers to cause a denial of service (segmentation fault) via crafted base64 input that triggers an out-of-bounds read with a negative index.Show less
7Canonical
DebianFedoraproject+4 more
9Debian Linux
Enterprise Linux DesktopFedora+6 more
Apr 29, 2026
Dec 15, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The jpc_crg_getparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 uses an incorrect data type during a certain size calculation, which allows remote attackers to trigger a heap-based buffer overflow and execute a...Show more
The jpc_crg_getparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 uses an incorrect data type during a certain size calculation, which allows remote attackers to trigger a heap-based buffer overflow and execute arbitrary code, or cause a denial of service (heap memory corruption), via a crafted component registration (CRG) marker segment in a JPEG2000 file.Show less
6Canonical
DebianFedoraproject+3 more
8Debian Linux
FedoraJasper+5 more
Apr 29, 2026
Dec 15, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Heap-based buffer overflow in the jpc_cox_getcompparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted...Show more
Heap-based buffer overflow in the jpc_cox_getcompparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted numrlvls value in a coding style default (COD) marker segment in a JPEG2000 file.Show less
3Debian
GoogleRedhat
6Chrome
Debian LinuxEnterprise Linux Desktop+3 more
Apr 29, 2026
Dec 13, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
libxml2, as used in Google Chrome before 16.0.912.63, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
3Canonical
DebianIsc
3Debian Linux
DhcpUbuntu Linux
Apr 29, 2026
Dec 8, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
dhcpd in ISC DHCP 4.x before 4.2.3-P1 and 4.1-ESV before 4.1-ESV-R4 does not properly handle regular expressions in dhcpd.conf, which allows remote attackers to cause a denial of service (daemon crash) via a crafted requ...Show more
dhcpd in ISC DHCP 4.x before 4.2.3-P1 and 4.1-ESV before 4.1-ESV-R4 does not properly handle regular expressions in dhcpd.conf, which allows remote attackers to cause a denial of service (daemon crash) via a crafted request packet.Show less
3Canonical
DebianPhp
3Debian Linux
PhpUbuntu Linux
Apr 29, 2026
Nov 29, 2011
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Integer overflow in the exif_process_IFD_TAG function in exif.c in the exif extension in PHP 5.4.0beta2 on 32-bit platforms allows remote attackers to read the contents of arbitrary memory locations or cause a denial of...Show more
Integer overflow in the exif_process_IFD_TAG function in exif.c in the exif extension in PHP 5.4.0beta2 on 32-bit platforms allows remote attackers to read the contents of arbitrary memory locations or cause a denial of service via a crafted offset_val value in an EXIF header in a JPEG file, a different vulnerability than CVE-2011-0708.Show less
3Debian
FedoraprojectPhpmyadmin
3Debian Linux
FedoraPhpmyadmin
Apr 29, 2026
Nov 17, 2011
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The simplexml_load_string function in the XML import plug-in (libraries/import/xml.php) in phpMyAdmin 3.4.x before 3.4.7.1 and 3.3.x before 3.3.10.5 allows remote authenticated users to read arbitrary files via XML data...Show more
The simplexml_load_string function in the XML import plug-in (libraries/import/xml.php) in phpMyAdmin 3.4.x before 3.4.7.1 and 3.3.x before 3.3.10.5 allows remote authenticated users to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack.Show less
2Debian
Google
2Chrome
Debian Linux
Apr 29, 2026
Nov 11, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
Heap-based buffer overflow in the Vorbis decoder in Google Chrome before 15.0.874.120 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted stream.
2Debian
Google
2Chrome
Debian Linux
Apr 29, 2026
Nov 11, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
Double free vulnerability in the Theora decoder in Google Chrome before 15.0.874.120 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted stream.
4Canonical
DebianLinux+1 more
5Debian Linux
Enterprise LinuxEnterprise Mrg+2 more
Apr 29, 2026
Oct 10, 2011
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
net/core/net_namespace.c in the Linux kernel 2.6.32 and earlier does not properly handle a high rate of creation and cleanup of network namespaces, which makes it easier for remote attackers to cause a denial of service...Show more
net/core/net_namespace.c in the Linux kernel 2.6.32 and earlier does not properly handle a high rate of creation and cleanup of network namespaces, which makes it easier for remote attackers to cause a denial of service (memory consumption) via requests to a daemon that requires a separate namespace per connection, as demonstrated by vsftpd.Show less
2Debian
Fast Cgi Project
2Debian Linux
Fast Cgi
Apr 29, 2026
Sep 23, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
The FCGI (aka Fast CGI) module 0.70 through 0.73 for Perl, as used by CGI::Fast, uses environment variable values from one request during processing of a later request, which allows remote attackers to bypass authenticat...Show more
The FCGI (aka Fast CGI) module 0.70 through 0.73 for Perl, as used by CGI::Fast, uses environment variable values from one request during processing of a later request, which allows remote attackers to bypass authentication via crafted HTTP headers.Show less
4Apple
DebianGoogle+1 more
8Chrome
Debian LinuxEnterprise Linux Desktop+5 more
Apr 29, 2026
Sep 19, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Double free vulnerability in libxml2, as used in Google Chrome before 14.0.835.163, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath handling.
9Canonical
DebianGoogle+6 more
15Chrome
CurlDebian Linux+12 more
Apr 29, 2026
Sep 6, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initializa...Show more
The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a "BEAST" attack.Show less
4Apple
DebianGoogle+1 more
8Chrome
Debian LinuxEnterprise Linux Desktop+5 more
Apr 29, 2026
Aug 29, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
Double free vulnerability in libxml2, as used in Google Chrome before 13.0.782.215, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted XPath expression.
3Canonical
DebianIsc
3Debian Linux
DhcpUbuntu Linux
Apr 29, 2026
Aug 15, 2011
N/A· v4
N/A· v3
7.8 HIGH· v2
The server in ISC DHCP 3.x and 4.x before 4.2.2, 3.1-ESV before 3.1-ESV-R3, and 4.1-ESV before 4.1-ESV-R3 allows remote attackers to cause a denial of service (daemon exit) via a crafted BOOTP packet.
3Canonical
DebianIsc
3Debian Linux
DhcpUbuntu Linux
Apr 29, 2026
Aug 15, 2011
N/A· v4
N/A· v3
7.8 HIGH· v2
The server in ISC DHCP 3.x and 4.x before 4.2.2, 3.1-ESV before 3.1-ESV-R3, and 4.1-ESV before 4.1-ESV-R3 allows remote attackers to cause a denial of service (daemon exit) via a crafted DHCP packet.
3Apple
DebianGoogle
5Chrome
Debian LinuxIphone Os+2 more
Apr 29, 2026
Aug 3, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to display box rendering.