← Back

Debian Linux

debian_linux

Vendor: Debian • 10,000 CVEs

CVEs (10,000)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Debian
Ettercap
2Debian Linux
Ettercap
Apr 16, 2026
May 31, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
Format string vulnerability in the curses_msg function in the Ncurses interface (ec_curses.c) for Ettercap before 0.7.3 allows remote attackers to execute arbitrary code.
4Apple
BzipCanonical+1 more
4Bzip2
Debian LinuxMac Os X+1 more
Apr 16, 2026
May 19, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
bzip2 allows remote attackers to cause a denial of service (hard drive consumption) via a crafted bzip2 file that causes an infinite loop (a.k.a "decompression bomb").
3Canonical
DebianQmail Project
3Debian Linux
QmailUbuntu Linux
Apr 16, 2026
May 11, 2005
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Integer overflow in the stralloc_readyplus function in qmail, when running on 64 bit platforms with a large amount of virtual memory, allows remote attackers to cause a denial of service and possibly execute arbitrary co...Show more
Integer overflow in the stralloc_readyplus function in qmail, when running on 64 bit platforms with a large amount of virtual memory, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large SMTP request.Show less
3Canonical
DebianGnu
3Cpio
Debian LinuxUbuntu Linux
Apr 16, 2026
May 2, 2005
N/A· v4
4.7 MEDIUM· v3
3.7 LOW· v2
Race condition in cpio 2.6 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by cpio after the decompre...Show more
Race condition in cpio 2.6 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by cpio after the decompression is complete.Show less
2Debian
Squid Cache
2Debian Linux
Squid
Apr 16, 2026
May 2, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in wccp.c in Squid 2.5 before 2.5.STABLE7 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long WCCP packet, which is processed by a recvfrom function call th...Show more
Buffer overflow in wccp.c in Squid 2.5 before 2.5.STABLE7 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long WCCP packet, which is processed by a recvfrom function call that uses an incorrect length parameter.Show less
3Debian
KdeRedhat
5Debian Linux
Enterprise LinuxEnterprise Linux Desktop+2 more
Apr 16, 2026
May 2, 2005
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The KDE screen saver in KDE before 3.0.5 does not properly check the return value from a certain function call, which allows attackers with physical access to cause a crash and access the desktop session.
4Debian
GentooRedhat+1 more
5Debian Linux
Enterprise LinuxEnterprise Linux Desktop+2 more
Apr 16, 2026
May 2, 2005
N/A· v4
N/A· v3
2.1 LOW· v2
The DBI library (libdbi-perl) for Perl allows local users to overwrite arbitrary files via a symlink attack on a temporary PID file.
1Debian
1Debian Linux
Apr 16, 2026
May 2, 2005
N/A· v4
N/A· v3
7.2 HIGH· v2
Multiple buffer overflows in the XView library 3.2 may allow local users to execute arbitrary code via setuid applications that use the library.
6Debian
GentooGraphicsmagick+3 more
6Debian Linux
GraphicsmagickImagemagick+3 more
Apr 16, 2026
May 2, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
Heap-based buffer overflow in psd.c for ImageMagick 6.1.0, 6.1.7, and possibly earlier versions allows remote attackers to execute arbitrary code via a .PSD image file with a large number of layers.
15Ascii
CstexDebian+12 more
22Advanced Linux Environment
CstetexCups+19 more
Apr 16, 2026
Apr 27, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the origin...Show more
The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities.Show less
1Debian
2Debian Linux
Toolchain Source
Apr 16, 2026
Apr 27, 2005
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The tpkg-* scripts in the toolchain-source 3.0.4 package on Debian GNU/Linux 3.0 allow local users to overwrite arbitrary files via a symlink attack on temporary files.
3Debian
MariadbOracle
3Debian Linux
MariadbMysql
Apr 16, 2026
Apr 14, 2005
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The mysqlaccess script in MySQL 4.0.23 and earlier, 4.1.x before 4.1.10, 5.0.x before 5.0.3, and other versions including 3.x, allows local users to overwrite arbitrary files or read temporary files via a symlink attack...Show more
The mysqlaccess script in MySQL 4.0.23 and earlier, 4.1.x before 4.1.10, 5.0.x before 5.0.3, and other versions including 3.x, allows local users to overwrite arbitrary files or read temporary files via a symlink attack on temporary files.Show less
6Debian
GentooMidnight Commander+3 more
8Debian Linux
Enterprise LinuxLinux+5 more
Apr 16, 2026
Apr 14, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer underflow in extfs.c in Midnight Commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code.
6Debian
GentooMidnight Commander+3 more
8Debian Linux
Enterprise LinuxLinux+5 more
Apr 16, 2026
Apr 14, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
fish.c in midnight commander allows remote attackers to execute arbitrary programs via "insecure filename quoting," possibly using shell metacharacters.
6Debian
GentooMidnight Commander+3 more
8Debian Linux
Enterprise LinuxLinux+5 more
Apr 16, 2026
Apr 14, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
direntry.c in Midnight Commander (mc) 4.5.55 and earlier allows attackers to cause a denial of service by "manipulating non-existing file handles."
6Debian
GentooMidnight Commander+3 more
8Debian Linux
Enterprise LinuxLinux+5 more
Apr 16, 2026
Apr 14, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service via "use of already freed memory."
6Debian
GentooMidnight Commander+3 more
8Debian Linux
Enterprise LinuxLinux+5 more
Apr 16, 2026
Apr 14, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service by causing mc to free unallocated memory.
6Debian
GentooMidnight Commander+3 more
8Debian Linux
Enterprise LinuxLinux+5 more
Apr 16, 2026
Apr 14, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service by triggering a null dereference.
6Debian
GentooMidnight Commander+3 more
8Debian Linux
Enterprise LinuxLinux+5 more
Apr 16, 2026
Apr 14, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service via "a corrupt section header."
6Debian
GentooMidnight Commander+3 more
8Debian Linux
Enterprise LinuxLinux+5 more
Apr 16, 2026
Apr 14, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service (infinite loop) via unknown attack vectors.