← Back

Debian Linux

debian_linux

Vendor: Debian • 10,000 CVEs

CVEs (10,000)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
6Debian
GentooMidnight Commander+3 more
8Debian Linux
Enterprise LinuxLinux+5 more
Apr 16, 2026
Apr 14, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple buffer overflows in Midnight Commander (mc) 4.5.55 and earlier allow remote attackers to have an unknown impact.
6Debian
GentooMidnight Commander+3 more
8Debian Linux
Enterprise LinuxLinux+5 more
Apr 16, 2026
Apr 14, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple format string vulnerabilities in Midnight Commander (mc) 4.5.55 and earlier allow remote attackers to have an unknown impact.
3Bnc
DebianGentoo
3Bnc
Debian LinuxLinux
Apr 16, 2026
Mar 1, 2005
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in the getnickuserhost function in BNC 2.8.9, and possibly other versions, allows remote IRC servers to execute arbitrary code via an IRC server response that contains many (1) ! (exclamation) or (2) @ (a...Show more
Buffer overflow in the getnickuserhost function in BNC 2.8.9, and possibly other versions, allows remote IRC servers to execute arbitrary code via an IRC server response that contains many (1) ! (exclamation) or (2) @ (at sign) characters.Show less
5Debian
MandrakesoftTodd Miller+2 more
7Debian Linux
Mandrake LinuxMandrake Linux Corporate Server+4 more
Apr 16, 2026
Mar 1, 2005
N/A· v4
N/A· v3
7.2 HIGH· v2
sudo before 1.6.8p2 allows local users to execute arbitrary commands by using "()" style environment variables to create functions that have the same name as any program within the bash script that is called without usin...Show more
sudo before 1.6.8p2 allows local users to execute arbitrary commands by using "()" style environment variables to create functions that have the same name as any program within the bash script that is called without using the program's full pathname.Show less
3Arjsoftware
DebianGentoo
3Debian Linux
LinuxUnarj
Apr 16, 2026
Mar 1, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in the -x (extract) command line option in unarj allows remote attackers to overwrite arbitrary files via an arj archive with filenames that contain .. (dot dot) sequences.
4Debian
LinuxRedhat+1 more
4Debian Linux
Fedora CoreLinux Kernel+1 more
Apr 16, 2026
Mar 1, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
Iptables before 1.2.11, under certain conditions, does not properly load the required modules at system startup, which causes the firewall rules to fail to load and protect the system from remote attackers.
4Debian
GentooImagemagick+1 more
4Debian Linux
ImagemagickLinux+1 more
Apr 16, 2026
Feb 9, 2005
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in the EXIF parsing routine in ImageMagick before 6.1.0 allows remote attackers to execute arbitrary code via a certain image file.
3Angus Mackay
DebianGentoo
3Debian Linux
Ez IpupdateLinux
Apr 16, 2026
Feb 9, 2005
N/A· v4
N/A· v3
10.0 HIGH· v2
Format string vulnerability in ez-ipupdate.c for ez-ipupdate 3.0.10 through 3.0.11b8, when running in daemon mode with certain service types in use, allows remote servers to execute arbitrary code.
2Debian
Zinf
2Debian Linux
Zinf
Apr 16, 2026
Feb 9, 2005
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in Zinf 2.2.1 on Windows, and other older versions for Linux, allows remote attackers or local users to execute arbitrary code via certain values in a .pls file.
11Debian
Easy Software ProductsGentoo+8 more
16Cups
Debian LinuxEnterprise Linux+13 more
Apr 16, 2026
Jan 27, 2005
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilit...Show more
Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0888.Show less
11Debian
Easy Software ProductsGentoo+8 more
16Cups
Debian LinuxEnterprise Linux+13 more
Apr 16, 2026
Jan 27, 2005
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code,...Show more
Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0889.Show less
1Debian
1Debian Linux
Apr 16, 2026
Jan 26, 2005
N/A· v4
N/A· v3
2.1 LOW· v2
Debian GNU/Linux 3.0 installs the libpam-radius-auth package with the pam_radius_auth.conf set to be world-readable, which allows local users to obtain sensitive information.
2Debian
Gnome
2Debian Linux
Evolution
Apr 16, 2026
Jan 24, 2005
N/A· v4
9.8 CRITICAL· v3
7.2 HIGH· v2
Integer overflow in camel-lock-helper in Evolution 2.0.2 and earlier allows local users or remote malicious POP3 servers to execute arbitrary code via a length value of -1, which leads to a zero byte memory allocation an...Show more
Integer overflow in camel-lock-helper in Evolution 2.0.2 and earlier allows local users or remote malicious POP3 servers to execute arbitrary code via a length value of -1, which leads to a zero byte memory allocation and a buffer overflow.Show less
2Debian
Zgv
3Debian Linux
Xzgv Image ViewerZgv Image Viewer
Apr 16, 2026
Jan 10, 2005
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple integer overflows in (1) readbmp.c, (2) readgif.c, (3) readgif.c, (4) readmrf.c, (5) readpcx.c, (6) readpng.c,(7) readpnm.c, (8) readprf.c, (9) readtiff.c, (10) readxbm.c, (11) readxpm.c in zgv 5.8 allow remote...Show more
Multiple integer overflows in (1) readbmp.c, (2) readgif.c, (3) readgif.c, (4) readmrf.c, (5) readpcx.c, (6) readpng.c,(7) readpnm.c, (8) readprf.c, (9) readtiff.c, (10) readxbm.c, (11) readxpm.c in zgv 5.8 allow remote attackers to execute arbitrary code via certain image headers that cause calculations to be overflowed and small buffers to be allocated, leading to buffer overflows. NOTE: CVE-2004-0994 and CVE-2004-1095 identify sets of bugs that only partially overlap, despite having the same developer. Therefore, they should be regarded as distinct.Show less
2Atari800
Debian
2Atari800
Debian Linux
Apr 16, 2026
Jan 10, 2005
N/A· v4
N/A· v3
7.2 HIGH· v2
Multiple buffer overflows in the RtConfigLoad function in rt-config.c for Atari800 before 1.3.4 allow local users to execute arbitrary code via large values in the configuration file.
4Debian
MandrakesoftNfs+1 more
6Debian Linux
Enterprise LinuxEnterprise Linux Desktop+3 more
Apr 16, 2026
Jan 10, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
statd in nfs-utils 1.257 and earlier does not ignore the SIGPIPE signal, which allows remote attackers to cause a denial of service (server process crash) via a TCP connection that is prematurely terminated.
4Cscope
DebianGentoo+1 more
4Cscope
Debian LinuxLinux+1 more
Apr 16, 2026
Jan 10, 2005
N/A· v4
N/A· v3
2.1 LOW· v2
main.c in cscope 15-4 and 15-5 creates temporary files with predictable filenames, which allows local users to overwrite arbitrary files via a symlink attack.
2Debian
Zgv
3Debian Linux
Xzgv Image ViewerZgv Image Viewer
Apr 16, 2026
Jan 10, 2005
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple integer overflows in xzgv 0.8 and earlier allow remote attackers to execute arbitrary code via images with large width and height values, which trigger a heap-based buffer overflow, as demonstrated in the read_p...Show more
Multiple integer overflows in xzgv 0.8 and earlier allow remote attackers to execute arbitrary code via images with large width and height values, which trigger a heap-based buffer overflow, as demonstrated in the read_prf_file function in readprf.c. NOTE: CVE-2004-0994 and CVE-2004-1095 identify sets of bugs that only partially overlap, despite having the same developer. Therefore, they should be regarded as distinct.Show less
2Debian
Viewcvs
2Debian Linux
Viewcvs
Apr 16, 2026
Jan 10, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Multiple unknown vulnerabilities in viewcvs before 0.9.2, when exporting a repository as a tar archive, does not properly implement the hide_cvsroot and forbidden settings, which could allow remote attackers to gain sens...Show more
Multiple unknown vulnerabilities in viewcvs before 0.9.2, when exporting a repository as a tar archive, does not properly implement the hide_cvsroot and forbidden settings, which could allow remote attackers to gain sensitive information.Show less
2Debian
Dgen
2Debian Linux
Emulator
Apr 16, 2026
Jan 10, 2005
N/A· v4
N/A· v3
2.1 LOW· v2
romload.c in DGen Emulator 1.23 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files during decompression of (1) gzip or (2) bzip ROM files.