← Back

Debian Linux

debian_linux

Vendor: Debian • 10,000 CVEs

CVEs (10,000)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Debian
1Debian Linux
Apr 16, 2026
Dec 23, 2004
N/A· v4
N/A· v3
7.5 HIGH· v2
Sendmail before 8.12.3 on Debian GNU/Linux, when using sasl and sasl-bin, uses a Sendmail configuration script with a fixed username and password, which could allow remote attackers to use Sendmail as an open mail relay...Show more
Sendmail before 8.12.3 on Debian GNU/Linux, when using sasl and sasl-bin, uses a Sendmail configuration script with a fixed username and password, which could allow remote attackers to use Sendmail as an open mail relay and send spam messages.Show less
2Debian
Roaring Penguin
2Debian Linux
Pppoe
Apr 16, 2026
Dec 23, 2004
N/A· v4
N/A· v3
2.1 LOW· v2
Roaring Penguin pppoe (rp-ppoe), if installed or configured to run setuid root contrary to its design, allows local users to overwrite arbitrary files. NOTE: the developer has publicly disputed the claim that this is a...Show more
Roaring Penguin pppoe (rp-ppoe), if installed or configured to run setuid root contrary to its design, allows local users to overwrite arbitrary files. NOTE: the developer has publicly disputed the claim that this is a vulnerability because pppoe "is NOT designed to run setuid-root." Therefore this identifier applies *only* to those configurations and installations under which pppoe is run setuid root despite the developer's warnings.Show less
7Altlinux
ConectivaDebian+4 more
9Alt Linux
Debian LinuxEnterprise Linux+6 more
Apr 16, 2026
Dec 15, 2004
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Multiple vulnerabilities in Konqueror in KDE 3.3.1 and earlier (1) allow access to restricted Java classes via JavaScript and (2) do not properly restrict access to certain Java classes from the Java applet, which allows...Show more
Multiple vulnerabilities in Konqueror in KDE 3.3.1 and earlier (1) allow access to restricted Java classes via JavaScript and (2) do not properly restrict access to certain Java classes from the Java applet, which allows remote attackers to bypass sandbox restrictions and read or write arbitrary files.Show less
7Altlinux
ConectivaDebian+4 more
9Alt Linux
Debian LinuxEnterprise Linux+6 more
Apr 16, 2026
Dec 15, 2004
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Ethereal 0.9.0 through 0.10.7 allows remote attackers to cause a denial of service (CPU consumption) via a certain malformed SMB packet.
7Altlinux
ConectivaDebian+4 more
9Alt Linux
Debian LinuxEnterprise Linux+6 more
Apr 16, 2026
Dec 15, 2004
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unknown vulnerability in the DICOM dissector in Ethereal 0.10.4 through 0.10.7 allows remote attackers to cause a denial of service (application crash).
3Debian
GentooPavuk
3Debian Linux
LinuxPavuk
Apr 16, 2026
Dec 6, 2004
N/A· v4
N/A· v3
7.6 HIGH· v2
Stack-based buffer overflow in pavuk 0.9pl28, 0.9pl27, and possibly other versions allows remote web sites to execute arbitrary code via a long HTTP Location header.
2Debian
Www Sql Project
2Debian Linux
Www Sql
Apr 16, 2026
Dec 6, 2004
N/A· v4
N/A· v3
7.2 HIGH· v2
Buffer overflow in cgi.c in www-sql before 0.5.7 allows local users to execute arbitrary code via a web page that is processed by www-sql.
2Debian
Sup
2Debian Linux
Sup
Apr 16, 2026
Dec 6, 2004
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple format string vulnerabilities in the (1) logquit, (2) logerr, or (3) loginfo functions in Software Upgrade Protocol (SUP) allows remote attackers to execute arbitrary code via format string specifiers in message...Show more
Multiple format string vulnerabilities in the (1) logquit, (2) logerr, or (3) loginfo functions in Software Upgrade Protocol (SUP) allows remote attackers to execute arbitrary code via format string specifiers in messages that are logged by syslog.Show less
2Debian
Mailreader.com
2Debian Linux
Mailreader.com
Apr 16, 2026
Dec 6, 2004
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in nph-mr.cgi in Mailreader.com 2.3.20 through 2.3.31 allows remote attackers to view arbitrary files via .. (dot dot) sequences and a null byte (%00) in the configLanguage parameter.
3Debian
MysqlOracle
3Debian Linux
MysqlMysql
Apr 16, 2026
Nov 3, 2004
N/A· v4
N/A· v3
2.6 LOW· v2
MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows attackers to cause a denial of service (crash or hang) via multiple threads that simultaneously alter MERGE table UNIONs.
2Debian
Oracle
2Debian Linux
Mysql
Apr 16, 2026
Nov 3, 2004
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in the mysql_real_connect function in MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows remote DNS servers to cause a denial of service and possibly execute arbitrary code via a DNS response with a...Show more
Buffer overflow in the mysql_real_connect function in MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows remote DNS servers to cause a denial of service and possibly execute arbitrary code via a DNS response with a large address length (h_length).Show less
3Debian
MysqlOracle
3Debian Linux
MysqlMysql
Apr 16, 2026
Nov 3, 2004
N/A· v4
N/A· v3
7.5 HIGH· v2
MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CREATE/INSERT rights of the original table instead of the target table in an ALTER TABLE RENAME operation, which could all...Show more
MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CREATE/INSERT rights of the original table instead of the target table in an ALTER TABLE RENAME operation, which could allow attackers to conduct unauthorized activities.Show less
3Debian
MitOpenpkg
3Debian Linux
Kerberos 5Openpkg
Apr 16, 2026
Oct 20, 2004
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Double free vulnerabilities in error handling code in krb524d for MIT Kerberos 5 (krb5) 1.2.8 and earlier may allow remote attackers to execute arbitrary code.
2Debian
Kde
2Debian Linux
Kde
Apr 16, 2026
Sep 28, 2004
N/A· v4
7.1 HIGH· v3
4.6 MEDIUM· v2
KDE before 3.3.0 does not properly handle when certain symbolic links point to "stale" locations, which could allow local users to create or truncate arbitrary files.
3Debian
MitRedhat
5Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+2 more
Apr 16, 2026
Sep 28, 2004
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Double free vulnerability in the krb5_rd_cred function for MIT Kerberos 5 (krb5) 1.3.1 and earlier may allow local users to execute arbitrary code.
3Debian
MitRedhat
5Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+2 more
Apr 16, 2026
Sep 28, 2004
N/A· v4
N/A· v3
7.5 HIGH· v2
Double free vulnerabilities in the error handling code for ASN.1 decoders in the (1) Key Distribution Center (KDC) library and (2) client library for MIT Kerberos 5 (krb5) 1.3.4 and earlier may allow remote attackers to...Show more
Double free vulnerabilities in the error handling code for ASN.1 decoders in the (1) Key Distribution Center (KDC) library and (2) client library for MIT Kerberos 5 (krb5) 1.3.4 and earlier may allow remote attackers to execute arbitrary code.Show less
2Debian
Nicolas Boullis
2Debian Linux
Mah Jong
Apr 16, 2026
Sep 28, 2004
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
mah-jong before 1.6.2 allows remote attackers to cause a denial of service (server crash) via a missing argument, which triggers a null pointer dereference.
8Apache
DebianGentoo+5 more
12Debian Linux
Enterprise LinuxEnterprise Linux Desktop+9 more
Apr 16, 2026
Sep 16, 2004
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The mod_dav module in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (child process crash) via a certain sequence of LOCK requests for a location that allows WebDAV authoring access.
3Debian
UserminWebmin
3Debian Linux
UserminWebmin
Apr 16, 2026
Aug 6, 2004
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The account lockout functionality in (1) Webmin 1.140 and (2) Usermin 1.070 does not parse certain character strings, which allows remote attackers to conduct a brute force attack to guess user IDs and passwords.
2Debian
William Deich
2Debian Linux
Super
Apr 16, 2026
Aug 6, 2004
N/A· v4
N/A· v3
7.2 HIGH· v2
Format string vulnerability in super before 3.23 allows local users to execute arbitrary code as root.