← Back

Debian Linux

debian_linux

Vendor: Debian • 10,000 CVEs

CVEs (10,000)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
6Debian
MandrakesoftMicrosoft+3 more
11Debian Linux
Enterprise LinuxEnterprise Linux Desktop+8 more
Apr 16, 2026
Dec 31, 2002
N/A· v4
N/A· v3
4.9 MEDIUM· v2
The Internet Group Management Protocol (IGMP) allows local users to cause a denial of service via an IGMP membership report to a target's Ethernet address instead of the Multicast group address, which causes the target t...Show more
The Internet Group Management Protocol (IGMP) allows local users to cause a denial of service via an IGMP membership report to a target's Ethernet address instead of the Multicast group address, which causes the target to stop sending reports to the router and effectively disconnect the group from the network.Show less
2Apple
Debian
3Cups
Debian LinuxMac Os X
Apr 16, 2026
Dec 26, 2002
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly check the return values of various file and socket operations, which could allow a remote attacker to cause a denial of service (resource exhaust...Show more
Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly check the return values of various file and socket operations, which could allow a remote attacker to cause a denial of service (resource exhaustion) by causing file descriptors to be assigned and not released, as demonstrated by fanta.Show less
3Debian
KthMit
4Debian Linux
Kerberos 5Kth Kerberos 4+1 more
Apr 16, 2026
Nov 4, 2002
N/A· v4
N/A· v3
10.0 HIGH· v2
The kadm_ser_in function in (1) the Kerberos v4compatibility administration daemon (kadmind4) in the MIT Kerberos 5 (krb5) krb5-1.2.6 and earlier, (2) kadmind in KTH Kerberos 4 (eBones) before 1.2.1, and (3) kadmind in K...Show more
The kadm_ser_in function in (1) the Kerberos v4compatibility administration daemon (kadmind4) in the MIT Kerberos 5 (krb5) krb5-1.2.6 and earlier, (2) kadmind in KTH Kerberos 4 (eBones) before 1.2.1, and (3) kadmind in KTH Kerberos 5 (Heimdal) before 0.5.1 when compiled with Kerberos 4 support, does not properly verify the length field of a request, which allows remote attackers to execute arbitrary code via a buffer overflow attack.Show less
3Debian
HpRedhat
3Debian Linux
LinuxSecure Os
Apr 16, 2026
Nov 4, 2002
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Memory leak in ypdb_open in yp_db.c for ypserv before 2.5 in the NIS package 3.9 and earlier allows remote attackers to cause a denial of service (memory consumption) via a large number of requests for a map that does no...Show more
Memory leak in ypdb_open in yp_db.c for ypserv before 2.5 in the NIS package 3.9 and earlier allows remote attackers to cause a denial of service (memory consumption) via a large number of requests for a map that does not exist.Show less
2Apache
Debian
2Debian Linux
Http Server
Apr 16, 2026
Oct 11, 2002
N/A· v4
N/A· v3
7.2 HIGH· v2
The shared memory scoreboard in the HTTP daemon for Apache 1.3.x before 1.3.27 allows any user running as the Apache UID to send a SIGUSR1 signal to any process as root, resulting in a denial of service (process kill) or...Show more
The shared memory scoreboard in the HTTP daemon for Apache 1.3.x before 1.3.27 allows any user running as the Apache UID to send a SIGUSR1 signal to any process as root, resulting in a denial of service (process kill) or possibly other behaviors that would not normally be allowed, by modifying the parent[].pid and parent[].last_rtime segments in the scoreboard.Show less
1Debian
1Debian Linux
Apr 16, 2026
Oct 4, 2002
N/A· v4
N/A· v3
5.0 MEDIUM· v2
in.uucpd UUCP server in Debian GNU/Linux 2.2, and possibly other operating systems, does not properly terminate long strings, which allows remote attackers to cause a denial of service, possibly due to a buffer overflow.
2Debian
Sgi
3Debian Linux
FamIrix
Apr 16, 2026
Sep 5, 2002
N/A· v4
N/A· v3
2.1 LOW· v2
Vulnerability in FAM 2.6.8, 2.6.6, and other versions allows unprivileged users to obtain the names of files whose access is restricted to the root group.
2Apache
Debian
2Debian Linux
Http Server
Apr 16, 2026
Jul 3, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
Apache 1.3 through 1.3.24, and Apache 2.0 through 2.0.36, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a chunk-encoded HTTP request that causes Apache to use an incorrect s...Show more
Apache 1.3 through 1.3.24, and Apache 2.0 through 2.0.36, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a chunk-encoded HTTP request that causes Apache to use an incorrect size.Show less
2Debian
Ethereal
2Debian Linux
Ethereal
Apr 16, 2026
Jun 18, 2002
N/A· v4
7.5 HIGH· v3
7.5 HIGH· v2
SMB dissector in Ethereal 0.9.3 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via malformed packets that cause Ethereal to dereference a NULL pointer.
2Debian
Sudo Project
2Debian Linux
Sudo
Apr 16, 2026
May 16, 2002
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Sudo before 1.6.6 contains an off-by-one error that can result in a heap-based buffer overflow that may allow local users to gain root privileges via special characters in the -p (prompt) argument, which are not properly...Show more
Sudo before 1.6.6 contains an off-by-one error that can result in a heap-based buffer overflow that may allow local users to gain root privileges via special characters in the -p (prompt) argument, which are not properly expanded.Show less
6Debian
FreebsdGnu+3 more
6Debian Linux
FreebsdLinux+3 more
Jul 23, 2026
Mar 8, 2002
N/A· v4
N/A· v3
7.2 HIGH· v2
Buffer overflow in ncurses 5.0, and the ncurses4 compatibility package as used in Red Hat Linux, allows local users to gain privileges, related to "routines for moving the physical cursor and scrolling."
8Caldera
DebianFreebsd+5 more
9Debian Linux
FreebsdLinux+6 more
Apr 16, 2026
Feb 27, 2002
N/A· v4
N/A· v3
7.2 HIGH· v2
Heap corruption vulnerability in the "at" program allows local users to execute arbitrary code via a malformed execution time, which causes at to free the same memory twice.
3Debian
GnuRedhat
3Debian Linux
EnscriptLinux
Apr 16, 2026
Jan 31, 2002
N/A· v4
N/A· v3
3.6 LOW· v2
GNU Enscript 1.6.1 and earlier allows local users to overwrite arbitrary files of the Enscript user via a symlink attack on temporary files.
2Debian
John Bovey
2Debian Linux
Xvt
Apr 16, 2026
Dec 31, 2001
N/A· v4
N/A· v3
7.2 HIGH· v2
Buffer overflow in Xvt 2.1 in Debian Linux 2.2 allows local users to execute arbitrary code via long (1) -name and (2) -T arguments.
2Debian
Redhat
2Debian Linux
Linux
Apr 16, 2026
Dec 21, 2001
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Buffer overflow in glob function of glibc allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a glob pattern that ends in a brace "{" character.
4Conectiva
DebianHtdig+1 more
4Debian Linux
HtdigLinux+1 more
Apr 16, 2026
Dec 6, 2001
N/A· v4
N/A· v3
6.4 MEDIUM· v2
htsearch CGI program in htdig (ht://Dig) 3.1.5 and earlier allows remote attackers to use the -c option to specify an alternate configuration file, which could be used to (1) cause a denial of service (CPU consumption) b...Show more
htsearch CGI program in htdig (ht://Dig) 3.1.5 and earlier allows remote attackers to use the -c option to specify an alternate configuration file, which could be used to (1) cause a denial of service (CPU consumption) by specifying a large file such as /dev/zero, or (2) read arbitrary files by uploading an alternate configuration file that specifies the target file.Show less
2Debian
Suse
2Debian Linux
Suse Linux
Apr 16, 2026
Oct 18, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in Linux xinetd 2.1.8.9pre11-1 and earlier may allow remote attackers to execute arbitrary code via a long ident response, which is not properly handled by the svc_logprint function.
1Debian
1Debian Linux
Apr 16, 2026
Oct 18, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in ftp daemon (ftpd) 6.2 in Debian GNU/Linux allows attackers to cause a denial of service and possibly execute arbitrary code via a long SITE command.
2Debian
Immunix
2Debian Linux
Immunix
Apr 16, 2026
Oct 18, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
LogLine function in klogd in sysklogd 1.3 in various Linux distributions allows an attacker to cause a denial of service (hang) by causing null bytes to be placed in log messages.
4Conectiva
DebianRedhat+1 more
4Debian Linux
EximLinux+1 more
Apr 16, 2026
Sep 20, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Format string vulnerability in exim (3.22-10 in Red Hat, 3.12 in Debian and 3.16 in Conectiva) in batched SMTP mode allows a remote attacker to execute arbitrary code via format strings in SMTP mail headers.