Debian
debian
10,145 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,145)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Heap-based buffer overflow in the ne_rfc1036_parse date parsing function for the neon library (libneon) 0.24.5 and earlier, as used by cadaver before 0.22, allows remote WebDAV servers to execute arbitrary code on the cl...Show more |
Multiple format string vulnerabilities in (1) neon 0.24.4 and earlier, and other products that use neon including (2) Cadaver, (3) Subversion, and (4) OpenOffice, allow remote malicious WebDAV servers to execute arbitrar...Show more |
2Debian Fte2Debian Linux Fte Text EditorApr 16, 2026 May 4, 2004 N/A· v4 N/A· v3 10.0 HIGH· v2 Multiple buffer overflows in vfte, based on FTE, before 0.50, allow local users to execute arbitrary code. |
Multiple vulnerabilities in suidperl 5.6.1 and earlier allow a local user to obtain sensitive information about files for which the user does not have appropriate permissions. |
3Debian MandrakesoftSun5Debian Linux Mandrake LinuxMandrake Linux Corporate Server+2 moreApr 16, 2026 Feb 16, 2004 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Unknown vulnerability in the rwho daemon (rwhod) before 0.17, on little endian architectures, allows remote attackers to cause a denial of service (application crash). |
Buffer overflow in fsp before 2.81.b18 allows remote users to execute arbitrary code. |
Directory traversal vulnerability in fsp before 2.81.b18 allows remote users to access files outside the FSP root directory. |
lintian 1.23 and earlier removes the working directory even if it was not created by lintian, which may allow local users to delete arbitrary files or directories via a symlink attack. |
3Cgi.pm DebianOpenpkg3Cgi.pm Debian LinuxOpenpkgApr 16, 2026 Aug 27, 2003 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in start_form() of CGI.pm allows remote attackers to insert web script via a URL that is fed into the form's action parameter. |
The (1) semi MIME library 1.14.5 and earlier, and (2) wemi 1.14.0 and possibly other versions, allows local users to overwrite arbitrary files via a symlink attack on temporary files. |
Buffer overflow in xaos 3.0-23 and earlier, when running setuid, allows local users to gain root privileges via a long -language option. |
2Debian Michael Jennings2Debian Linux EtermApr 16, 2026 Jul 2, 2003 N/A· v4 N/A· v3 4.6 MEDIUM· v2 Buffer overflow in Eterm 0.9.2 allows local users to gain privileges via a long ETERMPATH environment variable. |
znew in the gzip package allows local users to overwrite arbitrary files via a symlink attack on temporary files. |
Buffer overflow in gPS before 0.10.2 may allow local users to cause a denial of service (SIGSEGV) in rgpsp via long command lines. |
gPS before 1.1.0 does not properly follow the rgpsp connection source acceptation policy as specified in the rgpsp.conf file, which could allow unauthorized remote attackers to connect to rgpsp. |
Multiple buffer overflows in gPS before 1.0.0 allow attackers to cause a denial of service and possibly execute arbitrary code. |
3Debian Falconseye ProjectNethack3Debian Linux FalconseyeNethackApr 16, 2026 Jun 9, 2003 N/A· v4 N/A· v3 4.6 MEDIUM· v2 Buffer overflow in (1) nethack 3.4.0 and earlier, and (2) falconseye 1.9.3 and earlier, which is based on nethack, allows local users to gain privileges via a long -s command line option. |
The Sendmail 8.12.3 package in Debian GNU/Linux 3.0 does not securely create temporary files, which could allow local users to gain additional privileges via (1) expn, (2) checksendmail, or (3) doublebounce.pl. |
run-mailcap in mime-support 3.22 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files. |
Unknown vulnerability in apcupsd before 3.8.6, and 3.10.x before 3.10.5, allows remote attackers to gain root privileges, possibly via format strings in a request to a slave server. |