Debian
debian
10,149 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,149)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Conectiva DebianImmunix+1 more4Debian Linux ImmunixLinux+1 moreApr 16, 2026 Mar 26, 2001 N/A· v4 N/A· v3 2.1 LOW· v2 glibc 2.1.9x and earlier does not properly clear the RESOLV_HOST_CONF, HOSTALIASES, or RES_OPTIONS environmental variables when executing setuid/setgid programs, which could allow local users to read arbitrary files. |
2Apache Debian2Debian Linux Http ServerApr 16, 2026 Mar 12, 2001 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview index.html file via an HTTP request for a path that contains many / (slash) characters, which causes t...Show more |
5Caldera DebianImmunix+2 more7Debian Linux ImmunixLinux+4 moreApr 16, 2026 Mar 12, 2001 N/A· v4 N/A· v3 1.2 LOW· v2 inn 2.2.3 allows local users to overwrite arbitrary files via a symlink attack in some configurations. |
4Debian ImmunixMandrakesoft+1 more5Debian Linux ImmunixLinux+2 moreApr 16, 2026 Mar 12, 2001 N/A· v4 N/A· v3 1.2 LOW· v2 privatepw program in wu-ftpd before 2.6.1-6 allows local users to overwrite arbitrary files via a symlink attack. |
4Conectiva DebianMandrakesoft+1 more4Debian Linux LinuxMandrake Linux+1 moreApr 16, 2026 Mar 12, 2001 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Memory leak in ProFTPd 1.2.0rc2 allows remote attackers to cause a denial of service via a series of USER commands, and possibly SIZE commands if the server has been improperly installed. |
htpasswd and htdigest in Apache 2.0a9, 1.3.14, and others allows local users to overwrite arbitrary files via a symlink attack. |
6Conectiva DebianFreebsd+3 more7Debian Linux FreebsdLinux+4 moreApr 16, 2026 Mar 12, 2001 N/A· v4 N/A· v3 7.2 HIGH· v2 Zope before 2.2.4 does not properly compute local roles, which could allow users to bypass specified access restrictions and gain privileges. |
3Debian ExmhMandrakesoft4Debian Linux ExmhMandrake Linux+1 moreApr 16, 2026 Mar 12, 2001 N/A· v4 N/A· v3 1.2 LOW· v2 exmh 2.2 and earlier allows local users to overwrite arbitrary files via a symlink attack on the exmhErrorMsg temporary file. |
2Debian Sam Lantinga2Debian Linux SplitvtApr 16, 2026 Mar 12, 2001 N/A· v4 N/A· v3 7.2 HIGH· v2 Multiple buffer overflows in splitvt before 1.6.5 allow local users to execute arbitrary commands. |
2Debian Sam Lantinga2Debian Linux SplitvtApr 16, 2026 Mar 12, 2001 N/A· v4 N/A· v3 7.2 HIGH· v2 Format string vulnerability in splitvt before 1.6.5 allows local users to execute arbitrary commands via the -rcfile command line argument. |
5Debian DigitalNetbsd+2 more5Debian Linux LinuxNetbsd+2 moreApr 16, 2026 Mar 12, 2001 N/A· v4 N/A· v3 5.0 MEDIUM· v2 traceroute in NetBSD 1.3.3 and Linux systems allows local unprivileged users to modify the source address of the packets, which could be used in spoofing attacks. |
5Debian DigitalNetbsd+2 more5Debian Linux LinuxNetbsd+2 moreApr 16, 2026 Mar 12, 2001 N/A· v4 N/A· v3 5.0 MEDIUM· v2 traceroute in NetBSD 1.3.3 and Linux systems allows local users to flood other systems by providing traceroute with a large waittime (-w) option, which is not parsed properly and sets the time delay for sending packets t...Show more |
dialog before 0.9a-20000118-3bis in Debian GNU/Linux allows local users to overwrite arbitrary files via a symlink attack. |
elvis-tiny before 1.4-10 in Debian GNU/Linux, and possibly other Linux operating systems, allows local users to overwrite files of other users via a symlink attack. |
fshd (fsh daemon) in Debian GNU/Linux allows local users to overwrite files of other users via a symlink attack. |
named in BIND 8.2 through 8.2.2-P6 allows remote attackers to cause a denial of service by sending an SRV record to the server, aka the "srv bug." |
5Debian MandrakesoftRedhat+2 more5Debian Linux LinuxMandrake Linux+2 moreApr 16, 2026 Nov 14, 2000 N/A· v4 N/A· v3 7.2 HIGH· v2 Kernel logging daemon (klogd) in Linux does not properly cleanse user-injected format strings, which allows local users to gain root privileges by triggering malformed kernel messages. |
13Caldera ConectivaDebian+10 more16Aix Debian LinuxImmunix+13 moreApr 16, 2026 Nov 14, 2000 N/A· v4 N/A· v3 10.0 HIGH· v2 Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen. |
5Conectiva DebianRedhat+2 more5Debian Linux LinuxLinux+2 moreApr 16, 2026 Jul 16, 2000 N/A· v4 N/A· v3 10.0 HIGH· v2 rpc.statd in the nfs-utils package in various Linux distributions does not properly cleanse untrusted format strings, which allows remote attackers to gain root privileges. |
Buffer overflow in Canna input system allows remote attackers to execute arbitrary commands via an SR_INIT command with a long user name or group name. |