← Back

Debian

debian

10,147 CVEs • 112 products

Products (112)

Click to collapse
Toggle
Dpkg
dpkg
Shadow
shadow
Lintian
lintian
Apt
apt
Reportbug
reportbug
Horde
horde
Devscripts
devscripts
Mime Support
mime-support
Fsp
fsp
Netkit
netkit
Qpopper
qpopper
Apt Cacher
apt-cacher
Aptlinex
aptlinex
Python Dns
python-dns
Xsabre
xsabre
Cifs Utils
cifs-utils
Dpkg Dev
dpkg-dev
Python Apt
python-apt
Yubiserver
yubiserver
Elvis Tiny
elvis_tiny
Sgml Tools
sgml-tools
Netstd
netstd
Bsdmainutils
bsdmainutils
Tetex Bin
tetex-bin
Debmake
debmake
Bsmtpd
bsmtpd
Sympa
sympa
Ppxp
ppxp
Apt Setup
apt-setup
Backupninja
backupninja
Amaya
amaya
Base Config
base-config
Apache
apache
Gfax
gfax
Reprepro
reprepro
Debian Goodies
debian-goodies
Guilt
guilt
Unp
unp
Tss
tss
Projectl
projectl
Turba
turba
Honeyd Common
honeyd_common
Citadel Server
citadel_server
Feta
feta
Dpkg Cross
dpkg-cross
Myspell
myspell
Newsgate
newsgate
Os Prober
os-prober
Mailscanner
mailscanner
Ltp
ltp
Horde Imp
horde_imp
Nss Ldap
nss-ldap
Libdbd Pg Perl
libdbd-pg-perl
Pyftpd
pyftpd
Mono Debugger
mono-debugger
Tex Common
tex-common
Php5 Common
php5-common
Logol
logol
Devotee
devotee
Apache2
apache2
Cfingerd
cfingerd
Latd
latd
Phpbb3
phpbb3
Txt2man
txt2man
Adequate
adequate
Localepurge
localepurge
Syncevolution
syncevolution
Axiom
axiom
Ppthtml
ppthtml
Xbuffy
xbuffy
Strongswan
strongswan
Kde4libs
kde4libs
Python Imaging
python-imaging
Hivex
hivex
Dbd Firebird
dbd-firebird
Fuse
fuse
Tor
tor
Ftpsync
ftpsync
Most
most
Tin
tin
Crossroads
crossroads
Tmpreaper
tmpreaper
Cron
cron
Overkill
overkill
Duplicity
duplicity

CVEs (10,147)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Debian
Mahara
2Debian Linux
Mahara
Nov 21, 2024
Dec 17, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.4.x before 1.4.3 and 1.5.x before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) javascript innerHTML as use...Show more
Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.4.x before 1.4.3 and 1.5.x before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) javascript innerHTML as used when generating login forms, (2) links or (3) resources URLs, and (4) the Display name in a user profile.Show less
4Canonical
DebianLinux+1 more
13Active Iq Unified Manager
Aff A400 FirmwareAff A700s Firmware+10 more
Jun 17, 2026
Dec 17, 2019
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image and performing some operations can cause slab-out-of-bounds write access in __btrfs_map_block in fs/btrfs/volumes.c, because a value of 1 for the numb...Show more
In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image and performing some operations can cause slab-out-of-bounds write access in __btrfs_map_block in fs/btrfs/volumes.c, because a value of 1 for the number of data stripes is mishandled.Show less
4Canonical
DebianLinux+1 more
13Active Iq Unified Manager
Aff A400 FirmwareAff A700s Firmware+10 more
Jun 17, 2026
Dec 17, 2019
N/A· v4
5.5 MEDIUM· v3
7.1 HIGH· v2
In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in __mutex_lock in kernel/locking/mutex.c. This is rela...Show more
In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in __mutex_lock in kernel/locking/mutex.c. This is related to mutex_can_spin_on_owner in kernel/locking/mutex.c, __btrfs_qgroup_free_meta in fs/btrfs/qgroup.c, and btrfs_insert_delayed_items in fs/btrfs/delayed-inode.c.Show less
3Canonical
DebianSpip
3Debian Linux
SpipUbuntu Linux
Jun 17, 2026
Dec 17, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
_core_/plugins/medias in SPIP 3.2.x before 3.2.7 allows remote authenticated authors to inject content into the database.
3Debian
Excon ProjectOpensuse
4Backports Sle
Debian LinuxExcon+1 more
Jul 28, 2026
Dec 16, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
In RubyGem excon before 0.71.0, there was a race condition around persistent connections, where a connection which is interrupted (such as by a timeout) would leave data on the socket. Subsequent requests would then read...Show more
In RubyGem excon before 0.71.0, there was a race condition around persistent connections, where a connection which is interrupted (such as by a timeout) would leave data on the socket. Subsequent requests would then read this data, returning content from the previous response. The race condition window appears to be short, and it would be difficult to purposefully exploit this.Show less
2Debian
Nic
2Debian Linux
Knot Resolver
Jun 17, 2026
Dec 16, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
knot-resolver before version 4.3.0 is vulnerable to denial of service through high CPU utilization. DNS replies with very many resource records might be processed very inefficiently, in extreme cases taking even several...Show more
knot-resolver before version 4.3.0 is vulnerable to denial of service through high CPU utilization. DNS replies with very many resource records might be processed very inefficiently, in extreme cases taking even several CPU seconds for each such uncached message. For example, a few thousand A records can be squashed into one DNS message (limit is 64kB).Show less
4Canonical
CyrusDebian+1 more
4Debian Linux
FedoraImap+1 more
Jun 17, 2026
Dec 16, 2019
N/A· v4
6.5 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in Cyrus IMAP before 2.5.15, 3.0.x before 3.0.13, and 3.1.x through 3.1.8. If sieve script uploading is allowed (3.x) or certain non-default sieve options are enabled (2.x), a user with a mail acc...Show more
An issue was discovered in Cyrus IMAP before 2.5.15, 3.0.x before 3.0.13, and 3.1.x through 3.1.8. If sieve script uploading is allowed (3.x) or certain non-default sieve options are enabled (2.x), a user with a mail account on the service can use a sieve script containing a fileinto directive to create any mailbox with administrator privileges, because of folder mishandling in autosieve_createfolder() in imap/lmtp_sieve.c.Show less
2Debian
Requests Kerberos Project
2Debian Linux
Requests Kerberos
Nov 21, 2024
Dec 15, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
python-requests-Kerberos through 0.5 does not handle mutual authentication
2Debian
Imagemagick
2Debian Linux
Imagemagick
Nov 21, 2024
Dec 15, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
imagemagick 6.8.9.6 has remote DOS via infinite loop
2Debian
Zend
2Debian Linux
Zend Framework
Nov 21, 2024
Dec 15, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
ZF2014-03 has a potential cross site scripting vector in multiple view helpers
3Debian
FedoraprojectXfig Project
3Debian Linux
FedoraFig2dev
Jun 17, 2026
Dec 15, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
read_colordef in read.c in Xfig fig2dev 3.2.7b has an out-of-bounds write.
2Debian
Opensuse
3Debian Linux
DuplicityOpensuse
Nov 21, 2024
Dec 13, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
duplicity 0.6.24 has improper verification of SSL certificates
3Debian
OpensusePen Project
3Debian Linux
OpensusePen
Nov 21, 2024
Dec 13, 2019
N/A· v4
4.4 MEDIUM· v3
4.6 MEDIUM· v2
Pen 0.18.0 has Insecure Temporary File Creation vulnerabilities
3Debian
PuppetRedhat
3Debian Linux
Marionette CollectiveOpenshift
Nov 21, 2024
Dec 13, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
mcollective has a default password set at install
2Apache
Debian
2Debian Linux
Spamassassin
Jun 17, 2026
Dec 12, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Apache SpamAssassin before 3.4.3, a message can be crafted in a way to use excessive resources. Upgrading to SA 3.4.3 as soon as possible is the recommended fix but details will not be shared publicly.
2Apache
Debian
2Debian Linux
Spamassassin
Nov 21, 2024
Dec 12, 2019
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
In Apache SpamAssassin before 3.4.3, nefarious CF files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA...Show more
In Apache SpamAssassin before 3.4.3, nefarious CF files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA 3.4.3, we recommend that users should only use update channels or 3rd party .cf files from trusted places.Show less
2Davical
Debian
2Davical
Debian Linux
Jun 17, 2026
Dec 12, 2019
N/A· v4
9.3 CRITICAL· v3
4.3 MEDIUM· v2
A reflected XSS issue was discovered in DAViCal through 1.1.8. It echoes the action parameter without encoding. If a user visits an attacker-supplied link, the attacker can view all data the attacked user can view, as we...Show more
A reflected XSS issue was discovered in DAViCal through 1.1.8. It echoes the action parameter without encoding. If a user visits an attacker-supplied link, the attacker can view all data the attacked user can view, as well as perform all actions in the name of the user. If the user is an administrator, the attacker can for example add a new admin user to gain full access to the application.Show less
3Cacti
DebianOpensuse
3Cacti
Debian LinuxLeap
Jun 17, 2026
Dec 12, 2019
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
Cacti through 1.2.7 is affected by multiple instances of lib/functions.php unsafe deserialization of user-controlled data to populate arrays. An authenticated attacker could use this to influence object data values and c...Show more
Cacti through 1.2.7 is affected by multiple instances of lib/functions.php unsafe deserialization of user-controlled data to populate arrays. An authenticated attacker could use this to influence object data values and control actions taken by Cacti or potentially cause memory corruption in the PHP module.Show less
3Canonical
DebianSysstat Project
3Debian Linux
SysstatUbuntu Linux
Jun 17, 2026
Dec 11, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
sysstat through 12.2.0 has a double free in check_file_actlst in sa_common.c.
4Debian
FedoraprojectOpensuse+1 more
4Debian Linux
FedoraLeap+1 more
Jun 17, 2026
Dec 11, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Xen through 4.12.x allowing x86 HVM/PVH guest OS users to cause a denial of service (guest OS crash) because VMX VMEntry checks mishandle a certain case. Please see XSA-260 for background on th...Show more
An issue was discovered in Xen through 4.12.x allowing x86 HVM/PVH guest OS users to cause a denial of service (guest OS crash) because VMX VMEntry checks mishandle a certain case. Please see XSA-260 for background on the MovSS shadow. Please see XSA-156 for background on the need for #DB interception. The VMX VMEntry checks do not like the exact combination of state which occurs when #DB in intercepted, Single Stepping is active, and blocked by STI/MovSS is active, despite this being a legitimate state to be in. The resulting VMEntry failure is fatal to the guest. HVM/PVH guest userspace code may be able to crash the guest, resulting in a guest Denial of Service. All versions of Xen are affected. Only systems supporting VMX hardware virtual extensions (Intel, Cyrix, or Zhaoxin CPUs) are affected. Arm and AMD systems are unaffected. Only HVM/PVH guests are affected. PV guests cannot leverage the vulnerability.Show less