← Back

Debian

debian

10,147 CVEs • 112 products

Products (112)

Click to collapse
Toggle
Dpkg
dpkg
Shadow
shadow
Lintian
lintian
Apt
apt
Reportbug
reportbug
Horde
horde
Devscripts
devscripts
Mime Support
mime-support
Fsp
fsp
Netkit
netkit
Qpopper
qpopper
Apt Cacher
apt-cacher
Aptlinex
aptlinex
Python Dns
python-dns
Xsabre
xsabre
Cifs Utils
cifs-utils
Dpkg Dev
dpkg-dev
Python Apt
python-apt
Yubiserver
yubiserver
Elvis Tiny
elvis_tiny
Sgml Tools
sgml-tools
Netstd
netstd
Bsdmainutils
bsdmainutils
Tetex Bin
tetex-bin
Debmake
debmake
Bsmtpd
bsmtpd
Sympa
sympa
Ppxp
ppxp
Apt Setup
apt-setup
Backupninja
backupninja
Amaya
amaya
Base Config
base-config
Apache
apache
Gfax
gfax
Reprepro
reprepro
Debian Goodies
debian-goodies
Guilt
guilt
Unp
unp
Tss
tss
Projectl
projectl
Turba
turba
Honeyd Common
honeyd_common
Citadel Server
citadel_server
Feta
feta
Dpkg Cross
dpkg-cross
Myspell
myspell
Newsgate
newsgate
Os Prober
os-prober
Mailscanner
mailscanner
Ltp
ltp
Horde Imp
horde_imp
Nss Ldap
nss-ldap
Libdbd Pg Perl
libdbd-pg-perl
Pyftpd
pyftpd
Mono Debugger
mono-debugger
Tex Common
tex-common
Php5 Common
php5-common
Logol
logol
Devotee
devotee
Apache2
apache2
Cfingerd
cfingerd
Latd
latd
Phpbb3
phpbb3
Txt2man
txt2man
Adequate
adequate
Localepurge
localepurge
Syncevolution
syncevolution
Axiom
axiom
Ppthtml
ppthtml
Xbuffy
xbuffy
Strongswan
strongswan
Kde4libs
kde4libs
Python Imaging
python-imaging
Hivex
hivex
Dbd Firebird
dbd-firebird
Fuse
fuse
Tor
tor
Ftpsync
ftpsync
Most
most
Tin
tin
Crossroads
crossroads
Tmpreaper
tmpreaper
Cron
cron
Overkill
overkill
Duplicity
duplicity

CVEs (10,147)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Debian
Polipo Project
2Debian Linux
Polipo
Nov 21, 2024
Nov 26, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Polipo before 1.0.4.1 suffers from a DoD vulnerability via specially-crafted HTTP POST / PUT request.
1Debian
2Advanced Package Tool
Debian Linux
Nov 21, 2024
Nov 26, 2019
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
It was found that apt-key in apt, all versions, do not correctly validate gpg keys with the master keyring, leading to a potential man-in-the-middle attack.
3Canonical
DebianSuse
3Cloud Init
Debian LinuxLinux Enterprise Server
Nov 21, 2024
Nov 25, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
An privilege elevation vulnerability exists in Cloud-init before 0.7.0 when requests to an untrusted system are submitted for EC2 instance data.
5Canonical
DebianFedoraproject+2 more
5Debian Linux
FedoraOniguruma+2 more
Jun 17, 2026
Nov 25, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Oniguruma through 6.9.3, as used in PHP 7.3.x and other products, has a heap-based buffer over-read in str_lower_case_match in regexec.c.
2Debian
Gnu
2Debian Linux
Patch
Nov 21, 2024
Nov 25, 2019
N/A· v4
7.5 HIGH· v3
6.4 MEDIUM· v2
A Directory Traversal vulnerability exists in the GNU patch before 2.7.4. A remote attacker can write to arbitrary files via a symlink attack in a patch file. NOTE: this issue exists because of an incomplete fix for CVE-...Show more
A Directory Traversal vulnerability exists in the GNU patch before 2.7.4. A remote attacker can write to arbitrary files via a symlink attack in a patch file. NOTE: this issue exists because of an incomplete fix for CVE-2015-1196.Show less
4Debian
FedoraprojectLibuser Project+1 more
4Debian Linux
Enterprise LinuxFedora+1 more
Jan 23, 2026
Nov 25, 2019
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
libuser has information disclosure when moving user's home directory
3Debian
QuaggaRedhat
3Debian Linux
Enterprise LinuxQuagga
Nov 21, 2024
Nov 25, 2019
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
quagga (ospf6d) 0.99.21 has a DoS flaw in the way the ospf6d daemon performs routes removal
5Broadcom
DebianFedoraproject+2 more
5Debian Linux
FedoraOpenstack+2 more
Jun 17, 2026
Nov 23, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain a web management plugin that is v...Show more
Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain a web management plugin that is vulnerable to a denial of service attack. The "X-Reason" HTTP Header can be leveraged to insert a malicious Erlang format string that will expand and consume the heap, resulting in the server crashing.Show less
2Debian
Vanderbilt
2Adaptive Communication Environment
Debian Linux
Nov 21, 2024
Nov 22, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
generate_doygen.pl in ace before 6.2.7+dfsg-2 creates predictable file names in the /tmp directory which allows attackers to gain elevated privileges.
2Call Cc
Debian
2Chicken
Debian Linux
Nov 21, 2024
Nov 22, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Buffer overflow in CHICKEN 4.9.0 and 4.9.0.1 may allow remote attackers to execute arbitrary code via the 'select' function.
2Debian
Digium
3Asterisk
Certified AsteriskDebian Linux
Jun 17, 2026
Nov 22, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
An issue was discovered in manager.c in Sangoma Asterisk through 13.x, 16.x, 17.x and Certified Asterisk 13.21 through 13.21-cert4. A remote authenticated Asterisk Manager Interface (AMI) user without system authorizatio...Show more
An issue was discovered in manager.c in Sangoma Asterisk through 13.x, 16.x, 17.x and Certified Asterisk 13.21 through 13.21-cert4. A remote authenticated Asterisk Manager Interface (AMI) user without system authorization could use a specially crafted Originate AMI request to execute arbitrary system commands.Show less
2Debian
Digium
3Asterisk
Certified AsteriskDebian Linux
Jun 17, 2026
Nov 22, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in res_pjsip_t38.c in Sangoma Asterisk through 13.x and Certified Asterisk through 13.21-x. If it receives a re-invite initiating T.38 faxing and has a port of 0 and no c line in the SDP, a NULL p...Show more
An issue was discovered in res_pjsip_t38.c in Sangoma Asterisk through 13.x and Certified Asterisk through 13.21-x. If it receives a re-invite initiating T.38 faxing and has a port of 0 and no c line in the SDP, a NULL pointer dereference and crash will occur. This is different from CVE-2019-18940.Show less
2Debian
Digium
3Asterisk
Certified AsteriskDebian Linux
Jun 17, 2026
Nov 22, 2019
N/A· v4
6.5 MEDIUM· v3
5.8 MEDIUM· v2
An issue was discovered in channels/chan_sip.c in Sangoma Asterisk 13.x before 13.29.2, 16.x before 16.6.2, and 17.x before 17.0.1, and Certified Asterisk 13.21 before cert5. A SIP request can be sent to Asterisk that ca...Show more
An issue was discovered in channels/chan_sip.c in Sangoma Asterisk 13.x before 13.29.2, 16.x before 16.6.2, and 17.x before 17.0.1, and Certified Asterisk 13.21 before cert5. A SIP request can be sent to Asterisk that can change a SIP peer's IP address. A REGISTER does not need to occur, and calls can be hijacked as a result. The only thing that needs to be known is the peer's name; authentication details such as passwords do not need to be known. This vulnerability is only exploitable when the nat option is set to the default, or auto_force_rport.Show less
2Debian
Postfix Admin Project
2Debian Linux
Postfix Admin
Nov 21, 2024
Nov 22, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
PostfixAdmin 2.3.4 has multiple XSS vulnerabilities
4Debian
FedoraprojectRedhat+1 more
4Debian Linux
Enterprise LinuxFedora+1 more
Nov 21, 2024
Nov 22, 2019
N/A· v4
4.7 MEDIUM· v3
3.3 LOW· v2
libbluray MountManager class has a time-of-check time-of-use (TOCTOU) race when expanding JAR files
3Debian
OpenstackRedhat
3Debian Linux
DesignateEnterprise Linux Openstack Platform
Nov 21, 2024
Nov 22, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Designate does not enforce the DNS protocol limit concerning record set sizes
3Debian
OpensuseRedhat
4Ansible
Backports SleDebian Linux+1 more
Jun 17, 2026
Nov 22, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, prompt passwords by expanding them from templates as they could contain special characters....Show more
ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, prompt passwords by expanding them from templates as they could contain special characters. Passwords should be wrapped to prevent templates trigger and exposing them.Show less
4Canonical
DebianFedoraproject+1 more
4Debian Linux
FedoraLibarchive+1 more
Jun 17, 2026
Nov 21, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
In Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c has an out-of-bounds read because of an incorrect mbrtowc or mbtowc call. For example, bsdtar crashes via a crafted archive.
2Debian
Xcfa Project
2Debian Linux
Xcfa
Nov 21, 2024
Nov 21, 2019
N/A· v4
7.0 HIGH· v3
4.4 MEDIUM· v2
xcfa before 5.0.1 creates temporary files insecurely which could allow local users to launch a symlink attack and overwrite arbitrary files. Note: A different vulnerability than CVE-2014-5254.
3Debian
FedoraprojectOniguruma Project
3Debian Linux
FedoraOniguruma
Jun 17, 2026
Nov 21, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function fetch_interval_quantifier (formerly known as fetch_range_quantifier) in regparse.c, PFETCH is called without checking PEND. This leads to a heap-...Show more
An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function fetch_interval_quantifier (formerly known as fetch_range_quantifier) in regparse.c, PFETCH is called without checking PEND. This leads to a heap-based buffer over-read.Show less