← Back

Debian

debian

10,147 CVEs • 112 products

Products (112)

Click to collapse
Toggle
Dpkg
dpkg
Shadow
shadow
Lintian
lintian
Apt
apt
Reportbug
reportbug
Horde
horde
Devscripts
devscripts
Mime Support
mime-support
Fsp
fsp
Netkit
netkit
Qpopper
qpopper
Apt Cacher
apt-cacher
Aptlinex
aptlinex
Python Dns
python-dns
Xsabre
xsabre
Cifs Utils
cifs-utils
Dpkg Dev
dpkg-dev
Python Apt
python-apt
Yubiserver
yubiserver
Elvis Tiny
elvis_tiny
Sgml Tools
sgml-tools
Netstd
netstd
Bsdmainutils
bsdmainutils
Tetex Bin
tetex-bin
Debmake
debmake
Bsmtpd
bsmtpd
Sympa
sympa
Ppxp
ppxp
Apt Setup
apt-setup
Backupninja
backupninja
Amaya
amaya
Base Config
base-config
Apache
apache
Gfax
gfax
Reprepro
reprepro
Debian Goodies
debian-goodies
Guilt
guilt
Unp
unp
Tss
tss
Projectl
projectl
Turba
turba
Honeyd Common
honeyd_common
Citadel Server
citadel_server
Feta
feta
Dpkg Cross
dpkg-cross
Myspell
myspell
Newsgate
newsgate
Os Prober
os-prober
Mailscanner
mailscanner
Ltp
ltp
Horde Imp
horde_imp
Nss Ldap
nss-ldap
Libdbd Pg Perl
libdbd-pg-perl
Pyftpd
pyftpd
Mono Debugger
mono-debugger
Tex Common
tex-common
Php5 Common
php5-common
Logol
logol
Devotee
devotee
Apache2
apache2
Cfingerd
cfingerd
Latd
latd
Phpbb3
phpbb3
Txt2man
txt2man
Adequate
adequate
Localepurge
localepurge
Syncevolution
syncevolution
Axiom
axiom
Ppthtml
ppthtml
Xbuffy
xbuffy
Strongswan
strongswan
Kde4libs
kde4libs
Python Imaging
python-imaging
Hivex
hivex
Dbd Firebird
dbd-firebird
Fuse
fuse
Tor
tor
Ftpsync
ftpsync
Most
most
Tin
tin
Crossroads
crossroads
Tmpreaper
tmpreaper
Cron
cron
Overkill
overkill
Duplicity
duplicity

CVEs (10,147)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
5Avaya
DebianMozilla+2 more
27Aura Application Enablement Services
Aura Application Server 5300Aura Communication Manager+24 more
Nov 21, 2024
Nov 15, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a...Show more
A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a Denial of Service.Show less
3Chrony Project
DebianFedoraproject
3Chrony
Debian LinuxFedora
Nov 21, 2024
Nov 15, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Chrony before 1.29.1 has traffic amplification in cmdmon protocol
3Clamav
DebianFedoraproject
3Clamav
Debian LinuxFedora
Nov 21, 2024
Nov 15, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
ClamAV before 0.97.7: dbg_printhex possible information leak
3Clamav
DebianFedoraproject
3Clamav
Debian LinuxFedora
Nov 21, 2024
Nov 15, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ClamAV before 0.97.7 has buffer overflow in the libclamav component
3Clamav
DebianFedoraproject
3Clamav
Debian LinuxFedora
Nov 21, 2024
Nov 15, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ClamAV before 0.97.7 has WWPack corrupt heap memory
2Debian
Horms
2Debian Linux
Perdition
Nov 21, 2024
Nov 15, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Perdition before 2.2 may have weak security when handling outbound connections, caused by an error in the STARTTLS IMAP and POP server. ssl_outgoing_ciphers not being applied to STARTTLS connections
3Cyrus
DebianFedoraproject
3Debian Linux
FedoraImap
Jun 17, 2026
Nov 15, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connec...Show more
Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection.Show less
3Canonical
DebianRack Cors Project
3Debian Linux
Rack CorsUbuntu Linux
Jun 17, 2026
Nov 14, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in the rack-cors (aka Rack CORS Middleware) gem before 1.0.4 for Ruby. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in...Show more
An issue was discovered in the rack-cors (aka Rack CORS Middleware) gem before 1.0.4 for Ruby. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format.Show less
8Canonical
DebianF5+5 more
778Big Ip Access Policy Manager
Big Ip Advanced Firewall ManagerBig Ip Analytics+775 more
Nov 21, 2024
Nov 14, 2019
N/A· v4
6.5 MEDIUM· v3
4.9 MEDIUM· v2
Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to potentially enable denial of service of the host system via local acces...Show more
Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to potentially enable denial of service of the host system via local access.Show less
3Debian
IntelOpensuse
59Debian Linux
LeapXeon 3104 Firmware+56 more
Jun 17, 2026
Nov 14, 2019
N/A· v4
6.0 MEDIUM· v3
2.1 LOW· v2
Improper conditions check in the voltage modulation interface for some Intel(R) Xeon(R) Scalable Processors may allow a privileged user to potentially enable denial of service via local access.
9Canonical
DebianFedoraproject+6 more
160Apollo 2000 Firmware
Apollo 4200 FirmwareCeleron 5305u Firmware+157 more
Jun 17, 2026
Nov 14, 2019
N/A· v4
6.5 MEDIUM· v3
2.1 LOW· v2
TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access.
4Debian
FedoraprojectMoodle+1 more
4Debian Linux
Enterprise LinuxFedora+1 more
Nov 21, 2024
Nov 14, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from groups the user does not belong to
2Debian
Klibc Project
2Debian Linux
Klibc
Nov 21, 2024
Nov 14, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
In klibc 1.5.20 and 1.5.21, the DHCP options written by ipconfig to /tmp/net-$DEVICE.conf are not properly escaped. This may allow a remote attacker to send a specially crafted DHCP reply which could execute arbitrary co...Show more
In klibc 1.5.20 and 1.5.21, the DHCP options written by ipconfig to /tmp/net-$DEVICE.conf are not properly escaped. This may allow a remote attacker to send a specially crafted DHCP reply which could execute arbitrary code with the privileges of any process which sources DHCP options.Show less
3Debian
OpensuseXfce
3Debian Linux
OpensuseThunar
Nov 21, 2024
Nov 14, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Thunar before 1.3.1 could crash when copy and pasting a file name with % format characters due to a format string error.
3Debian
OpensuseRsyslog
3Debian Linux
OpensuseRsyslog
Nov 21, 2024
Nov 14, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when multiple rulesets were used and some output batches contained messages belonging to more than one ruleset. A local...Show more
A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when multiple rulesets were used and some output batches contained messages belonging to more than one ruleset. A local attacker could cause denial of the rsyslogd daemon service via a log message belonging to more than one rulesetShow less
3Debian
OpensuseRsyslog
3Debian Linux
OpensuseRsyslog
Nov 21, 2024
Nov 14, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages were logged when multiple rulesets were used and some output batches contained messages belonging to more than one ruleset. A local...Show more
A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages were logged when multiple rulesets were used and some output batches contained messages belonging to more than one ruleset. A local attacker could cause denial of the rsyslogd daemon service via a log message belonging to more than one ruleset.Show less
3Debian
OpensuseRsyslog
3Debian Linux
OpensuseRsyslog
Nov 21, 2024
Nov 14, 2019
N/A· v4
5.5 MEDIUM· v3
1.9 LOW· v2
A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when $RepeatedMsgReduction was enabled. A local attacker could use this flaw to cause a denial of the rsyslogd daemon se...Show more
A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when $RepeatedMsgReduction was enabled. A local attacker could use this flaw to cause a denial of the rsyslogd daemon service by crashing the service via a sequence of repeated log messages sent within short periods of time.Show less
4Debian
OpensuseRedhat+1 more
4Debian Linux
Enterprise LinuxOpensuse+1 more
Nov 21, 2024
Nov 14, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
The SQLDriverConnect() function in unixODBC before 2.2.14p2 have a possible buffer overflow condition when specifying a large value for SAVEFILE parameter in the connection string.
2Debian
Tesseract Project
2Debian Linux
Tesseract
Nov 21, 2024
Nov 14, 2019
N/A· v4
4.7 MEDIUM· v3
6.3 MEDIUM· v2
In tesseract 2.03 and 2.04, an attacker can rewrite an arbitrary user file by guessing the PID and creating a link to the user's file.
2Debian
V86d Project
2Debian Linux
V86d
Nov 21, 2024
Nov 14, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
v86d before 0.1.10 do not verify if received netlink messages are sent by the kernel. This could allow unprivileged users to manipulate the video mode and potentially other consequences.