← Back

Debian

debian

10,147 CVEs • 112 products

Products (112)

Click to collapse
Toggle
Dpkg
dpkg
Shadow
shadow
Lintian
lintian
Apt
apt
Reportbug
reportbug
Horde
horde
Devscripts
devscripts
Mime Support
mime-support
Fsp
fsp
Netkit
netkit
Qpopper
qpopper
Apt Cacher
apt-cacher
Aptlinex
aptlinex
Python Dns
python-dns
Xsabre
xsabre
Cifs Utils
cifs-utils
Dpkg Dev
dpkg-dev
Python Apt
python-apt
Yubiserver
yubiserver
Elvis Tiny
elvis_tiny
Sgml Tools
sgml-tools
Netstd
netstd
Bsdmainutils
bsdmainutils
Tetex Bin
tetex-bin
Debmake
debmake
Bsmtpd
bsmtpd
Sympa
sympa
Ppxp
ppxp
Apt Setup
apt-setup
Backupninja
backupninja
Amaya
amaya
Base Config
base-config
Apache
apache
Gfax
gfax
Reprepro
reprepro
Debian Goodies
debian-goodies
Guilt
guilt
Unp
unp
Tss
tss
Projectl
projectl
Turba
turba
Honeyd Common
honeyd_common
Citadel Server
citadel_server
Feta
feta
Dpkg Cross
dpkg-cross
Myspell
myspell
Newsgate
newsgate
Os Prober
os-prober
Mailscanner
mailscanner
Ltp
ltp
Horde Imp
horde_imp
Nss Ldap
nss-ldap
Libdbd Pg Perl
libdbd-pg-perl
Pyftpd
pyftpd
Mono Debugger
mono-debugger
Tex Common
tex-common
Php5 Common
php5-common
Logol
logol
Devotee
devotee
Apache2
apache2
Cfingerd
cfingerd
Latd
latd
Phpbb3
phpbb3
Txt2man
txt2man
Adequate
adequate
Localepurge
localepurge
Syncevolution
syncevolution
Axiom
axiom
Ppthtml
ppthtml
Xbuffy
xbuffy
Strongswan
strongswan
Kde4libs
kde4libs
Python Imaging
python-imaging
Hivex
hivex
Dbd Firebird
dbd-firebird
Fuse
fuse
Tor
tor
Ftpsync
ftpsync
Most
most
Tin
tin
Crossroads
crossroads
Tmpreaper
tmpreaper
Cron
cron
Overkill
overkill
Duplicity
duplicity

CVEs (10,147)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Debian
Json Jwt Project
2Debian Linux
Json Jwt
Jun 17, 2026
Nov 12, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string.
2Atop Project
Debian
2Atop
Debian Linux
Nov 21, 2024
Nov 12, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
atop: symlink attack possible due to insecure tempfile handling
3Debian
GnomeRedhat
3Debian Linux
Enterprise LinuxGdk Pixbuf
Nov 21, 2024
Nov 12, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
gdk-pixbuf through 2.31.1 has GIF loader buffer overflow when initializing decompression tables due to an input validation flaw
4Canonical
DebianFedoraproject+1 more
4Debian Linux
FedoraTnef+1 more
Jun 17, 2026
Nov 11, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In tnef before 1.4.18, an attacker may be able to write to the victim's .ssh/authorized_keys file via an e-mail message with a crafted winmail.dat application/ms-tnef attachment, because of a heap-based buffer over-read...Show more
In tnef before 1.4.18, an attacker may be able to write to the victim's .ssh/authorized_keys file via an e-mail message with a crafted winmail.dat application/ms-tnef attachment, because of a heap-based buffer over-read involving strdup.Show less
2Debian
Noping
2Debian Linux
Liboping
Nov 21, 2024
Nov 9, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
liboping 1.3.2 allows users reading arbitrary files upon the local system.
3Debian
FedoraprojectRedhat
3389 Directory Server
Debian LinuxEnterprise Linux
Jun 17, 2026
Nov 8, 2019
N/A· v4
6.5 MEDIUM· v3
3.5 LOW· v2
A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes,...Show more
A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.Show less
2Debian
Gri Project
2Debian Linux
Gri
Nov 21, 2024
Nov 8, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
gri before 2.12.18 generates temporary files in an insecure way.
2Debian
Mantisbt
2Debian Linux
Mantisbt
Nov 21, 2024
Nov 7, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
An access control issue in MantisBT before 1.2.13 allows users with "Reporter" permissions to change any issue to "New".
2Debian
Gambas Project
2Debian Linux
Gambas
Nov 21, 2024
Nov 7, 2019
N/A· v4
7.5 HIGH· v3
6.4 MEDIUM· v2
Gambas before 3.4.0 allows remote attackers to move or manipulate directory contents or perform symlink attacks due to the creation of insecure temporary directories.
2Clamav
Debian
2Clamav
Debian Linux
Nov 21, 2024
Nov 7, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
clamav 0.91.2 suffers from a floating point exception when using ScanOLE2.
2Canonical
Debian
3Debian Linux
LintianUbuntu Linux
Nov 21, 2024
Nov 7, 2019
N/A· v4
6.3 MEDIUM· v3
4.3 MEDIUM· v2
Lintian before 2.5.12 allows remote attackers to gather information about the "host" system using crafted symlinks.
2Debian
Viewvc
2Debian Linux
Viewvc
Nov 21, 2024
Nov 7, 2019
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
viewvc 1.0.3 allows improper access control to files in a repository when using the "forbidden" configuration option.
2Debian
Ldap Git Backup Project
2Debian Linux
Ldap Git Backup
Nov 21, 2024
Nov 7, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
ldap-git-backup before 1.0.4 exposes password hashes due to incorrect directory permissions.
2Debian
Shibboleth
2Debian Linux
Service Provider
Nov 21, 2024
Nov 7, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which is placed in sp-key.pm. It relies on the root umask (default 22) instead of chmod...Show more
The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which is placed in sp-key.pm. It relies on the root umask (default 22) instead of chmoding the resulting file itself, so the generated private key is world readable by default.Show less
3Debian
SimplesamlphpXmlseclibs Project
3Debian Linux
SimplesamlphpXmlseclibs
Jun 17, 2026
Nov 7, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Rob Richards XmlSecLibs, all versions prior to v3.0.3, as used for example by SimpleSAMLphp, performed incorrect validation of cryptographic signatures in XML messages, allowing an authenticated attacker to impersonate o...Show more
Rob Richards XmlSecLibs, all versions prior to v3.0.3, as used for example by SimpleSAMLphp, performed incorrect validation of cryptographic signatures in XML messages, allowing an authenticated attacker to impersonate others or elevate privileges by creating a crafted XML message.Show less
2Debian
Tahoe Lafs
2Debian Linux
Tahoe Lafs
Nov 21, 2024
Nov 7, 2019
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
Tahoe-LAFS 1.9.0 fails to ensure integrity which allows remote attackers to corrupt mutable files or directories upon retrieval.
3Debian
FedoraprojectOpenttd
3Debian Linux
FedoraOpenttd
Nov 21, 2024
Nov 7, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
OpenTTD before 1.1.5 contains a Denial of Service (slow read attack) that prevents users from joining the server.
5Canonical
DebianFedoraproject+2 more
5Debian Linux
FedoraLeap+2 more
Jun 17, 2026
Nov 7, 2019
N/A· v4
4.6 MEDIUM· v3
4.9 MEDIUM· v2
A memory leak in the af9005_identify_state() function in drivers/media/usb/dvb-usb/af9005.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption), aka CID-2289adbfa559.
5Canonical
DebianDjvulibre Project+2 more
5Debian Linux
DjvulibreFedora+2 more
Jun 17, 2026
Nov 7, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
DjVuLibre 3.5.27 has a NULL pointer dereference in the function DJVU::filter_fv at IW44EncodeCodec.cpp.
2Debian
Eclipse
2Debian Linux
Jetty
Nov 21, 2024
Nov 6, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
JSP Dump and Session Dump Servlet XSS in jetty before 6.1.22.