← Back

Debian

debian

10,146 CVEs • 112 products

Products (112)

Click to collapse
Toggle
Dpkg
dpkg
Shadow
shadow
Lintian
lintian
Apt
apt
Reportbug
reportbug
Horde
horde
Devscripts
devscripts
Mime Support
mime-support
Fsp
fsp
Netkit
netkit
Qpopper
qpopper
Apt Cacher
apt-cacher
Aptlinex
aptlinex
Python Dns
python-dns
Xsabre
xsabre
Cifs Utils
cifs-utils
Dpkg Dev
dpkg-dev
Python Apt
python-apt
Yubiserver
yubiserver
Elvis Tiny
elvis_tiny
Sgml Tools
sgml-tools
Netstd
netstd
Bsdmainutils
bsdmainutils
Tetex Bin
tetex-bin
Debmake
debmake
Bsmtpd
bsmtpd
Sympa
sympa
Ppxp
ppxp
Apt Setup
apt-setup
Backupninja
backupninja
Amaya
amaya
Base Config
base-config
Apache
apache
Gfax
gfax
Reprepro
reprepro
Debian Goodies
debian-goodies
Guilt
guilt
Unp
unp
Tss
tss
Projectl
projectl
Turba
turba
Honeyd Common
honeyd_common
Citadel Server
citadel_server
Feta
feta
Dpkg Cross
dpkg-cross
Myspell
myspell
Newsgate
newsgate
Os Prober
os-prober
Mailscanner
mailscanner
Ltp
ltp
Horde Imp
horde_imp
Nss Ldap
nss-ldap
Libdbd Pg Perl
libdbd-pg-perl
Pyftpd
pyftpd
Mono Debugger
mono-debugger
Tex Common
tex-common
Php5 Common
php5-common
Logol
logol
Devotee
devotee
Apache2
apache2
Cfingerd
cfingerd
Latd
latd
Phpbb3
phpbb3
Txt2man
txt2man
Adequate
adequate
Localepurge
localepurge
Syncevolution
syncevolution
Axiom
axiom
Ppthtml
ppthtml
Xbuffy
xbuffy
Strongswan
strongswan
Kde4libs
kde4libs
Python Imaging
python-imaging
Hivex
hivex
Dbd Firebird
dbd-firebird
Fuse
fuse
Tor
tor
Ftpsync
ftpsync
Most
most
Tin
tin
Crossroads
crossroads
Tmpreaper
tmpreaper
Cron
cron
Overkill
overkill
Duplicity
duplicity

CVEs (10,146)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Debian
Mediawiki
2Debian Linux
Mediawiki
Nov 21, 2024
Apr 13, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains an information disclosure flaw, where the api.log might contain passwords in plaintext.
2Debian
Reproducible Builds
2Debian Linux
Diffoscope
Nov 21, 2024
Apr 13, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
diffoscope before 77 writes to arbitrary locations on disk based on the contents of an untrusted archive.
2Debian
Tuxera
2Debian Linux
Ntfs 3g
Dec 4, 2025
Apr 13, 2018
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Jann Horn of Google Project Zero discovered that NTFS-3G, a read-write NTFS driver for FUSE, does not scrub the environment before executing modprobe with elevated privileges. A local user can take advantage of this flaw...Show more
Jann Horn of Google Project Zero discovered that NTFS-3G, a read-write NTFS driver for FUSE, does not scrub the environment before executing modprobe with elevated privileges. A local user can take advantage of this flaw for local root privilege escalation.Show less
2Debian
Iucode Tool Project
2Debian Linux
Iucode Tool
Nov 21, 2024
Apr 13, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A heap-overflow flaw exists in the -tr loader of iucode-tool starting with v1.4 and before v2.1.1, potentially leading to SIGSEGV, or heap corruption.
2Debian
Ikiwiki
2Debian Linux
Ikiwiki
Nov 21, 2024
Apr 13, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A flaw, similar to to CVE-2016-9646, exists in ikiwiki before 3.20170111, in the passwordauth plugin's use of CGI::FormBuilder, allowing an attacker to bypass authentication via repeated parameters.
2Debian
Ikiwiki
2Debian Linux
Ikiwiki
Nov 21, 2024
Apr 13, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
ikiwiki before 3.20161229 incorrectly called the CGI::FormBuilder->field method (similar to the CGI->param API that led to Bugzilla's CVE-2014-1572), which can be abused to lead to commit metadata forgery.
3Canonical
DebianLinux
3Debian Linux
Linux KernelUbuntu Linux
Nov 21, 2024
Apr 13, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The kernel_wait4 function in kernel/exit.c in the Linux kernel before 4.13, when an unspecified architecture and compiler is used, might allow local users to cause a denial of service by triggering an attempted use of th...Show more
The kernel_wait4 function in kernel/exit.c in the Linux kernel before 4.13, when an unspecified architecture and compiler is used, might allow local users to cause a denial of service by triggering an attempted use of the -INT_MIN value.Show less
4Canonical
CorosyncDebian+1 more
4Corosync
Debian LinuxEnterprise Linux Server+1 more
Nov 21, 2024
Apr 12, 2018
N/A· v4
7.5 HIGH· v3
7.5 HIGH· v2
corosync before version 2.4.4 is vulnerable to an integer overflow in exec/totemcrypto.c.
3Clusterlabs
DebianRedhat
3Debian Linux
Enterprise Linux Server EusPacemaker Command Line Interface
Nov 21, 2024
Apr 12, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
pcs before versions 0.9.164 and 0.10 is vulnerable to a debug parameter removal bypass. REST interface of the pcsd service did not properly remove the pcs debug argument from the /run_pcs query, possibly disclosing sensi...Show more
pcs before versions 0.9.164 and 0.10 is vulnerable to a debug parameter removal bypass. REST interface of the pcsd service did not properly remove the pcs debug argument from the /run_pcs query, possibly disclosing sensitive information. A remote attacker with a valid token could use this flaw to elevate their privilege.Show less
2Cacti
Debian
2Cacti
Debian Linux
Nov 21, 2024
Apr 12, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cacti before 1.1.37 has XSS because it makes certain htmlspecialchars calls without the ENT_QUOTES flag (these calls occur when the html_escape function in lib/html.php is not used).
2Cacti
Debian
2Cacti
Debian Linux
Nov 21, 2024
Apr 12, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cacti before 1.1.37 has XSS because it does not properly reject unintended characters, related to use of the sanitize_uri function in lib/functions.php.
2Debian
Ffmpeg
2Debian Linux
Ffmpeg
Nov 21, 2024
Apr 11, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The decode_init function in libavcodec/utvideodec.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial of service (out of array read) via an AVI file.
3Debian
LibsdlStarwindsoftware
3Debian Linux
Sdl ImageStarwind Virtual San
Nov 21, 2024
Apr 10, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An exploitable code execution vulnerability exists in the XCF image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A specially crafted XCF image can cause an out-of-bounds write on the heap, result...Show more
An exploitable code execution vulnerability exists in the XCF image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A specially crafted XCF image can cause an out-of-bounds write on the heap, resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability.Show less
2Debian
Libsdl
2Debian Linux
Sdl Image
Nov 21, 2024
Apr 10, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An exploitable information vulnerability exists in the XCF image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A specially crafted XCF image can cause an out-of-bounds read on the heap, resulting...Show more
An exploitable information vulnerability exists in the XCF image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A specially crafted XCF image can cause an out-of-bounds read on the heap, resulting in information disclosure. An attacker can display a specially crafted image to trigger this vulnerability.Show less
3Debian
LibsdlStarwindsoftware
3Debian Linux
Sdl ImageStarwind Virtual San
Nov 21, 2024
Apr 10, 2018
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An exploitable information disclosure vulnerability exists in the PCX image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A specially crafted PCX image can cause an out-of-bounds read on the heap,...Show more
An exploitable information disclosure vulnerability exists in the PCX image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A specially crafted PCX image can cause an out-of-bounds read on the heap, resulting in information disclosure . An attacker can display a specially crafted image to trigger this vulnerability.Show less
3Arm
DebianTrustedfirmware
3Debian Linux
Mbed TlsMbed Tls
Jun 17, 2026
Apr 10, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_server_psk_hint() that could cause a crash on invalid input.
3Arm
DebianTrustedfirmware
3Debian Linux
Mbed TlsMbed Tls
Jun 17, 2026
Apr 10, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_server_key_exchange() that could cause a crash on invalid input.
2Debian
Zabbix
2Debian Linux
Zabbix
Nov 21, 2024
Apr 9, 2018
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
An information disclosure vulnerability exists in the iConfig proxy request of Zabbix server 2.4.X. A specially crafted iConfig proxy request can cause the Zabbix server to send the configuration information of any Zabbi...Show more
An information disclosure vulnerability exists in the iConfig proxy request of Zabbix server 2.4.X. A specially crafted iConfig proxy request can cause the Zabbix server to send the configuration information of any Zabbix proxy, resulting in information disclosure. An attacker can make requests from an active Zabbix proxy to trigger this vulnerability.Show less
2Apache
Debian
2Debian Linux
Solr
Nov 21, 2024
Apr 9, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
This vulnerability in Apache Solr 1.2 to 6.6.2 and 7.0.0 to 7.2.1 relates to an XML external entity expansion (XXE) in the `&dataConfig=<inlinexml>` parameter of Solr's DataImportHandler. It can be used as XXE using file...Show more
This vulnerability in Apache Solr 1.2 to 6.6.2 and 7.0.0 to 7.2.1 relates to an XML external entity expansion (XXE) in the `&dataConfig=<inlinexml>` parameter of Solr's DataImportHandler. It can be used as XXE using file/ftp/http protocols in order to read arbitrary local files from the Solr server or the internal network.Show less
2Debian
Roundcube
2Debian Linux
Webmail
Jun 17, 2026
Apr 7, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In Roundcube from versions 1.2.0 to 1.3.5, with the archive plugin enabled and configured, it's possible to exploit the unsanitized, user-controlled "_uid" parameter (in an archive.php _task=mail&_mbox=INBOX&_action=plug...Show more
In Roundcube from versions 1.2.0 to 1.3.5, with the archive plugin enabled and configured, it's possible to exploit the unsanitized, user-controlled "_uid" parameter (in an archive.php _task=mail&_mbox=INBOX&_action=plugin.move2archive request) to perform an MX (IMAP) injection attack by placing an IMAP command after a %0d%0a sequence. NOTE: this is less easily exploitable in 1.3.4 and later because of a Same Origin Policy protection mechanism.Show less