← Back

Debian

debian

10,146 CVEs • 112 products

Products (112)

Click to collapse
Toggle
Dpkg
dpkg
Shadow
shadow
Lintian
lintian
Apt
apt
Reportbug
reportbug
Horde
horde
Devscripts
devscripts
Mime Support
mime-support
Fsp
fsp
Netkit
netkit
Qpopper
qpopper
Apt Cacher
apt-cacher
Aptlinex
aptlinex
Python Dns
python-dns
Xsabre
xsabre
Cifs Utils
cifs-utils
Dpkg Dev
dpkg-dev
Python Apt
python-apt
Yubiserver
yubiserver
Elvis Tiny
elvis_tiny
Sgml Tools
sgml-tools
Netstd
netstd
Bsdmainutils
bsdmainutils
Tetex Bin
tetex-bin
Debmake
debmake
Bsmtpd
bsmtpd
Sympa
sympa
Ppxp
ppxp
Apt Setup
apt-setup
Backupninja
backupninja
Amaya
amaya
Base Config
base-config
Apache
apache
Gfax
gfax
Reprepro
reprepro
Debian Goodies
debian-goodies
Guilt
guilt
Unp
unp
Tss
tss
Projectl
projectl
Turba
turba
Honeyd Common
honeyd_common
Citadel Server
citadel_server
Feta
feta
Dpkg Cross
dpkg-cross
Myspell
myspell
Newsgate
newsgate
Os Prober
os-prober
Mailscanner
mailscanner
Ltp
ltp
Horde Imp
horde_imp
Nss Ldap
nss-ldap
Libdbd Pg Perl
libdbd-pg-perl
Pyftpd
pyftpd
Mono Debugger
mono-debugger
Tex Common
tex-common
Php5 Common
php5-common
Logol
logol
Devotee
devotee
Apache2
apache2
Cfingerd
cfingerd
Latd
latd
Phpbb3
phpbb3
Txt2man
txt2man
Adequate
adequate
Localepurge
localepurge
Syncevolution
syncevolution
Axiom
axiom
Ppthtml
ppthtml
Xbuffy
xbuffy
Strongswan
strongswan
Kde4libs
kde4libs
Python Imaging
python-imaging
Hivex
hivex
Dbd Firebird
dbd-firebird
Fuse
fuse
Tor
tor
Ftpsync
ftpsync
Most
most
Tin
tin
Crossroads
crossroads
Tmpreaper
tmpreaper
Cron
cron
Overkill
overkill
Duplicity
duplicity

CVEs (10,146)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Debian
GoogleUclouvain
3Debian Linux
OpenjpegPdfium
May 13, 2026
Oct 18, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Double free vulnerability in the j2k_read_ppm_v3 function in OpenJPEG before r2997, as used in PDFium in Google Chrome, allows remote attackers to cause a denial of service (process crash) via a crafted PDF.
2Debian
Redmine
2Debian Linux
Redmine
May 13, 2026
Oct 18, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles the rendering of wiki links, which allows remote attackers to obtain sensitive information.
2Debian
Redmine
2Debian Linux
Redmine
May 13, 2026
Oct 18, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles Time Entry rendering in activity views, which allows remote attackers to obtain sensitive information.
2Debian
Redmine
2Debian Linux
Redmine
May 13, 2026
Oct 18, 2017
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
In Redmine before 3.2.6 and 3.3.x before 3.3.3, Redmine.pm lacks a check for whether the Repository module is enabled in a project's settings, which might allow remote attackers to obtain sensitive differences informatio...Show more
In Redmine before 3.2.6 and 3.3.x before 3.3.3, Redmine.pm lacks a check for whether the Repository module is enabled in a project's settings, which might allow remote attackers to obtain sensitive differences information or possibly have unspecified other impact.Show less
2Debian
Redmine
2Debian Linux
Redmine
May 13, 2026
Oct 18, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Redmine before 3.2.6 and 3.3.x before 3.3.3, stored XSS is possible by using an SVG document as an attachment.
2Debian
Redmine
2Debian Linux
Redmine
May 13, 2026
Oct 18, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Redmine before 3.2.6 and 3.3.x before 3.3.3, XSS exists because markup is mishandled in wiki content.
2Debian
Redmine
2Debian Linux
Redmine
May 13, 2026
Oct 18, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Redmine before 3.2.6 and 3.3.x before 3.3.3, remote attackers can obtain sensitive information (password reset tokens) by reading a Referer log, because account/lost_password does not use a redirect.
2Debian
Redmine
2Debian Linux
Redmine
May 13, 2026
Oct 18, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/views/issues/_list.html.erb via crafted column data.
2Debian
Redmine
2Debian Linux
Redmine
May 13, 2026
Oct 18, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/views/timelog/_list.html.erb via crafted column data.
2Debian
Redmine
2Debian Linux
Redmine
May 13, 2026
Oct 18, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/helpers/queries_helper.rb via a multi-value field with a crafted value that is mishandled during rendering of an issue list.
2Debian
Redmine
2Debian Linux
Redmine
May 13, 2026
Oct 18, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/helpers/application_helper.rb via a multi-value field with a crafted value that is mishandled during rendering of issue history.
2Debian
Freedesktop
2Debian Linux
Poppler
May 13, 2026
Oct 17, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In Poppler 0.59.0, a NULL Pointer Dereference exists in the GfxImageColorMap::getGrayLine() function in GfxState.cc via a crafted PDF document.
1Debian
1Ftpsync
May 13, 2026
Oct 17, 2017
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Debian ftpsync before 20171017 does not use the rsync --safe-links option, which allows remote attackers to conduct directory traversal attacks via a crafted upstream mirror.
7Canonical
DebianFreebsd+4 more
12Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+9 more
May 13, 2026
Oct 17, 2017
N/A· v4
5.3 MEDIUM· v3
2.9 LOW· v2
Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Integrity Group Temporal Key (IGTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame, allowing an attac...Show more
Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Integrity Group Temporal Key (IGTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame, allowing an attacker within radio range to replay frames from access points to clients.Show less
7Canonical
DebianFreebsd+4 more
12Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+9 more
May 13, 2026
Oct 17, 2017
N/A· v4
5.3 MEDIUM· v3
2.9 LOW· v2
Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Group Temporal Key (GTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame, allowing an attacker within...Show more
Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Group Temporal Key (GTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame, allowing an attacker within radio range to replay frames from access points to clients.Show less
7Canonical
DebianFreebsd+4 more
12Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+9 more
May 13, 2026
Oct 17, 2017
N/A· v4
6.8 MEDIUM· v3
5.4 MEDIUM· v2
Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Tunneled Direct-Link Setup (TDLS) Peer Key (TPK) during the TDLS handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames.
7Canonical
DebianFreebsd+4 more
12Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+9 more
May 13, 2026
Oct 17, 2017
N/A· v4
6.8 MEDIUM· v3
5.4 MEDIUM· v2
Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Station-To-Station-Link (STSL) Transient Key (STK) during the PeerKey handshake, allowing an attacker within radio range to replay, decrypt, or spoof fra...Show more
Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Station-To-Station-Link (STSL) Transient Key (STK) during the PeerKey handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames.Show less
7Canonical
DebianFreebsd+4 more
12Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+9 more
May 13, 2026
Oct 17, 2017
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11r allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during the fast BSS transmission (FT) handshake, allowing an attacker within ra...Show more
Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11r allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during the fast BSS transmission (FT) handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames.Show less
7Canonical
DebianFreebsd+4 more
12Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+9 more
May 13, 2026
Oct 17, 2017
N/A· v4
5.3 MEDIUM· v3
2.9 LOW· v2
Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the Integrity Group Temporal Key (IGTK) during the group key handshake, allowing an attacker within radio range to spoof frames fr...Show more
Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the Integrity Group Temporal Key (IGTK) during the group key handshake, allowing an attacker within radio range to spoof frames from access points to clients.Show less
7Canonical
DebianFreebsd+4 more
12Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+9 more
May 13, 2026
Oct 17, 2017
N/A· v4
5.3 MEDIUM· v3
2.9 LOW· v2
Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the group key handshake, allowing an attacker within radio range to replay frames from access points to clients.