Debian
debian
10,145 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,145)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Canonical DebianMariadb+2 more10Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+7 moreApr 29, 2026 Jan 15, 2014 N/A· v4 N/A· v3 4.0 MEDIUM· v2 Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.71 and earlier, 5.5.33 and earlier, and 5.6.13 and earlier allows remote authenticated users to affect availability via unknown vectors related...Show more |
5Canonical DebianMariadb+2 more10Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+7 moreApr 29, 2026 Jan 15, 2014 N/A· v4 N/A· v3 2.6 LOW· v2 Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.72 and earlier, 5.5.34 and earlier, and 5.6.14 and earlier allows remote attackers to affect availability via unknown vectors related to Error H...Show more |
5Canonical DebianMariadb+2 more7Debian Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreApr 29, 2026 Jan 15, 2014 N/A· v4 N/A· v3 4.0 MEDIUM· v2 Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.33 and earlier and 5.6.13 and earlier allows remote authenticated users to affect availability via unknown vectors related to Partition. |
4Canonical DebianPuppet+1 more4Debian Linux PuppetPuppet Enterprise+1 moreApr 29, 2026 Jan 7, 2014 N/A· v4 N/A· v3 2.1 LOW· v2 Puppet before 3.3.3 and 3.4 before 3.4.1 and Puppet Enterprise (PE) before 2.8.4 and 3.1 before 3.1.1 allows local users to overwrite arbitrary files via a symlink attack on unspecified files. |
3Debian FedoraprojectPhil Schwartz3Debian Linux DenyhostsFedoraApr 29, 2026 Dec 23, 2013 N/A· v4 N/A· v3 5.0 MEDIUM· v2 denyhosts 2.6 uses an incorrect regular expression when analyzing authentication logs, which allows remote attackers to cause a denial of service (incorrect block of IP addresses) via crafted login names. |
3Canonical DebianHaxx3Debian Linux LibcurlUbuntu LinuxApr 29, 2026 Dec 23, 2013 N/A· v4 N/A· v3 4.0 MEDIUM· v2 The GnuTLS backend in libcurl 7.21.4 through 7.33.0, when disabling digital signature verification (CURLOPT_SSL_VERIFYPEER), also disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it e...Show more |
The read_header function in libavcodec/ffv1dec.c in FFmpeg before 2.1 does not properly enforce certain bit-count and colorspace constraints, which allows remote attackers to cause a denial of service (out-of-bounds arra...Show more |
The atrac3_decode_init function in libavcodec/atrac3.c in FFmpeg before 1.0.4 allows remote attackers to have an unspecified impact via ATRAC3 data with the joint stereo coding mode set and fewer than two channels. |
3Canonical DebianWouter Verhelst3Debian Linux NbdUbuntu LinuxApr 29, 2026 Dec 7, 2013 N/A· v4 N/A· v3 7.5 HIGH· v2 nbd-server in Network Block Device (nbd) before 3.5 does not properly check IP addresses, which might allow remote attackers to bypass intended access restrictions via an IP address that has a partial match in the authfi...Show more |
Debian adequate before 0.8.1, when run by root with the --user option, allows local users to hijack the tty and possibly gain privileges via the TIOCSTI ioctl. |
5Apple CanonicalDebian+2 more5Debian Linux Mac Os XOpensuse+2 moreApr 29, 2026 Nov 28, 2013 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The scan function in ext/date/lib/parse_iso_intervals.c in PHP through 5.5.6 does not properly restrict creation of DateInterval objects, which might allow remote attackers to cause a denial of service (heap-based buffer...Show more |
3Debian LighttpdOpensuse3Debian Linux LighttpdOpensuseApr 29, 2026 Nov 20, 2013 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Use-after-free vulnerability in lighttpd before 1.4.33 allows remote attackers to cause a denial of service (segmentation fault and crash) via unspecified vectors that trigger FAMMonitorDirectory failures. |
3Debian LighttpdOpensuse3Debian Linux LighttpdOpensuseApr 29, 2026 Nov 20, 2013 N/A· v4 N/A· v3 7.6 HIGH· v2 lighttpd before 1.4.33 does not check the return value of the (1) setuid, (2) setgid, or (3) setgroups functions, which might cause lighttpd to run as root if it is restarted and allows remote attackers to gain privilege...Show more |
9Artifex CanonicalDebian+6 more11Chrome Debian LinuxFedora+8 moreApr 29, 2026 Nov 19, 2013 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, and other products, does not check for certain duplications of componen...Show more |
Integer overflow in Google Chrome before 31.0.1650.57 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, as demonstrated during a Mobile Pwn2Own co...Show more |
3Debian MitOpensuse3Debian Linux Kerberos 5OpensuseApr 29, 2026 Nov 18, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The setup_server_realm function in main.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.10.7, when multiple realms are configured, allows remote attackers to cause a denial of service (NULL p...Show more |
3Debian GoogleOpensuse3Chrome Debian LinuxOpensuseApr 29, 2026 Nov 13, 2013 N/A· v4 N/A· v3 7.5 HIGH· v2 Use-after-free vulnerability in Google Chrome before 31.0.1650.48 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the x-webkit-speech attribute in a t...Show more |
3Canonical DebianSamba3Debian Linux SambaUbuntu LinuxApr 29, 2026 Nov 13, 2013 N/A· v4 N/A· v3 4.0 MEDIUM· v2 Samba 3.2.x through 3.6.x before 3.6.20, 4.0.x before 4.0.11, and 4.1.x before 4.1.1, when vfs_streams_depot or vfs_streams_xattr is enabled, allows remote attackers to bypass intended file restrictions by leveraging ACL...Show more |
3Debian LighttpdOpensuse3Debian Linux LighttpdOpensuseApr 29, 2026 Nov 8, 2013 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 lighttpd before 1.4.34, when SNI is enabled, configures weak SSL ciphers, which makes it easier for remote attackers to hijack sessions by inserting packets into the client-server data stream or obtain sensitive informat...Show more |
The vos command in OpenAFS 1.6.x before 1.6.5, when using the -encrypt option, only enables integrity protection and sends data in cleartext, which allows remote attackers to obtain sensitive information by sniffing the...Show more |