Debian
debian
10,145 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,145)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
OpenAFS before 1.4.15, 1.6.x before 1.6.5, and 1.7.x before 1.7.26 uses weak encryption (DES) for Kerberos keys, which makes it easier for remote attackers to obtain the service key. |
Xen before 4.1.x, 4.2.x, and 4.3.x does not take the page_alloc_lock and grant_table.lock in the same order, which allows local guest administrators with access to multiple vcpus to cause a denial of service (host deadlo...Show more |
2Debian Systemd Project2Debian Linux SystemdApr 29, 2026 Oct 28, 2013 N/A· v4 N/A· v3 5.9 MEDIUM· v2 The SetX11Keyboard function in systemd, when PolicyKit Local Authority (PKLA) is used to change the group permissions on the X Keyboard Extension (XKB) layouts description, allows local users in the group to modify the X...Show more |
2Debian Systemd Project2Debian Linux SystemdApr 29, 2026 Oct 28, 2013 N/A· v4 N/A· v3 7.5 HIGH· v2 Integer overflow in the valid_user_field function in journal/journald-native.c in systemd allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large journal data field, w...Show more |
4Apache DebianOpensuse+1 more5Cloud Debian LinuxLinux Enterprise Software Development Kit+2 moreApr 29, 2026 Oct 17, 2013 N/A· v4 N/A· v3 7.5 HIGH· v2 Heap-based buffer overflow in the fcgid_header_bucket_read function in fcgid_bucket.c in the mod_fcgid module before 2.3.9 for the Apache HTTP Server allows remote attackers to have an unspecified impact via unknown vect...Show more |
3Debian OpensuseRubyonrails3Debian Linux OpensuseRailsApr 29, 2026 Oct 17, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Multiple format string vulnerabilities in log_subscriber.rb files in the log subscriber component in Action Mailer in Ruby on Rails 3.x before 3.2.15 allow remote attackers to cause a denial of service via a crafted e-ma...Show more |
3Debian GoogleOpensuse3Chrome Debian LinuxOpensuseApr 29, 2026 Oct 16, 2013 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Use-after-free vulnerability in the HTMLFormElement::prepareForSubmission function in core/html/HTMLFormElement.cpp in Blink, as used in Google Chrome before 30.0.1599.101, allows remote attackers to cause a denial of se...Show more |
5Canonical DebianMariadb+2 more7Debian Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreApr 29, 2026 Oct 16, 2013 N/A· v4 N/A· v3 4.9 MEDIUM· v2 Unspecified vulnerability in Oracle MySQL Server 5.5.x through 5.5.32 and 5.6.x through 5.6.12 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Replication. |
5Canonical DebianMariadb+2 more7Debian Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreApr 29, 2026 Oct 16, 2013 N/A· v4 N/A· v3 4.0 MEDIUM· v2 Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.70 and earlier, 5.5.32 and earlier, and 5.6.12 and earlier allows remote authenticated users to affect availability via unknown vectors related...Show more |
3Canonical DebianSystemd Project3Debian Linux SystemdUbuntu LinuxApr 29, 2026 Oct 3, 2013 N/A· v4 N/A· v3 6.9 MEDIUM· v2 systemd does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setu...Show more |
3Debian GoogleOpensuse3Chrome Debian LinuxOpensuseApr 29, 2026 Oct 2, 2013 N/A· v4 N/A· v3 7.5 HIGH· v2 Google V8, as used in Google Chrome before 30.0.1599.66, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors. |
A certain Debian patch for txt2man 1.5.5, as used in txt2man 1.5.5-2, 1.5.5-4, and others, allows local users to overwrite arbitrary files via a symlink attack on /tmp/2222. |
2Debian Konstanty Bialkowski2Debian Linux LibmodplugApr 29, 2026 Sep 16, 2013 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Multiple heap-based buffer overflows in the (1) abc_MIDI_drum and (2) abc_MIDI_gchord functions in load_abc.cpp in libmodplug 0.8.8.4 and earlier allow remote attackers to cause a denial of service (memory corruption and...Show more |
2Debian Konstanty Bialkowski2Debian Linux LibmodplugApr 29, 2026 Sep 16, 2013 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Integer overflow in the abc_set_parts function in load_abc.cpp in libmodplug 0.8.8.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted P header in an ABC f...Show more |
Phpbb3 before 3.0.11-4 for Debian GNU/Linux uses world-writable permissions for cache files, which allows local users to modify the file contents via standard filesystem write operations. |
Heap-based buffer overflow in the readgifimage function in the gif2tiff tool in libtiff 4.0.3 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted hei...Show more |
Use-after-free vulnerability in the t2p_readwrite_pdf_image function in tools/tiff2pdf.c in libtiff 4.0.3 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted TIFF...Show more |
3Cacti DebianOpensuse3Cacti Debian LinuxOpensuseApr 29, 2026 Aug 29, 2013 N/A· v4 N/A· v3 7.5 HIGH· v2 SQL injection vulnerability in cacti/host.php in Cacti 0.8.8b and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. |
Buffer overflow in the Python bindings for the xc_vcpu_setaffinity call in Xen 4.0.x, 4.1.x, and 4.2.x allows local administrators with permissions to configure VCPU affinity to cause a denial of service (memory corrupti...Show more |
The SharedMemory::Create function in memory/shared_memory_posix.cc in Google Chrome before 29.0.1547.57 uses weak permissions under /dev/shm/, which allows attackers to obtain sensitive information via direct access to a...Show more |