Debian
debian
10,145 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,145)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical DebianMozilla5Debian Linux FirefoxSeamonkey+2 moreApr 23, 2026 Dec 20, 2006 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Unspecified vulnerability in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to gain privileges and install malicious code via the...Show more |
3Canonical DebianMozilla5Debian Linux FirefoxSeamonkey+2 moreApr 23, 2026 Dec 20, 2006 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Heap-based buffer overflow in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to cause a denial of service (crash) and possibly exe...Show more |
3Canonical DebianMozilla5Debian Linux FirefoxSeamonkey+2 moreApr 23, 2026 Dec 20, 2006 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The js_dtoa function in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 overwrites memory instead of exiting when the floating point precision is reduced,...Show more |
2Debian Thomas Lange2Debian Linux Fully Automated InstallationApr 23, 2026 Dec 18, 2006 N/A· v4 N/A· v3 1.9 LOW· v2 The save_log_local function in Fully Automatic Installation (FAI) 2.10.1, and possibly 3.1.2, when verbose mode is enabled, stores the root password hash in /var/log/fai/current/fai.log, whose file permissions allow it t...Show more |
Buffer overflow in the cluster_process_heartbeat function in cluster.c in layer 2 tunneling protocol network server (l2tpns) before 2.1.21 allows remote attackers to cause a denial of service via a large heartbeat packet...Show more |
3Canonical DebianImagemagick3Debian Linux ImagemagickUbuntu LinuxApr 23, 2026 Nov 22, 2006 N/A· v4 N/A· v3 9.3 HIGH· v2 Multiple buffer overflows in Imagemagick 6.0 before 6.0.6.2, and 6.2 before 6.2.4.5, has unknown impact and user-assisted attack vectors via a crafted SGI image. |
3Debian FedoraprojectRedhat8Debian Linux Enterprise LinuxEnterprise Linux Desktop+5 moreApr 23, 2026 Oct 10, 2006 N/A· v4 N/A· v3 7.5 HIGH· v2 pam_ldap in nss_ldap on Red Hat Enterprise Linux 4, Fedora Core 3 and earlier, and possibly other distributions does not return an error condition when an LDAP directory server responds with a PasswordPolicyResponse cont...Show more |
3Canonical DebianOpenssl3Debian Linux OpensslUbuntu LinuxApr 23, 2026 Sep 28, 2006 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The get_server_hello function in the SSLv2 client code in OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions allows remote servers to cause a denial of service (client crash) via unknown vectors that...Show more |
3Apple DebianOpenbsd4Debian Linux Mac Os XMac Os X Server+1 moreApr 23, 2026 Sep 27, 2006 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 Signal handler race condition in OpenSSH before 4.4 allows remote attackers to cause a denial of service (crash), and possibly execute arbitrary code if GSSAPI authentication is enabled, via unspecified vectors that lead...Show more |
3Canonical DebianPhp3Debian Linux PhpUbuntu LinuxApr 16, 2026 Aug 31, 2006 N/A· v4 N/A· v3 9.3 HIGH· v2 Multiple heap-based buffer overflows in the (1) str_repeat and (2) wordwrap functions in ext/standard/string.c in PHP before 5.1.5, when used on a 64-bit system, have unspecified impact and attack vectors, a different vu...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxApr 16, 2026 Aug 21, 2006 N/A· v4 N/A· v3 4.9 MEDIUM· v2 Linux kernel 2.x.6 before 2.6.17.9 and 2.4.x before 2.4.33.1 on PowerPC PPC970 systems allows local users to cause a denial of service (crash) related to the "HID0 attention enable on PPC970 at boot time." |
3Apache CanonicalDebian3Debian Linux Http ServerUbuntu LinuxApr 16, 2026 Jul 28, 2006 N/A· v4 N/A· v3 7.6 HIGH· v2 Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before 2.0.59, and 2.2, when RewriteEngine is enabled, allows remote attackers to caus...Show more |
4Apache CanonicalDebian+1 more5Debian Linux Enterprise Linux ServerEnterprise Linux Workstation+2 moreApr 16, 2026 Jul 28, 2006 N/A· v4 N/A· v3 4.3 MEDIUM· v2 http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HTTP Server 1.3 before 1.3.35, 2.0 before 2.0.58, and 2.2 before 2.2.2, does not sanitize the Expect header from an HTTP r...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxApr 16, 2026 Jul 5, 2006 N/A· v4 N/A· v3 4.6 MEDIUM· v2 The dvd_read_bca function in the DVD handling code in drivers/cdrom/cdrom.c in Linux kernel 2.2.16, and later versions, assigns the wrong value to a length variable, which allows local users to execute arbitrary code via...Show more |
3Canonical DebianFreetype3Debian Linux FreetypeUbuntu LinuxApr 16, 2026 May 30, 2006 N/A· v4 N/A· v3 5.0 MEDIUM· v2 ftutil.c in Freetype before 2.2 allows remote attackers to cause a denial of service (crash) via a crafted font file that triggers a null dereference. |
useradd in shadow-utils before 4.0.3, and possibly other versions before 4.0.8, does not provide a required argument to the open function when creating a new user mailbox, which causes the mailbox to be created with unpr...Show more |
2Debian Phpldapadmin Project2Debian Linux PhpldapadminApr 16, 2026 Apr 25, 2006 N/A· v4 N/A· v3 2.6 LOW· v2 Multiple cross-site scripting (XSS) vulnerabilities in phpLDAPadmin 0.9.8 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) dn parameter in (a) compare_form.php, (b) copy_form.php, (c)...Show more |
The Debian installer for the (1) shadow 4.0.14 and (2) base-config 2.53.10 packages includes sensitive information in world-readable log files, including preseeded passwords and pppoeconf passwords, which might allow loc...Show more |
A cron job in fcheck before 2.7.59 allows local users to overwrite arbitrary files via a symlink attack on a temporary file. |
2Debian Mozilla5Debian Linux FirefoxMozilla Suite+2 moreApr 16, 2026 Apr 14, 2006 N/A· v4 N/A· v3 7.5 HIGH· v2 Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to cause a denial of service (crash) and possibly e...Show more |