Debian
debian
10,145 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,145)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Blender Debian2Blender Debian LinuxApr 16, 2026 Oct 24, 2005 N/A· v4 7.3 HIGH· v3 7.5 HIGH· v2 Eval injection vulnerability in bvh_import.py in Blender 2.36 allows attackers to execute arbitrary Python code via a hierarchy element in a .bvh file, which is supplied to an eval function call. |
2Debian Linux2Debian Linux Linux KernelApr 16, 2026 Oct 21, 2005 N/A· v4 4.7 MEDIUM· v3 1.2 LOW· v2 Race condition in ip_vs_conn_flush in Linux 2.6 before 2.6.13 and 2.4 before 2.4.32-pre2, when running on SMP systems, allows local users to cause a denial of service (null dereference) by causing a connection timer to e...Show more |
2Debian Invisible Island2Debian Linux LynxApr 16, 2026 Oct 17, 2005 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Stack-based buffer overflow in the HTrjis function in Lynx 2.8.6 and earlier allows remote NNTP servers to execute arbitrary code via certain article headers containing Asian characters that cause Lynx to add extra escap...Show more |
4Canonical DebianLinux+1 more4Debian Linux LinuxLinux Kernel+1 moreApr 16, 2026 Oct 12, 2005 N/A· v4 N/A· v3 2.1 LOW· v2 The audit system in Linux kernel 2.6.6, and other versions before 2.6.13.4, when CONFIG_AUDITSYSCALL is enabled, uses an incorrect function to free names_cache memory, which prevents the memory from being tracked by AUDI...Show more |
cfengine 1.6.5 and 2.1.16 allows local users to overwrite arbitrary files via a symlink attack on temporary files used by vicf.in, a different vulnerability than CVE-2005-3137. |
The handler code for backupninja 0.8 and earlier creates temporary files with predictable filenames, which allows local users to modify arbitrary files via a symlink attack. |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxApr 16, 2026 Sep 30, 2005 N/A· v4 4.7 MEDIUM· v3 1.2 LOW· v2 Race condition in Linux 2.6, when threads are sharing memory mapping via CLONE_VM (such as linuxthreads and vfork), might allow local users to cause a denial of service (deadlock) by triggering a core dump while waiting...Show more |
3Debian GentooMantis3Debian Linux LinuxMantisApr 16, 2026 Sep 28, 2005 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in view_all_set.php in Mantis 0.19.0a1 through 1.0.0a3 allows remote attackers to inject arbitrary web script or HTML via the dir parameter, as identified by bug#0005959, and a di...Show more |
Linux kernel 2.6.8 to 2.6.14-rc2 allows local users to cause a denial of service (kernel OOPS) via a userspace process that issues a USB Request Block (URB) to a USB device and terminates before the URB is finished, whic...Show more |
3Apache CanonicalDebian3Debian Linux Http ServerUbuntu LinuxApr 16, 2026 Sep 6, 2005 N/A· v4 N/A· v3 10.0 HIGH· v2 ssl_engine_kernel.c in mod_ssl before 2.8.24, when using "SSLVerifyClient optional" in the global virtual host configuration, does not properly enforce "SSLVerifyClient require" in a per-location context, which allows re...Show more |
2Debian Sukria2Backup Manager Debian LinuxApr 16, 2026 Aug 30, 2005 N/A· v4 N/A· v3 2.1 LOW· v2 Backup Manager (backup-manager) before 0.5.8 creates backup files with world-readable default permissions, which allows local users to obtain sensitive information. |
2Debian Linux2Debian Linux Linux KernelApr 16, 2026 Aug 23, 2005 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The huft_build function in inflate.c in the zlib routines in the Linux kernel before 2.6.12.5 returns the wrong value, which allows remote attackers to cause a denial of service (kernel crash) via a certain compressed fi...Show more |
2Debian Linux2Debian Linux Linux KernelApr 16, 2026 Aug 16, 2005 N/A· v4 N/A· v3 4.6 MEDIUM· v2 Linux kernel 2.6.x does not properly restrict socket policy access to users with the CAP_NET_ADMIN capability, which could allow local users to conduct unauthorized activities via (1) ipv4/ip_sockglue.c and (2) ipv6/ipv6...Show more |
Eval injection vulnerability in PHPXMLRPC 1.1.1 and earlier (PEAR XML-RPC for PHP), as used in multiple products including (1) Drupal, (2) phpAdsNew, (3) phpPgAds, and (4) phpgroupware, allows remote attackers to execute...Show more |
3Awstats CanonicalDebian3Awstats Debian LinuxUbuntu LinuxApr 16, 2026 Aug 15, 2005 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Eval injection vulnerability in awstats.pl in AWStats 6.4 and earlier, when a URLPlugin is enabled, allows remote attackers to execute arbitrary Perl code via the HTTP Referrer, which is used in a $url parameter that is...Show more |
Unknown vulnerability in apt-cacher in Debian 3.1, related to "missing input sanitising," allows remote attackers to execute arbitrary commands on the caching server. |
3Apache DebianRedhat5Debian Linux Enterprise Linux DesktopEnterprise Linux Server+2 moreApr 16, 2026 Aug 5, 2005 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Off-by-one error in the mod_ssl Certificate Revocation List (CRL) verification callback in Apache, when configured to use a CRL, allows remote attackers to cause a denial of service (child process crash) via a CRL that c...Show more |
2Debian Linux2Debian Linux Linux KernelApr 16, 2026 Aug 4, 2005 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Array index overflow in the xfrm_sk_policy_insert function in xfrm_user.c in Linux kernel 2.6 allows local users to cause a denial of service (oops or deadlock) and possibly execute arbitrary code via a p->dir value that...Show more |
The (1) Kate and (2) Kwrite applications in KDE KDE 3.2.x through 3.4.0 do not properly set the same permissions on the backup file as were set on the original file, which could allow local users and possibly remote atta...Show more |
3Apple DebianMit4Debian Linux Kerberos 5Mac Os X+1 moreApr 16, 2026 Jul 18, 2005 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to execute arbitrary code via certain error conditions. |