Debian
debian
10,145 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,145)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
apt-setup in Debian GNU/Linux installs the apt.conf file with insecure permissions, which allows local users to obtain sensitive information such as passwords. |
2Debian Ekg Project2Debian Linux EkgApr 16, 2026 Jul 6, 2005 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 linki.py in ekg 2005-06-05 and earlier allows local users to overwrite or create arbitrary files via a symlink attack on temporary files. |
2Apache Debian2Debian Linux Http ServerApr 16, 2026 Jul 5, 2005 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an HTTP proxy, allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTT...Show more |
5Debian DrupalGggeek+2 more5Debian Linux DrupalPhpxmlrpc+2 moreApr 16, 2026 Jul 5, 2005 N/A· v4 N/A· v3 7.5 HIGH· v2 Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earlier, as used in products such as (1) WordPress, (2) Serendipity, (3) Dr...Show more |
Format string vulnerability in the curses_msg function in the Ncurses interface (ec_curses.c) for Ettercap before 0.7.3 allows remote attackers to execute arbitrary code. |
popauth.c in qpopper 4.0.5 and earlier does not properly set the umask, which may cause qpopper to create files with group or world-writable permissions. |
qpopper 4.0.5 and earlier does not properly drop privileges before processing certain user-supplied files, which allows local users to overwrite or create arbitrary files as root. |
4Apple BzipCanonical+1 more4Bzip2 Debian LinuxMac Os X+1 moreApr 16, 2026 May 19, 2005 N/A· v4 N/A· v3 5.0 MEDIUM· v2 bzip2 allows remote attackers to cause a denial of service (hard drive consumption) via a crafted bzip2 file that causes an infinite loop (a.k.a "decompression bomb"). |
ppxp does not drop root privileges before opening log files, which allows local users to execute arbitrary commands. |
3Canonical DebianQmail Project3Debian Linux QmailUbuntu LinuxApr 16, 2026 May 11, 2005 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Integer overflow in the stralloc_readyplus function in qmail, when running on 64 bit platforms with a large amount of virtual memory, allows remote attackers to cause a denial of service and possibly execute arbitrary co...Show more |
3Canonical DebianGnu3Cpio Debian LinuxUbuntu LinuxApr 16, 2026 May 2, 2005 N/A· v4 4.7 MEDIUM· v3 3.7 LOW· v2 Race condition in cpio 2.6 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by cpio after the decompre...Show more |
Buffer overflow in wccp.c in Squid 2.5 before 2.5.STABLE7 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long WCCP packet, which is processed by a recvfrom function call th...Show more |
3Debian KdeRedhat5Debian Linux Enterprise LinuxEnterprise Linux Desktop+2 moreApr 16, 2026 May 2, 2005 N/A· v4 N/A· v3 4.6 MEDIUM· v2 The KDE screen saver in KDE before 3.0.5 does not properly check the return value from a certain function call, which allows attackers with physical access to cause a crash and access the desktop session. |
4Debian GentooRedhat+1 more5Debian Linux Enterprise LinuxEnterprise Linux Desktop+2 moreApr 16, 2026 May 2, 2005 N/A· v4 N/A· v3 2.1 LOW· v2 The DBI library (libdbi-perl) for Perl allows local users to overwrite arbitrary files via a symlink attack on a temporary PID file. |
Multiple buffer overflows in the XView library 3.2 may allow local users to execute arbitrary code via setuid applications that use the library. |
Buffer overflow in queue.c in a support script for sympa 3.3.3, when running setuid, allows local users to execute arbitrary code. |
6Debian GentooGraphicsmagick+3 more6Debian Linux GraphicsmagickImagemagick+3 moreApr 16, 2026 May 2, 2005 N/A· v4 N/A· v3 7.5 HIGH· v2 Heap-based buffer overflow in psd.c for ImageMagick 6.1.0, 6.1.7, and possibly earlier versions allows remote attackers to execute arbitrary code via a .PSD image file with a large number of layers. |
15Ascii CstexDebian+12 more22Advanced Linux Environment CstetexCups+19 moreApr 16, 2026 Apr 27, 2005 N/A· v4 N/A· v3 7.5 HIGH· v2 The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the origin...Show more |
1Debian 2Debian Linux Toolchain SourceApr 16, 2026 Apr 27, 2005 N/A· v4 N/A· v3 4.6 MEDIUM· v2 The tpkg-* scripts in the toolchain-source 3.0.4 package on Debian GNU/Linux 3.0 allow local users to overwrite arbitrary files via a symlink attack on temporary files. |
3Debian MariadbOracle3Debian Linux MariadbMysqlApr 16, 2026 Apr 14, 2005 N/A· v4 N/A· v3 4.6 MEDIUM· v2 The mysqlaccess script in MySQL 4.0.23 and earlier, 4.1.x before 4.1.10, 5.0.x before 5.0.3, and other versions including 3.x, allows local users to overwrite arbitrary files or read temporary files via a symlink attack...Show more |