Debian
debian
10,145 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,145)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
6Debian GentooMidnight Commander+3 more8Debian Linux Enterprise LinuxLinux+5 moreApr 16, 2026 Apr 14, 2005 N/A· v4 N/A· v3 7.5 HIGH· v2 Buffer underflow in extfs.c in Midnight Commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code. |
6Debian GentooMidnight Commander+3 more8Debian Linux Enterprise LinuxLinux+5 moreApr 16, 2026 Apr 14, 2005 N/A· v4 N/A· v3 7.5 HIGH· v2 fish.c in midnight commander allows remote attackers to execute arbitrary programs via "insecure filename quoting," possibly using shell metacharacters. |
6Debian GentooMidnight Commander+3 more8Debian Linux Enterprise LinuxLinux+5 moreApr 16, 2026 Apr 14, 2005 N/A· v4 N/A· v3 5.0 MEDIUM· v2 direntry.c in Midnight Commander (mc) 4.5.55 and earlier allows attackers to cause a denial of service by "manipulating non-existing file handles." |
6Debian GentooMidnight Commander+3 more8Debian Linux Enterprise LinuxLinux+5 moreApr 16, 2026 Apr 14, 2005 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service via "use of already freed memory." |
6Debian GentooMidnight Commander+3 more8Debian Linux Enterprise LinuxLinux+5 moreApr 16, 2026 Apr 14, 2005 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service by causing mc to free unallocated memory. |
6Debian GentooMidnight Commander+3 more8Debian Linux Enterprise LinuxLinux+5 moreApr 16, 2026 Apr 14, 2005 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service by triggering a null dereference. |
6Debian GentooMidnight Commander+3 more8Debian Linux Enterprise LinuxLinux+5 moreApr 16, 2026 Apr 14, 2005 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service via "a corrupt section header." |
6Debian GentooMidnight Commander+3 more8Debian Linux Enterprise LinuxLinux+5 moreApr 16, 2026 Apr 14, 2005 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service (infinite loop) via unknown attack vectors. |
6Debian GentooMidnight Commander+3 more8Debian Linux Enterprise LinuxLinux+5 moreApr 16, 2026 Apr 14, 2005 N/A· v4 N/A· v3 7.5 HIGH· v2 Multiple buffer overflows in Midnight Commander (mc) 4.5.55 and earlier allow remote attackers to have an unknown impact. |
6Debian GentooMidnight Commander+3 more8Debian Linux Enterprise LinuxLinux+5 moreApr 16, 2026 Apr 14, 2005 N/A· v4 N/A· v3 7.5 HIGH· v2 Multiple format string vulnerabilities in Midnight Commander (mc) 4.5.55 and earlier allow remote attackers to have an unknown impact. |
3Bnc DebianGentoo3Bnc Debian LinuxLinuxApr 16, 2026 Mar 1, 2005 N/A· v4 N/A· v3 10.0 HIGH· v2 Buffer overflow in the getnickuserhost function in BNC 2.8.9, and possibly other versions, allows remote IRC servers to execute arbitrary code via an IRC server response that contains many (1) ! (exclamation) or (2) @ (a...Show more |
5Debian MandrakesoftTodd Miller+2 more7Debian Linux Mandrake LinuxMandrake Linux Corporate Server+4 moreApr 16, 2026 Mar 1, 2005 N/A· v4 N/A· v3 7.2 HIGH· v2 sudo before 1.6.8p2 allows local users to execute arbitrary commands by using "()" style environment variables to create functions that have the same name as any program within the bash script that is called without usin...Show more |
3Arjsoftware DebianGentoo3Debian Linux LinuxUnarjApr 16, 2026 Mar 1, 2005 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Directory traversal vulnerability in the -x (extract) command line option in unarj allows remote attackers to overwrite arbitrary files via an arj archive with filenames that contain .. (dot dot) sequences. |
Unknown vulnerability in the passwd_check function in Shadow 4.0.4.1, and possibly other versions before 4.0.5, allows local users to conduct unauthorized activities when an error from a pam_chauthtok function call is no...Show more |
4Debian LinuxRedhat+1 more4Debian Linux Fedora CoreLinux Kernel+1 moreApr 16, 2026 Mar 1, 2005 N/A· v4 N/A· v3 7.5 HIGH· v2 Iptables before 1.2.11, under certain conditions, does not properly load the required modules at system startup, which causes the firewall rules to fail to load and protect the system from remote attackers. |
reportbug 3.2 includes settings from .reportbugrc in bug reports, which exposes sensitive information such as smtpuser and smtppasswd. |
reportbug before 2.62 creates the .reportbugrc configuration file with world-readable permissions, which allows local users to obtain email smarthost passwords. |
bsmtpd 2.3 and earlier does not properly sanitize e-mail addresses, which allows remote attackers to execute arbitrary commands. |
4Debian GentooImagemagick+1 more4Debian Linux ImagemagickLinux+1 moreApr 16, 2026 Feb 9, 2005 N/A· v4 N/A· v3 10.0 HIGH· v2 Buffer overflow in the EXIF parsing routine in ImageMagick before 6.1.0 allows remote attackers to execute arbitrary code via a certain image file. |
3Angus Mackay DebianGentoo3Debian Linux Ez IpupdateLinuxApr 16, 2026 Feb 9, 2005 N/A· v4 N/A· v3 10.0 HIGH· v2 Format string vulnerability in ez-ipupdate.c for ez-ipupdate 3.0.10 through 3.0.11b8, when running in daemon mode with certain service types in use, allows remote servers to execute arbitrary code. |