Skip to main content

Vendor/product archive

debian / debian_linux CVEs

Beta · best-effort

10,009 CVEs tagged to debian / debian_linux1,070 Critical, 4,128 High, 4,391 Medium, 418 Low, 2 Unrated.

CVE-2026-14355

Published Jul 3, 2026

In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer…

CVSS 5.6 · Medium
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-56968

Published Jun 23, 2026

GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a crafted server.

CVSS 3.7 · Low
evidence mentions
4
Buzz score
36.1
Vendor/product tagsBeta · best-effort

CVE-2026-49975

Published Jun 8, 2026

Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP…

CVSS 7.5 · High
evidence mentions
25
Buzz score
54.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-46333

Published May 15, 2026

In the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner 'get_dumpable()' logic The 'dumpability' of a task is fundamentally about the memory i…

CVSS 7.1 · High
evidence mentions
49
Buzz score
54.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-34757

Published Apr 9, 2026

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.0.9 to before 1.6.57, passing a…

CVSS 5.1 · Medium
evidence mentions
7
Buzz score
40.3
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-25506

Published Feb 10, 2026

MUNGE is an authentication service for creating and validating user credentials. From 0.5 to 0.5.17, local attacker can exploit a buffer overflow vulnerability in munged (the MUNG…

CVSS 7.7 · High
evidence mentions
22
Buzz score
46.0
Vendor/product tagsBeta · best-effort

CVE-2025-62603

Published Feb 3, 2026

Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ). ParticipantGenericMessage is the DDS Security control-messa…

CVSS 1.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2026-25061

Published Jan 29, 2026

tcpflow is a TCP/IP packet demultiplexer. In versions up to and including 1.61, wifipcap parses 802.11 management frame elements and performs a length check on the wrong field whe…

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-24765

Published Jan 27, 2026

PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of c…

CVSS 7.8 · High
evidence mentions
8
Buzz score
32.0
Vendor/product tagsBeta · best-effort

CVE-2026-24061

Published Jan 21, 2026

telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.

CVSS 9.8 · Critical
evidence mentions
23
Buzz score
88.0
KEV listedPublic PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-23490

Published Jan 16, 2026

pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to memory exhaustion from malformed RELATIVE-OID with excessive c…

CVSS 7.5 · High
evidence mentions
59
Buzz score
44.5
Vendor/product tagsBeta · best-effort

CVE-2025-68615

Published Dec 23, 2025

net-snmp is a SNMP application library, tools and daemon. Prior to versions 5.9.5 and 5.10.pre2, a specially crafted packet to an net-snmp snmptrapd daemon can cause a buffer over…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 10,009 CVEsPage 1 of 401