Debian / Debian Linux
9,996 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-12996 | OpenVPN: OpenVPN: Denial of Service or memory leak via crafted packets | MEDIUM | 6.0 | Jul 30, 2026 |
| CVE-2026-14355 | ext/openssl: Memory corruption in openssl_encrypt with AES-WRAP-PAD | MEDIUM | 5.6 | Jul 3, 2026 |
| CVE-2026-56968 | GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a craf… | MEDIUM | 5.3 | Jun 23, 2026 |
| CVE-2026-49975 | Apache HTTP Server: mod_http2 denial of service | HIGH | 7.5 | Jun 8, 2026 |
| CVE-2026-9256 | NGINX ngx_http_rewrite_module vulnerability | CRITICAL | 9.2 | May 22, 2026 |
| CVE-2026-46333 | ptrace: slightly saner 'get_dumpable()' logic | HIGH | 7.8 | May 15, 2026 |
| CVE-2026-31431 KEV | crypto: algif_aead - Revert to operating out-of-place | HIGH | 7.8 | Apr 22, 2026 |
| CVE-2026-41082 | ocaml-opam: path traversal via the .install field | HIGH | 7.8 | Apr 16, 2026 |
| CVE-2026-34757 | LIBPNG has a yse-after-free in png_set_PLTE, png_set_tRNS and png_set_hIST leading to corrupted chunk data and potential heap information disclosure | MEDIUM | 5.1 | Apr 9, 2026 |
| CVE-2026-4775 | Libtiff: libtiff: arbitrary code execution or denial of service via signed integer overflow in tiff file processing | HIGH | 7.8 | Mar 24, 2026 |
| CVE-2026-1940 | Gstreamer: incomplete fix of cve-2026-1940 | HIGH | 7.5 | Mar 23, 2026 |
| CVE-2025-63261 | AWStats 8.0 is vulnerable to Command Injection via the open function | HIGH | 7.8 | Mar 20, 2026 |
| CVE-2026-3497 | openssh: OpenSSH GSSAPI: Information disclosure or denial of service due to uninitialized variables | MEDIUM | 6.9 | Mar 12, 2026 |
| CVE-2026-25506 | MUNGE has a buffer overflow in message unpacking allows key leakage and credential forgery | HIGH | 7.8 | Feb 10, 2026 |
| CVE-2025-64098 | FastDDS has Out-of-memory in readOctetVector via Manipulated DATA Submessage when DDS Security is enabled | LOW | 1.7 | Feb 3, 2026 |
| CVE-2025-62799 | FastDDS's heap buffer overflow in RTPS DATA_FRAG enables unauthenticated DoS (potential RCE) | HIGH | 7.2 | Feb 3, 2026 |
| CVE-2025-62603 | FastDDS has Out-of-memory while parsing GenericMessage when DDS Security is enabled | LOW | 1.7 | Feb 3, 2026 |
| CVE-2025-62602 | FastDDS has heap buffer overflow in readData via Manipulated DATA Submessage when DDS Security is enabled | LOW | 1.7 | Feb 3, 2026 |
| CVE-2025-62600 | eprosima Fast DDS affected by Out-of-Memory in readBinaryPropertySeq via Manipulated DATA Submessage when DDS Security is enabled | HIGH | 8.6 | Feb 3, 2026 |
| CVE-2025-62599 | eprosima Fast DDS affected by Out-of-Memory in readPropertySeq via Manipulated DATA Submessage when DDS Security is enabled | HIGH | 8.6 | Feb 3, 2026 |
| CVE-2026-25061 | tcpflow has TIM Element OOB Write in wifipcap | MEDIUM | 5.5 | Jan 29, 2026 |
| CVE-2026-24765 | PHPUnit Vulnerable to Unsafe Deserialization in PHPT Code Coverage Handling | HIGH | 7.8 | Jan 27, 2026 |
| CVE-2025-68670 | xrdp improperly checks bounds of domain string length, which leads to Stack-based Buffer Overflow | CRITICAL | 9.8 | Jan 27, 2026 |
| CVE-2026-24061 KEV | telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable. | CRITICAL | 9.8 | Jan 21, 2026 |
| CVE-2026-23490 | pyasn1 has a DoS vulnerability in decoder | HIGH | 7.5 | Jan 16, 2026 |
Showing 1 to 25 of 9,996 CVEs