Debian Security Vulnerabilities (CVEs)

Track 1,587 security vulnerabilities affecting Debian products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.

245 Critical
1,042 High
300 Medium
🔔 Get Alerts for Debian
CVE-2021-43579 7.8

CVE-2021-43579 is a stack-based buffer overflow vulnerability in HTMLDOC's BMP image processing function that allows remote code execution when proces...

Jan 10, 2022
CVE-2021-42392 9.8

CVE-2021-42392 is a critical remote code execution vulnerability in H2 Database where attackers can exploit JNDI injection through the database driver...

Jan 10, 2022
CVE-2020-29050 7.5

This CVE describes a directory traversal vulnerability in SphinxSearch that allows attackers to read arbitrary files on the server. When combined with...

Jan 10, 2022
CVE-2022-21664 7.4

CVE-2022-21664 is an SQL injection vulnerability in WordPress caused by insufficient input sanitization in a core class. This allows attackers to exec...

Jan 6, 2022
CVE-2022-21661 8.0

CVE-2022-21661 is an SQL injection vulnerability in WordPress's WP_Query class due to improper input sanitization. This allows attackers to execute ar...

Jan 6, 2022
CVE-2021-45972 7.1

CVE-2021-45972 is a stack-based buffer overflow vulnerability in giftrans 1.12.2's giftrans function, where attacker-controlled input determines how m...

Jan 1, 2022
CVE-2021-41819 7.5

This vulnerability in Ruby's CGI::Cookie.parse function mishandles security prefixes in cookie names, allowing attackers to bypass cookie security mec...

Jan 1, 2022
CVE-2021-41817 7.5

CVE-2021-41817 is a regular expression denial of service (ReDoS) vulnerability in Ruby's date gem. Attackers can cause denial of service by sending sp...

Jan 1, 2022
CVE-2021-4184 7.5

This vulnerability in Wireshark's BitTorrent DHT dissector allows attackers to cause a denial of service (DoS) by triggering an infinite loop. Attacke...

Dec 30, 2021
CVE-2021-45909 7.8

CVE-2021-45909 is a heap-based buffer overflow vulnerability in gif2apng's DecodeLZW function that allows attackers to write arbitrary data beyond buf...

Dec 28, 2021
CVE-2021-45911 7.8

CVE-2021-45911 is a heap-based buffer overflow vulnerability in gif2apng 1.9 that allows attackers to write 2 bytes outside buffer boundaries. This af...

Dec 28, 2021
CVE-2021-43845 8.2

CVE-2021-43845 is an out-of-bounds read vulnerability in PJSIP multimedia communication library versions 2.11.1 and earlier. A malicious actor can sen...

Dec 27, 2021
CVE-2021-4166 7.1

CVE-2021-4166 is an out-of-bounds read vulnerability in Vim text editor that allows attackers to read memory contents beyond allocated buffers. This a...

Dec 25, 2021
CVE-2021-45469 7.8

This vulnerability allows an attacker to trigger an out-of-bounds memory access in the Linux kernel's F2FS filesystem when processing extended attribu...

Dec 23, 2021
CVE-2021-4063 8.8

This is a use-after-free vulnerability in Chrome's developer tools that allows remote attackers to potentially exploit heap corruption via a crafted H...

Dec 23, 2021
CVE-2021-4065 8.8

This vulnerability is a use-after-free memory corruption flaw in Chrome's autofill feature that allows attackers to potentially execute arbitrary code...

Dec 23, 2021
CVE-2021-4067 8.8

This is a use-after-free vulnerability in ChromeOS's window manager that allows remote attackers to potentially exploit heap corruption via a crafted ...

Dec 23, 2021
CVE-2021-4078 8.8

This vulnerability is a type confusion flaw in Chrome's V8 JavaScript engine that allows a remote attacker to potentially exploit heap corruption. Att...

Dec 23, 2021
CVE-2021-38011 8.8

This is a use-after-free vulnerability in Chrome's storage foundation that allows remote attackers to potentially exploit heap corruption via crafted ...

Dec 23, 2021
CVE-2021-38013 9.6

This vulnerability allows a remote attacker who has already compromised a Chrome WebUI renderer process to exploit a heap buffer overflow in ChromeOS ...

Dec 23, 2021
CVE-2021-38015 8.8

This vulnerability in Google Chrome allowed malicious extensions to bypass navigation restrictions, enabling attackers to redirect users to malicious ...

Dec 23, 2021
CVE-2021-38017 8.8

This vulnerability allows attackers to bypass iframe sandbox navigation restrictions in Google Chrome, potentially enabling malicious websites to perf...

Dec 23, 2021
CVE-2021-4052 8.8

This is a use-after-free vulnerability in Google Chrome's web app component that allows heap corruption. Attackers can exploit it by tricking users in...

Dec 23, 2021
CVE-2021-4055 8.8

This vulnerability is a heap buffer overflow in Google Chrome extensions that allows an attacker to potentially exploit heap corruption. It affects us...

Dec 23, 2021
CVE-2021-4057 8.8

This is a use-after-free vulnerability in Chrome's file API that allows a remote attacker who has already compromised the renderer process to potentia...

Dec 23, 2021
CVE-2021-4061 8.8

This vulnerability is a type confusion flaw in Chrome's V8 JavaScript engine that could allow an attacker to execute arbitrary code or cause heap corr...

Dec 23, 2021
CVE-2021-38005 8.8

This is a use-after-free vulnerability in Chrome's loader component that allows remote attackers to potentially exploit heap corruption via a crafted ...

Dec 23, 2021
CVE-2021-38007 8.8

This vulnerability is a type confusion flaw in Chrome's V8 JavaScript engine that could allow a remote attacker to trigger heap corruption. Attackers ...

Dec 23, 2021
CVE-2021-40394 9.8

CVE-2021-40394 is a critical out-of-bounds write vulnerability in Gerbv's RS-274X aperture macro handling that allows remote code execution via malici...

Dec 22, 2021
CVE-2021-37706 7.3

CVE-2021-37706 is an integer underflow vulnerability in PJSIP's STUN message processing that allows remote code execution. Attackers on the same netwo...

Dec 22, 2021
CVE-2021-44733 7.0

This CVE describes a use-after-free vulnerability in the TEE subsystem of the Linux kernel caused by a race condition in tee_shm_get_from_id. Attacker...

Dec 22, 2021
CVE-2021-44224 8.2

This vulnerability in Apache HTTP Server allows attackers to crash the server via NULL pointer dereference or perform Server-Side Request Forgery (SSR...

Dec 20, 2021
CVE-2021-45098 7.5

This vulnerability allows attackers to bypass HTTP-based intrusion detection signatures in Suricata by sending a crafted RST TCP packet with random TC...

Dec 16, 2021
CVE-2021-45078 7.8

This vulnerability in GNU Binutils allows attackers to trigger a heap-based buffer overflow via the stab_xcoff_builtin_type function in stabs.c. It ca...

Dec 15, 2021
CVE-2021-43113 9.8

CVE-2021-43113 is a command injection vulnerability in iTextPDF that allows attackers to execute arbitrary commands on the server by manipulating Ghos...

Dec 15, 2021
CVE-2021-45046 9.0

CVE-2021-45046 is an incomplete fix for the Log4Shell vulnerability (CVE-2021-44228) in Apache Log4j 2.15.0 that allows attackers to execute arbitrary...

Dec 14, 2021
CVE-2021-44538 9.8

A buffer overflow vulnerability in Matrix libolm's olm_session_describe function allows remote attackers to execute arbitrary code or cause denial of ...

Dec 14, 2021
CVE-2021-44228 10.0

CVE-2021-44228 (Log4Shell) is a critical remote code execution vulnerability in Apache Log4j2 that allows attackers to execute arbitrary code by explo...

Dec 10, 2021
CVE-2021-43534 8.8

This CVE describes memory safety bugs in Mozilla products that could lead to memory corruption. With sufficient effort, attackers could potentially ex...

Dec 8, 2021
CVE-2021-43537 8.8

This vulnerability involves an incorrect type conversion from 64-bit to 32-bit integers in Mozilla products, allowing memory corruption that could lea...

Dec 8, 2021
CVE-2021-43539 8.8

A use-after-free vulnerability in Mozilla's WebAssembly (wasm) implementation could allow an attacker to cause memory corruption and potentially execu...

Dec 8, 2021
CVE-2021-38503 10.0

This vulnerability allows malicious iframes to bypass sandbox restrictions when loading XSLT stylesheets, enabling script execution and top-level fram...

Dec 8, 2021
CVE-2021-44420 7.3

This Django vulnerability allows attackers to bypass URL-based access controls by appending trailing newlines to HTTP request URLs. Attackers could ac...

Dec 8, 2021
CVE-2021-42717 7.5

CVE-2021-42717 is a denial-of-service vulnerability in ModSecurity's JSON parser where excessively nested JSON objects cause excessive CPU consumption...

Dec 7, 2021
CVE-2021-4069 7.8

CVE-2021-4069 is a use-after-free vulnerability in Vim that could allow an attacker to execute arbitrary code by tricking a user into opening a specia...

Dec 6, 2021
CVE-2021-44227 8.8

CVE-2021-44227 is a Cross-Site Request Forgery (CSRF) vulnerability in GNU Mailman that allows authenticated list members or moderators to obtain CSRF...

Dec 2, 2021
CVE-2021-4019 7.8

CVE-2021-4019 is a heap-based buffer overflow vulnerability in Vim text editor that allows attackers to execute arbitrary code by tricking users into ...

Dec 1, 2021
CVE-2019-8922 8.8

This heap-based buffer overflow vulnerability in BlueZ's bluetoothd service allows attackers to execute arbitrary code or cause denial of service by s...

Nov 29, 2021
CVE-2021-28705 7.8

This vulnerability in Xen hypervisor allows x86 HVM and PVH guests to cause memory corruption through improper error handling in partially successful ...

Nov 24, 2021
CVE-2021-28706 8.6

CVE-2021-28706 is an integer overflow vulnerability in Xen hypervisor memory management that allows virtual machine guests to exceed their allocated m...

Nov 24, 2021

Why Monitor Debian Security Vulnerabilities?

Real-time CVE tracking: Our automated system monitors 1,587+ known vulnerabilities affecting Debian products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.

Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Debian packages in under 60 seconds. No agents required - completely agentless scanning that works across Debian deployments.

Free vulnerability database: Access detailed information about every Debian CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.

🚀 Get Started in 60 Seconds

  • Register free account & add your servers
  • Run one-time scan or schedule automatic monitoring (every 1-24 hours)
  • Receive instant alerts when new Debian CVEs affect your systems
  • Access dashboard with severity breakdown & fix instructions
Start Monitoring Debian CVEs Free