Debian Security Vulnerabilities (CVEs)

Track 1,826 security vulnerabilities affecting Debian products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.

320 Critical
1,206 High
300 Medium
🔔 Get Alerts for Debian
CVE-2021-28702 7.6

This vulnerability allows PCI devices with Reserved Memory Region Reporting (RMRR) to be improperly deassigned when passed through to virtual machine ...

Oct 6, 2021
CVE-2021-32762 7.5

This CVE describes an integer overflow vulnerability in Redis' hiredis library that affects redis-cli and redis-sentinel when parsing large multi-bulk...

Oct 4, 2021
CVE-2021-41099 7.5

CVE-2021-41099 is an integer overflow vulnerability in Redis' string library that allows heap corruption when the proto-max-bulk-len configuration is ...

Oct 4, 2021
CVE-2021-32627 7.5

CVE-2021-32627 is an integer overflow vulnerability in Redis that allows remote attackers to corrupt heap memory by setting configuration parameters t...

Oct 4, 2021
CVE-2021-32675 7.5

CVE-2021-32675 is a memory allocation vulnerability in Redis where specially crafted RESP protocol requests can cause excessive memory consumption, po...

Oct 4, 2021
CVE-2021-3653 8.8

A vulnerability in KVM's AMD SVM nested virtualization allows a malicious L1 guest to enable AVIC support for L2 guests, bypassing proper validation. ...

Sep 29, 2021
CVE-2021-32273 7.8

CVE-2021-32273 is a stack buffer overflow vulnerability in the ftypin function of faad2 MP4/AAC audio decoder library. It allows remote attackers to e...

Sep 20, 2021
CVE-2021-32277 7.8

This vulnerability in faad2 audio decoding library allows heap buffer overflow in the sbr_qmf_analysis_32 function, potentially enabling remote code e...

Sep 20, 2021
CVE-2021-38300 7.8

This vulnerability in the Linux kernel's MIPS BPF JIT compiler allows unprivileged users to execute arbitrary code with kernel privileges. It affects ...

Sep 20, 2021
CVE-2021-41073 7.8

This is a local privilege escalation vulnerability in the Linux kernel's io_uring subsystem. It allows local users to trigger a use-after-free conditi...

Sep 19, 2021
CVE-2021-3805 7.5

CVE-2021-3805 is a prototype pollution vulnerability in the object-path npm package that allows attackers to modify JavaScript object prototypes, pote...

Sep 17, 2021
CVE-2020-21598 8.8

CVE-2020-21598 is a heap buffer overflow vulnerability in libde265 v1.0.4's ff_hevc_put_unweighted_pred_8_sse function that allows remote code executi...

Sep 16, 2021
CVE-2021-36160 7.5

CVE-2021-36160 is an out-of-bounds read vulnerability in Apache HTTP Server's mod_proxy_uwsgi module. A specially crafted URI path can cause the serve...

Sep 16, 2021
CVE-2021-39275 9.8

CVE-2021-39275 is a critical buffer overflow vulnerability in Apache HTTP Server's ap_escape_quotes() function that could allow remote code execution ...

Sep 16, 2021
CVE-2021-41079 7.5

This vulnerability in Apache Tomcat allows denial of service attacks when using specific TLS configurations. Attackers can send specially crafted TLS ...

Sep 16, 2021
CVE-2021-3778 7.8

CVE-2021-3778 is a heap-based buffer overflow vulnerability in Vim text editor that could allow attackers to execute arbitrary code or cause denial of...

Sep 15, 2021
CVE-2021-39201 7.6

This vulnerability allows authenticated low-privileged WordPress users (like contributors or authors) to execute cross-site scripting (XSS) attacks in...

Sep 9, 2021
CVE-2021-3761 7.5

This vulnerability allows any Certificate Authority (CA) issuer in the Resource Public Key Infrastructure (RPKI) to trick OctoRPKI versions prior to 1...

Sep 9, 2021
CVE-2021-40346 7.5

CVE-2021-40346 is an integer overflow vulnerability in HAProxy's HTTP header processing that enables HTTP request smuggling attacks. This allows attac...

Sep 8, 2021
CVE-2021-28701 7.8

CVE-2021-28701 is a race condition vulnerability in Xen's grant table v2 status page handling that allows guest VMs to retain access to freed memory p...

Sep 8, 2021
CVE-2021-39256 7.8

This vulnerability allows an attacker to trigger a heap-based buffer overflow by providing a malicious NTFS image to NTFS-3G. Systems using NTFS-3G ve...

Sep 7, 2021
CVE-2021-39258 7.8

CVE-2021-39258 is an out-of-bounds read vulnerability in NTFS-3G that allows attackers to read sensitive memory contents from a crafted NTFS image. Th...

Sep 7, 2021
CVE-2021-39260 7.8

This vulnerability in NTFS-3G allows attackers to trigger an out-of-bounds memory access by providing a malicious NTFS image. When exploited, it can l...

Sep 7, 2021
CVE-2021-39262 7.8

CVE-2021-39262 is an out-of-bounds memory access vulnerability in NTFS-3G's decompression function that can be triggered by a specially crafted NTFS i...

Sep 7, 2021
CVE-2020-19131 7.5

This vulnerability is a buffer overflow in LibTiff's tiffcrop utility that allows attackers to cause denial of service through the invertImage() funct...

Sep 7, 2021
CVE-2021-33287 7.8

A heap buffer overflow vulnerability in NTFS-3G allows attackers to write to arbitrary memory or cause denial of service when reading specially crafte...

Sep 7, 2021
CVE-2021-35267 7.8

A stack buffer overflow vulnerability in NTFS-3G versions before 2021.8.22 allows local attackers to execute arbitrary code or escalate privileges whe...

Sep 7, 2021
CVE-2021-39252 7.8

CVE-2021-39252 is an out-of-bounds read vulnerability in NTFS-3G's ntfs_ie_lookup function. Attackers can exploit this by mounting a specially crafted...

Sep 7, 2021
CVE-2021-39254 7.8

CVE-2021-39254 is an integer overflow vulnerability in NTFS-3G that can lead to heap-based buffer overflow when processing a malicious NTFS image. Thi...

Sep 7, 2021
CVE-2021-33285 7.8

A heap buffer overflow vulnerability in NTFS-3G allows memory disclosure or denial of service when mounting a specially crafted NTFS partition. Attack...

Sep 7, 2021
CVE-2021-35268 7.8

This vulnerability allows attackers to execute arbitrary code and escalate privileges by exploiting a heap buffer overflow in NTFS-3G when processing ...

Sep 7, 2021
CVE-2021-40516 7.5

CVE-2021-40516 is an out-of-bounds read vulnerability in WeeChat's Relay plugin that allows remote attackers to crash the application via specially cr...

Sep 5, 2021
CVE-2021-40490 7.0

A race condition vulnerability in the ext4 filesystem's inline data handling in Linux kernel versions up to 5.13.13 allows local attackers to corrupt ...

Sep 3, 2021
CVE-2021-39847 7.8

CVE-2021-39847 is a stack-based buffer overflow vulnerability in Adobe XMP Toolkit SDK versions 2020.1 and earlier. It allows arbitrary code execution...

Sep 1, 2021
CVE-2021-36064 7.8

CVE-2021-36064 is a buffer underflow vulnerability in Adobe XMP Toolkit that could allow arbitrary code execution when a user opens a malicious file. ...

Sep 1, 2021
CVE-2021-36046 7.8

CVE-2021-36046 is a memory corruption vulnerability in Adobe XMP Toolkit versions 2020.1 and earlier that could allow arbitrary code execution when pr...

Sep 1, 2021
CVE-2021-36048 7.8

CVE-2021-36048 is an improper input validation vulnerability in Adobe XMP Toolkit SDK that could allow arbitrary code execution when a user opens a ma...

Sep 1, 2021
CVE-2021-36050 7.8

CVE-2021-36050 is a heap-based buffer overflow vulnerability in Adobe XMP Toolkit SDK that could allow arbitrary code execution when processing malici...

Sep 1, 2021
CVE-2021-36055 7.8

CVE-2021-36055 is a use-after-free vulnerability in Adobe XMP Toolkit SDK that could allow arbitrary code execution when a user opens a malicious file...

Sep 1, 2021
CVE-2021-37712 8.2

This vulnerability in the npm tar package allows attackers to bypass symlink checks by exploiting Unicode normalization and Windows short path behavio...

Aug 31, 2021
CVE-2020-35633 8.8

This vulnerability allows remote code execution through a specially crafted file that triggers an out-of-bounds read and type confusion in CGAL's Nef ...

Aug 30, 2021
CVE-2020-35635 8.8

This vulnerability allows remote code execution through an out-of-bounds read and type confusion in CGAL's Nef polygon-parsing functionality. Attacker...

Aug 30, 2021
CVE-2021-28697 7.8

This Xen hypervisor vulnerability allows guest virtual machines to retain access to freed memory pages after switching from grant table v2 to v1. A ra...

Aug 27, 2021
CVE-2021-40153 8.1

This vulnerability in Squashfs-Tools allows directory traversal attacks during archive extraction. Attackers can craft malicious squashfs archives tha...

Aug 27, 2021
CVE-2021-3713 7.4

This vulnerability allows a malicious guest user in QEMU virtual machines to perform out-of-bounds writes in the UAS device emulation, potentially lea...

Aug 25, 2021
CVE-2021-21840 8.8

This integer overflow vulnerability in GPAC's MPEG-4 decoder allows heap-based buffer overflow via specially crafted video files. Attackers can achiev...

Aug 25, 2021
CVE-2021-21842 8.8

This vulnerability allows remote code execution through a specially crafted MPEG-4 video file. Attackers can exploit an integer overflow in GPAC's MPE...

Aug 25, 2021
CVE-2021-21849 8.8

An integer overflow vulnerability in GPAC's MPEG-4 decoder allows heap-based buffer overflow via specially crafted video files. Attackers can exploit ...

Aug 25, 2021
CVE-2021-30951 8.8

This is a use-after-free vulnerability in Apple's WebKit browser engine that could allow arbitrary code execution when processing malicious web conten...

Aug 24, 2021
CVE-2021-30953 8.8

This vulnerability allows attackers to execute arbitrary code on affected Apple devices by tricking users into visiting malicious web pages. It affect...

Aug 24, 2021

Why Monitor Debian Security Vulnerabilities?

Real-time CVE tracking: Our automated system monitors 1,826+ known vulnerabilities affecting Debian products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.

Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Debian packages in under 60 seconds. No agents required - completely agentless scanning that works across Debian deployments.

Free vulnerability database: Access detailed information about every Debian CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.

🚀 Get Started in 60 Seconds

  • Register free account & add your servers
  • Run one-time scan or schedule automatic monitoring (every 1-24 hours)
  • Receive instant alerts when new Debian CVEs affect your systems
  • Access dashboard with severity breakdown & fix instructions
Start Monitoring Debian CVEs Free