Debian Security Vulnerabilities (CVEs)

Track 1,955 security vulnerabilities affecting Debian products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.

358 Critical
1,297 High
300 Medium
🔔 Get Alerts for Debian
CVE-2011-4625 7.5

CVE-2011-4625 is an XML encryption vulnerability in SimpleSAMLphp that allows attackers to decrypt or forge SAML messages. This affects SimpleSAMLphp ...

Nov 6, 2019
CVE-2007-0899 9.8

CVE-2007-0899 is a heap overflow vulnerability in ClamAV's libclamav/fsg.c that allows remote attackers to execute arbitrary code by sending specially...

Nov 6, 2019
CVE-2013-6364 8.8

CVE-2013-6364 is a combined CSRF and XSS vulnerability in Horde Groupware Webmail Edition that allows attackers to execute arbitrary web scripts or pe...

Nov 5, 2019
CVE-2017-5332 7.8

CVE-2017-5332 is a memory corruption vulnerability in icoutils' wrestool component that allows local users to crash processes and potentially execute ...

Nov 4, 2019
CVE-2013-4251 7.8

CVE-2013-4251 is a privilege escalation vulnerability in SciPy's scipy.weave component that creates temporary directories with insecure permissions. T...

Nov 4, 2019
CVE-2005-4890 7.8

This vulnerability allows local users to escape restricted shell sessions and execute arbitrary commands with elevated privileges. It affects systems ...

Nov 4, 2019
CVE-2019-18683 7.0

CVE-2019-18683 is a race condition vulnerability in the Linux kernel's VIVID video driver that can lead to use-after-free conditions. It allows local ...

Nov 4, 2019
CVE-2013-4412 7.5

CVE-2013-4412 is a NULL pointer dereference vulnerability in the slim display manager when using the crypt() method from glibc 2.17. This vulnerabilit...

Nov 4, 2019
CVE-2013-2600 7.5

MiniUPnPd contains an information disclosure vulnerability due to improper use of snprintf() that can leak sensitive memory contents. This affects sys...

Nov 1, 2019
CVE-2019-5010 7.5

This vulnerability allows attackers to cause denial-of-service by exploiting a NULL pointer dereference in Python's X509 certificate parser. When Pyth...

Oct 31, 2019
CVE-2013-2012 7.3

This vulnerability in autojump allows local users to escalate privileges by placing a malicious custom_install directory in the current working direct...

Oct 31, 2019
CVE-2013-1910 9.8

This vulnerability in yum (Yellowdog Updater Modified) allows attackers to cause denial of service or potentially execute arbitrary code by providing ...

Oct 31, 2019
CVE-2009-5042 9.1

CVE-2009-5042 is a vulnerability in python-docutils where insecure temporary file handling allows local attackers to create or overwrite arbitrary fil...

Oct 31, 2019
CVE-2019-18425 9.8

A privilege escalation vulnerability in Xen hypervisor allows 32-bit paravirtualized (PV) guest users to gain guest kernel privileges by exploiting mi...

Oct 31, 2019
CVE-2019-18423 8.8

This vulnerability allows ARM guest OS users with administrative privileges to cause a hypervisor crash via specially crafted XENMEM_add_to_physmap hy...

Oct 31, 2019
CVE-2019-18421 7.5

This CVE allows x86 PV guest administrators in Xen hypervisors to exploit race conditions in pagetable promotion/demotion operations, potentially gain...

Oct 31, 2019
CVE-2010-0748 9.8

This vulnerability in Transmission BitTorrent client allows attackers to cause denial of service (crash) or potentially execute arbitrary code via spe...

Oct 30, 2019
CVE-2018-5735 7.5

This vulnerability is an assertion failure in the BIND DNS server's validator component, specifically affecting Debian backports of a previous CVE-201...

Oct 30, 2019
CVE-2009-3723 7.5

CVE-2009-3723 is an access control vulnerability in Asterisk that allows SIP calls to bypass network restrictions. Attackers can make unauthorized cal...

Oct 29, 2019
CVE-2012-5577 7.5

Python keyring library versions before 0.10 created keyring files with world-readable permissions (0666), allowing any user on the system to read stor...

Oct 28, 2019
CVE-2019-11043 8.7

This vulnerability allows remote attackers to execute arbitrary code on PHP servers running vulnerable versions with specific FPM configurations. It a...

Oct 28, 2019
CVE-2019-17596 7.5

A vulnerability in Go's crypto/dsa package causes a panic when processing network traffic containing invalid DSA public keys. This can lead to denial ...

Oct 24, 2019
CVE-2019-18408 7.5

CVE-2019-18408 is a use-after-free vulnerability in libarchive's RAR archive parsing functionality. When processing specially crafted RAR archives, an...

Oct 24, 2019
CVE-2019-17498 8.1

CVE-2019-17498 is an integer overflow vulnerability in libssh2 v1.9.0 and earlier that allows a malicious SSH server to read arbitrary memory from a c...

Oct 21, 2019
CVE-2019-18197 7.5

CVE-2019-18197 is a use-after-free vulnerability in libxslt's XSLT transformation function that can lead to memory corruption. When exploited, it coul...

Oct 18, 2019
CVE-2019-17673 7.5

WordPress sites running versions before 5.2.4 are vulnerable to cache poisoning attacks on JSON GET requests due to missing Vary: Origin headers. This...

Oct 17, 2019
CVE-2019-17675 8.8

This is a Cross-Site Request Forgery (CSRF) vulnerability in WordPress admin pages that occurs due to type confusion during referer validation. Attack...

Oct 17, 2019
CVE-2019-17669 9.8

WordPress before version 5.2.4 contains a Server-Side Request Forgery (SSRF) vulnerability in URL validation that allows hex character interpretation ...

Oct 17, 2019
CVE-2019-17666 8.8

This vulnerability is a buffer overflow in the Linux kernel's Realtek wireless driver (rtlwifi) due to missing bounds checking in the rtl_p2p_noa_ie f...

Oct 17, 2019
CVE-2019-17539 9.8

This vulnerability in FFmpeg before version 4.2 allows a NULL pointer dereference in the avcodec_open2 function, potentially leading to crashes, denia...

Oct 14, 2019
CVE-2019-17542 9.8

CVE-2019-17542 is a critical heap-based buffer overflow vulnerability in FFmpeg's VQA video decoder. Attackers can exploit this by crafting malicious ...

Oct 14, 2019
CVE-2019-17533 8.2

CVE-2019-17533 is a heap-based buffer over-read vulnerability in MATIO library versions before 1.5.18. It allows attackers to read uninitialized memor...

Oct 13, 2019
CVE-2019-17531 9.8

This vulnerability allows remote code execution via Java deserialization in Jackson databind when Default Typing is enabled and the apache-log4j-extra...

Oct 12, 2019
CVE-2019-2215 7.8

CVE-2019-2215 is a use-after-free vulnerability in Android's Binder inter-process communication driver that allows a malicious local application to ga...

Oct 11, 2019
CVE-2019-17455 9.8

CVE-2019-17455 is a critical stack-based buffer over-read vulnerability in Libntlm versions through 1.5. It allows attackers to read beyond allocated ...

Oct 10, 2019
CVE-2019-17362 9.1

CVE-2019-17362 is a buffer overflow vulnerability in LibTomCrypt's UTF-8 DER decoding function that allows attackers to cause denial of service or rea...

Oct 9, 2019
CVE-2019-14846 7.8

This vulnerability in Ansible Engine allows credential disclosure through DEBUG-level logging when plugins use libraries that log credentials at that ...

Oct 8, 2019
CVE-2019-17340 8.8

This vulnerability in Xen hypervisor allows x86 guest OS users to cause denial of service or potentially gain elevated privileges by exploiting mishan...

Oct 8, 2019
CVE-2019-17342 7.0

This CVE describes a race condition vulnerability in Xen's XENMEM_exchange hypercall that allows x86 PV guest OS users to cause denial of service or p...

Oct 8, 2019
CVE-2019-17346 8.8

This vulnerability in Xen hypervisor allows x86 PV (paravirtualized) guest operating systems to cause denial of service or potentially gain elevated p...

Oct 8, 2019
CVE-2019-17041 9.8

CVE-2019-17041 is a critical heap overflow vulnerability in Rsyslog's AIX log message parser that allows remote code execution. Attackers can exploit ...

Oct 7, 2019
CVE-2018-14879 7.0

CVE-2018-14879 is a buffer overflow vulnerability in tcpdump's command-line argument parser that allows attackers to execute arbitrary code or cause d...

Oct 3, 2019
CVE-2018-14881 7.5

This vulnerability is a buffer over-read in tcpdump's BGP parser that allows attackers to cause denial of service or potentially leak memory contents....

Oct 3, 2019
CVE-2018-16227 7.5

This vulnerability is a buffer over-read in tcpdump's IEEE 802.11 parser when processing Mesh Flags subfields. It allows attackers to cause denial of ...

Oct 3, 2019
CVE-2018-16229 7.5

This vulnerability in tcpdump's DCCP parser allows attackers to cause a buffer over-read when processing malicious network packets. Systems running vu...

Oct 3, 2019
CVE-2018-16451 7.5

This vulnerability is a buffer over-read in tcpdump's SMB parser that could allow attackers to cause denial of service or potentially leak memory cont...

Oct 3, 2019
CVE-2018-14461 7.5

This vulnerability in tcpdump's LDP parser allows attackers to trigger a buffer over-read when processing specially crafted LDP packets. Systems runni...

Oct 3, 2019
CVE-2018-14463 7.5

CVE-2018-14463 is a buffer over-read vulnerability in tcpdump's VRRP parser that could allow attackers to cause denial of service or potentially leak ...

Oct 3, 2019
CVE-2018-14465 7.5

CVE-2018-14465 is a buffer over-read vulnerability in the RSVP parser of tcpdump, a network packet analyzer. It allows attackers to cause denial-of-se...

Oct 3, 2019
CVE-2018-14467 7.5

This vulnerability in tcpdump's BGP parser allows attackers to cause a buffer over-read when processing specially crafted BGP packets. Systems running...

Oct 3, 2019

Why Monitor Debian Security Vulnerabilities?

Real-time CVE tracking: Our automated system monitors 1,955+ known vulnerabilities affecting Debian products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.

Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Debian packages in under 60 seconds. No agents required - completely agentless scanning that works across Debian deployments.

Free vulnerability database: Access detailed information about every Debian CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.

🚀 Get Started in 60 Seconds

  • Register free account & add your servers
  • Run one-time scan or schedule automatic monitoring (every 1-24 hours)
  • Receive instant alerts when new Debian CVEs affect your systems
  • Access dashboard with severity breakdown & fix instructions
Start Monitoring Debian CVEs Free