debian
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting debian.
- CVE-2026-12996A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to potentially cause a denial of service or leak memory via crafted packets during TL...8.1
- CVE-2026-14355ext/openssl: Memory corruption in openssl_encrypt with AES-WRAP-PAD5.6
- CVE-2026-56968GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a crafted server.3.7
- CVE-2026-11853Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. Debian source packages (.dsc) and upload artifacts (.changes) are manifest files that name the file...6.5
- CVE-2026-11852Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. Files managed by debusine are organized into artifacts. The endpoints that create and delete relati...6.5
- CVE-2026-49975Apache HTTP Server: mod_http2 denial of service7.5
- CVE-2026-46333ptrace: slightly saner 'get_dumpable()' logic7.1
- CVE-2026-31431crypto: algif_aead - Revert to operating out-of-placeKEV7.8
- CVE-2026-41082In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.7.3
- CVE-2026-34757LIBPNG has a yse-after-free in png_set_PLTE, png_set_tRNS and png_set_hIST leading to corrupted chunk data and potential heap information disclosure5.1
- CVE-2026-4775Libtiff: libtiff: arbitrary code execution or denial of service via signed integer overflow in tiff file processing7.8
- CVE-2026-1940Gstreamer: incomplete fix of cve-2026-19405.1
- CVE-2025-63261AWStats 8.0 is vulnerable to Command Injection via the open function7.8
- CVE-2026-3497Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerability affects the GSSAPI patches added by various Linux distributions and does not affect the OpenSSH...7.5
- CVE-2026-2219It was discovered that dpkg-deb (a component of dpkg, the Debian package management system) does not properly validate the end of the data stream when uncompressing a zstd-compressed .deb archive, ...7.5