About “Debian”

A curated feed of “Debian”-related CVEs appears below. We currently track 370 CVEs for this tag (all time). In the last 365 days, 95 were published. Average CVSS is 6.5 (all time; 6.8 over 365d), and 45% are rated High/Critical (all time). Top CWEs (last 365 days): CWE-416 - Use After Free, CWE-476 - NULL Pointer Dereference, CWE-125 - Out-of-bounds Read.

In our taxonomy this topic maps to a MODERATE impact class. Issues here typically affect operating system packages or kernels. Plan reboots or service restarts and coordinate rollouts across fleets. Use the filters below to sort by CVSS, risk and CWE. Each detail page highlights vendor advisories and mitigation tips.

CVEs tagged with this topic. Filters apply to the whole list (loaded from JSON).

CVSS ≥ 0.0
1999-02-18
High

CVE-2000-0367

Vulnerability in eterm 0.8.8 in Debian GNU/Linux allows an attacker to gain root privileges.

1999-02-16
Low

CVE-1999-0374

Debian GNU/Linux cfengine package is susceptible to a symlink attack.

1999-02-01
High

CVE-1999-0373

Buffer overflow in the "Super" utility in Debian GNU/Linux, and other operating systems, allows local users to execute commands as root.

1999-01-17
Medium

CVE-1999-0678

A default configuration of Apache on Debian GNU/Linux sets the ServerRoot to /usr/doc, which allows remote users to read documentation files for the entire server.

1999-01-03
High

CVE-1999-0389

Buffer overflow in the bootp server in the Debian Linux netstd package.

High

CVE-1999-0914

Buffer overflow in the FTP client in the Debian GNU/Linux netstd package.

1999-01-01
Critical

CVE-1999-0698

Denial of service in IP protocol logger (ippl) on Red Hat and Debian Linux.

1998-11-26
High

CVE-1999-1411

The installation of the fsp package 2.71-10 in Debian GNU/Linux 2.0 adds the anonymous FTP user without notifying the administrator, which could automatically enable anonymous FTP on some servers suc…

1998-04-28
High

CVE-1999-1390

suidexec in suidmanager 0.18 on Debian 2.0 allows local users to gain root privileges by specifying a malicious program on the command line.

1996-07-16
Low

CVE-1999-1572

cpio on FreeBSD 2.1.0, Debian GNU/Linux 3.0, and possibly other operating systems, uses a 0 umask when creating files using the -O (archive) or -F options, which creates the files with mode 0666 and…