debian security advisories
60 threat alerts tracking vulnerabilities and security advisories that affect debian products.
Vulnios monitors debian CVE feeds, vendor advisories, CISA KEV listings, and exploit-prediction data continuously. Each alert below is enriched with severity, exploitation status, affected products, and a remediation path. Use this page to scan recent debian security news in one place, or click into an individual alert for full detail.
Critical Vulnerability: CVE-2018-5188 — debian, canonical — debian_linux, ubuntu_linux
Memory safety bugs present in Firefox 60, Firefox ESR 60, and Firefox ESR 52.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could
criticalCVE-2018-5188Critical Vulnerability: CVE-2018-5187 — debian, canonical — debian_linux, ubuntu_linux
Memory safety bugs present in Firefox 60 and Firefox ESR 60. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run
criticalCVE-2018-5187Critical Vulnerability: CVE-2018-17141 — debian, hylafax — debian_linux, hylafax
HylaFAX 6.0.6 and HylaFAX+ 5.6.0 allow remote attackers to execute arbitrary code via a dial-in session that provides a FAX page with the JPEG bit enabled, which is mishandled in FaxModem::writeECMDat
criticalCVE-2018-17141Critical Vulnerability: CVE-2018-16657 — debian, kamailio — debian_linux, kamailio
In Kamailio before 5.0.7 and 5.1.x before 5.1.4, a crafted SIP message with an invalid Via header causes a segmentation fault and crashes Kamailio. The reason is missing input validation in the crcitt
criticalCVE-2018-16657Critical Vulnerability: CVE-2015-9262 — debian, canonical — debian_linux, ubuntu_linux
_XcursorThemeInherits in library.c in libXcursor before 1.1.15 allows remote attackers to cause denial of service or potentially code execution via a one-byte heap overflow.
criticalCVE-2015-9262Critical Vulnerability: CVE-2018-14767 — debian, kamailio — debian_linux, kamailio
In Kamailio before 5.0.7 and 5.1.x before 5.1.4, a crafted SIP message with a double "To" header and an empty "To" tag causes a segmentation fault and crash. The reason is missing input validation in
criticalCVE-2018-14767Critical Vulnerability: CVE-2018-14356 — debian, mutt — debian_linux, mutt
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c mishandles a zero-length UID.
criticalCVE-2018-14356Critical Vulnerability: CVE-2018-14349 — debian, mutt — debian_linux, mutt
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/command.c mishandles a NO response without a message.
criticalCVE-2018-14349Critical Vulnerability: CVE-2018-14361 — debian, neomutt — debian_linux, neomutt
An issue was discovered in NeoMutt before 2018-07-16. nntp.c proceeds even if memory allocation fails for messages data.
criticalCVE-2018-14361Critical Vulnerability: CVE-2018-14360 — debian, neomutt — debian_linux, neomutt
An issue was discovered in NeoMutt before 2018-07-16. nntp_add_group in newsrc.c has a stack-based buffer overflow because of incorrect sscanf usage.
criticalCVE-2018-14360Critical Vulnerability: CVE-2018-12892 — debian, xen — debian_linux, xen
An issue was discovered in Xen 4.7 through 4.10.x. libxl fails to pass the readonly flag to qemu when setting up a SCSI disk, due to what was probably an erroneous merge conflict resolution. Malicious
criticalCVE-2018-12892Critical Vulnerability: CVE-2018-13043 — debian, canonical — devscripts, ubuntu_linux
scripts/grep-excuses.pl in Debian devscripts through 2.18.3 allows code execution through unsafe YAML loading because YAML::Syck is used without a configuration that prevents unintended blessing.
criticalCVE-2018-13043Critical Vulnerability: CVE-2018-13006 — debian, gpac — debian_linux, gpac
An issue was discovered in MP4Box in GPAC 0.7.1. There is a heap-based buffer over-read in the isomedia/box_dump.c function hdlr_dump.
criticalCVE-2018-13006Critical Vulnerability: CVE-2018-13005 — debian, gpac — debian_linux, gpac
An issue was discovered in MP4Box in GPAC 0.7.1. The function urn_Read in isomedia/box_code_base.c has a heap-based buffer over-read.
criticalCVE-2018-13005Critical Vulnerability: CVE-2018-5095 — debian, redhat — debian_linux, enterprise_linux
An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 8 GB of RAM. This results in the use of uninitialized memory, resulting in
criticalCVE-2018-5095Critical Vulnerability: CVE-2018-5097 — debian, redhat — debian_linux, enterprise_linux_desktop
A use-after-free vulnerability can occur during XSL transformations when the source document for the transformation is manipulated by script content during the transformation. This results in a potent
criticalCVE-2018-5097Critical Vulnerability: CVE-2018-5147 — debian, mozilla — debian_linux, firefox
The libtremor library has the same flaw as CVE-2018-5146. This library is used by Firefox in place of libvorbis on Android and ARM platforms. This vulnerability affects Firefox ESR < 52.7.2 and Firefo
criticalCVE-2018-5147Critical Vulnerability: CVE-2018-5096 — debian, redhat — debian_linux, enterprise_linux
A use-after-free vulnerability can occur while editing events in form elements on a page, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR < 52.6 and Thunderbird <
criticalCVE-2018-5096Critical Vulnerability: CVE-2018-5103 — debian, redhat — debian_linux, enterprise_linux_desktop
A use-after-free vulnerability can occur during mouse event handling due to issues with multiprocess support. This results in a potentially exploitable crash. This vulnerability affects Thunderbird <
criticalCVE-2018-5103Critical Vulnerability: CVE-2018-5104 — debian, redhat — debian_linux, enterprise_linux_desktop
A use-after-free vulnerability can occur during font face manipulation when a font face is freed while still in use, resulting in a potentially exploitable crash. This vulnerability affects Thunderbir
criticalCVE-2018-5104Critical Vulnerability: CVE-2018-5155 — debian, redhat — debian_linux, enterprise_linux_desktop
A use-after-free vulnerability can occur while adjusting layout during SVG animations with text paths. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.8, T
criticalCVE-2018-5155Critical Vulnerability: CVE-2018-5150 — debian, redhat — debian_linux, enterprise_linux_desktop
Memory safety bugs were reported in Firefox 59, Firefox ESR 52.7, and Thunderbird 52.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of thes
criticalCVE-2018-5150Critical Vulnerability: CVE-2018-5148 — debian, redhat — debian_linux, enterprise_linux_desktop
A use-after-free vulnerability can occur in the compositor during certain graphics operations when a raw pointer is used instead of a reference counted one. This results in a potentially exploitable c
criticalCVE-2018-5148Critical Vulnerability: CVE-2018-5154 — debian, redhat — debian_linux, enterprise_linux_desktop
A use-after-free vulnerability can occur while enumerating attributes during SVG animations with clip paths. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 5
criticalCVE-2018-5154Critical Vulnerability: CVE-2018-5102 — debian, redhat — debian_linux, enterprise_linux_desktop
A use-after-free vulnerability can occur when manipulating HTML media elements with media streams, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox
criticalCVE-2018-5102Critical Vulnerability: CVE-2018-5145 — debian, redhat — debian_linux, enterprise_linux_desktop
Memory safety bugs were reported in Firefox ESR 52.6. These bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code
criticalCVE-2018-5145Critical Vulnerability: CVE-2018-5091 — debian, redhat — debian_linux, enterprise_linux
A use-after-free vulnerability can occur during WebRTC connections when interacting with the DTMF timers. This results in a potentially exploitable crash. This vulnerability affects Firefox ESR < 52.6
criticalCVE-2018-5091Critical Vulnerability: CVE-2018-5159 — debian, redhat — debian_linux, enterprise_linux_desktop
An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resulting in possible out-of-bounds writes. This could lead to a potentially ex
criticalCVE-2018-5159Critical Vulnerability: CVE-2018-5099 — debian, redhat — debian_linux, enterprise_linux_desktop
A use-after-free vulnerability can occur when the widget listener is holding strong references to browser objects that have previously been freed, resulting in a potentially exploitable crash when the
criticalCVE-2018-5099Critical Vulnerability: CVE-2018-5098 — debian, redhat — debian_linux, enterprise_linux_desktop
A use-after-free vulnerability can occur when form input elements, focus, and selections are manipulated by script content. This results in a potentially exploitable crash. This vulnerability affects
criticalCVE-2018-5098Critical Vulnerability: CVE-2017-7809 — debian, redhat — debian_linux, enterprise_linux
A use-after-free vulnerability can occur when an editor DOM node is deleted prematurely during tree traversal while still bound to the document. This results in a potentially exploitable crash. This v
criticalCVE-2017-7809Critical Vulnerability: CVE-2017-5404 — debian, redhat — debian_linux, enterprise_linux
A use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and one node outside of it. This results in a potentially exploitable crash. This v
criticalCVE-2017-5404Critical Vulnerability: CVE-2017-5435 — debian, redhat — debian_linux, enterprise_linux
A use-after-free vulnerability occurs during transaction processing in the editor during design mode interactions. This results in a potentially exploitable crash. This vulnerability affects Thunderbi
criticalCVE-2017-5435Critical Vulnerability: CVE-2016-9899 — debian, redhat — debian_linux, enterprise_linux
Use-after-free while manipulating DOM events and removing audio elements due to errors in the handling of node adoption. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird
criticalCVE-2016-9899Critical Vulnerability: CVE-2017-5390 — debian, redhat — debian_linux, enterprise_linux
The JSON viewer in the Developer Tools uses insecure methods to create a communication channel for copying and viewing JSON or HTTP headers data, allowing for potential privilege escalation. This vuln
criticalCVE-2017-5390Critical Vulnerability: CVE-2017-7793 — debian, redhat — debian_linux, enterprise_linux
A use-after-free vulnerability can occur in the Fetch API when the worker or the associated window are freed when still in use, resulting in a potentially exploitable crash. This vulnerability affects
criticalCVE-2017-7793Critical Vulnerability: CVE-2017-5464 — debian, redhat — debian_linux, enterprise_linux
During DOM manipulations of the accessibility tree through script, the DOM tree can become out of sync with the accessibility tree, leading to memory corruption and a potentially exploitable crash. Th
criticalCVE-2017-5464Critical Vulnerability: CVE-2017-5398 — debian, redhat — debian_linux, enterprise_linux_desktop
Memory safety bugs were reported in Thunderbird 45.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitr
criticalCVE-2017-5398Critical Vulnerability: CVE-2017-5472 — debian, redhat — debian_linux, enterprise_linux
A use-after-free vulnerability with the frameloader during tree reconstruction while regenerating CSS layout when attempting to use a node in the tree that no longer exists. This results in a potentia
criticalCVE-2017-5472Critical Vulnerability: CVE-2017-7802 — debian, redhat — debian_linux, enterprise_linux
A use-after-free vulnerability can occur when manipulating the DOM during the resize event of an image element. If these elements have been freed due to a lack of strong references, a potentially expl
criticalCVE-2017-7802Critical Vulnerability: CVE-2017-5401 — debian, redhat — debian_linux, enterprise_linux
A crash triggerable by web content in which an "ErrorResult" references unassigned memory due to a logic error. The resulting crash may be exploitable. This vulnerability affects Firefox < 52, Firefox
criticalCVE-2017-5401Critical Vulnerability: CVE-2017-5465 — debian, redhat — debian_linux, enterprise_linux
An out-of-bounds read while processing SVG content in "ConvolvePixel". This results in a crash and also allows for otherwise inaccessible memory being copied into SVG graphic content, which could then
criticalCVE-2017-5465Critical Vulnerability: CVE-2017-5380 — debian, redhat — debian_linux, enterprise_linux
A potential use-after-free found through fuzzing during DOM manipulation of SVG content. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
criticalCVE-2017-5380Critical Vulnerability: CVE-2017-7753 — debian, redhat — debian_linux, enterprise_linux
An out-of-bounds read occurs when applying style rules to pseudo-elements, such as ::first-line, using cached style data. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox
criticalCVE-2017-7753Critical Vulnerability: CVE-2017-7750 — debian, redhat — debian_linux, enterprise_linux
A use-after-free vulnerability during video control operations when a "<track>" element holds a reference to an older window if that window has been replaced in the DOM. This results in a potentially
criticalCVE-2017-7750Critical Vulnerability: CVE-2017-5446 — debian, redhat — debian_linux, enterprise_linux
An out-of-bounds read when an HTTP/2 connection to a servers sends "DATA" frames with incorrect data content. This leads to a potentially exploitable crash. This vulnerability affects Thunderbird < 52
criticalCVE-2017-5446Critical Vulnerability: CVE-2017-7801 — debian, redhat — debian_linux, enterprise_linux
A use-after-free vulnerability can occur while re-computing layout for a "marquee" element during window resizing where the updated style object is freed while still in use. This results in a potentia
criticalCVE-2017-7801Critical Vulnerability: CVE-2016-9893 — debian, redhat — debian_linux, enterprise_linux
Memory safety bugs were reported in Thunderbird 45.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitr
criticalCVE-2016-9893Critical Vulnerability: CVE-2017-5441 — debian, redhat — debian_linux, enterprise_linux
A use-after-free vulnerability when holding a selection during scroll events. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefo
criticalCVE-2017-5441Critical Vulnerability: CVE-2017-5469 — debian, redhat — debian_linux, enterprise_linux
Fixed potential buffer overflows in generated Firefox code due to CVE-2016-6354 issue in Flex. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
criticalCVE-2017-5469Critical Vulnerability: CVE-2017-5402 — debian, redhat — debian_linux, enterprise_linux
A use-after-free can occur when events are fired for a "FontFace" object after the object has been already been destroyed while working with fonts. This results in a potentially exploitable crash. Thi
criticalCVE-2017-5402Critical Vulnerability: CVE-2017-7810 — debian, redhat — debian_linux, enterprise_linux_desktop
Memory safety bugs were reported in Firefox 55 and Firefox ESR 52.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploite
criticalCVE-2017-7810Critical Vulnerability: CVE-2017-5470 — debian, redhat — debian_linux, enterprise_linux
Memory safety bugs were reported in Firefox 53 and Firefox ESR 52.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploite
criticalCVE-2017-5470Critical Vulnerability: CVE-2017-7751 — debian, redhat — debian_linux, enterprise_linux
A use-after-free vulnerability with content viewer listeners that results in a potentially exploitable crash. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
criticalCVE-2017-7751Critical Vulnerability: CVE-2017-5376 — debian, redhat — debian_linux, enterprise_linux
Use-after-free while manipulating XSL in XSLT documents. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
criticalCVE-2017-5376Critical Vulnerability: CVE-2017-7826 — debian, redhat — debian_linux, enterprise_linux_desktop
Memory safety bugs were reported in Firefox 56 and Firefox ESR 52.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploite
criticalCVE-2017-7826Critical Vulnerability: CVE-2017-7800 — debian, redhat — debian_linux, enterprise_linux
A use-after-free vulnerability can occur in WebSockets when the object holding the connection is freed before the disconnection operation is finished. This results in an exploitable crash. This vulner
criticalCVE-2017-7800Critical Vulnerability: CVE-2016-9898 — debian, redhat — debian_linux, enterprise_linux
Use-after-free resulting in potentially exploitable crash when manipulating DOM subtrees in the Editor. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
criticalCVE-2016-9898Critical Vulnerability: CVE-2017-7779 — debian, redhat — debian_linux, enterprise_linux_desktop
Memory safety bugs were reported in Firefox 54, Firefox ESR 52.2, and Thunderbird 52.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of thes
criticalCVE-2017-7779Critical Vulnerability: CVE-2017-5442 — debian, redhat — debian_linux, enterprise_linux
A use-after-free vulnerability during changes in style when manipulating DOM elements. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.
criticalCVE-2017-5442
Showing the 60 most recent. Older alerts are archived but still reachable via search and the main feed.
Track debian exposure across your environment
Vulnios automatically cross-references your asset inventory against new debian CVEs and surfaces only what affects you. No more sifting manually — actionable findings only.
Start a free scan