Security Bugs
(Total: 1593, 21-40, 69.8808 ms)
| # | Comment | Popcon | Updated | Title |
|---|---|---|---|---|
|
normal done |
13 |
56022 |
3 months ago |
screen hardcopy and screen-exchange are insecure by default
|
|
wishlist pending-fixed |
13 |
6118 |
about 1 year ago |
pristine-tar please add -S (sign commit) option
stable
testing
unstable
|
|
wishlist |
12 |
1986 |
6 months ago |
QA
ssmtp ssmtp doesn't validate server TLS certificates
stable
testing
unstable
|
|
serious done |
12 |
1528 |
over 4 years ago |
roundcube CVE-2021-46144: XSS vulnerability via HTML messages with malicious CSS content
unstable
|
|
normal
|
12 |
539 |
8 months ago |
src:radare2 Is radare2 suitable for stable Debian releases?
|
|
normal done |
12 |
26 |
7 days ago |
glance CVE-2026-71196, CVE-2026-71197, CVE-2026-71198, OSSA-2026-038: Multiple SSRF vulnerabilities in Glance web-download and HTTP image APIs
|
|
normal done |
12 |
0 |
5 months ago |
cpp-httplib CVE-2025-52887 CVE-2025-53628 CVE-2025-53629
|
|
normal |
11 |
7197 |
about 1 year ago |
spamassassin Default: spamd runs as root (uid/gid 0)
stable
testing
unstable
|
|
normal done |
11 |
107868 |
about 1 year ago |
src:djvulibre djvulibre: CVE-2025-53367
|
|
normal done |
11 |
36 |
23 days ago |
src:neutron Neutron sub-resource APIs do not verify parent ownership
|
|
important |
11 |
316 |
over 2 years ago |
swaylock Occassional unlock without password entered
testing
unstable
|
|
normal done |
11 |
4 |
17 days ago |
src:designate CVE-2026-71193, CVE-2026-71194 / OSSA-2026-034: Cross-tenant DNS zone overlap and mDNS DoS via pool scheduling
|
|
normal |
11 |
36946 |
almost 5 years ago |
spice-client-glib-usb-acl-helper SECURITY - normal users are allowed full access to USB devices per default
stable
testing
unstable
|
|
normal |
11 |
7758 |
11 months ago |
libpodofo0.9.8 Debian Bug Tracking System <submit@bugs.debian.org>
|
|
normal |
11 |
9698 |
about 1 year ago |
devscripts /usr/bin/uscan: uscan must not skip OpenPGP check after failed check in previous run
|
|
important |
11 |
119 |
about 11 years ago |
debian-installer Accepting a preseed URL from DHCP allows attacker to hijack installation
stable
testing
unstable
|
|
normal done |
10 |
196075 |
11 days ago |
src:glib2.0 glib2.0: CVE-2026-16118
|
|
normal |
10 |
206571 |
3 months ago |
src:shadow shadow: CVE-2024-56433
|
|
normal |
10 |
113 |
about 1 year ago |
src:matrix-synapse matrix-synapse: not suitable for inclusion in trixie
|
|
important |
10 |
251368 |
about 4 years ago |
adduser general: access granted to /home files of another user
stable
testing
unstable
|
(Total: 1593, 21-40, 69.8808 ms)