Security Bugs

(Total: 1593, 21-40, 69.8808 ms)

# Comment Popcon Updated Title

#1100699

normal

done

  13

  56022

3 months ago
screen hardcopy and screen-exchange are insecure by default

#913772

wishlist

pending-fixed

  13

  6118

about 1 year ago
pristine-tar please add -S (sign commit) option
stable testing unstable

#662960

wishlist

  12

  1986

6 months ago
QA ssmtp ssmtp doesn't validate server TLS certificates
stable testing unstable

#1003027

serious

done

  12

  1528

over 4 years ago
roundcube CVE-2021-46144: XSS vulnerability via HTML messages with malicious CSS content
unstable

#950372

normal

  12

  539

8 months ago
src:radare2 Is radare2 suitable for stable Debian releases?

#1146594

normal

done

  12

  26

7 days ago
glance CVE-2026-71196, CVE-2026-71197, CVE-2026-71198, OSSA-2026-038: Multiple SSRF vulnerabilities in Glance web-download and HTTP image APIs

#1109340

normal

done

  12

  0

5 months ago
cpp-httplib CVE-2025-52887 CVE-2025-53628 CVE-2025-53629

#486914

normal

  11

  7197

about 1 year ago
spamassassin Default: spamd runs as root (uid/gid 0)
stable testing unstable

#1108729

normal

done

  11

  107868

about 1 year ago
src:djvulibre djvulibre: CVE-2025-53367

#1142937

normal

done

  11

  36

23 days ago
src:neutron Neutron sub-resource APIs do not verify parent ownership

#987360

important

  11

  316

over 2 years ago
swaylock Occassional unlock without password entered
testing unstable

#1144145

normal

done

  11

  4

17 days ago
src:designate CVE-2026-71193, CVE-2026-71194 / OSSA-2026-034: Cross-tenant DNS zone overlap and mDNS DoS via pool scheduling

#765017

normal

  11

  36946

almost 5 years ago
spice-client-glib-usb-acl-helper SECURITY - normal users are allowed full access to USB devices per default
stable testing unstable

#1036938

normal

  11

  7758

11 months ago
libpodofo0.9.8 Debian Bug Tracking System <submit@bugs.debian.org>

#1109251

normal

  11

  9698

about 1 year ago
devscripts /usr/bin/uscan: uscan must not skip OpenPGP check after failed check in previous run

#788634

important

  11

  119

about 11 years ago
debian-installer Accepting a preseed URL from DHCP allows attacker to hijack installation
stable testing unstable

#1142717

normal

done

  10

  196075

11 days ago
src:glib2.0 glib2.0: CVE-2026-16118

#1103832

normal

  10

  206571

3 months ago
src:shadow shadow: CVE-2024-56433

#1036806

normal

  10

  113

about 1 year ago
src:matrix-synapse matrix-synapse: not suitable for inclusion in trixie

#782001

important

  10

  251368

about 4 years ago
adduser general: access granted to /home files of another user
stable testing unstable

(Total: 1593, 21-40, 69.8808 ms)