You are here
Debian Security
DSA-6092-1 smb4k - security update
DSA-6090-1 rails - security update
DSA-6091-1 wordpress - security update
DSA-6089-1 chromium - security update
DSA-6088-1 php8.4 - security update
DSA-6087-1 roundcube - security update
DSA-6086-1 dropbear - security update
The oldstable distribution (bookworm) is not affected.
DSA-6085-1 mediawiki - security update
DSA-6084-1 c-ares - security update
DSA-6083-1 webkit2gtk - security update
CVE-2025-14174
Apple and the Google Threat Analysis Group discovered that processing maliciously crafted web content may lead to memory corruption. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-43529 was also issued in response to this report.
CVE-2025-43501
Hossein Lotfi discovered that processing maliciously crafted web content may lead to an unexpected process crash.
CVE-2025-43529
The Google Threat Analysis Group discovered that processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 was also issued in response to this report.
CVE-2025-43531
Phil Pizlo discovered that processing maliciously crafted web content may lead to an unexpected process crash.
CVE-2025-43535
Google Big Sleep / Nan Wang discovered that processing maliciously crafted web content may lead to an unexpected process crash.
CVE-2025-43536
Nan Wang discovered that processing maliciously crafted web content may lead to an unexpected process crash.
CVE-2025-43541
Hossein Lotfi discovered that processing maliciously crafted web content may lead to an unexpected process crash.
DSA-6082-1 vlc - security update
DSA-6081-1 thunderbird - security update
DSA-6080-1 chromium - security update
DSA-6079-1 ffmpeg - security update
DSA-6078-1 firefox-esr - security update
DSA-6077-1 pdns-recursor - security update
DSA-6076-1 libpng1.6 - security update
DSA-6075-1 wordpress - security update
DSA-6074-1 webkit2gtk - security update
CVE-2025-13947
Janet Black discovered that a website may be able to exfiltrate sensitive system information.
CVE-2025-43421
Nan Wang discovered that processing maliciously crafted web content may lead to an unexpected process crash.
CVE-2025-43458
Phil Beauvoir discovered that processing maliciously crafted web content may lead to an unexpected process crash.
CVE-2025-66287
Stanislav Fort discovered that processing maliciously crafted web content may lead to an unexpected process crash.
