cbcvebase.

Debian Linux vulnerabilities

9,953 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358

Vulnerabilities

Page 101 of 498
CVE-2015-5300P3HIGHCVSS 7.5v7.0v8.02017-07-21
CVE-2015-5300 [HIGH] CWE-361 CVE-2015-5300: The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system c The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseconds by default, which allows remote attackers to set NTP to an arbitrary time when started with the -g option, or to alter the time by up to 900 seconds otherwise by responding to an unspecified number of requests f
nvd
CVE-2021-20305P3HIGHCVSS 8.1v9.0v10.02021-04-05
CVE-2021-20305 [HIGH] CWE-327 CVE-2021-20305: A flaw was found in Nettle in versions before 3.7.2, where several Nettle signature verification fun A flaw was found in Nettle in versions before 3.7.2, where several Nettle signature verification functions (GOST DSA, EDDSA & ECDSA) result in the Elliptic Curve Cryptography point (ECC) multiply function being called with out-of-range scalers, possibly resulting in incorrect results. This flaw allows an attacker to force an invalid signature, causing
nvd
CVE-2021-32558P3HIGHCVSS 7.5v9.0v11.02021-07-30
CVE-2021-32558 [HIGH] CWE-74 CVE-2021-32558: An issue was discovered in Sangoma Asterisk 13.x before 13.38.3, 16.x before 16.19.1, 17.x before 17 An issue was discovered in Sangoma Asterisk 13.x before 13.38.3, 16.x before 16.19.1, 17.x before 17.9.4, and 18.x before 18.5.1, and Certified Asterisk before 16.8-cert10. If the IAX2 channel driver receives a packet that contains an unsupported media format, a crash can occur.
nvd
CVE-2016-3162P3HIGHCVSS 8.1v7.0v8.02016-04-12
CVE-2016-3162 [HIGH] CWE-284 CVE-2016-3162: The File module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allows remote authenticated users to The File module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allows remote authenticated users to bypass access restrictions and read, delete, or substitute a link to a file uploaded to an unprocessed form by leveraging permission to create content or comment and upload files.
nvd
CVE-2018-20750P3CRITICALCVSS 9.8v8.0v9.02019-01-30
CVE-2018-20750 [CRITICAL] CVE-2018-20750: LibVNC through 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. LibVNC through 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018-15127 was incomplete.
nvd
CVE-2020-25694P3HIGHCVSS 8.1v9.02020-11-16
CVE-2020-25694 [HIGH] CWE-327 CVE-2020-25694: A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. If a client application that creates additional database connections only reuses the basic connection parameters while dropping security-relevant parameters, an opportunity for a man-in-the-middle attack, or the ability to obs
nvd
CVE-2017-9233P3HIGHCVSS 7.5v8.0v9.0+1 more2017-07-25
CVE-2017-9233 [HIGH] CWE-611 CVE-2017-9233: XML External Entity vulnerability in libexpat 2.2.0 and earlier (Expat XML Parser Library) allows at XML External Entity vulnerability in libexpat 2.2.0 and earlier (Expat XML Parser Library) allows attackers to put the parser in an infinite loop using a malformed external entity definition from an external DTD.
nvd
CVE-2018-20748P3CRITICALCVSS 9.8v8.02019-01-30
CVE-2018-20748 [CRITICAL] CVE-2018-20748: LibVNC before 0.9.12 contains multiple heap out-of-bounds write vulnerabilities in libvncclient/rfbp LibVNC before 0.9.12 contains multiple heap out-of-bounds write vulnerabilities in libvncclient/rfbproto.c. The fix for CVE-2018-20019 was incomplete.
nvd
CVE-2018-20749P3CRITICALCVSS 9.8v8.0v9.02019-01-30
CVE-2018-20749 [CRITICAL] CVE-2018-20749: LibVNC before 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. LibVNC before 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018-15127 was incomplete.
nvd
CVE-2006-2661P4MEDIUMCVSS 5.0PoCv3.0v3.12006-05-30
CVE-2006-2661 [MEDIUM] CWE-476 CVE-2006-2661: ftutil.c in Freetype before 2.2 allows remote attackers to cause a denial of service (crash) via a c ftutil.c in Freetype before 2.2 allows remote attackers to cause a denial of service (crash) via a crafted font file that triggers a null dereference.
nvd
CVE-2014-1513P3HIGHCVSS 8.8v7.0v8.02014-03-19
CVE-2014-1513 [HIGH] CWE-787 CVE-2014-1513: TypedArrayObject.cpp in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird befor TypedArrayObject.cpp in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 does not prevent a zero-length transition during use of an ArrayBuffer object, which allows remote attackers to execute arbitrary code or cause a denial of service (heap-based out-of-bounds write or read) via a crafted we
nvd
CVE-2020-2816P3HIGHCVSS 7.5v10.02020-04-15
CVE-2020-2816 [HIGH] CVE-2020-2816: Vulnerability in the Java SE product of Oracle Java SE (component: JSSE). Supported versions that ar Vulnerability in the Java SE product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 11.0.6 and 14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification acc
nvd
CVE-2018-12020P3HIGHCVSS 7.5v8.0v9.02018-06-08
CVE-2018-12020 [HIGH] CWE-706 CVE-2018-12020: mainproc.c in GnuPG before 2.2.8 mishandles the original filename during decryption and verification mainproc.c in GnuPG before 2.2.8 mishandles the original filename during decryption and verification actions, which allows remote attackers to spoof the output that GnuPG sends on file descriptor 2 to other programs that use the "--status-fd 2" option. For example, the OpenPGP data might represent an original filename that contains line feed character
nvd
CVE-2010-4253P3CRITICALCVSS 9.3v5.0v6.02011-01-28
CVE-2010-4253 [CRITICAL] CWE-787 CVE-2010-4253: Heap-based buffer overflow in Impress in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote a Heap-based buffer overflow in Impress in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file in an ODF or Microsoft Office document, as demonstrated by a PowerPoint (aka PPT) document.
nvd
CVE-2020-25696P3HIGHCVSS 7.5v9.02020-11-23
CVE-2020-25696 [HIGH] CWE-183 CVE-2020-25696: A flaw was found in the psql interactive terminal of PostgreSQL in versions before 13.1, before 12.5 A flaw was found in the psql interactive terminal of PostgreSQL in versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. If an interactive psql session uses \gset when querying a compromised server, the attacker can execute arbitrary code as the operating system account running psql. The highest threat from th
nvd
CVE-2019-12046P3CRITICALCVSS 9.8v9.02019-05-22
CVE-2019-12046 [CRITICAL] CWE-522 CVE-2019-12046: LemonLDAP::NG -2.0.3 has Incorrect Access Control. LemonLDAP::NG -2.0.3 has Incorrect Access Control.
nvd
CVE-2021-3935P3HIGHCVSS 8.1v9.02021-11-22
CVE-2021-3935 [HIGH] CWE-89 CVE-2021-3935: When PgBouncer is configured to use "cert" authentication, a man-in-the-middle attacker can inject a When PgBouncer is configured to use "cert" authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of TLS certificate verification and encryption. This flaw affects PgBouncer versions prior to 1.16.1.
nvd
CVE-2019-12450P3CRITICALCVSS 9.8v8.02019-05-29
CVE-2019-12450 [CRITICAL] CWE-276 CVE-2019-12450: file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict fil file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict file permissions while a copy operation is in progress. Instead, default permissions are used.
nvd
CVE-2014-6051P3HIGHCVSS 7.5v7.02014-09-30
CVE-2014-6051 [HIGH] CWE-189 CVE-2014-6051: Integer overflow in the MallocFrameBuffer function in vncviewer.c in LibVNCServer 0.9.9 and earlier Integer overflow in the MallocFrameBuffer function in vncviewer.c in LibVNCServer 0.9.9 and earlier allows remote VNC servers to cause a denial of service (crash) and possibly execute arbitrary code via an advertisement for a large screen size, which triggers a heap-based buffer overflow.
nvd
CVE-2022-31090P3HIGHCVSS 7.7v11.02022-06-27
CVE-2022-31090 [HIGH] CWE-200 CVE-2022-31090: Guzzle, an extensible PHP HTTP client. `Authorization` headers on requests are sensitive information Guzzle, an extensible PHP HTTP client. `Authorization` headers on requests are sensitive information. In affected versions when using our Curl handler, it is possible to use the `CURLOPT_HTTPAUTH` option to specify an `Authorization` header. On making a request which responds with a redirect to a URI with a different origin (change in host, scheme or
nvd
Debian Linux vulnerabilities | cvebase