Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 102 of 498
CVE-2012-0444P3CRITICALCVSS 10.0v5.0v6.02012-02-01
CVE-2012-0444 [CRITICAL] CWE-119 CVE-2012-0444: Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, an
Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 do not properly initialize nsChildView data structures, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted Ogg Vorbis file.
nvd
CVE-2019-13451P3CRITICALCVSS 9.8v8.02019-08-27
CVE-2019-13451 [CRITICAL] CWE-119 CVE-2019-13451: In Xymon through 4.3.28, a buffer overflow vulnerability exists in history.c.
In Xymon through 4.3.28, a buffer overflow vulnerability exists in history.c.
nvd
CVE-2021-38171P3CRITICALCVSS 9.8v9.0v10.0+1 more2021-08-21
CVE-2021-38171 [CRITICAL] CWE-252 CVE-2021-38171: adts_decode_extradata in libavformat/adtsenc.c in FFmpeg 4.4 does not check the init_get_bits return
adts_decode_extradata in libavformat/adtsenc.c in FFmpeg 4.4 does not check the init_get_bits return value, which is a necessary step because the second argument to init_get_bits can be crafted.
nvd
CVE-2016-4463P3HIGHCVSS 7.5v8.02016-07-08
CVE-2016-4463 [HIGH] CWE-119 CVE-2016-4463: Stack-based buffer overflow in Apache Xerces-C++ before 3.1.4 allows context-dependent attackers to
Stack-based buffer overflow in Apache Xerces-C++ before 3.1.4 allows context-dependent attackers to cause a denial of service via a deeply nested DTD.
nvd
CVE-2018-19198P3CRITICALCVSS 9.8v8.02018-11-12
CVE-2018-19198 [CRITICAL] CWE-787 CVE-2018-19198: An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an out-of-bounds write via a ur
An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an out-of-bounds write via a uriComposeQuery* or uriComposeQueryEx* function because the '&' character is mishandled in certain contexts.
nvd
CVE-2018-19199P3CRITICALCVSS 9.8v8.02018-11-12
CVE-2018-19199 [CRITICAL] CWE-190 CVE-2018-19199: An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an integer overflow via a uriCo
An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an integer overflow via a uriComposeQuery* or uriComposeQueryEx* function because of an unchecked multiplication.
nvd
CVE-2019-11040P3CRITICALCVSS 9.1v9.0v10.02019-06-19
CVE-2019-11040 [CRITICAL] CWE-125 CVE-2019-11040: When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() functio
When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.
nvd
CVE-2019-7653P3CRITICALCVSS 9.8v8.0v9.02019-02-09
CVE-2019-7653 [CRITICAL] CWE-427 CVE-2019-7653: The Debian python-rdflib-tools 4.2.2-1 package for RDFLib 4.2.2 has CLI tools that can load Python m
The Debian python-rdflib-tools 4.2.2-1 package for RDFLib 4.2.2 has CLI tools that can load Python modules from the current working directory, allowing code injection, because "python -m" looks in this directory, as demonstrated by rdf2dot. This issue is specific to use of the debian/scripts directory.
nvd
CVE-2021-45098P3HIGHCVSS 7.5v9.0v10.0+1 more2021-12-16
CVE-2021-45098 [HIGH] CVE-2021-45098: An issue was discovered in Suricata before 6.0.4. It is possible to bypass/evade any HTTP-based sign
An issue was discovered in Suricata before 6.0.4. It is possible to bypass/evade any HTTP-based signature by faking an RST TCP packet with random TCP options of the md5header from the client side. After the three-way handshake, it's possible to inject an RST ACK with a random TCP md5header option. Then, the client can send an HTTP GET request with a forbidden
nvd
CVE-2012-1149P3HIGHCVSS 7.5v6.0v7.02012-06-21
CVE-2012-1149 [HIGH] CWE-189 CVE-2012-1149: Integer overflow in the vclmi.dll module in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier
Integer overflow in the vclmi.dll module in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted embedded image object, as demonstrated by a JPEG image in a .DOC file, which triggers a heap-based b
nvd
CVE-2018-1000878P3HIGHCVSS 8.8v8.0v9.02018-12-20
CVE-2018-1000878 [HIGH] CWE-416 CVE-2018-1000878: libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards)
libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-416: Use After Free vulnerability in RAR decoder - libarchive/archive_read_support_format_rar.c that can result in Crash/DoS - it is unknown if RCE is possible. This attack appear to be exploitable via the victim must open a specially
nvd
CVE-2016-4001P3HIGHCVSS 8.6v8.02016-05-23
CVE-2016-4001 [HIGH] CWE-120 CVE-2016-4001: Buffer overflow in the stellaris_enet_receive function in hw/net/stellaris_enet.c in QEMU, when the
Buffer overflow in the stellaris_enet_receive function in hw/net/stellaris_enet.c in QEMU, when the Stellaris ethernet controller is configured to accept large packets, allows remote attackers to cause a denial of service (QEMU crash) via a large packet.
nvd
CVE-2022-25763P3HIGHCVSS 7.5v11.02022-08-10
CVE-2022-25763 [HIGH] CWE-444 CVE-2022-25763: Improper Input Validation vulnerability in HTTP/2 request validation of Apache Traffic Server allows
Improper Input Validation vulnerability in HTTP/2 request validation of Apache Traffic Server allows an attacker to create smuggle or cache poison attacks. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.
nvd
CVE-2021-20247P3HIGHCVSS 7.4v9.02021-02-23
CVE-2021-20247 [HIGH] CWE-20 CVE-2021-20247: A flaw was found in mbsync before v1.3.5 and v1.4.1. Validations of the mailbox names returned by IM
A flaw was found in mbsync before v1.3.5 and v1.4.1. Validations of the mailbox names returned by IMAP LIST/LSUB do not occur allowing a malicious or compromised server to use specially crafted mailbox names containing '..' path components to access data outside the designated mailbox on the opposite end of the synchronization channel. The highest thre
nvd
CVE-2019-13452P3CRITICALCVSS 9.8v8.02019-08-27
CVE-2019-13452 [CRITICAL] CWE-119 CVE-2019-13452: In Xymon through 4.3.28, a buffer overflow vulnerability exists in reportlog.c.
In Xymon through 4.3.28, a buffer overflow vulnerability exists in reportlog.c.
nvd
CVE-2018-18313P3CRITICALCVSS 9.1v9.02018-12-07
CVE-2018-18313 [CRITICAL] CWE-125 CVE-2018-18313: Perl before 5.26.3 has a buffer over-read via a crafted regular expression that triggers disclosure
Perl before 5.26.3 has a buffer over-read via a crafted regular expression that triggers disclosure of sensitive information from process memory.
nvd
CVE-2025-3891P3HIGHCVSS 7.5v11.02025-04-29
CVE-2025-3891 [HIGH] CWE-248 CVE-2025-3891: A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthe
A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is enabled. The server crashes consistently, affecting availability.
nvd
CVE-2025-10922P3HIGHCVSS 7.8v11.02025-10-29
CVE-2025-10922 [HIGH] CWE-122 CVE-2025-10922: GIMP DCM File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabi
GIMP DCM File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists withi
nvd
CVE-2017-12873P3CRITICALCVSS 9.8v7.0v8.0+1 more2017-09-01
CVE-2017-12873 [CRITICAL] CWE-384 CVE-2017-12873: SimpleSAMLphp 1.7.0 through 1.14.10 might allow attackers to obtain sensitive information, gain unau
SimpleSAMLphp 1.7.0 through 1.14.10 might allow attackers to obtain sensitive information, gain unauthorized access, or have unspecified other impacts by leveraging incorrect persistent NameID generation when an Identity Provider (IdP) is misconfigured.
nvd
CVE-2008-1673P3CRITICALCVSS 10.0v4.02008-06-10
CVE-2008-1673 [CRITICAL] CWE-119 CVE-2008-1673: The asn1 implementation in (a) the Linux kernel 2.4 before 2.4.36.6 and 2.6 before 2.6.25.5, as used
The asn1 implementation in (a) the Linux kernel 2.4 before 2.4.36.6 and 2.6 before 2.6.25.5, as used in the cifs and ip_nat_snmp_basic modules; and (b) the gxsnmp package; does not properly validate length values during decoding of ASN.1 BER data, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via (1) a
nvd