Debian Linux vulnerabilities
9,952 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,952
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4311LOW358
Vulnerabilities
Page 11 of 498
CVE-2022-24785P2HIGHCVSS 7.5Exploitedv10.02022-04-04
CVE-2022-24785 [HIGH] CWE-22 CVE-2022-24785: Moment.js is a JavaScript date library for parsing, validating, manipulating, and formatting dates.
Moment.js is a JavaScript date library for parsing, validating, manipulating, and formatting dates. A path traversal vulnerability impacts npm (server) users of Moment.js between versions 1.0.1 and 2.29.1, especially if a user-provided locale string is directly used to switch moment locale. This problem is patched in 2.29.2, and the patch can be applied
nvd
CVE-2017-6922P2MEDIUMCVSS 6.5Exploitedv8.0v9.02019-01-22
CVE-2017-6922 [MEDIUM] CWE-552 CVE-2017-6922: In Drupal core 8.x prior to 8.3.4 and Drupal core 7.x prior to 7.56; Private files that have been up
In Drupal core 8.x prior to 8.3.4 and Drupal core 7.x prior to 7.56; Private files that have been uploaded by an anonymous user but not permanently attached to content on the site should only be visible to the anonymous user that uploaded them, rather than all anonymous users. Drupal core did not previously provide this protection, allowing an access
nvd
CVE-2020-28034P2MEDIUMCVSS 6.1Exploitedv9.0v10.02020-11-02
CVE-2020-28034 [MEDIUM] CWE-79 CVE-2020-28034: WordPress before 5.5.2 allows XSS associated with global variables.
WordPress before 5.5.2 allows XSS associated with global variables.
nvd
CVE-2019-5420P1CRITICALCVSS 9.8PoCv8.02019-03-27
CVE-2019-5420 [CRITICAL] CWE-77 CVE-2019-5420: A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess the automatically generated development mode secret token. This secret token can be used in combination with other Rails internals to escalate to a remote code execution exploit.
nvd
CVE-2021-44790P1CRITICALCVSS 9.8PoCv10.0v11.02021-12-20
CVE-2021-44790 [CRITICAL] CWE-787 CVE-2021-44790: A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:pars
A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an exploit for the vulnerabilty though it might be possible to craft one. This issue affects Apache HTTP Server 2.4.51 and earlier.
nvd
CVE-2017-14491P1CRITICALCVSS 9.8PoCv7.0v7.1+2 more2017-10-04
CVE-2017-14491 [CRITICAL] CWE-787 CVE-2017-14491: Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of servi
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response.
nvd
CVE-2016-1000110P2MEDIUMCVSS 6.1Exploitedv8.0v9.0+1 more2019-11-27
CVE-2016-1000110 [MEDIUM] CWE-601 CVE-2016-1000110: The CGIHandler class in Python before 2.7.12 does not protect against the HTTP_PROXY variable name c
The CGIHandler class in Python before 2.7.12 does not protect against the HTTP_PROXY variable name clash in a CGI script, which could allow a remote attacker to redirect HTTP requests.
nvd
CVE-2022-31197P2HIGHCVSS 8.0Exploitedv10.02022-08-03
CVE-2022-31197 [HIGH] CWE-89 CVE-2022-31197: PostgreSQL JDBC Driver (PgJDBC for short) allows Java programs to connect to a PostgreSQL database u
PostgreSQL JDBC Driver (PgJDBC for short) allows Java programs to connect to a PostgreSQL database using standard, database independent Java code. The PGJDBC implementation of the `java.sql.ResultRow.refreshRow()` method is not performing escaping of column names so a malicious column name that contains a statement terminator, e.g. `;`, could lead to S
nvd
CVE-2017-14493P1CRITICALCVSS 9.8PoCv7.0v7.1+1 more2017-10-03
CVE-2017-14493 [CRITICAL] CWE-119 CVE-2017-14493: Stack-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of serv
Stack-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DHCPv6 request.
nvd
CVE-2019-5840P2MEDIUMCVSS 4.3Exploitedv10.02019-06-27
CVE-2019-5840 [MEDIUM] CWE-362 CVE-2019-5840: Incorrect security UI in popup blocker in Google Chrome on iOS prior to 75.0.3770.80 allowed a remot
Incorrect security UI in popup blocker in Google Chrome on iOS prior to 75.0.3770.80 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2015-2331P2HIGHCVSS 7.5Exploitedv7.02015-03-30
CVE-2015-2331 [HIGH] CWE-189 CVE-2015-2331: Integer overflow in the _zip_cdir_new function in zip_dirent.c in libzip 0.11.2 and earlier, as used
Integer overflow in the _zip_cdir_new function in zip_dirent.c in libzip 0.11.2 and earlier, as used in the ZIP extension in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a ZIP archive that contains many en
nvd
CVE-2021-21345P1CRITICALCVSS 9.9PoCv9.0v10.0+1 more2021-03-23
CVE-2021-21345 [CRITICAL] CWE-94 CVE-2021-21345: XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker who has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security
nvd
CVE-2020-8518P1CRITICALCVSS 9.8PoCv8.02020-02-17
CVE-2020-8518 [CRITICAL] CWE-94 CVE-2020-8518: Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading
Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execution.
nvd
CVE-2020-8794P2CRITICALCVSS 9.8PoCv9.0v10.02020-02-25
CVE-2020-8794 [CRITICAL] CWE-125 CVE-2020-8794: OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mt
OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for multi-line replies. Although this vulnerability affects the client side of OpenSMTPD, it is possible to attack a server because the server code launches the client code during bounce handling.
nvd
CVE-2021-29505P1HIGHCVSS 8.8PoCv9.0v10.0+1 more2021-05-28
CVE-2021-29505 [HIGH] CWE-94 CVE-2021-29505: XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream v
XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user who followed the recommendation to setup XStream's security framework with a whitelist limi
nvd
CVE-2021-25282P2CRITICALCVSS 9.1PoCv9.0v10.0+1 more2021-02-27
CVE-2021-25282 [CRITICAL] CWE-22 CVE-2021-25282: An issue was discovered in through SaltStack Salt before 3002.5. The salt.wheel.pillar_roots.write m
An issue was discovered in through SaltStack Salt before 3002.5. The salt.wheel.pillar_roots.write method is vulnerable to directory traversal.
nvd
CVE-2020-26217P2HIGHCVSS 8.8PoCv9.0v10.02020-11-16
CVE-2020-26217 [HIGH] CWE-78 CVE-2020-26217: XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a r
XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone using XStream's Security Framework allowlist is not affected. The linked advisory provides code workaro
nvd
CVE-2018-7584P2CRITICALCVSS 9.8PoCv7.0v8.0+1 more2018-03-01
CVE-2018-7584 [CRITICAL] CWE-119 CVE-2018-7584: In PHP through 5.6.33, 7.0.x before 7.0.28, 7.1.x through 7.1.14, and 7.2.x through 7.2.2, there is
In PHP through 5.6.33, 7.0.x before 7.0.28, 7.1.x through 7.1.14, and 7.2.x through 7.2.2, there is a stack-based buffer under-read while parsing an HTTP response in the php_stream_url_wrap_http_ex function in ext/standard/http_fopen_wrapper.c. This subsequently results in copying a large string.
nvd
CVE-2020-8163P2HIGHCVSS 8.8PoCv9.02020-07-02
CVE-2020-8163 [HIGH] CWE-94 CVE-2020-8163: The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacke
The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the `locals` argument of a `render` call to perform a RCE.
nvd
CVE-2011-1752P2MEDIUMCVSS 5.0Exploitedv5.0v6.02011-06-06
CVE-2011-1752 [MEDIUM] CWE-476 CVE-2011-1752: The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.17
The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.17, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request for a baselined WebDAV resource, as exploited in the wild in May 2011.
nvd