Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 111 of 498
CVE-2018-14362P3CRITICALCVSS 9.8v8.0v9.02018-07-17
CVE-2018-14362 [CRITICAL] CWE-119 CVE-2018-14362: An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c does not forbid c
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c does not forbid characters that may have unsafe interaction with message-cache pathnames, as demonstrated by a '/' character.
nvd
CVE-2021-38161P3HIGHCVSS 8.1v10.0v11.02021-11-03
CVE-2021-38161 [HIGH] CWE-287 CVE-2021-38161: Improper Authentication vulnerability in TLS origin verification of Apache Traffic Server allows for
Improper Authentication vulnerability in TLS origin verification of Apache Traffic Server allows for man in the middle attacks. This issue affects Apache Traffic Server 8.0.0 to 8.0.8.
nvd
CVE-2018-12392P3CRITICALCVSS 9.8v8.0v9.02019-02-28
CVE-2018-12392 [CRITICAL] CVE-2018-12392: When manipulating user events in nested loops while opening a document through script, it is possibl
When manipulating user events in nested loops while opening a document through script, it is possible to trigger a potentially exploitable crash due to poor event handling. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 60.3.
nvd
CVE-2020-25717P3HIGHCVSS 8.1v9.0v10.02022-02-18
CVE-2020-25717 [HIGH] CWE-20 CVE-2020-25717: A flaw was found in the way Samba maps domain users to local users. An authenticated attacker could
A flaw was found in the way Samba maps domain users to local users. An authenticated attacker could use this flaw to cause possible privilege escalation.
nvd
CVE-2021-44759P3HIGHCVSS 8.1v10.0v11.02022-03-23
CVE-2021-44759 [HIGH] CWE-287 CVE-2021-44759: Improper Authentication vulnerability in TLS origin validation of Apache Traffic Server allows an at
Improper Authentication vulnerability in TLS origin validation of Apache Traffic Server allows an attacker to create a man in the middle attack. This issue affects Apache Traffic Server 8.0.0 to 8.1.0.
nvd
CVE-2020-8162P3HIGHCVSS 7.5v10.02020-06-19
CVE-2020-8162 [HIGH] CWE-602 CVE-2020-8162: A client side enforcement of server side security vulnerability exists in rails < 5.2.4.2 and rails
A client side enforcement of server side security vulnerability exists in rails < 5.2.4.2 and rails < 6.0.3.1 ActiveStorage's S3 adapter that allows the Content-Length of a direct file upload to be modified by an end user bypassing upload limits.
nvd
CVE-2017-3137P3HIGHCVSS 7.5v8.02019-01-16
CVE-2017-3137 [HIGH] CWE-617 CVE-2017-3137: Mistaken assumptions about the ordering of records in the answer section of a response containing CN
Mistaken assumptions about the ordering of records in the answer section of a response containing CNAME or DNAME resource records could lead to a situation in which named would exit with an assertion failure when processing a response in which records occurred in an unusual order. Affects BIND 9.9.9-P6, 9.9.10b1->9.9.10rc1, 9.10.4-P6, 9.10.5b1->9.10.5rc
nvd
CVE-2017-10118P3HIGHCVSS 7.5v8.0v9.02017-08-08
CVE-2017-10118 [HIGH] CVE-2017-10118: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: J
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JCE). Supported versions that are affected are Java SE: 7u141 and 8u131; Java SE Embedded: 8u131; JRockit: R28.3.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedd
nvd
CVE-2022-21663P3HIGHCVSS 7.2v9.0v10.0+1 more2022-01-06
CVE-2022-21663 [HIGH] CWE-74 CVE-2022-21663: WordPress is a free and open-source content management system written in PHP and paired with a Maria
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. On a multisite, users with Super Admin role can bypass explicit/additional hardening under certain conditions through object injection. This has been patched in WordPress version 5.8.3. Older affected versions are also fixed via security rel
nvd
CVE-2016-2090P3CRITICALCVSS 9.8v8.02017-01-13
CVE-2016-2090 [CRITICAL] CWE-119 CVE-2016-2090: Off-by-one vulnerability in the fgetwln function in libbsd before 0.8.2 allows attackers to have uns
Off-by-one vulnerability in the fgetwln function in libbsd before 0.8.2 allows attackers to have unspecified impact via unknown vectors, which trigger a heap-based buffer overflow.
nvd
CVE-2007-6427P3CRITICALCVSS 9.3v3.1v4.02008-01-18
CVE-2007-6427 [CRITICAL] CVE-2007-6427: The XInput extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to execute arb
The XInput extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to execute arbitrary code via requests related to byte swapping and heap corruption within multiple functions, a different vulnerability than CVE-2007-4990.
nvd
CVE-2010-3452P3CRITICALCVSS 9.3v5.0v6.02011-01-28
CVE-2010-3452 [CRITICAL] CWE-416 CVE-2010-3452: Use-after-free vulnerability in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remot
Use-after-free vulnerability in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted tags in an RTF document.
nvd
CVE-2018-11319P3HIGHCVSS 7.5v8.0v9.02018-05-20
CVE-2018-11319 [HIGH] CWE-22 CVE-2018-11319: Syntastic (aka vim-syntastic) through 3.9.0 does not properly handle searches for configuration file
Syntastic (aka vim-syntastic) through 3.9.0 does not properly handle searches for configuration files (it searches the current directory up to potentially the root). This improper handling might be exploited for arbitrary code execution via a malicious gcc plugin, if an attacker has write access to a directory that is a parent of the base directory of
nvd
CVE-2011-4516P3MEDIUMCVSS 6.8v6.02011-12-15
CVE-2011-4516 [MEDIUM] CWE-787 CVE-2011-4516: Heap-based buffer overflow in the jpc_cox_getcompparms function in libjasper/jpc/jpc_cs.c in JasPer
Heap-based buffer overflow in the jpc_cox_getcompparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted numrlvls value in a coding style default (COD) marker segment in a JPEG2000 file.
nvd
CVE-2011-4517P3MEDIUMCVSS 6.8v6.02011-12-15
CVE-2011-4517 [MEDIUM] CWE-787 CVE-2011-4517: The jpc_crg_getparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 uses an incorrect data typ
The jpc_crg_getparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 uses an incorrect data type during a certain size calculation, which allows remote attackers to trigger a heap-based buffer overflow and execute arbitrary code, or cause a denial of service (heap memory corruption), via a crafted component registration (CRG) marker segment in a
nvd
CVE-2015-8871P3CRITICALCVSS 9.8v8.02016-09-21
CVE-2015-8871 [CRITICAL] CWE-416 CVE-2015-8871: Use-after-free vulnerability in the opj_j2k_write_mco function in j2k.c in OpenJPEG before 2.1.1 all
Use-after-free vulnerability in the opj_j2k_write_mco function in j2k.c in OpenJPEG before 2.1.1 allows remote attackers to have unspecified impact via unknown vectors.
nvd
CVE-2021-45845P3HIGHCVSS 7.8v11.02022-01-25
CVE-2021-45845 [HIGH] CWE-78 CVE-2021-45845: The Path Sanity Check script of FreeCAD 0.19 is vulnerable to OS command injection, allowing an atta
The Path Sanity Check script of FreeCAD 0.19 is vulnerable to OS command injection, allowing an attacker to execute arbitrary commands via a crafted FCStd document.
nvd
CVE-2015-2301P3HIGHCVSS 7.5v7.02015-03-30
CVE-2015-2301 [HIGH] CWE-416 CVE-2015-2301: Use-after-free vulnerability in the phar_rename_archive function in phar_object.c in PHP before 5.5.
Use-after-free vulnerability in the phar_rename_archive function in phar_object.c in PHP before 5.5.22 and 5.6.x before 5.6.6 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an attempted renaming of a Phar archive to the name of an existing file.
nvd
CVE-2020-29600P3CRITICALCVSS 9.8v9.02020-12-07
CVE-2020-29600 [CRITICAL] CVE-2020-29600: In AWStats through 7.7, cgi-bin/awstats.pl?config= accepts an absolute pathname, even though it was
In AWStats through 7.7, cgi-bin/awstats.pl?config= accepts an absolute pathname, even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000501.
nvd
CVE-2009-4538P3CRITICALCVSS 10.0v4.0v5.02010-01-12
CVE-2009-4538 [CRITICAL] CVE-2009-4538: drivers/net/e1000e/netdev.c in the e1000e driver in the Linux kernel 2.6.32.3 and earlier does not p
drivers/net/e1000e/netdev.c in the e1000e driver in the Linux kernel 2.6.32.3 and earlier does not properly check the size of an Ethernet frame that exceeds the MTU, which allows remote attackers to have an unspecified impact via crafted packets, a related issue to CVE-2009-4537.
nvd