Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 112 of 498
CVE-2016-10711P3CRITICALCVSS 9.8v7.02018-01-29
CVE-2016-10711 [CRITICAL] CWE-444 CVE-2016-10711: Apsis Pound before 2.8a allows request smuggling via crafted headers, a different vulnerability than
Apsis Pound before 2.8a allows request smuggling via crafted headers, a different vulnerability than CVE-2005-3751.
nvd
CVE-2021-41073P3HIGHCVSS 7.8v10.02021-09-19
CVE-2021-41073 [HIGH] CWE-763 CVE-2021-41073: loop_rw_iter in fs/io_uring.c in the Linux kernel 5.10 through 5.14.6 allows local users to gain pri
loop_rw_iter in fs/io_uring.c in the Linux kernel 5.10 through 5.14.6 allows local users to gain privileges by using IORING_OP_PROVIDE_BUFFERS to trigger a free of a kernel buffer, as demonstrated by using /proc//maps for exploitation.
nvd
CVE-2014-9089P3HIGHCVSS 7.5v1.22014-11-28
CVE-2014-9089 [HIGH] CWE-89 CVE-2014-9089: Multiple SQL injection vulnerabilities in view_all_bug_page.php in MantisBT before 1.2.18 allow remo
Multiple SQL injection vulnerabilities in view_all_bug_page.php in MantisBT before 1.2.18 allow remote attackers to execute arbitrary SQL commands via the (1) sort or (2) dir parameter to view_all_set.php.
nvd
CVE-2019-16869P3HIGHCVSS 7.5v8.0v9.0+1 more2019-09-26
CVE-2019-16869 [HIGH] CWE-444 CVE-2019-16869: Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfe
Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which leads to HTTP request smuggling.
nvd
CVE-2019-11035P3CRITICALCVSS 9.1v8.0v9.02019-04-18
CVE-2019-11035 [CRITICAL] CWE-125 CVE-2019-11035: When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.28, 7.2.x below 7.2.17
When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.28, 7.2.x below 7.2.17 and 7.3.x below 7.3.4 can be caused to read past allocated buffer in exif_iif_add_value function. This may lead to information disclosure or crash.
nvd
CVE-2024-3864P3HIGHCVSS 8.1v10.02024-04-16
CVE-2024-3864 [HIGH] CWE-119 CVE-2024-3864: Memory safety bug present in Firefox 124, Firefox ESR 115.9, and Thunderbird 115.9. This bug showed
Memory safety bug present in Firefox 124, Firefox ESR 115.9, and Thunderbird 115.9. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited to run arbitrary code. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
nvd
CVE-2019-19617P3CRITICALCVSS 9.8v8.0v9.02019-12-06
CVE-2019-19617 [CRITICAL] CVE-2019-19617: phpMyAdmin before 4.9.2 does not escape certain Git information, related to libraries/classes/Displa
phpMyAdmin before 4.9.2 does not escape certain Git information, related to libraries/classes/Display/GitRevision.php and libraries/classes/Footer.php.
nvd
CVE-2019-19725P3CRITICALCVSS 9.8v10.02019-12-11
CVE-2019-19725 [CRITICAL] CWE-415 CVE-2019-19725: sysstat through 12.2.0 has a double free in check_file_actlst in sa_common.c.
sysstat through 12.2.0 has a double free in check_file_actlst in sa_common.c.
nvd
CVE-2015-0859P3HIGHCVSS 7.5v7.0v8.02015-12-03
CVE-2015-0859 [HIGH] CWE-17 CVE-2015-0859: The Debian build procedure for the smokeping package in wheezy before 2.6.8-2+deb7u1 and jessie befo
The Debian build procedure for the smokeping package in wheezy before 2.6.8-2+deb7u1 and jessie before 2.6.9-1+deb8u1 does not properly configure the way Apache httpd passes arguments to smokeping_cgi, which allows remote attackers to execute arbitrary code via crafted CGI arguments.
nvd
CVE-2022-42890P3HIGHCVSS 7.5v10.0v11.02022-10-25
CVE-2022-42890 [HIGH] CWE-918 CVE-2022-42890: A vulnerability in Batik of Apache XML Graphics allows an attacker to run Java code from untrusted S
A vulnerability in Batik of Apache XML Graphics allows an attacker to run Java code from untrusted SVG via JavaScript. This issue affects Apache XML Graphics prior to 1.16. Users are recommended to upgrade to version 1.16.
nvd
CVE-2014-7844P3HIGHCVSS 7.8v7.02020-01-14
CVE-2014-7844 [HIGH] CWE-74 CVE-2014-7844: BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via a crafted emai
BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via a crafted email address.
nvd
CVE-2020-29599P3HIGHCVSS 7.8v9.02020-12-07
CVE-2020-29599 [HIGH] CWE-91 CVE-2020-29599: ImageMagick before 6.9.11-40 and 7.x before 7.0.10-40 mishandles the -authenticate option, which all
ImageMagick before 6.9.11-40 and 7.x before 7.0.10-40 mishandles the -authenticate option, which allows setting a password for password-protected PDF files. The user-controlled password was not properly escaped/sanitized and it was therefore possible to inject additional shell commands via coders/pdf.c.
nvd
CVE-2010-3453P3CRITICALCVSS 9.3v5.0v6.02011-01-28
CVE-2010-3453 [CRITICAL] CWE-787 CVE-2010-3453: The WW8ListManager::WW8ListManager function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3
The WW8ListManager::WW8ListManager function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle an unspecified number of list levels in user-defined list styles in WW8 data in a Microsoft Word document, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code vi
nvd
CVE-2019-6256P3CRITICALCVSS 9.8v8.0v9.02019-01-14
CVE-2019-6256 [CRITICAL] CWE-755 CVE-2019-6256: A Denial of Service issue was discovered in the LIVE555 Streaming Media libraries as used in Live555
A Denial of Service issue was discovered in the LIVE555 Streaming Media libraries as used in Live555 Media Server 0.93. It can cause an RTSPServer crash in handleHTTPCmd_TunnelingPOST, when RTSP-over-HTTP tunneling is supported, via x-sessioncookie HTTP headers in a GET request and a POST request within the same TCP session. This occurs because of a
nvd
CVE-2020-15953P3HIGHCVSS 7.4v9.02020-07-27
CVE-2020-15953 [HIGH] CWE-74 CVE-2020-15953: LibEtPan through 1.9.4, as used in MailCore 2 through 0.6.3 and other products, has a STARTTLS buffe
LibEtPan through 1.9.4, as used in MailCore 2 through 0.6.3 and other products, has a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS" response, the client reads additional data (e.g., from a meddler-in-the-middle attacker) and evaluates it in a TLS context, aka "response injection."
nvd
CVE-2022-41704P3HIGHCVSS 7.5v10.0v11.02022-10-25
CVE-2022-41704 [HIGH] CWE-918 CVE-2022-41704: A vulnerability in Batik of Apache XML Graphics allows an attacker to run untrusted Java code from a
A vulnerability in Batik of Apache XML Graphics allows an attacker to run untrusted Java code from an SVG. This issue affects Apache XML Graphics prior to 1.16. It is recommended to update to version 1.16.
nvd
CVE-2022-24790P3HIGHCVSS 7.5v10.0v11.02022-03-30
CVE-2022-24790 [HIGH] CWE-444 CVE-2022-24790: Puma is a simple, fast, multi-threaded, parallel HTTP 1.1 server for Ruby/Rack applications. When us
Puma is a simple, fast, multi-threaded, parallel HTTP 1.1 server for Ruby/Rack applications. When using Puma behind a proxy that does not properly validate that the incoming HTTP request matches the RFC7230 standard, Puma and the frontend proxy may disagree on where a request starts and ends. This would allow requests to be smuggled via the front-end
nvd
CVE-2019-11034P3CRITICALCVSS 9.1v8.0v9.02019-04-18
CVE-2019-11034 [CRITICAL] CWE-125 CVE-2019-11034: When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.28, 7.2.x below 7.2.17
When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.28, 7.2.x below 7.2.17 and 7.3.x below 7.3.4 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to information disclosure or crash.
nvd
CVE-2020-35498P3HIGHCVSS 7.5v9.0v10.02021-02-11
CVE-2020-35498 [HIGH] CWE-400 CVE-2020-35498: A vulnerability was found in openvswitch. A limitation in the implementation of userspace packet par
A vulnerability was found in openvswitch. A limitation in the implementation of userspace packet parsing can allow a malicious user to send a specially crafted packet causing the resulting megaflow in the kernel to be too wide, potentially causing a denial of service. The highest threat from this vulnerability is to system availability.
nvd
CVE-2014-9057P3HIGHCVSS 7.5v7.02014-12-16
CVE-2014-9057 [HIGH] CWE-89 CVE-2014-9057: SQL injection vulnerability in the XML-RPC interface in Movable Type before 5.18, 5.2.x before 5.2.1
SQL injection vulnerability in the XML-RPC interface in Movable Type before 5.18, 5.2.x before 5.2.11, and 6.x before 6.0.6 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
nvd