Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 113 of 498
CVE-2007-6745P3CRITICALCVSS 9.8v8.0v9.0+1 more2019-11-07
CVE-2007-6745 [CRITICAL] CVE-2007-6745: clamav 0.91.2 suffers from a floating point exception when using ScanOLE2.
clamav 0.91.2 suffers from a floating point exception when using ScanOLE2.
nvd
CVE-2021-44040P3HIGHCVSS 7.5v10.0v11.02022-03-23
CVE-2021-44040 [HIGH] CWE-20 CVE-2021-44040: Improper Input Validation vulnerability in request line parsing of Apache Traffic Server allows an a
Improper Input Validation vulnerability in request line parsing of Apache Traffic Server allows an attacker to send invalid requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.3 and 9.0.0 to 9.1.1.
nvd
CVE-2022-31779P3HIGHCVSS 7.5v11.02022-08-10
CVE-2022-31779 [HIGH] CWE-20 CVE-2022-31779: Improper Input Validation vulnerability in HTTP/2 header parsing of Apache Traffic Server allows an
Improper Input Validation vulnerability in HTTP/2 header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.
nvd
CVE-2018-1000024P3HIGHCVSS 7.5v7.0v8.0+1 more2018-02-09
CVE-2018-1000024 [HIGH] CVE-2018-1000024: The Squid Software Foundation Squid HTTP Caching Proxy version 3.0 to 3.5.27, 4.0 to 4.0.22 contains
The Squid Software Foundation Squid HTTP Caching Proxy version 3.0 to 3.5.27, 4.0 to 4.0.22 contains a Incorrect Pointer Handling vulnerability in ESI Response Processing that can result in Denial of Service for all clients using the proxy.. This attack appear to be exploitable via Remote server delivers an HTTP response payload containing valid but unusu
nvd
CVE-2021-31873P3CRITICALCVSS 9.8v9.02021-04-30
CVE-2021-31873 [CRITICAL] CWE-190 CVE-2021-31873: An issue was discovered in klibc before 2.0.9. Additions in the malloc() function may result in an i
An issue was discovered in klibc before 2.0.9. Additions in the malloc() function may result in an integer overflow and a subsequent heap buffer overflow.
nvd
CVE-2021-39925P3HIGHCVSS 7.5v9.02021-11-19
CVE-2021-39925 [HIGH] CWE-120 CVE-2021-39925: Buffer overflow in the Bluetooth SDP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allow
Buffer overflow in the Bluetooth SDP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
nvd
CVE-2018-1000877P3HIGHCVSS 8.8v8.0v9.02018-12-20
CVE-2018-1000877 [HIGH] CWE-415 CVE-2018-1000877: libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards)
libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-415: Double Free vulnerability in RAR decoder - libarchive/archive_read_support_format_rar.c, parse_codes(), realloc(rar->lzss.window, new_size) with new_size = 0 that can result in Crash/DoS. This attack appear to be exploitable via t
nvd
CVE-2022-31043P3HIGHCVSS 7.5v11.02022-06-10
CVE-2022-31043 [HIGH] CWE-200 CVE-2022-31043: Guzzle is an open source PHP HTTP client. In affected versions `Authorization` headers on requests a
Guzzle is an open source PHP HTTP client. In affected versions `Authorization` headers on requests are sensitive information. On making a request using the `https` scheme to a server which responds with a redirect to a URI with the `http` scheme, we should not forward the `Authorization` header on. This is much the same as to how we don't forward on t
nvd
CVE-2015-5211P3CRITICALCVSS 9.6v8.02017-05-25
CVE-2015-5211 [CRITICAL] CWE-552 CVE-2015-5211: Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and olde
Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to a Reflected File Download (RFD) attack. The attack involves a malicious user crafting a URL with a batch script extension that results in the response being downloaded rather than rendered and also includes some
nvd
CVE-2021-31870P3CRITICALCVSS 9.8v9.02021-04-30
CVE-2021-31870 [CRITICAL] CWE-190 CVE-2021-31870: An issue was discovered in klibc before 2.0.9. Multiplication in the calloc() function may result in
An issue was discovered in klibc before 2.0.9. Multiplication in the calloc() function may result in an integer overflow and a subsequent heap buffer overflow.
nvd
CVE-2020-8287P3MEDIUMCVSS 6.5v10.02021-01-06
CVE-2020-8287 [MEDIUM] CWE-444 CVE-2020-8287: Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 allow two copies of a header field in an H
Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 allow two copies of a header field in an HTTP request (for example, two Transfer-Encoding header fields). In this case, Node.js identifies the first header field and ignores the second. This can lead to HTTP Request Smuggling.
nvd
CVE-2021-44420P3HIGHCVSS 7.3v10.0v11.02021-12-08
CVE-2021-44420 [HIGH] CVE-2021-44420: In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with t
In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines could bypass upstream access control based on URL paths.
nvd
CVE-2021-3618P3HIGHCVSS 7.4v10.02022-03-23
CVE-2021-3618 [HIGH] CWE-295 CVE-2021-3618: ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementin
ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim's traffic at the TCP/IP layer can redirect traffic from one subdomain to another, resulting in a valid TLS sess
nvd
CVE-2022-24761P3HIGHCVSS 7.5v9.02022-03-17
CVE-2022-24761 [HIGH] CWE-444 CVE-2022-24761: Waitress is a Web Server Gateway Interface server for Python 2 and 3. When using Waitress versions 2
Waitress is a Web Server Gateway Interface server for Python 2 and 3. When using Waitress versions 2.1.0 and prior behind a proxy that does not properly validate the incoming HTTP request matches the RFC7230 standard, Waitress and the frontend proxy may disagree on where one request starts and where it ends. This would allow requests to be smuggled vi
nvd
CVE-2021-37150P3HIGHCVSS 7.5v10.0v11.02022-08-10
CVE-2021-37150 [HIGH] CWE-20 CVE-2021-37150: Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacke
Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to request secure resources. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.
nvd
CVE-2014-8145P3HIGHCVSS 7.5v7.0v8.02014-12-31
CVE-2014-8145 [HIGH] CWE-119 CVE-2014-8145: Multiple heap-based buffer overflows in Sound eXchange (SoX) 14.4.1 and earlier allow remote attacke
Multiple heap-based buffer overflows in Sound eXchange (SoX) 14.4.1 and earlier allow remote attackers to have unspecified impact via a crafted WAV file to the (1) start_read or (2) AdpcmReadBlock function.
nvd
CVE-2021-44731P3HIGHCVSS 7.8v10.0v11.02022-02-17
CVE-2021-44731 [HIGH] CWE-362 CVE-2021-44731: A race condition existed in the snapd 2.54.2 snap-confine binary when preparing a private mount name
A race condition existed in the snapd 2.54.2 snap-confine binary when preparing a private mount namespace for a snap. This could allow a local attacker to gain root privileges by bind-mounting their own contents inside the snap's private mount namespace and causing snap-confine to execute arbitrary code and hence gain privilege escalation. Fixed in sn
nvd
CVE-2021-43804P3HIGHCVSS 7.3v9.0v10.02021-12-22
CVE-2021-43804 [HIGH] CWE-125 CVE-2021-43804: PJSIP is a free and open source multimedia communication library written in C language implementing
PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In affected versions if the incoming RTCP BYE message contains a reason's length, this declared length is not checked against the actual received packet size, potentially resulting in a
nvd
CVE-2020-11729P3CRITICALCVSS 9.8v9.0v10.02020-04-15
CVE-2020-11729 [CRITICAL] CWE-384 CVE-2020-11729: An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60. Long-term session cook
An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60. Long-term session cookies, uses to provide long-term session continuity, are not generated securely, enabling a brute-force attack that may be successful.
nvd
CVE-2011-2726P3HIGHCVSS 7.5v8.0v9.02019-11-15
CVE-2011-2726 [HIGH] CWE-863 CVE-2011-2726: An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability
An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type in the system or has the ability to point individual File upload fields to the private file directory in comments, and the parent node is denied access, non-privileged users can still download the file attach
nvd