cbcvebase.

Debian Linux vulnerabilities

9,953 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358

Vulnerabilities

Page 114 of 498
CVE-2021-39926P3HIGHCVSS 7.5v10.0v11.02021-11-19
CVE-2021-39926 [HIGH] CWE-120 CVE-2021-39926: Buffer overflow in the Bluetooth HCI_ISO dissector in Wireshark 3.4.0 to 3.4.9 allows denial of serv Buffer overflow in the Bluetooth HCI_ISO dissector in Wireshark 3.4.0 to 3.4.9 allows denial of service via packet injection or crafted capture file
nvd
CVE-2021-39371P3HIGHCVSS 7.5v9.02021-08-23
CVE-2021-39371 [HIGH] CWE-611 CVE-2021-39371: An XML external entity (XXE) injection in PyWPS before 4.4.5 allows an attacker to view files on the An XML external entity (XXE) injection in PyWPS before 4.4.5 allows an attacker to view files on the application server filesystem by assigning a path to the entity. OWSLib 0.24.1 may also be affected.
nvd
CVE-2012-0051P3HIGHCVSS 7.4v8.0v9.0+1 more2019-11-07
CVE-2012-0051 [HIGH] CWE-20 CVE-2012-0051: Tahoe-LAFS 1.9.0 fails to ensure integrity which allows remote attackers to corrupt mutable files or Tahoe-LAFS 1.9.0 fails to ensure integrity which allows remote attackers to corrupt mutable files or directories upon retrieval.
nvd
CVE-2021-32919P3HIGHCVSS 7.5v10.02021-05-13
CVE-2021-32919 [HIGH] CWE-295 CVE-2021-32919: An issue was discovered in Prosody before 0.11.9. The undocumented dialback_without_dialback option An issue was discovered in Prosody before 0.11.9. The undocumented dialback_without_dialback option in mod_dialback enables an experimental feature for server-to-server authentication. It does not correctly authenticate remote server certificates, allowing a remote server to impersonate another server (when this option is enabled).
nvd
CVE-2023-4050P3HIGHCVSS 7.5v11.0v12.02023-08-01
CVE-2023-4050 [HIGH] CWE-787 CVE-2023-4050: In some cases, an untrusted input stream was copied to a stack buffer without checking its size. Thi In some cases, an untrusted input stream was copied to a stack buffer without checking its size. This resulted in a potentially exploitable crash which could have led to a sandbox escape. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.
nvd
CVE-2018-1304P3MEDIUMCVSS 5.9v7.0v8.0+1 more2018-02-28
CVE-2018-1304 [MEDIUM] CVE-2018-1304: The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly ha The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of a security constraint definition. This caused the constraint to be ignored. It was, therefore, possible for unauthorised users to gain access
nvd
CVE-2025-10921P3HIGHCVSS 7.8v11.02025-10-29
CVE-2025-10921 [HIGH] CWE-122 CVE-2025-10921: GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabi GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists withi
nvd
CVE-2025-10934P3HIGHCVSS 7.8v11.02025-10-29
CVE-2025-10934 [HIGH] CWE-122 CVE-2025-10934: GIMP XWD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabi GIMP XWD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists withi
nvd
CVE-2022-1586P3CRITICALCVSS 9.1v10.02022-05-16
CVE-2022-1586 [CRITICAL] CWE-125 CVE-2022-1586: An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchi An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.
nvd
CVE-2008-4582P4MEDIUMCVSS 4.3PoCv4.02008-10-15
CVE-2008-4582 [MEDIUM] CWE-264 CVE-2008-4582: Mozilla Firefox 3.0.1 through 3.0.3, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13, w Mozilla Firefox 3.0.1 through 3.0.3, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13, when running on Windows, do not properly identify the context of Windows .url shortcut files, which allows user-assisted remote attackers to bypass the Same Origin Policy and obtain sensitive information via an HTML document that is directly accessible t
nvd
CVE-2021-41079P3HIGHCVSS 7.5v9.0v10.0+1 more2021-09-16
CVE-2021-41079 [HIGH] CWE-20 CVE-2021-41079: Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets. When Tomcat was configured to use NIO+OpenSSL or NIO2+OpenSSL for TLS, a specially crafted packet could be used to trigger an infinite loop resulting in a denial of service.
nvd
CVE-2008-7291P3CRITICALCVSS 9.8v8.0v9.0+1 more2019-11-08
CVE-2008-7291 [CRITICAL] CWE-668 CVE-2008-7291: gri before 2.12.18 generates temporary files in an insecure way. gri before 2.12.18 generates temporary files in an insecure way.
nvd
CVE-2019-11039P3CRITICALCVSS 9.1v9.0v10.02019-06-19
CVE-2019-11039 [CRITICAL] CWE-125 CVE-2019-11039: Function iconv_mime_decode_headers() in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3. Function iconv_mime_decode_headers() in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6 may perform out-of-buffer read due to integer overflow when parsing MIME headers. This may lead to information disclosure or crash.
nvd
CVE-2021-3563P3HIGHCVSS 7.4v10.0v11.02022-08-26
CVE-2021-3563 [HIGH] CWE-863 CVE-2021-3563: A flaw was found in openstack-keystone. Only the first 72 characters of an application secret are ve A flaw was found in openstack-keystone. Only the first 72 characters of an application secret are verified allowing attackers bypass some password complexity which administrators may be counting on. The highest threat from this vulnerability is to data confidentiality and integrity.
nvd
CVE-2013-1430P3CRITICALCVSS 9.8v7.0v8.02016-12-16
CVE-2013-1430 [CRITICAL] CWE-255 CVE-2013-1430: An issue was discovered in xrdp before 0.9.1. When successfully logging in using RDP into an xrdp se An issue was discovered in xrdp before 0.9.1. When successfully logging in using RDP into an xrdp session, the file ~/.vnc/sesman_${username}_passwd is created. Its content is the equivalent of the user's cleartext password, DES encrypted with a known key.
nvd
CVE-2012-0247P3HIGHCVSS 8.8v6.0v7.02012-06-05
CVE-2012-0247 [HIGH] CWE-20 CVE-2012-0247: ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (memory corrupt ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via crafted offset and count values in the ResolutionUnit tag in the EXIF IFD0 of an image.
nvd
CVE-2014-1529P3HIGHCVSS 8.8v7.0v8.02014-04-30
CVE-2014-1529 [HIGH] CWE-269 CVE-2014-1529: The Web Notification API in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird b The Web Notification API in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to bypass intended source-component restrictions and execute arbitrary JavaScript code in a privileged context via a crafted web page for which Notification.permission is granted.
nvd
CVE-2022-39958P3HIGHCVSS 7.5v10.02022-09-20
CVE-2022-39958 [HIGH] CWE-863 CVE-2022-39958: The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass to sequentially exfi The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass to sequentially exfiltrate small and undetectable sections of data by repeatedly submitting an HTTP Range header field with a small byte range. A restricted resource, access to which would ordinarily be detected, may be exfiltrated from the backend, despite being protected
nvd
CVE-2023-5176P3CRITICALCVSS 9.8v10.0v11.0+1 more2023-09-27
CVE-2023-5176 [CRITICAL] CWE-787 CVE-2023-5176: Memory safety bugs present in Firefox 117, Firefox ESR 115.2, and Thunderbird 115.2. Some of these b Memory safety bugs present in Firefox 117, Firefox ESR 115.2, and Thunderbird 115.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.
nvd
CVE-2022-39353P3CRITICALCVSS 9.8v10.02022-11-02
CVE-2022-39353 [CRITICAL] CVE-2022-39353: xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. xmldom parses XML that is not well-formed because it contains multiple top level elements, and adds all root nodes to the `childNodes` collection of the `Document`, without reporting any error or throwing. This breaks the assumption that there is
nvd
Debian Linux vulnerabilities | cvebase