cbcvebase.

Debian Linux vulnerabilities

9,953 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358

Vulnerabilities

Page 122 of 498
CVE-2017-5202P3CRITICALCVSS 9.8v8.0v9.02017-01-28
CVE-2017-5202 [CRITICAL] CWE-119 CVE-2017-5202: The ISO CLNS parser in tcpdump before 4.9.0 has a buffer overflow in print-isoclns.c:clnp_print(). The ISO CLNS parser in tcpdump before 4.9.0 has a buffer overflow in print-isoclns.c:clnp_print().
nvd
CVE-2020-29479P3HIGHCVSS 8.8v10.02020-12-15
CVE-2020-29479 [HIGH] CWE-862 CVE-2020-29479: An issue was discovered in Xen through 4.14.x. In the Ocaml xenstored implementation, the internal r An issue was discovered in Xen through 4.14.x. In the Ocaml xenstored implementation, the internal representation of the tree has special cases for the root node, because this node has no parent. Unfortunately, permissions were not checked for certain operations on the root node. Unprivileged guests can get and modify permissions, list, and delete the
nvd
CVE-2021-27577P3HIGHCVSS 7.5v8.02021-06-29
CVE-2021-27577 [HIGH] CWE-444 CVE-2021-27577: Incorrect handling of url fragment vulnerability of Apache Traffic Server allows an attacker to pois Incorrect handling of url fragment vulnerability of Apache Traffic Server allows an attacker to poison the cache. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.
nvd
CVE-2015-9542P3HIGHCVSS 7.5v8.0v9.02020-02-24
CVE-2015-9542 [HIGH] CWE-787 CVE-2015-9542: add_password in pam_radius_auth.c in pam_radius 1.4.0 does not correctly check the length of the inp add_password in pam_radius_auth.c in pam_radius 1.4.0 does not correctly check the length of the input password, and is vulnerable to a stack-based buffer overflow during memcpy(). An attacker could send a crafted password to an application (loading the pam_radius library) and crash it. Arbitrary code execution might be possible, depending on the applic
nvd
CVE-2020-29363P3HIGHCVSS 7.5v10.02020-12-16
CVE-2020-29363 [HIGH] CWE-787 CVE-2020-29363: An issue was discovered in p11-kit 0.23.6 through 0.23.21. A heap-based buffer overflow has been dis An issue was discovered in p11-kit 0.23.6 through 0.23.21. A heap-based buffer overflow has been discovered in the RPC protocol used by p11-kit server/remote commands and the client library. When the remote entity supplies a serialized byte array in a CK_ATTRIBUTE, the receiving entity may not allocate sufficient length for the buffer to store the des
nvd
CVE-2018-5156P3CRITICALCVSS 9.8v8.0v9.02018-10-18
CVE-2018-5156 [CRITICAL] CWE-20 CVE-2018-5156: A vulnerability can occur when capturing a media stream when the media source type is changed as the A vulnerability can occur when capturing a media stream when the media source type is changed as the capture is occurring. This can result in stream data being cast to the wrong type causing a potentially exploitable crash. This vulnerability affects Thunderbird < 60, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.
nvd
CVE-2020-8955P3CRITICALCVSS 9.8v8.0v9.02020-02-12
CVE-2020-8955 [CRITICAL] CWE-120 CVE-2020-8955: irc_mode_channel_update in plugins/irc/irc-mode.c in WeeChat through 2.7 allows remote attackers to irc_mode_channel_update in plugins/irc/irc-mode.c in WeeChat through 2.7 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a malformed IRC message 324 (channel mode).
nvd
CVE-2019-13031P3HIGHCVSS 8.1v8.02019-06-28
CVE-2019-13031 [HIGH] CWE-611 CVE-2019-13031: LemonLDAP::NG before 1.9.20 has an XML External Entity (XXE) issue when submitting a notification to LemonLDAP::NG before 1.9.20 has an XML External Entity (XXE) issue when submitting a notification to the notification server. By default, the notification server is not enabled and has a "deny all" rule.
nvd
CVE-2020-3341P3HIGHCVSS 7.5v8.02020-05-13
CVE-2020-3341 [HIGH] CWE-20 CVE-2020-3341: A vulnerability in the PDF archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.101 A vulnerability in the PDF archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.101 - 0.102.2 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to a stack buffer overflow read. An attacker could exploit this vulnerability by sending a crafted PDF file to
nvd
CVE-2017-10067P3HIGHCVSS 7.5v8.0v9.02017-08-08
CVE-2017-10067 [HIGH] CVE-2017-10067: Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Security). Supported version Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than t
nvd
CVE-2015-1396P3HIGHCVSS 7.5v8.0v9.0+2 more2019-11-25
CVE-2015-1396 [HIGH] CVE-2015-1396: A Directory Traversal vulnerability exists in the GNU patch before 2.7.4. A remote attacker can writ A Directory Traversal vulnerability exists in the GNU patch before 2.7.4. A remote attacker can write to arbitrary files via a symlink attack in a patch file. NOTE: this issue exists because of an incomplete fix for CVE-2015-1196.
nvd
CVE-2020-11501P3HIGHCVSS 7.4v10.02020-04-03
CVE-2020-11501 [HIGH] CWE-330 CVE-2020-11501: GnuTLS 3.6.x before 3.6.13 uses incorrect cryptography for DTLS. The earliest affected version is 3. GnuTLS 3.6.x before 3.6.13 uses incorrect cryptography for DTLS. The earliest affected version is 3.6.3 (2018-07-16) because of an error in a 2017-10-06 commit. The DTLS client always uses 32 '\0' bytes instead of a random value, and thus contributes no randomness to a DTLS negotiation. This breaks the security guarantees of the DTLS protocol.
nvd
CVE-2020-10802P3HIGHCVSS 8.0v8.02020-03-22
CVE-2020-10802 [HIGH] CWE-89 CVE-2020-10802: In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability has been discover In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability has been discovered where certain parameters are not properly escaped when generating certain queries for search actions in libraries/classes/Controllers/Table/TableSearchController.php. An attacker can generate a crafted database or table name. The attack can be perform
nvd
CVE-2017-2835P3HIGHCVSS 8.1v8.0v9.02018-04-24
CVE-2017-2835 [HIGH] CWE-787 CVE-2017-2835: An exploitable code execution vulnerability exists in the RDP receive functionality of FreeRDP 2.0.0 An exploitable code execution vulnerability exists in the RDP receive functionality of FreeRDP 2.0.0-beta1+android11. A specially crafted server response can cause an out-of-bounds write resulting in an exploitable condition. An attacker can compromise the server or use a man in the middle to trigger this vulnerability.
nvd
CVE-2018-14883P3HIGHCVSS 7.5v8.0v9.02018-08-03
CVE-2018-14883 [HIGH] CWE-125 CVE-2018-14883: An issue was discovered in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2.x be An issue was discovered in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2.x before 7.2.8. An Integer Overflow leads to a heap-based buffer over-read in exif_thumbnail_extract of exif.c.
nvd
CVE-2018-14356P3CRITICALCVSS 9.8v8.0v9.02018-07-17
CVE-2018-14356 [CRITICAL] CWE-824 CVE-2018-14356: An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c mishandles a zero An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c mishandles a zero-length UID.
nvd
CVE-2022-2469P3HIGHCVSS 8.1v10.0v11.02022-07-19
CVE-2022-2469 [HIGH] CWE-125 CVE-2022-2469: GNU SASL libgsasl server-side read-out-of-bounds with malicious authenticated GSS-API client GNU SASL libgsasl server-side read-out-of-bounds with malicious authenticated GSS-API client
nvd
CVE-2017-5460P3CRITICALCVSS 9.8v8.02018-06-11
CVE-2017-5460 [CRITICAL] CWE-416 CVE-2017-5460: A use-after-free vulnerability in frame selection triggered by a combination of malicious script con A use-after-free vulnerability in frame selection triggered by a combination of malicious script content and key presses by a user. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2010-3451P3CRITICALCVSS 9.3v5.0v6.02011-01-28
CVE-2010-3451 [CRITICAL] CWE-416 CVE-2010-3451: Use-after-free vulnerability in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remot Use-after-free vulnerability in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via malformed tables in an RTF document.
nvd
CVE-2017-0357P3CRITICALCVSS 9.8v9.02018-04-13
CVE-2017-0357 [CRITICAL] CWE-119 CVE-2017-0357: A heap-overflow flaw exists in the -tr loader of iucode-tool starting with v1.4 and before v2.1.1, p A heap-overflow flaw exists in the -tr loader of iucode-tool starting with v1.4 and before v2.1.1, potentially leading to SIGSEGV, or heap corruption.
nvd
Debian Linux vulnerabilities | cvebase