Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 124 of 498
CVE-2023-30631P3HIGHCVSS 7.5v10.0v11.0+1 more2023-06-14
CVE-2023-30631 [HIGH] CWE-20 CVE-2023-30631: Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server. The co
Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server. The configuration option proxy.config.http.push_method_enabled didn't function. However, by default the PUSH method is blocked in the ip_allow configuration file.This issue affects Apache Traffic Server: from 8.0.0 through 9.2.0.
8.x users should upgrade to 8.1
nvd
CVE-2022-28129P3HIGHCVSS 7.5v10.0v11.02022-08-10
CVE-2022-28129 [HIGH] CWE-20 CVE-2022-28129: Improper Input Validation vulnerability in HTTP/1.1 header parsing of Apache Traffic Server allows a
Improper Input Validation vulnerability in HTTP/1.1 header parsing of Apache Traffic Server allows an attacker to send invalid headers. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.
nvd
CVE-2022-31091P3HIGHCVSS 7.7v11.02022-06-27
CVE-2022-31091 [HIGH] CWE-200 CVE-2022-31091: Guzzle, an extensible PHP HTTP client. `Authorization` and `Cookie` headers on requests are sensitiv
Guzzle, an extensible PHP HTTP client. `Authorization` and `Cookie` headers on requests are sensitive information. In affected versions on making a request which responds with a redirect to a URI with a different port, if we choose to follow it, we should remove the `Authorization` and `Cookie` headers from the request, before containing. Previously,
nvd
CVE-2022-31780P3HIGHCVSS 7.5v10.0v11.02022-08-10
CVE-2022-31780 [HIGH] CWE-20 CVE-2022-31780: Improper Input Validation vulnerability in HTTP/2 frame handling of Apache Traffic Server allows an
Improper Input Validation vulnerability in HTTP/2 frame handling of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.
nvd
CVE-2018-16151P3HIGHCVSS 7.5v8.0v9.02018-09-26
CVE-2018-16151 [HIGH] CWE-347 CVE-2018-16151: In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x
In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the RSA implementation based on GMP does not reject excess data after the encoded algorithm OID during PKCS#1 v1.5 signature verification. Similar to the flaw in the same version of strongSwan regarding digestAlgorithm.parameters, a remot
nvd
CVE-2016-7163P3HIGHCVSS 7.8v8.02016-09-21
CVE-2016-7163 [HIGH] CWE-190 CVE-2016-7163: Integer overflow in the opj_pi_create_decode function in pi.c in OpenJPEG allows remote attackers to
Integer overflow in the opj_pi_create_decode function in pi.c in OpenJPEG allows remote attackers to execute arbitrary code via a crafted JP2 file, which triggers an out-of-bounds read or write.
nvd
CVE-2022-31042P3HIGHCVSS 7.5v11.02022-06-10
CVE-2022-31042 [HIGH] CWE-200 CVE-2022-31042: Guzzle is an open source PHP HTTP client. In affected versions the `Cookie` headers on requests are
Guzzle is an open source PHP HTTP client. In affected versions the `Cookie` headers on requests are sensitive information. On making a request using the `https` scheme to a server which responds with a redirect to a URI with the `http` scheme, or on making a request to a server which responds with a redirect to a a URI to a different host, we should no
nvd
CVE-2021-3578P3HIGHCVSS 7.8v9.02022-02-16
CVE-2021-3578 [HIGH] CWE-704 CVE-2021-3578: A flaw was found in mbsync before v1.3.6 and v1.4.2, where an unchecked pointer cast allows a malici
A flaw was found in mbsync before v1.3.6 and v1.4.2, where an unchecked pointer cast allows a malicious or compromised server to write an arbitrary integer value past the end of a heap-allocated structure by issuing an unexpected APPENDUID response. This could be plausibly exploited for remote code execution on the client.
nvd
CVE-2021-31863P3HIGHCVSS 7.5v9.02021-04-28
CVE-2021-31863 [HIGH] CWE-20 CVE-2021-31863: Insufficient input validation in the Git repository integration of Redmine before 4.0.9, 4.1.x befor
Insufficient input validation in the Git repository integration of Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows Redmine users to read arbitrary local files accessible by the application server process.
nvd
CVE-2016-6306P3MEDIUMCVSS 5.9v8.02016-09-26
CVE-2016-6306 [MEDIUM] CWE-125 CVE-2016-6306: The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might allow remote attackers
The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might allow remote attackers to cause a denial of service (out-of-bounds read) via crafted certificate operations, related to s3_clnt.c and s3_srvr.c.
nvd
CVE-2023-6478P3HIGHCVSS 7.5v10.0v11.0+1 more2023-12-13
CVE-2023-6478 [HIGH] CWE-190 CVE-2023-6478: A flaw was found in xorg-server. A specially crafted request to RRChangeProviderProperty or RRChange
A flaw was found in xorg-server. A specially crafted request to RRChangeProviderProperty or RRChangeOutputProperty can trigger an integer overflow which may lead to a disclosure of sensitive information.
nvd
CVE-2013-0858P3CRITICALCVSS 9.3v7.02013-12-07
CVE-2013-0858 [CRITICAL] CVE-2013-0858: The atrac3_decode_init function in libavcodec/atrac3.c in FFmpeg before 1.0.4 allows remote attacker
The atrac3_decode_init function in libavcodec/atrac3.c in FFmpeg before 1.0.4 allows remote attackers to have an unspecified impact via ATRAC3 data with the joint stereo coding mode set and fewer than two channels.
nvd
CVE-2023-3389P3HIGHCVSS 7.8v10.0v11.02023-06-28
CVE-2023-3389 [HIGH] CWE-416 CVE-2023-3389: A use-after-free vulnerability in the Linux Kernel io_uring subsystem can be exploited to achieve lo
A use-after-free vulnerability in the Linux Kernel io_uring subsystem can be exploited to achieve local privilege escalation.
Racing a io_uring cancel poll request with a linked timeout can cause a UAF in a hrtimer.
We recommend upgrading past commit ef7dfac51d8ed961b742218f526bd589f3900a59 (4716c73b188566865bdd79c3a6709696a224ac04 for 5.10 stable and
nvd
CVE-2010-0012P3HIGHCVSS 8.8v5.02010-01-08
CVE-2010-0012 [HIGH] CWE-22 CVE-2010-0012: Directory traversal vulnerability in libtransmission/metainfo.c in Transmission 1.22, 1.34, 1.75, an
Directory traversal vulnerability in libtransmission/metainfo.c in Transmission 1.22, 1.34, 1.75, and 1.76 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in a pathname within a .torrent file.
nvd
CVE-2014-6311P3CRITICALCVSS 9.8v8.0v9.0+1 more2019-11-22
CVE-2014-6311 [CRITICAL] CWE-330 CVE-2014-6311: generate_doygen.pl in ace before 6.2.7+dfsg-2 creates predictable file names in the /tmp directory w
generate_doygen.pl in ace before 6.2.7+dfsg-2 creates predictable file names in the /tmp directory which allows attackers to gain elevated privileges.
nvd
CVE-2021-37698P3HIGHCVSS 7.5v9.02021-08-19
CVE-2021-37698 [HIGH] CWE-295 CVE-2021-37698: Icinga is a monitoring system which checks the availability of network resources, notifies users of
Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. In versions 2.5.0 through 2.13.0, ElasticsearchWriter, GelfWriter, InfluxdbWriter and Influxdb2Writer do not verify the server's certificate despite a certificate authority being specified. Icinga 2
nvd
CVE-2021-36369P3HIGHCVSS 7.5v10.02022-10-12
CVE-2021-36369 [HIGH] CWE-287 CVE-2021-36369: An issue was discovered in Dropbear through 2020.81. Due to a non-RFC-compliant check of the availab
An issue was discovered in Dropbear through 2020.81. Due to a non-RFC-compliant check of the available authentication methods in the client-side SSH code, it is possible for an SSH server to change the login process in its favor. This attack can bypass additional security measures such as FIDO2 tokens or SSH-Askpass. Thus, it allows an attacker to abu
nvd
CVE-2015-1803P3HIGHCVSS 8.5v7.02015-03-20
CVE-2015-1803 [HIGH] CVE-2015-1803: The bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x before 1
The bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x before 1.5.1 does not properly handle character bitmaps it cannot read, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) and possibly execute arbitrary code via a crafted BDF font file.
nvd
CVE-2016-8862P3HIGHCVSS 8.8v8.02017-02-15
CVE-2016-8862 [HIGH] CWE-119 CVE-2016-8862: The AcquireMagickMemory function in MagickCore/memory.c in ImageMagick before 7.0.3.3 allows remote
The AcquireMagickMemory function in MagickCore/memory.c in ImageMagick before 7.0.3.3 allows remote attackers to have unspecified impact via a crafted image, which triggers a memory allocation failure.
nvd
CVE-2023-3090P3HIGHCVSS 7.8v10.0v11.0+1 more2023-06-28
CVE-2023-3090 [HIGH] CWE-787 CVE-2023-3090: A heap out-of-bounds write vulnerability in the Linux Kernel ipvlan network driver can be exploited
A heap out-of-bounds write vulnerability in the Linux Kernel ipvlan network driver can be exploited to achieve local privilege escalation.
The out-of-bounds write is caused by missing skb->cb initialization in the ipvlan network driver. The vulnerability is reachable if CONFIG_IPVLAN is enabled.
We recommend upgrading past commit 90cbed5247439a966b645
nvd