cbcvebase.

Debian Linux vulnerabilities

9,953 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358

Vulnerabilities

Page 125 of 498
CVE-2023-0361P3HIGHCVSS 7.4v10.02023-02-15
CVE-2023-0361 [HIGH] CWE-203 CVE-2023-0361: A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. Th A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbacher style attack. To achieve a successful decryption the attacker would need to send a large amount of specially crafted messages to the
nvd
CVE-2022-31214P3HIGHCVSS 7.8v9.0v10.02022-06-09
CVE-2022-31214 [HIGH] CWE-269 CVE-2022-31214: A Privilege Context Switching issue was discovered in join.c in Firejail 0.9.68. By crafting a bogus A Privilege Context Switching issue was discovered in join.c in Firejail 0.9.68. By crafting a bogus Firejail container that is accepted by the Firejail setuid-root program as a join target, a local attacker can enter an environment in which the Linux user namespace is still the initial user namespace, the NO_NEW_PRIVS prctl is not activated, and the
nvd
CVE-2018-20843P3HIGHCVSS 7.5v8.0v9.02019-06-24
CVE-2018-20843 [HIGH] CWE-611 CVE-2018-20843: In libexpat in Expat before 2.2.7, XML input including XML names that contain a large number of colo In libexpat in Expat before 2.2.7, XML input including XML names that contain a large number of colons could make the XML parser consume a high amount of RAM and CPU resources while processing (enough to be usable for denial-of-service attacks).
nvd
CVE-2022-40284P3HIGHCVSS 7.8v10.02022-11-06
CVE-2022-40284 [HIGH] CWE-120 CVE-2022-40284: A buffer overflow was discovered in NTFS-3G before 2022.10.3. Crafted metadata in an NTFS image can A buffer overflow was discovered in NTFS-3G before 2022.10.3. Crafted metadata in an NTFS image can cause code execution. A local attacker can exploit this if the ntfs-3g binary is setuid root. A physically proximate attacker can exploit this if NTFS-3G software is configured to execute upon attachment of an external storage device.
nvd
CVE-2018-8971P3CRITICALCVSS 9.8v9.02018-03-24
CVE-2018-8971 [CRITICAL] CWE-20 CVE-2018-8971: The Auth0 integration in GitLab before 10.3.9, 10.4.x before 10.4.6, and 10.5.x before 10.5.6 has an The Auth0 integration in GitLab before 10.3.9, 10.4.x before 10.4.6, and 10.5.x before 10.5.6 has an incorrect omniauth-auth0 configuration, leading to signing in unintended users.
nvd
CVE-2025-64512P3HIGHCVSS 7.8v11.02025-11-10
CVE-2025-64512 [HIGH] CWE-502 CVE-2025-64512: Pdfminer.six is a community maintained fork of the original PDFMiner, a tool for extracting informat Pdfminer.six is a community maintained fork of the original PDFMiner, a tool for extracting information from PDF documents. Prior to version 20251107, pdfminer.six will execute arbitrary code from a malicious pickle file if provided with a malicious PDF file. The `CMapDB._load_data()` function in pdfminer.six uses `pickle.loads()` to deserialize pickl
nvd
CVE-2023-2007P3HIGHCVSS 7.8v10.0v11.02023-04-24
CVE-2023-2007 [HIGH] CWE-367 CVE-2023-2007: The specific flaw exists within the DPT I2O Controller driver. The issue results from the lack of pr The specific flaw exists within the DPT I2O Controller driver. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this in conjunction with other vulnerabilities to escalate privileges and execute arbitrary code in the context of the kernel.
nvd
CVE-2016-8677P3HIGHCVSS 8.8v8.02017-02-15
CVE-2016-8677 [HIGH] CVE-2016-8677: The AcquireQuantumPixels function in MagickCore/quantum.c in ImageMagick before 7.0.3-1 allows remot The AcquireQuantumPixels function in MagickCore/quantum.c in ImageMagick before 7.0.3-1 allows remote attackers to have unspecified impact via a crafted image file, which triggers a memory allocation failure.
nvd
CVE-2015-5345P3MEDIUMCVSS 5.3v7.0v8.02016-02-25
CVE-2015-5345 [MEDIUM] CWE-22 CVE-2015-5345: The Mapper component in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.30, and 9 The Mapper component in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.30, and 9.x before 9.0.0.M2 processes redirects before considering security constraints and Filters, which allows remote attackers to determine the existence of a directory via a URL that lacks a trailing / (slash) character.
nvd
CVE-2020-11112P3HIGHCVSS 8.8v8.02020-03-31
CVE-2020-11112 [HIGH] CWE-502 CVE-2020-11112: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadg FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy).
nvd
CVE-2020-10663P3HIGHCVSS 7.5v8.0v10.02020-04-28
CVE-2020-10663 [HIGH] CVE-2020-10663: The JSON gem through 2.2.0 for Ruby, as used in Ruby 2.4 through 2.4.9, 2.5 through 2.5.7, and 2.6 t The JSON gem through 2.2.0 for Ruby, as used in Ruby 2.4 through 2.4.9, 2.5 through 2.5.7, and 2.6 through 2.6.5, has an Unsafe Object Creation Vulnerability. This is quite similar to CVE-2013-0269, but does not rely on poor garbage-collection behavior within Ruby. Specifically, use of JSON parsing methods can lead to creation of a malicious object within the
nvd
CVE-2022-39957P3HIGHCVSS 7.5v10.02022-09-20
CVE-2022-39957 [HIGH] CWE-693 CVE-2022-39957: The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass. A client can issue The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass. A client can issue an HTTP Accept header field containing an optional "charset" parameter in order to receive the response in an encoded form. Depending on the "charset", this response can not be decoded by the web application firewall. A restricted resource, access to whi
nvd
CVE-2010-4533P3CRITICALCVSS 9.8v8.0v9.0+1 more2019-11-13
CVE-2010-4533 [CRITICAL] CWE-295 CVE-2010-4533: offlineimap before 6.3.4 added support for SSL server certificate validation but it is still possibl offlineimap before 6.3.4 added support for SSL server certificate validation but it is still possible to use SSL v2 protocol, which is a flawed protocol with multiple security deficiencies.
nvd
CVE-2018-17462P3CRITICALCVSS 9.6v9.02018-11-14
CVE-2018-17462 [CRITICAL] CWE-416 CVE-2018-17462: Incorrect refcounting in AppCache in Google Chrome prior to 70.0.3538.67 allowed a remote attacker t Incorrect refcounting in AppCache in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to perform a sandbox escape via a crafted HTML page.
nvd
CVE-2019-9200P3HIGHCVSS 8.8v8.02019-02-26
CVE-2019-9200 [HIGH] CWE-787 CVE-2019-9200: A heap-based buffer underwrite exists in ImageStream::getLine() located at Stream.cc in Poppler 0.74 A heap-based buffer underwrite exists in ImageStream::getLine() located at Stream.cc in Poppler 0.74.0 that can (for example) be triggered by sending a crafted PDF file to the pdfimages binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact.
nvd
CVE-2021-35942P3CRITICALCVSS 9.1v10.02021-07-22
CVE-2021-35942 [CRITICAL] CWE-190 CVE-2021-35942: The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or read arbitrary memor The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or read arbitrary memory in parse_param (in posix/wordexp.c) when called with an untrusted, crafted pattern, potentially resulting in a denial of service or disclosure of information. This occurs because atoi was used but strtoul should have been used to ensure correct ca
nvd
CVE-2014-4343P3HIGHCVSS 7.6v7.02014-08-14
CVE-2014-4343 [HIGH] CWE-415 CVE-2014-4343: Double free vulnerability in the init_ctx_reselect function in the SPNEGO initiator in lib/gssapi/sp Double free vulnerability in the init_ctx_reselect function in the SPNEGO initiator in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.10.x through 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via network traffic that appears to come from an intended accep
nvd
CVE-2020-6471P3CRITICALCVSS 9.6v9.0v10.02020-05-21
CVE-2020-6471 [CRITICAL] CWE-276 CVE-2020-6471: Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
nvd
CVE-2018-12599P3HIGHCVSS 8.8v8.0v9.02018-06-20
CVE-2018-12599 [HIGH] CWE-787 CVE-2018-12599: In ImageMagick 7.0.8-3 Q16, ReadBMPImage and WriteBMPImage in coders/bmp.c allow attackers to cause In ImageMagick 7.0.8-3 Q16, ReadBMPImage and WriteBMPImage in coders/bmp.c allow attackers to cause an out of bounds write via a crafted file.
nvd
CVE-2018-12600P3HIGHCVSS 8.8v8.0v9.02018-06-20
CVE-2018-12600 [HIGH] CWE-787 CVE-2018-12600: In ImageMagick 7.0.8-3 Q16, ReadDIBImage and WriteDIBImage in coders/dib.c allow attackers to cause In ImageMagick 7.0.8-3 Q16, ReadDIBImage and WriteDIBImage in coders/dib.c allow attackers to cause an out of bounds write via a crafted file.
nvd
Debian Linux vulnerabilities | cvebase