Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 131 of 498
CVE-2018-6553P3HIGHCVSS 8.8v8.0v9.02018-08-10
CVE-2018-6553 [HIGH] CVE-2018-6553: The CUPS AppArmor profile incorrectly confined the dnssd backend due to use of hard links. A local a
The CUPS AppArmor profile incorrectly confined the dnssd backend due to use of hard links. A local attacker could possibly use this issue to escape confinement. This flaw affects versions prior to 2.2.7-1ubuntu2.1 in Ubuntu 18.04 LTS, prior to 2.2.4-7ubuntu3.1 in Ubuntu 17.10, prior to 2.1.3-4ubuntu0.5 in Ubuntu 16.04 LTS, and prior to 1.7.2-0ubuntu1.10 in Ubun
nvd
CVE-2020-14593P3HIGHCVSS 7.4v9.0v10.02020-07-15
CVE-2020-14593 [HIGH] CVE-2020-14593: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 7u261, 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful atta
nvd
CVE-2017-14062P3CRITICALCVSS 9.8v8.0v9.0+1 more2017-08-31
CVE-2017-14062 [CRITICAL] CWE-190 CVE-2017-14062: Integer overflow in the decode_digit function in puny_decode.c in Libidn2 before 2.0.4 allows remote
Integer overflow in the decode_digit function in puny_decode.c in Libidn2 before 2.0.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact.
nvd
CVE-2019-5755P3HIGHCVSS 8.1v9.02019-02-19
CVE-2019-5755 [HIGH] CWE-189 CVE-2019-5755: Incorrect handling of negative zero in V8 in Google Chrome prior to 72.0.3626.81 allowed a remote at
Incorrect handling of negative zero in V8 in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page.
nvd
CVE-2017-7824P3CRITICALCVSS 9.8v7.0v8.0+1 more2018-06-11
CVE-2017-7824 [CRITICAL] CWE-119 CVE-2017-7824: A buffer overflow occurs when drawing and validating elements with the ANGLE graphics library, used
A buffer overflow occurs when drawing and validating elements with the ANGLE graphics library, used for WebGL content. This is due to an incorrect value being passed within the library during checks and results in a potentially exploitable crash. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.
nvd
CVE-2019-8322P3HIGHCVSS 7.5v9.02019-06-17
CVE-2019-8322 [HIGH] CWE-74 CVE-2019-8322: An issue was discovered in RubyGems 2.6 and later through 3.0.2. The gem owner command outputs the c
An issue was discovered in RubyGems 2.6 and later through 3.0.2. The gem owner command outputs the contents of the API response directly to stdout. Therefore, if the response is crafted, escape sequence injection may occur.
nvd
CVE-2017-5438P3CRITICALCVSS 9.8v9.02018-06-11
CVE-2017-5438 [CRITICAL] CWE-416 CVE-2017-5438: A use-after-free vulnerability during XSLT processing due to the result handler being held by a free
A use-after-free vulnerability during XSLT processing due to the result handler being held by a freed handler during handling. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2022-32293P3HIGHCVSS 8.1v11.02022-08-03
CVE-2022-32293 [HIGH] CWE-416 CVE-2022-32293: In ConnMan through 1.41, a man-in-the-middle attack against a WISPR HTTP query could be used to trig
In ConnMan through 1.41, a man-in-the-middle attack against a WISPR HTTP query could be used to trigger a use-after-free in WISPR handling, leading to crashes or code execution.
nvd
CVE-2017-5205P3CRITICALCVSS 9.8v8.0v9.02017-01-28
CVE-2017-5205 [CRITICAL] CWE-119 CVE-2017-5205: The ISAKMP parser in tcpdump before 4.9.0 has a buffer overflow in print-isakmp.c:ikev2_e_print().
The ISAKMP parser in tcpdump before 4.9.0 has a buffer overflow in print-isakmp.c:ikev2_e_print().
nvd
CVE-2017-10388P3HIGHCVSS 7.5v7.0v8.0+1 more2017-10-19
CVE-2017-10388 [HIGH] CVE-2017-10388: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries)
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Kerberos to compromise Java SE, Java SE Embedded. Successful attac
nvd
CVE-2017-7818P3CRITICALCVSS 9.8v7.0v8.0+1 more2018-06-11
CVE-2017-7818 [CRITICAL] CWE-416 CVE-2017-7818: A use-after-free vulnerability can occur when manipulating arrays of Accessible Rich Internet Applic
A use-after-free vulnerability can occur when manipulating arrays of Accessible Rich Internet Applications (ARIA) elements within containers through the DOM. This results in a potentially exploitable crash. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.
nvd
CVE-2021-1405P3HIGHCVSS 7.5v9.02021-04-08
CVE-2021-1405 [HIGH] CWE-120 CVE-2021-1405: A vulnerability in the email parsing module in Clam AntiVirus (ClamAV) Software version 0.103.1 and
A vulnerability in the email parsing module in Clam AntiVirus (ClamAV) Software version 0.103.1 and all prior versions could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to improper variable initialization that may result in an NULL pointer read. An attacker could exploit
nvd
CVE-2021-21172P3HIGHCVSS 8.1v10.02021-03-09
CVE-2021-21172 [HIGH] CVE-2021-21172: Insufficient policy enforcement in File System API in Google Chrome on Windows prior to 89.0.4389.72
Insufficient policy enforcement in File System API in Google Chrome on Windows prior to 89.0.4389.72 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.
nvd
CVE-2018-5091P3CRITICALCVSS 9.8v7.0v8.0+1 more2018-06-11
CVE-2018-5091 [CRITICAL] CWE-416 CVE-2018-5091: A use-after-free vulnerability can occur during WebRTC connections when interacting with the DTMF ti
A use-after-free vulnerability can occur during WebRTC connections when interacting with the DTMF timers. This results in a potentially exploitable crash. This vulnerability affects Firefox ESR < 52.6 and Firefox < 58.
nvd
CVE-2015-8467P3HIGHCVSS 7.5v7.0v8.02015-12-29
CVE-2015-8467 [HIGH] CVE-2015-8467: The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_modules/samldb.c in Samba 4.x b
The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_modules/samldb.c in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not properly check for administrative privileges during creation of machine accounts, which allows remote authenticated users to bypass intended access restrictions by leveraging the existence of a dom
nvd
CVE-2017-16840P3CRITICALCVSS 9.8v9.02017-11-21
CVE-2017-16840 [CRITICAL] CWE-125 CVE-2017-16840: The VC-2 Video Compression encoder in FFmpeg 3.0 and 3.4 allows remote attackers to cause a denial o
The VC-2 Video Compression encoder in FFmpeg 3.0 and 3.4 allows remote attackers to cause a denial of service (out-of-bounds read) because of incorrect buffer padding for non-Haar wavelets, related to libavcodec/vc2enc.c and libavcodec/vc2enc_dwt.c.
nvd
CVE-2022-20698P3HIGHCVSS 7.5v9.0v10.0+1 more2022-01-14
CVE-2022-20698 [HIGH] CWE-20 CVE-2022-20698: A vulnerability in the OOXML parsing module in Clam AntiVirus (ClamAV) Software version 0.104.1 and
A vulnerability in the OOXML parsing module in Clam AntiVirus (ClamAV) Software version 0.104.1 and LTS version 0.103.4 and prior versions could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to improper checks that may result in an invalid pointer read. An attacker could
nvd
CVE-2023-1668P3HIGHCVSS 8.2v11.02023-04-10
CVE-2023-1668 [HIGH] CWE-670 CVE-2023-1668: A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will instal
A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will install the datapath flow without the action modifying the IP header. This issue results (for both kernel and userspace datapath) in installing a datapath flow matching all IP protocols (nw_proto is wildcarded) for this flow, but with an incorrect action, possi
nvd
CVE-2020-8184P3HIGHCVSS 7.5v9.0v10.02020-06-19
CVE-2020-8184 [HIGH] CWE-784 CVE-2020-8184: A reliance on cookies without validation/integrity check security vulnerability exists in rack < 2.2
A reliance on cookies without validation/integrity check security vulnerability exists in rack < 2.2.3, rack < 2.1.4 that makes it is possible for an attacker to forge a secure or host-only cookie prefix.
nvd
CVE-2017-5443P3CRITICALCVSS 9.8v9.02018-06-11
CVE-2017-5443 [CRITICAL] CWE-787 CVE-2017-5443: An out-of-bounds write vulnerability while decoding improperly formed BinHex format archives. This v
An out-of-bounds write vulnerability while decoding improperly formed BinHex format archives. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd