Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 132 of 498
CVE-2017-18187P3CRITICALCVSS 9.8v8.0v9.02018-02-14
CVE-2017-18187 [CRITICAL] CWE-190 CVE-2017-18187: In ARM mbed TLS before 2.7.0, there is a bounds-check bypass through an integer overflow in PSK iden
In ARM mbed TLS before 2.7.0, there is a bounds-check bypass through an integer overflow in PSK identity parsing in the ssl_parse_client_psk_identity() function in library/ssl_srv.c.
nvd
CVE-2020-25709P3HIGHCVSS 7.5v9.0v10.02021-05-18
CVE-2020-25709 [HIGH] CWE-617 CVE-2020-25709: A flaw was found in OpenLDAP. This flaw allows an attacker who can send a malicious packet to be pro
A flaw was found in OpenLDAP. This flaw allows an attacker who can send a malicious packet to be processed by OpenLDAP’s slapd server, to trigger an assertion failure. The highest threat from this vulnerability is to system availability.
nvd
CVE-2012-3163P3CRITICALCVSS 9.0v6.0v7.02012-10-17
CVE-2012-3163 [CRITICAL] CVE-2012-3163: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.64 and earlier, and 5.5.
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.64 and earlier, and 5.5.26 and earlier, allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Information Schema.
nvd
CVE-2020-11077P3HIGHCVSS 7.5v9.02020-05-22
CVE-2020-11077 [HIGH] CVE-2020-11077: In Puma (RubyGem) before 4.3.5 and 3.12.6, a client could smuggle a request through a proxy, causing
In Puma (RubyGem) before 4.3.5 and 3.12.6, a client could smuggle a request through a proxy, causing the proxy to send a response back to another unknown client. If the proxy uses persistent connections and the client adds another request in via HTTP pipelining, the proxy may mistake it as the first request's body. Puma, however, would see it as two requests,
nvd
CVE-2015-3144P3CRITICALCVSS 9.0v7.02015-04-24
CVE-2015-3144 [CRITICAL] CWE-119 CVE-2015-3144: The fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 does not properly calculate an i
The fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) or possibly have other unspecified impact via a zero-length host name, as demonstrated by "http://:80" and ":80."
nvd
CVE-2019-14817P3HIGHCVSS 7.8v8.0v9.0+1 more2019-09-03
CVE-2019-14817 [HIGH] CWE-648 CVE-2019-14817: A flaw was found in, ghostscript versions prior to 9.50, in the .pdfexectoken and other procedures w
A flaw was found in, ghostscript versions prior to 9.50, in the .pdfexectoken and other procedures where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.
nvd
CVE-2021-3516P3HIGHCVSS 7.8v9.02021-06-01
CVE-2021-3516 [HIGH] CWE-416 CVE-2021-3516: There's a flaw in libxml2's xmllint in versions before 2.9.11. An attacker who is able to submit a c
There's a flaw in libxml2's xmllint in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by xmllint could trigger a use-after-free. The greatest impact of this flaw is to confidentiality, integrity, and availability.
nvd
CVE-2018-11531P3CRITICALCVSS 9.8v8.0v9.02018-05-29
CVE-2018-11531 [CRITICAL] CWE-787 CVE-2018-11531: Exiv2 0.26 has a heap-based buffer overflow in getData in preview.cpp.
Exiv2 0.26 has a heap-based buffer overflow in getData in preview.cpp.
nvd
CVE-2023-43804P3HIGHCVSS 8.1v10.02023-10-04
CVE-2023-43804 [HIGH] CWE-200 CVE-2023-43804: urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn't treat the `Cookie` HTTP h
urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn't treat the `Cookie` HTTP header special or provide any helpers for managing cookies over HTTP, that is the responsibility of the user. However, it is possible for a user to specify a `Cookie` header and unknowingly leak information via HTTP redirects to a different origin if tha
nvd
CVE-2020-35662P3HIGHCVSS 7.4v9.0v10.0+1 more2021-02-27
CVE-2020-35662 [HIGH] CWE-295 CVE-2020-35662: In SaltStack Salt before 3002.5, when authenticating to services using certain modules, the SSL cert
In SaltStack Salt before 3002.5, when authenticating to services using certain modules, the SSL certificate is not always validated.
nvd
CVE-2021-33574P3CRITICALCVSS 9.8v10.02021-05-25
CVE-2021-33574 [CRITICAL] CWE-416 CVE-2021-33574: The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free.
The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It may use the notification thread attributes object (passed through its struct sigevent parameter) after it has been freed by the caller, leading to a denial of service (application crash) or possibly unspecified other impact.
nvd
CVE-2020-25643P3HIGHCVSS 7.2v9.0v10.02020-10-06
CVE-2020-25643 [HIGH] CWE-20 CVE-2020-25643: A flaw was found in the HDLC_PPP module of the Linux kernel in versions before 5.9-rc7. Memory corru
A flaw was found in the HDLC_PPP module of the Linux kernel in versions before 5.9-rc7. Memory corruption and a read overflow is caused by improper input validation in the ppp_cp_parse_cr function which can cause the system to crash or cause a denial of service. The highest threat from this vulnerability is to data confidentiality and integrity as well
nvd
CVE-2013-6410P3HIGHCVSS 7.5v6.0v7.02013-12-07
CVE-2013-6410 [HIGH] CWE-264 CVE-2013-6410: nbd-server in Network Block Device (nbd) before 3.5 does not properly check IP addresses, which migh
nbd-server in Network Block Device (nbd) before 3.5 does not properly check IP addresses, which might allow remote attackers to bypass intended access restrictions via an IP address that has a partial match in the authfile configuration file.
nvd
CVE-2021-37149P3HIGHCVSS 7.5v10.0v11.02021-11-03
CVE-2021-37149 [HIGH] CWE-20 CVE-2021-37149: Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacke
Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.1.0.
nvd
CVE-2021-37148P3HIGHCVSS 7.5v10.0v11.02021-11-03
CVE-2021-37148 [HIGH] CWE-20 CVE-2021-37148: Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacke
Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.0.1.
nvd
CVE-2016-9842P3HIGHCVSS 8.8v8.02017-05-23
CVE-2016-9842 [HIGH] CWE-1335 CVE-2016-9842: The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have
The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.
nvd
CVE-2023-2911P3HIGHCVSS 7.5v11.0v12.02023-06-21
CVE-2023-2911 [HIGH] CWE-787 CVE-2023-2911: If the `recursive-clients` quota is reached on a BIND 9 resolver configured with both `stale-answer-
If the `recursive-clients` quota is reached on a BIND 9 resolver configured with both `stale-answer-enable yes;` and `stale-answer-client-timeout 0;`, a sequence of serve-stale-related lookups could cause `named` to loop and terminate unexpectedly due to a stack overflow.
This issue affects BIND 9 versions 9.16.33 through 9.16.41, 9.18.7 through 9.18.15
nvd
CVE-2021-21707P3MEDIUMCVSS 5.3v10.0v11.02021-11-29
CVE-2021-21707 [MEDIUM] CWE-159 CVE-2021-21707: In PHP versions 7.3.x below 7.3.33, 7.4.x below 7.4.26 and 8.0.x below 8.0.13, certain XML parsing f
In PHP versions 7.3.x below 7.3.33, 7.4.x below 7.4.26 and 8.0.x below 8.0.13, certain XML parsing functions, like simplexml_load_file(), URL-decode the filename passed to them. If that filename contains URL-encoded NUL character, this may cause the function to interpret this as the end of the filename, thus interpreting the filename differently fro
nvd
CVE-2016-2849P3HIGHCVSS 7.5v8.02016-05-13
CVE-2016-2849 [HIGH] CWE-200 CVE-2016-2849: Botan before 1.10.13 and 1.11.x before 1.11.29 do not use a constant-time algorithm to perform a mod
Botan before 1.10.13 and 1.11.x before 1.11.29 do not use a constant-time algorithm to perform a modular inverse on the signature nonce k, which might allow remote attackers to obtain ECDSA secret keys via a timing side-channel attack.
nvd
CVE-2021-37147P3HIGHCVSS 7.5v10.0v11.02021-11-03
CVE-2021-37147 [HIGH] CWE-20 CVE-2021-37147: Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacke
Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.1.0.
nvd