cbcvebase.

Debian Linux vulnerabilities

9,953 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358

Vulnerabilities

Page 133 of 498
CVE-2020-15683P3CRITICALCVSS 9.8v9.0v10.02020-10-22
CVE-2020-15683 [CRITICAL] CWE-416 CVE-2020-15683: Mozilla developers and community members reported memory safety bugs present in Firefox 81 and Firef Mozilla developers and community members reported memory safety bugs present in Firefox 81 and Firefox ESR 78.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 78.4, Firefox < 82, and Thunderbird <
nvd
CVE-2023-0045P3HIGHCVSS 7.5v10.02023-04-25
CVE-2023-0045 [HIGH] CWE-610 CVE-2023-0045: The current implementation of the prctl syscall does not issue an IBPB immediately during the syscal The current implementation of the prctl syscall does not issue an IBPB immediately during the syscall. The ib_prctl_set function updates the Thread Information Flags (TIFs) for the task and updates the SPEC_CTRL MSR on the function __speculation_ctrl_update, but the IBPB is only issued on the next schedule, when the TIF bits are checked. This leaves the
nvd
CVE-2019-13574P3HIGHCVSS 7.8v9.0v10.02019-07-12
CVE-2019-13574 [HIGH] CWE-78 CVE-2019-13574: In lib/mini_magick/image.rb in MiniMagick before 4.9.4, a fetched remote image filename could cause In lib/mini_magick/image.rb in MiniMagick before 4.9.4, a fetched remote image filename could cause remote command execution because Image.open input is directly passed to Kernel#open, which accepts a '|' character followed by a command.
nvd
CVE-2016-1835P3HIGHCVSS 8.8v8.02016-05-20
CVE-2016-1835 [HIGH] CWE-119 CVE-2016-1835: Use-after-free vulnerability in the xmlSAX2AttributeNs function in libxml2 before 2.9.4, as used in Use-after-free vulnerability in the xmlSAX2AttributeNs function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2 and OS X before 10.11.5, allows remote attackers to cause a denial of service via a crafted XML document.
nvd
CVE-2022-27377P3HIGHCVSS 7.5v10.02022-04-12
CVE-2022-27377 [HIGH] CWE-416 CVE-2022-27377: MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component Item_f MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component Item_func_in::cleanup(), which is exploited via specially crafted SQL statements.
nvd
CVE-2021-44732P3CRITICALCVSS 9.8v10.02021-12-20
CVE-2021-44732 [CRITICAL] CWE-415 CVE-2021-44732: Mbed TLS before 3.0.1 has a double free in certain out-of-memory conditions, as demonstrated by an m Mbed TLS before 3.0.1 has a double free in certain out-of-memory conditions, as demonstrated by an mbedtls_ssl_set_session() failure.
nvd
CVE-2023-35001P3HIGHCVSS 7.8v11.02023-07-05
CVE-2023-35001 [HIGH] CWE-787 CVE-2023-35001: Linux Kernel nftables Out-Of-Bounds Read/Write Vulnerability; nft_byteorder poorly handled vm regist Linux Kernel nftables Out-Of-Bounds Read/Write Vulnerability; nft_byteorder poorly handled vm register contents when CAP_NET_ADMIN is in any user or network namespace
nvd
CVE-2018-3836P3HIGHCVSS 7.8v7.02018-04-24
CVE-2018-3836 [HIGH] CWE-78 CVE-2018-3836: An exploitable command injection vulnerability exists in the gplotMakeOutput function of Leptonica 1 An exploitable command injection vulnerability exists in the gplotMakeOutput function of Leptonica 1.74.4. A specially crafted gplot rootname argument can cause a command injection resulting in arbitrary code execution. An attacker can provide a malicious path as input to an application that passes attacker data to this function to trigger this vulnerabi
nvd
CVE-2022-27376P3HIGHCVSS 7.5v10.02022-04-12
CVE-2022-27376 [HIGH] CWE-416 CVE-2022-27376: MariaDB Server v10.6.5 and below was discovered to contain an use-after-free in the component Item_a MariaDB Server v10.6.5 and below was discovered to contain an use-after-free in the component Item_args::walk_arg, which is exploited via specially crafted SQL statements.
nvd
CVE-2023-4236P3HIGHCVSS 7.5v10.0v11.02023-09-20
CVE-2023-4236 [HIGH] CWE-617 CVE-2023-4236: A flaw in the networking code handling DNS-over-TLS queries may cause `named` to terminate unexpecte A flaw in the networking code handling DNS-over-TLS queries may cause `named` to terminate unexpectedly due to an assertion failure. This happens when internal data structures are incorrectly reused under significant DNS-over-TLS query load. This issue affects BIND 9 versions 9.18.0 through 9.18.18 and 9.18.11-S1 through 9.18.18-S1.
nvd
CVE-2021-32565P3HIGHCVSS 7.5v10.02021-06-29
CVE-2021-32565 [HIGH] CWE-444 CVE-2021-32565: Invalid values in the Content-Length header sent to Apache Traffic Server allows an attacker to smug Invalid values in the Content-Length header sent to Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.
nvd
CVE-2018-5208P3CRITICALCVSS 9.8v9.02018-01-06
CVE-2018-5208 [CRITICAL] CWE-119 CVE-2018-5208: In Irssi before 1.0.6, a calculation error in the completion code could cause a heap buffer overflow In Irssi before 1.0.6, a calculation error in the completion code could cause a heap buffer overflow when completing certain strings.
nvd
CVE-2022-24793P3HIGHCVSS 7.5v9.0v10.0+1 more2022-04-06
CVE-2022-24793 [HIGH] CWE-120 CVE-2022-24793: PJSIP is a free and open source multimedia communication library written in C. A buffer overflow vul PJSIP is a free and open source multimedia communication library written in C. A buffer overflow vulnerability in versions 2.12 and prior affects applications that use PJSIP DNS resolution. It doesn't affect PJSIP users who utilize an external resolver. This vulnerability is related to CVE-2023-27585. The difference is that this issue is in parsing th
nvd
CVE-2025-38501P3HIGHCVSS 7.5v11.02025-08-16
CVE-2025-38501 [HIGH] CWE-400 CVE-2025-38501: In the Linux kernel, the following vulnerability has been resolved: ksmbd: limit repeated connectio In the Linux kernel, the following vulnerability has been resolved: ksmbd: limit repeated connections from clients with the same IP Repeated connections from clients with the same IP address may exhaust the max connections and prevent other normal client connections. This patch limit repeated connections from clients with the same IP.
nvd
CVE-2022-27383P3HIGHCVSS 7.5v10.02022-04-12
CVE-2022-27383 [HIGH] CWE-416 CVE-2022-27383: MariaDB Server v10.6 and below was discovered to contain an use-after-free in the component my_strca MariaDB Server v10.6 and below was discovered to contain an use-after-free in the component my_strcasecmp_8bit, which is exploited via specially crafted SQL statements.
nvd
CVE-2020-14386P3HIGHCVSS 7.8v9.02020-09-16
CVE-2020-14386 [HIGH] CWE-250 CVE-2020-14386: A flaw was found in the Linux kernel before 5.9-rc4. Memory corruption can be exploited to gain root A flaw was found in the Linux kernel before 5.9-rc4. Memory corruption can be exploited to gain root privileges from unprivileged processes. The highest threat from this vulnerability is to data confidentiality and integrity.
nvd
CVE-2016-9840P3HIGHCVSS 8.8v8.02017-05-23
CVE-2016-9840 [HIGH] CVE-2016-9840: inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by lever inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
nvd
CVE-2022-26662P3HIGHCVSS 7.5v9.0v10.0+1 more2022-03-10
CVE-2022-26662 [HIGH] CWE-776 CVE-2022-26662: An XML Entity Expansion (XEE) issue was discovered in Tryton Application Platform (Server) 5.x throu An XML Entity Expansion (XEE) issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.5, and Tryton Application Platform (Command Line Client (proteus)) 5.x through 5.0.11, 6.x through 6.0.4, and 6.1.x and 6.2.x through 6.2.1. An unauthenticated user can send a crafted XML-RP
nvd
CVE-2012-2130P3HIGHCVSS 7.4v8.02019-12-06
CVE-2012-2130 [HIGH] CWE-326 CVE-2012-2130: A Security Bypass vulnerability exists in PolarSSL 0.99pre4 through 1.1.1 due to a weak encryption e A Security Bypass vulnerability exists in PolarSSL 0.99pre4 through 1.1.1 due to a weak encryption error when generating Diffie-Hellman values and RSA keys.
nvd
CVE-2018-12359P3HIGHCVSS 8.8v8.0v9.02018-10-18
CVE-2018-12359 [HIGH] CWE-119 CVE-2018-12359: A buffer overflow can occur when rendering canvas content while adjusting the height and width of th A buffer overflow can occur when rendering canvas content while adjusting the height and width of the canvas element dynamically, causing data to be written outside of the currently computed boundaries. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52
nvd
Debian Linux vulnerabilities | cvebase