cbcvebase.

Debian Linux vulnerabilities

9,953 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358

Vulnerabilities

Page 135 of 498
CVE-2007-0899P3CRITICALCVSS 9.8v8.0v9.0+1 more2019-11-06
CVE-2007-0899 [CRITICAL] CWE-787 CVE-2007-0899: There is a possible heap overflow in libclamav/fsg.c before 0.100.0. There is a possible heap overflow in libclamav/fsg.c before 0.100.0.
nvd
CVE-2024-24814P3HIGHCVSS 7.5v10.02024-02-13
CVE-2024-24814 [HIGH] CWE-400 CVE-2024-24814: mod_auth_openidc is an OpenID Certified™ authentication and authorization module for the Apache 2.x mod_auth_openidc is an OpenID Certified™ authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. In affected versions missing input validation on mod_auth_openidc_session_chunks cookie value makes the server vulnerable to a denial of service (DoS) attack. An internal securit
nvd
CVE-2020-25654P3HIGHCVSS 7.2v9.02020-11-24
CVE-2020-25654 [HIGH] CWE-284 CVE-2020-25654: An ACL bypass flaw was found in pacemaker. An attacker having a local account on the cluster and in An ACL bypass flaw was found in pacemaker. An attacker having a local account on the cluster and in the haclient group could use IPC communication with various daemons directly to perform certain tasks that they would be prevented by ACLs from doing if they went through the configuration.
nvd
CVE-2014-6262P3HIGHCVSS 7.5v8.02020-02-12
CVE-2014-6262 [HIGH] CVE-2014-6262: Multiple format string vulnerabilities in the python module in RRDtool, as used in Zenoss Core befor Multiple format string vulnerabilities in the python module in RRDtool, as used in Zenoss Core before 4.2.5 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted third argument to the rrdtool.graph function, aka ZEN-15415, a related issue to CVE-2013-2131.
nvd
CVE-2021-35267P3HIGHCVSS 7.8v9.0v10.0+1 more2021-09-07
CVE-2021-35267 [HIGH] CWE-787 CVE-2021-35267: NTFS-3G versions < 2021.8.22, a stack buffer overflow can occur when correcting differences in the M NTFS-3G versions < 2021.8.22, a stack buffer overflow can occur when correcting differences in the MFT and MFTMirror allowing for code execution or escalation of privileges when setuid-root.
nvd
CVE-2022-29187P3HIGHCVSS 7.8v10.02022-07-12
CVE-2022-29187 [HIGH] CVE-2022-29187: Git is a distributed revision control system. Git prior to versions 2.37.1, 2.36.2, 2.35.4, 2.34.4, Git is a distributed revision control system. Git prior to versions 2.37.1, 2.36.2, 2.35.4, 2.34.4, 2.33.4, 2.32.3, 2.31.4, and 2.30.5, is vulnerable to privilege escalation in all platforms. An unsuspecting user could still be affected by the issue reported in CVE-2022-24765, for example when navigating as root into a shared tmp directory that is owned by the
nvd
CVE-2021-41133P3HIGHCVSS 7.8v11.02021-10-08
CVE-2021-41133 [HIGH] CWE-20 CVE-2021-41133: Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In versions prior to 1.10.4 and 1.12.0, Flatpak apps with direct access to AF_UNIX sockets such as those used by Wayland, Pipewire or pipewire-pulse can trick portals and other host-OS services into treating the Flatpak app as though it was an ordinary,
nvd
CVE-2019-1559P3MEDIUMCVSS 5.9v8.0v9.02019-02-27
CVE-2019-1559 [MEDIUM] CWE-203 CVE-2019-1559: If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to sen If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid MAC. If the application then behave
nvd
CVE-2021-3483P3HIGHCVSS 7.8v9.02021-05-17
CVE-2021-3483 [HIGH] CWE-416 CVE-2021-3483: A flaw was found in the Nosy driver in the Linux kernel. This issue allows a device to be inserted t A flaw was found in the Nosy driver in the Linux kernel. This issue allows a device to be inserted twice into a doubly-linked list, leading to a use-after-free when one of these devices is removed. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. Versions before kernel 5.12-rc6 are affected
nvd
CVE-2019-17362P3CRITICALCVSS 9.1v8.02019-10-09
CVE-2019-17362 [CRITICAL] CWE-125 CVE-2019-17362: In LibTomCrypt through 1.18.2, the der_decode_utf8_string function (in der_decode_utf8_string.c) doe In LibTomCrypt through 1.18.2, the der_decode_utf8_string function (in der_decode_utf8_string.c) does not properly detect certain invalid UTF-8 sequences. This allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) or read information from other memory locations via carefully crafted DER-encoded data.
nvd
CVE-2025-38708P3HIGHCVSS 7.8v11.02025-09-04
CVE-2025-38708 [HIGH] CWE-416 CVE-2025-38708: In the Linux kernel, the following vulnerability has been resolved: drbd: add missing kref_get in h In the Linux kernel, the following vulnerability has been resolved: drbd: add missing kref_get in handle_write_conflicts With `two-primaries` enabled, DRBD tries to detect "concurrent" writes and handle write conflicts, so that even if you write to the same sector simultaneously on both nodes, they end up with the identical data once the writes are c
nvd
CVE-2022-4337P3CRITICALCVSS 9.8v11.02023-01-10
CVE-2022-4337 [CRITICAL] CWE-125 CVE-2022-4337: An out-of-bounds read in Organization Specific TLV was found in various versions of OpenvSwitch. An out-of-bounds read in Organization Specific TLV was found in various versions of OpenvSwitch.
nvd
CVE-2023-3611P3HIGHCVSS 7.8v10.0v11.0+1 more2023-07-21
CVE-2023-3611 [HIGH] CWE-787 CVE-2023-3611: An out-of-bounds write vulnerability in the Linux kernel's net/sched: sch_qfq component can be explo An out-of-bounds write vulnerability in the Linux kernel's net/sched: sch_qfq component can be exploited to achieve local privilege escalation. The qfq_change_agg() function in net/sched/sch_qfq.c allows an out-of-bounds write because lmax is updated according to packet sizes without bounds checks. We recommend upgrading past commit 3e337087c3b5805fe0
nvd
CVE-2012-2665P3HIGHCVSS 7.5v6.0v7.02012-08-06
CVE-2012-2665 [HIGH] CWE-787 CVE-2012-2665: Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in Ope Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in OpenOffice.org and LibreOffice before 3.5.5 allow remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted Open Document Text (.odt) file with (1) a child tag within an incorrect parent tag, (2) duplicate tags, or (3) a
nvd
CVE-2023-3610P3HIGHCVSS 7.8v10.0v11.02023-07-21
CVE-2023-3610 [HIGH] CWE-416 CVE-2023-3610: A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. Flaw in the error handling of bound chains causes a use-after-free in the abort path of NFT_MSG_NEWRULE. The vulnerability requires CAP_NET_ADMIN to be triggered. We recommend upgrading past commit 4bedf9eee016286
nvd
CVE-2019-12814P3MEDIUMCVSS 5.9v8.02019-06-19
CVE-2019-12814 [MEDIUM] CWE-502 CVE-2019-12814: A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x through 2.9.9. When Defa A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x through 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has JDOM 1.x or 2.x jar in the classpath, an attacker can send a specifically crafted JSON message that allows them to read arbi
nvd
CVE-2015-3279P3HIGHCVSS 7.5v7.1v8.02015-07-14
CVE-2015-3279 [HIGH] CWE-189 CVE-2015-3279: Integer overflow in filter/texttopdf.c in texttopdf in cups-filters before 1.0.71 allows remote atta Integer overflow in filter/texttopdf.c in texttopdf in cups-filters before 1.0.71 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted line size in a print job, which triggers a heap-based buffer overflow.
nvd
CVE-2019-20367P3CRITICALCVSS 9.1v9.02020-01-08
CVE-2019-20367 [CRITICAL] CWE-125 CVE-2019-20367: nlist.c in libbsd before 0.10.0 has an out-of-bounds read during a comparison for a symbol name from nlist.c in libbsd before 0.10.0 has an out-of-bounds read during a comparison for a symbol name from the string table (strtab).
nvd
CVE-2020-10968P3HIGHCVSS 8.8v8.02020-03-26
CVE-2020-10968 [HIGH] CWE-502 CVE-2020-10968: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadg FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy).
nvd
CVE-2025-47287P3HIGHCVSS 7.5v11.02025-05-15
CVE-2025-47287 [HIGH] CWE-770 CVE-2025-47287: Tornado is a Python web framework and asynchronous networking library. When Tornado's ``multipart/fo Tornado is a Python web framework and asynchronous networking library. When Tornado's ``multipart/form-data`` parser encounters certain errors, it logs a warning but continues trying to parse the remainder of the data. This allows remote attackers to generate an extremely high volume of logs, constituting a DoS attack. This DoS is compounded by the fa
nvd
Debian Linux vulnerabilities | cvebase