cbcvebase.

Debian Linux vulnerabilities

9,953 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358

Vulnerabilities

Page 142 of 498
CVE-2018-1000180P3HIGHCVSS 7.5v9.02018-06-05
CVE-2018-1000180 [HIGH] CWE-327 CVE-2018-1000180: Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level in Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. This appears to be fixed in versions BC 1.60 beta 4 and later, BC-FJA 1.0.2 and later.
nvd
CVE-2021-28707P3HIGHCVSS 8.8v11.02021-11-24
CVE-2021-28707 [HIGH] CVE-2021-28707: PoD operations on misaligned GFNs T[his CNA information record relates to multiple CVEs; the text ex PoD operations on misaligned GFNs T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] x86 HVM and PVH guests may be started in populate-on-demand (PoD) mode, to provide a way for them to later easily have more memory assigned. Guests are permitted to control certain P2M aspects of in
nvd
CVE-2020-7062P3HIGHCVSS 7.5v8.0v9.0+1 more2020-02-27
CVE-2020-7062 [HIGH] CWE-476 CVE-2020-7062: In PHP versions 7.2.x below 7.2.28, 7.3.x below 7.3.15 and 7.4.x below 7.4.3, when using file upload In PHP versions 7.2.x below 7.2.28, 7.3.x below 7.3.15 and 7.4.x below 7.4.3, when using file upload functionality, if upload progress tracking is enabled, but session.upload_progress.cleanup is set to 0 (disabled), and the file upload fails, the upload procedure would try to clean up data that does not exist and encounter null pointer dereference, whic
nvd
CVE-2021-28704P3HIGHCVSS 8.8v9.02021-11-24
CVE-2021-28704 [HIGH] CVE-2021-28704: PoD operations on misaligned GFNs T[his CNA information record relates to multiple CVEs; the text ex PoD operations on misaligned GFNs T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] x86 HVM and PVH guests may be started in populate-on-demand (PoD) mode, to provide a way for them to later easily have more memory assigned. Guests are permitted to control certain P2M aspects of in
nvd
CVE-2021-28708P3HIGHCVSS 8.8v11.02021-11-24
CVE-2021-28708 [HIGH] CVE-2021-28708: PoD operations on misaligned GFNs T[his CNA information record relates to multiple CVEs; the text ex PoD operations on misaligned GFNs T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] x86 HVM and PVH guests may be started in populate-on-demand (PoD) mode, to provide a way for them to later easily have more memory assigned. Guests are permitted to control certain P2M aspects of in
nvd
CVE-2017-3309P3HIGHCVSS 7.7v8.02017-04-24
CVE-2017-3309 [HIGH] CVE-2017-3309: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Suppo Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.5.54 and earlier, 5.6.35 and earlier and 5.7.17 and earlier. Easily "exploitable" vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. While the vulnerability is
nvd
CVE-2017-3308P3HIGHCVSS 7.7v8.02017-04-24
CVE-2017-3308 [HIGH] CVE-2017-3308: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML). Supported v Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML). Supported versions that are affected are 5.5.54 and earlier, 5.6.35 and earlier and 5.7.17 and earlier. Easily "exploitable" vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. While the vulnerability is in MyS
nvd
CVE-2017-9098P3HIGHCVSS 7.5v8.0v9.02017-05-19
CVE-2017-9098 [HIGH] CWE-908 CVE-2017-9098: ImageMagick before 7.0.5-2 and GraphicsMagick before 1.3.24 use uninitialized memory in the RLE deco ImageMagick before 7.0.5-2 and GraphicsMagick before 1.3.24 use uninitialized memory in the RLE decoder, allowing an attacker to leak sensitive information from process memory space, as demonstrated by remote attacks against ImageMagick code in a long-running server process that converts image data on behalf of multiple users. This is caused by a missin
nvd
CVE-2022-33745P3HIGHCVSS 8.8v11.02022-07-26
CVE-2022-33745 [HIGH] CVE-2022-33745: insufficient TLB flush for x86 PV guests in shadow mode For migration as well as to work around kern insufficient TLB flush for x86 PV guests in shadow mode For migration as well as to work around kernels unaware of L1TF (see XSA-273), PV guests may be run in shadow paging mode. To address XSA-401, code was moved inside a function in Xen. This code movement missed a variable changing meaning / value between old and new code positions. The now wrong use of th
nvd
CVE-2017-7548P3HIGHCVSS 7.5v8.0v9.02017-08-16
CVE-2017-7548 [HIGH] CWE-862 CVE-2017-7548: PostgreSQL versions before 9.4.13, 9.5.8 and 9.6.4 are vulnerable to authorization flaw allowing rem PostgreSQL versions before 9.4.13, 9.5.8 and 9.6.4 are vulnerable to authorization flaw allowing remote authenticated attackers with no privileges on a large object to overwrite the entire contents of the object, resulting in a denial of service.
nvd
CVE-2018-11385P3HIGHCVSS 8.1v8.0v9.02018-06-13
CVE-2018-11385 [HIGH] CWE-384 CVE-2018-11385: An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.4 An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. A session fixation vulnerability within the "Guard" login feature may allow an attacker to impersonate a victim towards the web application if the session id value was previously know
nvd
CVE-2022-21716P3HIGHCVSS 7.5v9.02022-03-03
CVE-2022-21716 [HIGH] CWE-120 CVE-2022-21716: Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 22.2 Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 22.2.0, Twisted SSH client and server implement is able to accept an infinite amount of data for the peer's SSH version identifier. This ends up with a buffer using all the available memory. The attach is a simple as `nc -rv localhost 22 < /dev/zero`. A pat
nvd
CVE-2021-36055P3HIGHCVSS 7.8v10.02021-09-01
CVE-2021-36055 [HIGH] CWE-416 CVE-2021-36055: XMP Toolkit SDK versions 2020.1 (and earlier) are affected by a use-after-free vulnerability that co XMP Toolkit SDK versions 2020.1 (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2018-16402P3CRITICALCVSS 9.8v9.02018-09-03
CVE-2018-16402 [CRITICAL] CWE-415 CVE-2018-16402: libelf/elf_end.c in elfutils 0.173 allows remote attackers to cause a denial of service (double free libelf/elf_end.c in elfutils 0.173 allows remote attackers to cause a denial of service (double free and application crash) or possibly have unspecified other impact because it tries to decompress twice.
nvd
CVE-2017-17439P3HIGHCVSS 7.5v9.02017-12-06
CVE-2017-17439 [HIGH] CWE-476 CVE-2017-17439: In Heimdal through 7.4, remote unauthenticated attackers are able to crash the KDC by sending a craf In Heimdal through 7.4, remote unauthenticated attackers are able to crash the KDC by sending a crafted UDP packet containing empty data fields for client name or realm. The parser would unconditionally dereference NULL pointers in that case, leading to a segmentation fault. This is related to the _kdc_as_rep function in kdc/kerberos5.c and the der_le
nvd
CVE-2024-32487P3HIGHCVSS 8.6v10.02024-04-13
CVE-2024-32487 [HIGH] CWE-96 CVE-2024-32487: less through 653 allows OS command execution via a newline character in the name of a file, because less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation typically requires use with attacker-controlled file names, such as the files extracted from an untrusted archive. Exploitation also requires the LESSOPEN environment variable, but this is set by default i
nvd
CVE-2019-8323P3HIGHCVSS 7.5v9.02019-06-17
CVE-2019-8323 [HIGH] CWE-74 CVE-2019-8323: An issue was discovered in RubyGems 2.6 and later through 3.0.2. Gem::GemcutterUtilities#with_respon An issue was discovered in RubyGems 2.6 and later through 3.0.2. Gem::GemcutterUtilities#with_response may output the API response to stdout as it is. Therefore, if the API side modifies the response, escape sequence injection may occur.
nvd
CVE-2017-5433P3CRITICALCVSS 9.8v8.02018-06-11
CVE-2017-5433 [CRITICAL] CWE-416 CVE-2017-5433: A use-after-free vulnerability in SMIL animation functions occurs when pointers to animation element A use-after-free vulnerability in SMIL animation functions occurs when pointers to animation elements in an array are dropped from the animation controller while still in use. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2017-5434P3CRITICALCVSS 9.8v8.02018-06-11
CVE-2017-5434 [CRITICAL] CWE-416 CVE-2017-5434: A use-after-free vulnerability occurs when redirecting focus handling which results in a potentially A use-after-free vulnerability occurs when redirecting focus handling which results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2017-5439P3CRITICALCVSS 9.8v9.02018-06-11
CVE-2017-5439 [CRITICAL] CWE-416 CVE-2017-5439: A use-after-free vulnerability during XSLT processing due to poor handling of template parameters. T A use-after-free vulnerability during XSLT processing due to poor handling of template parameters. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
Debian Linux vulnerabilities | cvebase