Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 144 of 498
CVE-2018-5098P3CRITICALCVSS 9.8v7.0v8.0+1 more2018-06-11
CVE-2018-5098 [CRITICAL] CWE-416 CVE-2018-5098: A use-after-free vulnerability can occur when form input elements, focus, and selections are manipul
A use-after-free vulnerability can occur when form input elements, focus, and selections are manipulated by script content. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.
nvd
CVE-2021-27365P3HIGHCVSS 7.8v9.02021-03-07
CVE-2021-27365 [HIGH] CWE-787 CVE-2021-27365: An issue was discovered in the Linux kernel through 5.11.3. Certain iSCSI data structures do not hav
An issue was discovered in the Linux kernel through 5.11.3. Certain iSCSI data structures do not have appropriate length constraints or checks, and can exceed the PAGE_SIZE value. An unprivileged user can send a Netlink message that is associated with iSCSI, and has a length up to the maximum length of a Netlink message.
nvd
CVE-2023-4761P3HIGHCVSS 8.1v11.0v12.02023-09-05
CVE-2023-4761 [HIGH] CWE-125 CVE-2023-4761: Out of bounds memory access in FedCM in Google Chrome prior to 116.0.5845.179 allowed a remote attac
Out of bounds memory access in FedCM in Google Chrome prior to 116.0.5845.179 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2017-7800P3CRITICALCVSS 9.8v8.0v9.02018-06-11
CVE-2017-7800 [CRITICAL] CWE-416 CVE-2017-7800: A use-after-free vulnerability can occur in WebSockets when the object holding the connection is fre
A use-after-free vulnerability can occur in WebSockets when the object holding the connection is freed before the disconnection operation is finished. This results in an exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
nvd
CVE-2021-45444P3HIGHCVSS 7.8v9.0v10.0+1 more2022-02-14
CVE-2021-45444 [HIGH] CVE-2021-45444: In zsh before 5.8.1, an attacker can achieve code execution if they control a command output inside
In zsh before 5.8.1, an attacker can achieve code execution if they control a command output inside the prompt, as demonstrated by a %F argument. This occurs because of recursive PROMPT_SUBST expansion.
nvd
CVE-2020-25710P3HIGHCVSS 7.5v9.02021-05-28
CVE-2020-25710 [HIGH] CWE-617 CVE-2020-25710: A flaw was found in OpenLDAP in versions before 2.4.56. This flaw allows an attacker who sends a mal
A flaw was found in OpenLDAP in versions before 2.4.56. This flaw allows an attacker who sends a malicious packet processed by OpenLDAP to force a failed assertion in csnNormalize23(). The highest threat from this vulnerability is to system availability.
nvd
CVE-2015-8607P3HIGHCVSS 7.3v8.02016-01-13
CVE-2015-8607 [HIGH] CWE-20 CVE-2015-8607: The canonpath function in the File::Spec module in PathTools before 3.62, as used in Perl, does not
The canonpath function in the File::Spec module in PathTools before 3.62, as used in Perl, does not properly preserve the taint attribute of data, which might allow context-dependent attackers to bypass the taint protection mechanism via a crafted string.
nvd
CVE-2021-32566P3HIGHCVSS 7.5v10.02021-06-30
CVE-2021-32566 [HIGH] CWE-20 CVE-2021-32566: Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS
Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.
nvd
CVE-2017-0900P3HIGHCVSS 7.5v8.0v9.02017-08-31
CVE-2017-0900 [HIGH] CWE-20 CVE-2017-0900: RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications to cause
RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications to cause a denial of service attack against RubyGems clients who have issued a `query` command.
nvd
CVE-2022-27387P3HIGHCVSS 7.5v10.02022-04-12
CVE-2022-27387 [HIGH] CWE-120 CVE-2022-27387: MariaDB Server v10.7 and below was discovered to contain a global buffer overflow in the component d
MariaDB Server v10.7 and below was discovered to contain a global buffer overflow in the component decimal_bin_size, which is exploited via specially crafted SQL statements.
nvd
CVE-2018-1000164P3HIGHCVSS 7.5v7.0v8.02018-04-18
CVE-2018-1000164 [HIGH] CWE-93 CVE-2018-1000164: gunicorn version 19.4.5 contains a CWE-113: Improper Neutralization of CRLF Sequences in HTTP Header
gunicorn version 19.4.5 contains a CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers vulnerability in "process_headers" function in "gunicorn/http/wsgi.py" that can result in an attacker causing the server to return arbitrary HTTP headers. This vulnerability appears to have been fixed in 19.5.0.
nvd
CVE-2021-32567P3HIGHCVSS 7.5v10.02021-06-30
CVE-2021-32567 [HIGH] CWE-20 CVE-2021-32567: Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS
Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.
nvd
CVE-2015-7827P3HIGHCVSS 7.5v8.02016-05-13
CVE-2015-7827 [HIGH] CWE-200 CVE-2015-7827: Botan before 1.10.13 and 1.11.x before 1.11.22 make it easier for remote attackers to conduct millio
Botan before 1.10.13 and 1.11.x before 1.11.22 make it easier for remote attackers to conduct million-message attacks by measuring time differences, related to decoding of PKCS#1 padding.
nvd
CVE-2017-7749P3CRITICALCVSS 9.8v8.0v9.02018-06-11
CVE-2017-7749 [CRITICAL] CWE-416 CVE-2017-7749: A use-after-free vulnerability when using an incorrect URL during the reloading of a docshell. This
A use-after-free vulnerability when using an incorrect URL during the reloading of a docshell. This results in a potentially exploitable crash. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
nvd
CVE-2021-20312P3HIGHCVSS 7.5v9.02021-05-11
CVE-2021-20312 [HIGH] CWE-190 CVE-2021-20312: A flaw was found in ImageMagick in versions 7.0.11, where an integer overflow in WriteTHUMBNAILImage
A flaw was found in ImageMagick in versions 7.0.11, where an integer overflow in WriteTHUMBNAILImage of coders/thumbnail.c may trigger undefined behavior via a crafted image file that is submitted by an attacker and processed by an application using ImageMagick. The highest threat from this vulnerability is to system availability.
nvd
CVE-2022-24764P3HIGHCVSS 7.5v9.0v10.02022-03-22
CVE-2022-24764 [HIGH] CWE-120 CVE-2022-24764: PJSIP is a free and open source multimedia communication library written in C. Versions 2.12 and pri
PJSIP is a free and open source multimedia communication library written in C. Versions 2.12 and prior contain a stack buffer overflow vulnerability that affects PJSUA2 users or users that call the API `pjmedia_sdp_print(), pjmedia_sdp_media_print()`. Applications that do not use PJSUA2 and do not directly call `pjmedia_sdp_print()` or `pjmedia_sdp_me
nvd
CVE-2015-3202P4LOWCVSS 3.6PoCv8.02015-07-02
CVE-2015-3202 [LOW] CWE-264 CVE-2015-3202: fusermount in FUSE before 2.9.3-15 does not properly clear the environment before invoking (1) mount
fusermount in FUSE before 2.9.3-15 does not properly clear the environment before invoking (1) mount or (2) umount as root, which allows local users to write to arbitrary files via a crafted LIBMOUNT_MTAB environment variable that is used by mount's debugging feature.
nvd
CVE-2018-14361P3CRITICALCVSS 9.8v8.0v9.02018-07-17
CVE-2018-14361 [CRITICAL] CWE-20 CVE-2018-14361: An issue was discovered in NeoMutt before 2018-07-16. nntp.c proceeds even if memory allocation fail
An issue was discovered in NeoMutt before 2018-07-16. nntp.c proceeds even if memory allocation fails for messages data.
nvd
CVE-2022-27447P3HIGHCVSS 7.5v10.02022-04-14
CVE-2022-27447 [HIGH] CWE-416 CVE-2022-27447: MariaDB Server v10.9 and below was discovered to contain a use-after-free via the component Binary_s
MariaDB Server v10.9 and below was discovered to contain a use-after-free via the component Binary_string::free_buffer() at /sql/sql_string.h.
nvd
CVE-2022-29970P3HIGHCVSS 7.5v10.02022-05-02
CVE-2022-29970 [HIGH] CWE-22 CVE-2022-29970: Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files.
nvd