Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 145 of 498
CVE-2022-20001P3HIGHCVSS 7.8v11.02022-03-14
CVE-2022-20001 [HIGH] CWE-74 CVE-2022-20001: fish is a command line shell. fish version 3.1.0 through version 3.3.1 is vulnerable to arbitrary co
fish is a command line shell. fish version 3.1.0 through version 3.3.1 is vulnerable to arbitrary code execution. git repositories can contain per-repository configuration that change the behavior of git, including running arbitrary commands. When using the default configuration of fish, changing to a directory automatically runs `git` commands in orde
nvd
CVE-2022-29970P3HIGHCVSS 7.5v10.02022-05-02
CVE-2022-29970 [HIGH] CWE-22 CVE-2022-29970: Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files.
nvd
CVE-2015-1854P3HIGHCVSS 7.5v8.02017-09-19
CVE-2015-1854 [HIGH] CWE-284 CVE-2015-1854: 389 Directory Server before 1.3.3.10 allows attackers to bypass intended access restrictions and mod
389 Directory Server before 1.3.3.10 allows attackers to bypass intended access restrictions and modify directory entries via a crafted ldapmodrdn call.
nvd
CVE-2019-14868P3HIGHCVSS 7.8v9.02020-04-02
CVE-2019-14868 [HIGH] CWE-77 CVE-2019-14868: In ksh version 20120801, a flaw was found in the way it evaluates certain environment variables. An
In ksh version 20120801, a flaw was found in the way it evaluates certain environment variables. An attacker could use this flaw to override or bypass environment restrictions to execute shell commands. Services and applications that allow remote unauthenticated attackers to provide one of those environment variables could allow them to exploit this iss
nvd
CVE-2021-3347P3HIGHCVSS 7.8v9.0v10.02021-01-29
CVE-2021-3347 [HIGH] CWE-416 CVE-2021-3347: An issue was discovered in the Linux kernel through 5.10.11. PI futexes have a kernel stack use-afte
An issue was discovered in the Linux kernel through 5.10.11. PI futexes have a kernel stack use-after-free during fault handling, allowing local users to execute code in the kernel, aka CID-34b1a1ce1458.
nvd
CVE-2022-27456P3HIGHCVSS 7.5v10.02022-04-14
CVE-2022-27456 [HIGH] CWE-416 CVE-2022-27456: MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component VDec::
MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component VDec::VDec at /sql/sql_type.cc.
nvd
CVE-2019-16792P3HIGHCVSS 7.5v9.02020-01-22
CVE-2019-16792 [HIGH] CWE-444 CVE-2019-16792: Waitress through version 1.3.1 allows request smuggling by sending the Content-Length header twice.
Waitress through version 1.3.1 allows request smuggling by sending the Content-Length header twice. Waitress would header fold a double Content-Length header and due to being unable to cast the now comma separated value to an integer would set the Content-Length to 0 internally. If two Content-Length headers are sent in a single request, Waitress would
nvd
CVE-2020-27918P3HIGHCVSS 7.8v10.02020-12-08
CVE-2020-27918 [HIGH] CWE-416 CVE-2020-27918: A use after free issue was addressed with improved memory management. This issue is fixed in macOS B
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 14.2 and iPadOS 14.2, iCloud for Windows 11.5, Safari 14.0.1, tvOS 14.2, iTunes 12.11 for Windows. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2015-5299P3MEDIUMCVSS 5.3v7.0v8.02015-12-29
CVE-2015-5299 [MEDIUM] CWE-200 CVE-2015-5299: The shadow_copy2_get_shadow_copy_data function in modules/vfs_shadow_copy2.c in Samba 3.x and 4.x be
The shadow_copy2_get_shadow_copy_data function in modules/vfs_shadow_copy2.c in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not verify that the DIRECTORY_LIST access right has been granted, which allows remote attackers to access snapshots by visiting a shadow copy directory.
nvd
CVE-2021-20228P3HIGHCVSS 7.5v10.02021-04-29
CVE-2021-20228 [HIGH] CWE-200 CVE-2021-20228: A flaw was found in the Ansible Engine 2.9.18, where sensitive info is not masked by default and is
A flaw was found in the Ansible Engine 2.9.18, where sensitive info is not masked by default and is not protected by the no_log feature when using the sub-option feature of the basic.py module. This flaw allows an attacker to obtain sensitive information. The highest threat from this vulnerability is to confidentiality.
nvd
CVE-2024-32004P3HIGHCVSS 7.8v10.0v11.02024-05-14
CVE-2024-32004 [HIGH] CWE-114 CVE-2024-32004: Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2,
Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, an attacker can prepare a local repository in such a way that, when cloned, will execute arbitrary code during the operation. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. As a workaround
nvd
CVE-2020-0034P3HIGHCVSS 7.5v9.02020-03-10
CVE-2020-0034 [HIGH] CWE-125 CVE-2020-0034: In vp8_decode_frame of decodeframe.c, there is a possible out of bounds read due to improper input v
In vp8_decode_frame of decodeframe.c, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure if error correction were turned on, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1Android ID: A-
nvd
CVE-2021-35197P3HIGHCVSS 7.5v9.0v10.0+1 more2021-07-02
CVE-2021-35197 [HIGH] CWE-863 CVE-2021-35197: In MediaWiki before 1.31.15, 1.32.x through 1.35.x before 1.35.3, and 1.36.x before 1.36.1, bots hav
In MediaWiki before 1.31.15, 1.32.x through 1.35.x before 1.35.3, and 1.36.x before 1.36.1, bots have certain unintended API access. When a bot account has a "sitewide block" applied, it is able to still "purge" pages through the MediaWiki Action API (which a "sitewide block" should have prevented).
nvd
CVE-2016-10729P3HIGHCVSS 7.8v7.0v8.0+2 more2018-10-24
CVE-2016-10729 [HIGH] CWE-77 CVE-2016-10729: An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a cl
An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. The "runtar" setuid root binary does not check for additional arguments supplied after --create, allowing users to manipulate commands and perform command injection as root.
nvd
CVE-2022-1011P3HIGHCVSS 7.8v9.0v10.02022-03-18
CVE-2022-1011 [HIGH] CWE-416 CVE-2022-1011: A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers wri
A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write(). This flaw allows a local user to gain unauthorized access to data from the FUSE filesystem, resulting in privilege escalation.
nvd
CVE-2018-19857P3CRITICALCVSS 9.1v9.02018-12-05
CVE-2018-19857 [CRITICAL] CWE-824 CVE-2018-19857: The CAF demuxer in modules/demux/caf.c in VideoLAN VLC media player 3.0.4 may read memory from an un
The CAF demuxer in modules/demux/caf.c in VideoLAN VLC media player 3.0.4 may read memory from an uninitialized pointer when processing magic cookies in CAF files, because a ReadKukiChunk() cast converts a return value to an unsigned int even if that value is negative. This could result in a denial of service and/or a potential infoleak.
nvd
CVE-2021-33038P3HIGHCVSS 7.5v10.02021-05-26
CVE-2021-33038 [HIGH] CWE-276 CVE-2021-33038: An issue was discovered in management/commands/hyperkitty_import.py in HyperKitty through 1.3.4. Whe
An issue was discovered in management/commands/hyperkitty_import.py in HyperKitty through 1.3.4. When importing a private mailing list's archives, these archives are publicly visible for the duration of the import. For example, sensitive information might be available on the web for an hour during a large migration from Mailman 2 to Mailman 3.
nvd
CVE-2019-11766P3CRITICALCVSS 9.8v8.0v9.0+1 more2019-05-05
CVE-2019-11766 [CRITICAL] CWE-125 CVE-2019-11766: dhcp6.c in dhcpcd before 6.11.7 and 7.x before 7.2.2 has a buffer over-read in the D6_OPTION_PD_EXCL
dhcp6.c in dhcpcd before 6.11.7 and 7.x before 7.2.2 has a buffer over-read in the D6_OPTION_PD_EXCLUDE feature.
nvd
CVE-2022-32209P3MEDIUMCVSS 6.1v10.02022-06-24
CVE-2022-32209 [MEDIUM] CWE-79 CVE-2022-32209: # Possible XSS Vulnerability in Rails::Html::SanitizerThere is a possible XSS vulnerability with cer
# Possible XSS Vulnerability in Rails::Html::SanitizerThere is a possible XSS vulnerability with certain configurations of Rails::Html::Sanitizer.This vulnerability has been assigned the CVE identifier CVE-2022-32209.Versions Affected: ALLNot affected: NONEFixed Versions: v1.4.3## ImpactA possible XSS vulnerability with certain configurations of Rail
nvd
CVE-2014-1493P3CRITICALCVSS 9.8v7.0v8.02014-03-19
CVE-2014-1493 [CRITICAL] CWE-119 CVE-2014-1493: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 28.0, Firefox E
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd