cbcvebase.

Debian Linux vulnerabilities

9,953 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358

Vulnerabilities

Page 154 of 498
CVE-2015-8852P3HIGHCVSS 7.5v7.02016-04-25
CVE-2015-8852 [HIGH] CVE-2015-8852: Varnish 3.x before 3.0.7, when used in certain stacked installations, allows remote attackers to inj Varnish 3.x before 3.0.7, when used in certain stacked installations, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a header line terminated by a \r (carriage return) character in conjunction with multiple Content-Length headers in an HTTP request.
nvd
CVE-2018-17540P3HIGHCVSS 7.5v8.0v9.02018-10-03
CVE-2018-17540 [HIGH] CWE-119 CVE-2018-17540: The gmp plugin in strongSwan before 5.7.1 has a Buffer Overflow via a crafted certificate. The gmp plugin in strongSwan before 5.7.1 has a Buffer Overflow via a crafted certificate.
nvd
CVE-2022-1616P3HIGHCVSS 7.8v9.0v10.02022-05-07
CVE-2022-1616 [HIGH] CWE-416 CVE-2022-1616: Use after free in append_command in GitHub repository vim/vim prior to 8.2.4895. This vulnerability Use after free in append_command in GitHub repository vim/vim prior to 8.2.4895. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution
nvd
CVE-2021-36064P3HIGHCVSS 7.8v10.02021-09-01
CVE-2021-36064 [HIGH] CWE-124 CVE-2021-36064: XMP Toolkit version 2020.1 (and earlier) is affected by a Buffer Underflow vulnerability which could XMP Toolkit version 2020.1 (and earlier) is affected by a Buffer Underflow vulnerability which could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2020-10704P3HIGHCVSS 7.5v9.02020-05-06
CVE-2020-10704 [HIGH] CWE-674 CVE-2020-10704: A flaw was found when using samba as an Active Directory Domain Controller. Due to the way samba han A flaw was found when using samba as an Active Directory Domain Controller. Due to the way samba handles certain requests as an Active Directory Domain Controller LDAP server, an unauthorized user can cause a stack overflow leading to a denial of service. The highest threat from this vulnerability is to system availability. This issue affects all samb
nvd
CVE-2020-8169P3HIGHCVSS 7.5v10.02020-12-14
CVE-2020-8169 [HIGH] CWE-200 CVE-2020-8169: curl 7.62.0 through 7.70.0 is vulnerable to an information disclosure vulnerability that can lead to curl 7.62.0 through 7.70.0 is vulnerable to an information disclosure vulnerability that can lead to a partial password being leaked over the network and to the DNS server(s).
nvd
CVE-2017-5400P3CRITICALCVSS 9.8v8.02018-06-11
CVE-2017-5400 [CRITICAL] CWE-119 CVE-2017-5400: JIT-spray targeting asm.js combined with a heap spray allows for a bypass of ASLR and DEP protection JIT-spray targeting asm.js combined with a heap spray allows for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
nvd
CVE-2018-1000121P3HIGHCVSS 7.5v7.0v8.0+1 more2018-03-14
CVE-2018-1000121 [HIGH] CWE-476 CVE-2018-1000121: A NULL pointer dereference exists in curl 7.21.0 to and including curl 7.58.0 in the LDAP code that A NULL pointer dereference exists in curl 7.21.0 to and including curl 7.58.0 in the LDAP code that allows an attacker to cause a denial of service
nvd
CVE-2022-24921P3HIGHCVSS 7.5v9.02022-03-05
CVE-2022-24921 [HIGH] CWE-674 CVE-2022-24921: regexp.Compile in Go before 1.16.15 and 1.17.x before 1.17.8 allows stack exhaustion via a deeply ne regexp.Compile in Go before 1.16.15 and 1.17.x before 1.17.8 allows stack exhaustion via a deeply nested expression.
nvd
CVE-2018-18501P3CRITICALCVSS 9.8v8.0v9.02019-02-05
CVE-2018-18501 [CRITICAL] CWE-119 CVE-2018-18501: Mozilla developers and community members reported memory safety bugs present in Firefox 64 and Firef Mozilla developers and community members reported memory safety bugs present in Firefox 64 and Firefox ESR 60.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60.5, Firefox ESR < 60.5, and Firefox <
nvd
CVE-2021-21702P3HIGHCVSS 7.5v9.0v10.02021-02-15
CVE-2021-21702 [HIGH] CWE-476 CVE-2021-21702: In PHP versions 7.3.x below 7.3.27, 7.4.x below 7.4.15 and 8.0.x below 8.0.2, when using SOAP extens In PHP versions 7.3.x below 7.3.27, 7.4.x below 7.4.15 and 8.0.x below 8.0.2, when using SOAP extension to connect to a SOAP server, a malicious SOAP server could return malformed XML data as a response that would cause PHP to access a null pointer and thus cause a crash.
nvd
CVE-2020-12662P3HIGHCVSS 7.5v9.0v10.02020-05-19
CVE-2020-12662 [HIGH] CWE-400 CVE-2020-12662: Unbound before 1.10.1 has Insufficient Control of Network Message Volume, aka an "NXNSAttack" issue. Unbound before 1.10.1 has Insufficient Control of Network Message Volume, aka an "NXNSAttack" issue. This is triggered by random subdomains in the NSDNAME in NS records.
nvd
CVE-2016-7798P3HIGHCVSS 7.5v8.0v9.02017-01-30
CVE-2016-7798 [HIGH] CWE-326 CVE-2016-7798: The openssl gem for Ruby uses the same initialization vector (IV) in GCM Mode (aes-*-gcm) when the I The openssl gem for Ruby uses the same initialization vector (IV) in GCM Mode (aes-*-gcm) when the IV is set before the key, which makes it easier for context-dependent attackers to bypass the encryption protection mechanism.
nvd
CVE-2022-1621P3HIGHCVSS 7.8v9.0v10.02022-05-10
CVE-2022-1621 [HIGH] CWE-122 CVE-2022-1621: Heap buffer overflow in vim_strncpy find_word in GitHub repository vim/vim prior to 8.2.4919. This v Heap buffer overflow in vim_strncpy find_word in GitHub repository vim/vim prior to 8.2.4919. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution
nvd
CVE-2021-40330P3HIGHCVSS 7.5v10.02021-08-31
CVE-2021-40330 [HIGH] CVE-2021-40330: git_connect_git in connect.c in Git before 2.30.1 allows a repository path to contain a newline char git_connect_git in connect.c in Git before 2.30.1 allows a repository path to contain a newline character, which may result in unexpected cross-protocol requests, as demonstrated by the git://localhost:1234/%0d%0a%0d%0aGET%20/%20HTTP/1.1 substring.
nvd
CVE-2018-5154P3CRITICALCVSS 9.8v7.0v8.0+1 more2018-06-11
CVE-2018-5154 [CRITICAL] CWE-416 CVE-2018-5154: A use-after-free vulnerability can occur while enumerating attributes during SVG animations with cli A use-after-free vulnerability can occur while enumerating attributes during SVG animations with clip paths. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.
nvd
CVE-2017-12987P3CRITICALCVSS 9.8v9.0v10.02017-09-14
CVE-2017-12987 [CRITICAL] CWE-125 CVE-2017-12987: The IEEE 802.11 parser in tcpdump before 4.9.2 has a buffer over-read in print-802_11.c:parse_elemen The IEEE 802.11 parser in tcpdump before 4.9.2 has a buffer over-read in print-802_11.c:parse_elements().
nvd
CVE-2019-20916P3HIGHCVSS 7.5v9.02020-09-04
CVE-2019-20916 [HIGH] CWE-22 CVE-2019-20916: The pip package before 19.2 for Python allows Directory Traversal when a URL is given in an install The pip package before 19.2 for Python allows Directory Traversal when a URL is given in an install command, because a Content-Disposition header can have ../ in a filename, as demonstrated by overwriting the /root/.ssh/authorized_keys file. This occurs in _download_http_url in _internal/download.py.
nvd
CVE-2015-5230P3HIGHCVSS 7.5v8.0v9.02020-01-15
CVE-2015-5230 [HIGH] CWE-20 CVE-2015-5230: The DNS packet parsing/generation code in PowerDNS (aka pdns) Authoritative Server 3.4.x before 3.4. The DNS packet parsing/generation code in PowerDNS (aka pdns) Authoritative Server 3.4.x before 3.4.6 allows remote attackers to cause a denial of service (crash) via crafted query packets.
nvd
CVE-2022-27775P3HIGHCVSS 7.5v11.02022-06-02
CVE-2022-27775 [HIGH] CWE-200 CVE-2022-27775: An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a connection instead.
nvd
Debian Linux vulnerabilities | cvebase