Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 156 of 498
CVE-2018-5096P3CRITICALCVSS 9.8v7.0v8.0+1 more2018-06-11
CVE-2018-5096 [CRITICAL] CWE-416 CVE-2018-5096: A use-after-free vulnerability can occur while editing events in form elements on a page, resulting
A use-after-free vulnerability can occur while editing events in form elements on a page, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR < 52.6 and Thunderbird < 52.6.
nvd
CVE-2018-9363P3HIGHCVSS 8.4v8.0v9.02018-11-06
CVE-2018-9363 [HIGH] CWE-190 CVE-2018-9363: In the hidp_process_report in bluetooth, there is an integer overflow. This could lead to an out of
In the hidp_process_report in bluetooth, there is an integer overflow. This could lead to an out of bounds write with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-65853588 References: Upstream kernel.
nvd
CVE-2018-16884P3HIGHCVSS 8.0v8.02018-12-18
CVE-2018-16884 [HIGH] CWE-416 CVE-2018-16884: A flaw was found in the Linux kernel's NFS41+ subsystem. NFS41+ shares mounted in different network
A flaw was found in the Linux kernel's NFS41+ subsystem. NFS41+ shares mounted in different network namespaces at the same time can make bc_svc_process() use wrong back-channel IDs and cause a use-after-free vulnerability. Thus a malicious container user can cause a host kernel memory corruption and a system panic. Due to the nature of the flaw, privil
nvd
CVE-2018-7711P3HIGHCVSS 8.1v7.02018-03-05
CVE-2018-7711 [HIGH] CWE-347 CVE-2018-7711: HTTPRedirect.php in the saml2 library in SimpleSAMLphp before 1.15.4 has an incorrect check of retur
HTTPRedirect.php in the saml2 library in SimpleSAMLphp before 1.15.4 has an incorrect check of return values in the signature validation utilities, allowing an attacker to get invalid signatures accepted as valid by forcing an error during validation. This occurs because of a dependency on PHP functionality that interprets a -1 error code as a true bool
nvd
CVE-2017-5402P3CRITICALCVSS 9.8v9.02018-06-11
CVE-2017-5402 [CRITICAL] CWE-416 CVE-2017-5402: A use-after-free can occur when events are fired for a "FontFace" object after the object has been a
A use-after-free can occur when events are fired for a "FontFace" object after the object has been already been destroyed while working with fonts. This results in a potentially exploitable crash. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
nvd
CVE-2017-16654P3HIGHCVSS 7.5v8.0v9.02018-08-06
CVE-2017-16654 [HIGH] CWE-22 CVE-2017-16654: An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5.
An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. The Intl component includes various bundle readers that are used to read resource bundles from the local filesystem. The read() methods of these classes use a path and a locale to determine the language bundle to retrieve. The locale argument value is com
nvd
CVE-2020-35523P3HIGHCVSS 7.8v9.0v10.02021-03-09
CVE-2020-35523 [HIGH] CWE-190 CVE-2020-35523: An integer overflow flaw was found in libtiff that exists in the tif_getimage.c file. This flaw allo
An integer overflow flaw was found in libtiff that exists in the tif_getimage.c file. This flaw allows an attacker to inject and execute arbitrary code when a user opens a crafted TIFF file. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
nvd
CVE-2018-6101P3HIGHCVSS 7.5v8.0v9.02018-12-04
CVE-2018-6101 [HIGH] CWE-20 CVE-2018-6101: A lack of host validation in DevTools in Google Chrome prior to 66.0.3359.117 allowed a remote attac
A lack of host validation in DevTools in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code via a crafted HTML page, if the user is running a remote DevTools debugging server.
nvd
CVE-2018-9264P3HIGHCVSS 7.5v8.0v9.02018-04-04
CVE-2018-9264 [HIGH] CWE-787 CVE-2018-9264: In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the ADB dissector could crash with a heap-based buf
In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the ADB dissector could crash with a heap-based buffer overflow. This was addressed in epan/dissectors/packet-adb.c by checking for a length inconsistency.
nvd
CVE-2020-14148P3HIGHCVSS 7.5v8.02020-06-15
CVE-2020-14148 [HIGH] CWE-125 CVE-2020-14148: The Server-Server protocol implementation in ngIRCd before 26~rc2 allows an out-of-bounds access, as
The Server-Server protocol implementation in ngIRCd before 26~rc2 allows an out-of-bounds access, as demonstrated by the IRC_NJOIN() function.
nvd
CVE-2017-9214P3CRITICALCVSS 9.8v9.02017-05-23
CVE-2017-9214 [CRITICAL] CWE-191 CVE-2017-9214: In Open vSwitch (OvS) 2.7.0, while parsing an OFPT_QUEUE_GET_CONFIG_REPLY type OFP 1.0 message, ther
In Open vSwitch (OvS) 2.7.0, while parsing an OFPT_QUEUE_GET_CONFIG_REPLY type OFP 1.0 message, there is a buffer over-read that is caused by an unsigned integer underflow in the function `ofputil_pull_queue_get_config_reply10` in `lib/ofp-util.c`.
nvd
CVE-2024-2608P3HIGHCVSS 8.4v10.02024-03-19
CVE-2024-2608 [HIGH] CWE-680 CVE-2024-2608: `AppendEncodedAttributeValue(), ExtraSpaceNeededForAttrEncoding()` and `AppendEncodedCharacters()` c
`AppendEncodedAttributeValue(), ExtraSpaceNeededForAttrEncoding()` and `AppendEncodedCharacters()` could have experienced integer overflows, causing underallocation of an output buffer leading to an out of bounds write. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
nvd
CVE-2013-4508P3HIGHCVSS 7.5v6.0v7.0+1 more2013-11-08
CVE-2013-4508 [HIGH] CWE-326 CVE-2013-4508: lighttpd before 1.4.34, when SNI is enabled, configures weak SSL ciphers, which makes it easier for
lighttpd before 1.4.34, when SNI is enabled, configures weak SSL ciphers, which makes it easier for remote attackers to hijack sessions by inserting packets into the client-server data stream or obtain sensitive information by sniffing the network.
nvd
CVE-2017-7750P3CRITICALCVSS 9.8v8.0v9.02018-06-11
CVE-2017-7750 [CRITICAL] CWE-416 CVE-2017-7750: A use-after-free vulnerability during video control operations when a "<track>" element holds a refe
A use-after-free vulnerability during video control operations when a "" element holds a reference to an older window if that window has been replaced in the DOM. This results in a potentially exploitable crash. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
nvd
CVE-2019-10181P3HIGHCVSS 8.1v8.02019-07-31
CVE-2019-10181 [HIGH] CWE-345 CVE-2019-10181: It was found that in icedtea-web up to and including 1.7.2 and 1.8.2 executable code could be inject
It was found that in icedtea-web up to and including 1.7.2 and 1.8.2 executable code could be injected in a JAR file without compromising the signature verification. An attacker could use this flaw to inject code in a trusted JAR. The code would be executed inside the sandbox.
nvd
CVE-2020-35524P3HIGHCVSS 7.8v9.0v10.02021-03-09
CVE-2020-35524 [HIGH] CWE-787 CVE-2020-35524: A heap-based buffer overflow flaw was found in libtiff in the handling of TIFF images in libtiff's T
A heap-based buffer overflow flaw was found in libtiff in the handling of TIFF images in libtiff's TIFF2PDF tool. A specially crafted TIFF file can lead to arbitrary code execution. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
nvd
CVE-2019-18218P3HIGHCVSS 7.8v8.0v9.0+1 more2019-10-21
CVE-2019-18218 [HIGH] CWE-787 CVE-2019-18218: cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elem
cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a heap-based buffer overflow (4-byte out-of-bounds write).
nvd
CVE-2020-11724P3HIGHCVSS 7.5v9.0v10.02020-04-12
CVE-2020-11724 [HIGH] CWE-444 CVE-2020-11724: An issue was discovered in OpenResty before 1.15.8.4. ngx_http_lua_subrequest.c allows HTTP request
An issue was discovered in OpenResty before 1.15.8.4. ngx_http_lua_subrequest.c allows HTTP request smuggling, as demonstrated by the ngx.location.capture API.
nvd
CVE-2018-17189P3MEDIUMCVSS 5.3v9.02019-01-30
CVE-2018-17189 [MEDIUM] CWE-400 CVE-2018-17189: In Apache HTTP server versions 2.4.37 and prior, by sending request bodies in a slow loris way to pl
In Apache HTTP server versions 2.4.37 and prior, by sending request bodies in a slow loris way to plain resources, the h2 stream for that request unnecessarily occupied a server thread cleaning up that incoming data. This affects only HTTP/2 (mod_http2) connections.
nvd
CVE-2019-16786P3HIGHCVSS 7.5v9.02019-12-20
CVE-2019-16786 [HIGH] CWE-444 CVE-2019-16786: Waitress through version 1.3.1 would parse the Transfer-Encoding header and only look for a single s
Waitress through version 1.3.1 would parse the Transfer-Encoding header and only look for a single string value, if that value was not chunked it would fall through and use the Content-Length header instead. According to the HTTP standard Transfer-Encoding should be a comma separated list, with the inner-most encoding first, followed by any further tr
nvd