Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 158 of 498
CVE-2021-25329P3HIGHCVSS 7.0v9.0v10.02021-03-01
CVE-2021-25329 [HIGH] CVE-2021-25329: The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to
The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikely to be used, the Tomcat instance was still vulnerable to CVE-2020-9494. Note that both the previously published prerequisites for CVE-2020-9484 and the previously
nvd
CVE-2022-27449P3HIGHCVSS 7.5v10.02022-04-14
CVE-2022-27449 [HIGH] CVE-2022-27449: MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/
MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_func.cc:148.
nvd
CVE-2022-27452P3HIGHCVSS 7.5v10.02022-04-14
CVE-2022-27452 [HIGH] CVE-2022-27452: MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/
MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_cmpfunc.cc.
nvd
CVE-2018-1002200P3MEDIUMCVSS 5.5v8.0v9.02018-07-25
CVE-2018-1002200 [MEDIUM] CWE-22 CVE-2018-1002200: plexus-archiver before 3.6.0 is vulnerable to directory traversal, allowing attackers to write to ar
plexus-archiver before 3.6.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in an archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.
nvd
CVE-2022-27445P3HIGHCVSS 7.5v10.02022-04-14
CVE-2022-27445 [HIGH] CVE-2022-27445: MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/
MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/sql_window.cc.
nvd
CVE-2020-29050P3HIGHCVSS 7.5v9.02022-01-10
CVE-2020-29050 [HIGH] CVE-2020-29050: SphinxSearch in Sphinx Technologies Sphinx through 3.1.1 allows directory traversal (in conjunction
SphinxSearch in Sphinx Technologies Sphinx through 3.1.1 allows directory traversal (in conjunction with CVE-2019-14511) because the mysql client can be used for CALL SNIPPETS and load_file operations on a full pathname (e.g., a file in the /etc directory). NOTE: this is unrelated to CMUSphinx.
nvd
CVE-2023-27522P3HIGHCVSS 7.5v10.02023-03-07
CVE-2023-27522 [HIGH] CWE-444 CVE-2023-27522: HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects
HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55.
Special characters in the origin response header can truncate/split the response forwarded to the client.
nvd
CVE-2018-8740P3HIGHCVSS 7.5v8.02018-03-17
CVE-2018-8740 [HIGH] CWE-476 CVE-2018-8740: In SQLite through 3.22.0, databases whose schema is corrupted using a CREATE TABLE AS statement coul
In SQLite through 3.22.0, databases whose schema is corrupted using a CREATE TABLE AS statement could cause a NULL pointer dereference, related to build.c and prepare.c.
nvd
CVE-2019-11709P3CRITICALCVSS 9.8v8.02019-07-23
CVE-2019-11709 [CRITICAL] CWE-787 CVE-2019-11709: Mozilla developers and community members reported memory safety bugs present in Firefox 67 and Firef
Mozilla developers and community members reported memory safety bugs present in Firefox 67 and Firefox ESR 60.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 6
nvd
CVE-2022-31001P3HIGHCVSS 7.5v10.0v11.02022-05-31
CVE-2022-31001 [HIGH] CWE-125 CVE-2022-31001: Sofia-SIP is an open-source Session Initiation Protocol (SIP) User-Agent library. Prior to version 1
Sofia-SIP is an open-source Session Initiation Protocol (SIP) User-Agent library. Prior to version 1.13.8, an attacker can send a message with evil sdp to FreeSWITCH, which may cause crash. This type of crash may be caused by `#define MATCH(s, m) (strncmp(s, m, n = sizeof(m) - 1) == 0)`, which will make `n` bigger and trigger out-of-bound access when
nvd
CVE-2020-11868P3HIGHCVSS 7.5v8.02020-04-17
CVE-2020-11868 [HIGH] CWE-346 CVE-2020-11868: ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker to block unauthenti
ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker to block unauthenticated synchronization via a server mode packet with a spoofed source IP address, because transmissions are rescheduled even when a packet lacks a valid origin timestamp.
nvd
CVE-2022-37797P3HIGHCVSS 7.5v10.02022-09-12
CVE-2022-37797 [HIGH] CWE-476 CVE-2022-37797: In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer if an invalid HTTP r
In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer if an invalid HTTP request (websocket handshake) is received. It leads to null pointer dereference which crashes the server. It could be used by an external attacker to cause denial of service condition.
nvd
CVE-2017-15924P3HIGHCVSS 7.8v9.22017-10-27
CVE-2017-15924 [HIGH] CWE-78 CVE-2017-15924: In manager.c in ss-manager in shadowsocks-libev 3.1.0, improper parsing allows command injection via
In manager.c in ss-manager in shadowsocks-libev 3.1.0, improper parsing allows command injection via shell metacharacters in a JSON configuration request received via 127.0.0.1 UDP traffic, related to the add_server, build_config, and construct_command_line functions.
nvd
CVE-2013-0775P3CRITICALCVSS 9.3v7.02013-02-19
CVE-2013-0775 [CRITICAL] CWE-416 CVE-2013-0775: Use-after-free vulnerability in the nsImageLoadingContent::OnStopContainer function in Mozilla Firef
Use-after-free vulnerability in the nsImageLoadingContent::OnStopContainer function in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 allows remote attackers to execute arbitrary code via crafted web script.
nvd
CVE-2024-26146P3HIGHCVSS 7.5v10.02024-02-29
CVE-2024-26146 [HIGH] CWE-1333 CVE-2024-26146: Rack is a modular Ruby web server interface. Carefully crafted headers can cause header parsing in R
Rack is a modular Ruby web server interface. Carefully crafted headers can cause header parsing in Rack to take longer than expected resulting in a possible denial of service issue. Accept and Forwarded headers are impacted. Ruby 3.2 has mitigations for this problem, so Rack applications using Ruby 3.2 or newer are unaffected. This vulnerability is f
nvd
CVE-2016-4447P3HIGHCVSS 7.5v7.0v8.02016-06-09
CVE-2016-4447 [HIGH] CWE-119 CVE-2016-4447: The xmlParseElementDecl function in parser.c in libxml2 before 2.9.4 allows context-dependent attack
The xmlParseElementDecl function in parser.c in libxml2 before 2.9.4 allows context-dependent attackers to cause a denial of service (heap-based buffer underread and application crash) via a crafted file, involving xmlParseName.
nvd
CVE-2023-38403P3HIGHCVSS 7.5v10.02023-07-17
CVE-2023-38403 [HIGH] CWE-190 CVE-2023-38403: iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted lengt
iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field.
nvd
CVE-2019-7524P3HIGHCVSS 7.8v8.0v9.02019-03-28
CVE-2019-7524 [HIGH] CWE-119 CVE-2019-7524: In Dovecot before 2.2.36.3 and 2.3.x before 2.3.5.1, a local attacker can cause a buffer overflow in
In Dovecot before 2.2.36.3 and 2.3.x before 2.3.5.1, a local attacker can cause a buffer overflow in the indexer-worker process, which can be used to elevate to root. This occurs because of missing checks in the fts and pop3-uidl components.
nvd
CVE-2019-9215P3CRITICALCVSS 9.8v8.0v9.02019-02-28
CVE-2019-9215 [CRITICAL] CVE-2019-9215: In Live555 before 2019.02.27, malformed headers lead to invalid memory access in the parseAuthorizat
In Live555 before 2019.02.27, malformed headers lead to invalid memory access in the parseAuthorizationHeader function.
nvd
CVE-2018-5207P3HIGHCVSS 7.5v9.02018-01-06
CVE-2018-5207 [HIGH] CWE-134 CVE-2018-5207: When using an incomplete variable argument, Irssi before 1.0.6 may access data beyond the end of the
When using an incomplete variable argument, Irssi before 1.0.6 may access data beyond the end of the string.
nvd