cbcvebase.

Debian Linux vulnerabilities

9,952 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,952
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4311LOW358

Vulnerabilities

Page 16 of 498
CVE-2009-1185P3HIGHCVSS 7.2PoCv4.0v5.02009-04-17
CVE-2009-1185 [HIGH] CWE-346 CVE-2009-1185: udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allo udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space.
nvd
CVE-2019-6974P2HIGHCVSS 8.1PoCv8.02019-02-15
CVE-2019-6974 [HIGH] CWE-362 CVE-2019-6974: In the Linux kernel before 4.20.8, kvm_ioctl_create_device in virt/kvm/kvm_main.c mishandles referen In the Linux kernel before 4.20.8, kvm_ioctl_create_device in virt/kvm/kvm_main.c mishandles reference counting because of a race condition, leading to a use-after-free.
nvd
CVE-2019-10092P3MEDIUMCVSS 6.1PoCv8.0v9.0+1 more2019-09-26
CVE-2019-10092 [MEDIUM] CWE-79 CVE-2019-10092: In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could cause the link on the error page to be malformed and instead point to a page of their choice. This would only be exploitable where a server was set up with proxying enabled but was misconfigured in such a way that
nvd
CVE-2021-21346P2CRITICALCVSS 9.8v9.0v10.0+1 more2021-03-23
CVE-2021-21346 [CRITICAL] CWE-434 CVE-2021-21346: XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4. XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security fr
nvd
CVE-2021-21344P2CRITICALCVSS 9.8v9.0v10.0+1 more2021-03-23
CVE-2021-21344 [CRITICAL] CWE-434 CVE-2021-21344: XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4. XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security fr
nvd
CVE-2021-42392P1CRITICALCVSS 9.8v9.0v10.0+1 more2022-01-10
CVE-2021-42392 [CRITICAL] CWE-502 CVE-2021-42392: The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. An attacker may pass a JNDI driver name and a URL leading to a LDAP or RMI servers, causing remote code execution. This can be exploited through various attack vectors, most notably through the H2 Console whic
nvd
CVE-2020-10188P2CRITICALCVSS 9.8v8.0v9.02020-03-06
CVE-2020-10188 [CRITICAL] CWE-120 CVE-2020-10188: utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a buffer overflow involving the netclear and nextitem functions.
nvd
CVE-2016-2819P2HIGHCVSS 8.8PoCv8.02016-06-13
CVE-2016-2819 [HIGH] CWE-119 CVE-2016-2819: Heap-based buffer overflow in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows re Heap-based buffer overflow in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows remote attackers to execute arbitrary code via foreign-context HTML5 fragments, as demonstrated by fragments within an SVG element.
nvd
CVE-2018-5702P2HIGHCVSS 8.8PoCv7.0v8.0+1 more2018-01-15
CVE-2018-5702 [HIGH] CVE-2018-5702: Transmission through 2.92 relies on X-Transmission-Session-Id (which is not a forbidden header for F Transmission through 2.92 relies on X-Transmission-Session-Id (which is not a forbidden header for Fetch) for access control, which allows remote attackers to execute arbitrary RPC commands, and consequently write to arbitrary files, via POST requests to /transmission/rpc in conjunction with a DNS rebinding attack.
nvd
CVE-2016-9899P2CRITICALCVSS 9.8PoCv9.02018-06-11
CVE-2016-9899 [CRITICAL] CWE-416 CVE-2016-9899: Use-after-free while manipulating DOM events and removing audio elements due to errors in the handli Use-after-free while manipulating DOM events and removing audio elements due to errors in the handling of node adoption. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
nvd
CVE-2020-11027P2HIGHCVSS 8.1PoCv8.0v9.0+1 more2020-04-30
CVE-2020-11027 [HIGH] CWE-672 CVE-2020-11027: In affected versions of WordPress, a password reset link emailed to a user does not expire upon chan In affected versions of WordPress, a password reset link emailed to a user does not expire upon changing the user password. Access would be needed to the email account of the user by a malicious party for successful execution. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1
nvd
CVE-2016-5018P2CRITICALCVSS 9.1PoCv8.02017-08-10
CVE-2016-5018 [CRITICAL] CVE-2016-5018: In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0. In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 a malicious web application was able to bypass a configured SecurityManager via a Tomcat utility method that was accessible to web applications.
nvd
CVE-2019-2698P2HIGHCVSS 8.1PoCv8.0v9.02019-04-23
CVE-2019-2698 [HIGH] CVE-2019-2698: Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D). Supported versions that Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Java SE: 7u211 and 8u202. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in takeover of Java SE. Note: This
nvd
CVE-2016-5108P2CRITICALCVSS 9.8PoCv8.02016-06-08
CVE-2016-5108 [CRITICAL] CWE-119 CVE-2016-5108: Buffer overflow in the DecodeAdpcmImaQT function in modules/codec/adpcm.c in VideoLAN VLC media play Buffer overflow in the DecodeAdpcmImaQT function in modules/codec/adpcm.c in VideoLAN VLC media player before 2.2.4 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted QuickTime IMA file.
nvd
CVE-2008-3529P2CRITICALCVSS 10.0PoCv4.02008-09-12
CVE-2008-3529 [CRITICAL] CWE-119 CVE-2008-3529: Heap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7 Heap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7.0 allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via a long XML entity name.
nvd
CVE-2009-1955P3HIGHCVSS 7.5PoCv4.02009-06-08
CVE-2009-1955 [HIGH] CWE-776 CVE-2009-1955: The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, as demonstrated by a PROPFI
nvd
CVE-2017-10176P3HIGHCVSS 7.5Exploitedv9.02017-08-08
CVE-2017-10176 [HIGH] CVE-2017-10176: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: S Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 7u141 and 8u131; Java SE Embedded: 8u131; JRockit: R28.3.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE E
nvd
CVE-2019-17571P2CRITICALCVSS 9.8v8.0v9.0+1 more2019-12-20
CVE-2019-17571 [CRITICAL] CWE-502 CVE-2019-17571: Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted dat Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2 up to 1.2.17.
nvd
CVE-2017-0372P2CRITICALCVSS 9.8PoCv7.0v9.02018-04-13
CVE-2017-0372 [CRITICAL] CWE-74 CVE-2017-0372: Parameters injection in the SyntaxHighlight extension of Mediawiki before 1.23.16, 1.27.3 and 1.28.2 Parameters injection in the SyntaxHighlight extension of Mediawiki before 1.23.16, 1.27.3 and 1.28.2 might result in multiple vulnerabilities.
nvd
CVE-2021-3711P2CRITICALCVSS 9.8v10.0v11.02021-08-24
CVE-2021-3711 [CRITICAL] CWE-120 CVE-2021-3711: In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_ In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first time, on entry, the "out" parameter can be NULL and, on exit, the "outlen" parameter is populated with the buffer size required to hold the decrypted plaintext. The applicati
nvd
Debian Linux vulnerabilities | cvebase