Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 168 of 498
CVE-2012-3158P3HIGHCVSS 7.5v6.0v7.02012-10-16
CVE-2012-3158 [HIGH] CVE-2012-3158: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.64 and earlier, and 5.5.
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.64 and earlier, and 5.5.26 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Protocol.
nvd
CVE-2019-5811P3HIGHCVSS 8.8v10.02019-06-27
CVE-2019-5811 [HIGH] CVE-2019-5811: Incorrect handling of CORS in ServiceWorker in Google Chrome prior to 74.0.3729.108 allowed a remote
Incorrect handling of CORS in ServiceWorker in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass same origin policy via a crafted HTML page.
nvd
CVE-2021-42531P3HIGHCVSS 7.8v10.02022-05-02
CVE-2021-42531 [HIGH] CWE-121 CVE-2021-42531: XMP Toolkit SDK version 2021.07 (and earlier) is affected by a stack-based buffer overflow vulnerabi
XMP Toolkit SDK version 2021.07 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file.
nvd
CVE-2021-42532P3HIGHCVSS 7.8v10.02022-05-02
CVE-2021-42532 [HIGH] CWE-121 CVE-2021-42532: XMP Toolkit SDK version 2021.07 (and earlier) is affected by a stack-based buffer overflow vulnerabi
XMP Toolkit SDK version 2021.07 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file.
nvd
CVE-2021-42529P3HIGHCVSS 7.8v10.02022-05-02
CVE-2021-42529 [HIGH] CWE-121 CVE-2021-42529: XMP Toolkit SDK version 2021.07 (and earlier) is affected by a stack-based buffer overflow vulnerabi
XMP Toolkit SDK version 2021.07 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file.
nvd
CVE-2021-42530P3HIGHCVSS 7.8v10.02022-05-02
CVE-2021-42530 [HIGH] CWE-121 CVE-2021-42530: XMP Toolkit SDK version 2021.07 (and earlier) is affected by a stack-based buffer overflow vulnerabi
XMP Toolkit SDK version 2021.07 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file.
nvd
CVE-2015-6764P3CRITICALCVSS 9.8v8.0v9.02015-12-06
CVE-2015-6764 [CRITICAL] CWE-119 CVE-2015-6764: The BasicJsonStringifier::SerializeJSArray function in json-stringifier.h in the JSON stringifier in
The BasicJsonStringifier::SerializeJSArray function in json-stringifier.h in the JSON stringifier in Google V8, as used in Google Chrome before 47.0.2526.73, improperly loads array elements, which allows remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other impact via crafted JavaScript code.
nvd
CVE-2020-10995P3HIGHCVSS 7.5v10.02020-05-19
CVE-2020-10995 [HIGH] CWE-400 CVE-2020-10995: PowerDNS Recursor from 4.1.0 up to and including 4.3.0 does not sufficiently defend against amplific
PowerDNS Recursor from 4.1.0 up to and including 4.3.0 does not sufficiently defend against amplification attacks. An issue in the DNS protocol has been found that allow malicious parties to use recursive DNS services to attack third party authoritative name servers. The attack uses a crafted reply by an authoritative name server to amplify the result
nvd
CVE-2019-5783P3HIGHCVSS 8.8v9.02019-02-19
CVE-2019-5783 [HIGH] CWE-20 CVE-2019-5783: Missing URI encoding of untrusted input in DevTools in Google Chrome prior to 72.0.3626.81 allowed a
Missing URI encoding of untrusted input in DevTools in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to perform a Dangling Markup Injection attack via a crafted HTML page.
nvd
CVE-2020-6459P3HIGHCVSS 8.8v9.0v10.02020-05-21
CVE-2020-6459 [HIGH] CWE-416 CVE-2020-6459: Use after free in payments in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to pote
Use after free in payments in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-4055P3HIGHCVSS 8.8v10.0v11.02021-12-23
CVE-2021-4055 [HIGH] CWE-787 CVE-2021-4055: Heap buffer overflow in extensions in Google Chrome prior to 96.0.4664.93 allowed an attacker who co
Heap buffer overflow in extensions in Google Chrome prior to 96.0.4664.93 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.
nvd
CVE-2020-36224P3HIGHCVSS 7.5v9.0v10.02021-01-26
CVE-2020-36224 [HIGH] CWE-763 CVE-2020-36224: A flaw was discovered in OpenLDAP before 2.4.57 leading to an invalid pointer free and slapd crash i
A flaw was discovered in OpenLDAP before 2.4.57 leading to an invalid pointer free and slapd crash in the saslAuthzTo processing, resulting in denial of service.
nvd
CVE-2013-1915P3HIGHCVSS 7.5v6.0v7.02013-04-25
CVE-2013-1915 [HIGH] CWE-611 CVE-2013-1915: ModSecurity before 2.7.3 allows remote attackers to read arbitrary files, send HTTP requests to intr
ModSecurity before 2.7.3 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an XML external entity declaration in conjunction with an entity reference, aka an XML External Entity (XXE) vulnerability.
nvd
CVE-2019-12529P3MEDIUMCVSS 5.9v8.0v9.0+1 more2019-07-11
CVE-2019-12529 [MEDIUM] CWE-125 CVE-2019-12529: An issue was discovered in Squid 2.x through 2.7.STABLE9, 3.x through 3.5.28, and 4.x through 4.7. W
An issue was discovered in Squid 2.x through 2.7.STABLE9, 3.x through 3.5.28, and 4.x through 4.7. When Squid is configured to use Basic Authentication, the Proxy-Authorization header is parsed via uudecode. uudecode determines how many bytes will be decoded by iterating over the input and checking its table. The length is then used to start decodin
nvd
CVE-2019-19816P3HIGHCVSS 7.8v9.02019-12-17
CVE-2019-19816 [HIGH] CWE-787 CVE-2019-19816: In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image and performing some operations
In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image and performing some operations can cause slab-out-of-bounds write access in __btrfs_map_block in fs/btrfs/volumes.c, because a value of 1 for the number of data stripes is mishandled.
nvd
CVE-2018-5095P3CRITICALCVSS 9.8v8.0v9.02018-06-11
CVE-2018-5095 [CRITICAL] CWE-190 CVE-2018-5095: An integer overflow vulnerability in the Skia library when allocating memory for edge builders on so
An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 8 GB of RAM. This results in the use of uninitialized memory, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.
nvd
CVE-2018-6798P3HIGHCVSS 7.5v7.0v8.0+1 more2018-04-17
CVE-2018-6798 [HIGH] CWE-125 CVE-2018-6798: An issue was discovered in Perl 5.22 through 5.26. Matching a crafted locale dependent regular expre
An issue was discovered in Perl 5.22 through 5.26. Matching a crafted locale dependent regular expression can cause a heap-based buffer over-read and potentially information disclosure.
nvd
CVE-2021-36052P3HIGHCVSS 7.8v10.02021-09-01
CVE-2021-36052 [HIGH] CWE-788 CVE-2021-36052: XMP Toolkit version 2020.1 (and earlier) is affected by a memory corruption vulnerability, potential
XMP Toolkit version 2020.1 (and earlier) is affected by a memory corruption vulnerability, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.
nvd
CVE-2016-2347P3HIGHCVSS 7.8v7.0v8.02017-04-21
CVE-2016-2347 [HIGH] CWE-190 CVE-2016-2347: Integer underflow in the decode_level3_header function in lib/lha_file_header.c in Lhasa before 0.3.
Integer underflow in the decode_level3_header function in lib/lha_file_header.c in Lhasa before 0.3.1 allows remote attackers to execute arbitrary code via a crafted archive.
nvd
CVE-2021-44716P3HIGHCVSS 7.5v9.02022-01-01
CVE-2021-44716 [HIGH] CWE-400 CVE-2021-44716: net/http in Go before 1.16.12 and 1.17.x before 1.17.5 allows uncontrolled memory consumption in the
net/http in Go before 1.16.12 and 1.17.x before 1.17.5 allows uncontrolled memory consumption in the header canonicalization cache via HTTP/2 requests.
nvd