Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 169 of 498
CVE-2018-12393P3HIGHCVSS 7.5v8.0v9.02019-02-28
CVE-2018-12393 [HIGH] CWE-190 CVE-2018-12393: A potential vulnerability was found in 32-bit builds where an integer overflow during the conversion
A potential vulnerability was found in 32-bit builds where an integer overflow during the conversion of scripts to an internal UTF-16 representation could result in allocating a buffer too small for the conversion. This leads to a possible out-of-bounds write. *Note: 64-bit builds are not vulnerable to this issue.*. This vulnerability affects Firefox
nvd
CVE-2022-45442P3HIGHCVSS 8.8v10.02022-11-28
CVE-2022-45442 [HIGH] CWE-494 CVE-2022-45442: Sinatra is a domain-specific language for creating web applications in Ruby. An issue was discovered
Sinatra is a domain-specific language for creating web applications in Ruby. An issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a response when the filename is derived from user-supplied input. Version 2.2.3 and 3.0
nvd
CVE-2012-2248P3HIGHCVSS 8.1v8.0v9.0+1 more2019-11-27
CVE-2012-2248 [HIGH] CWE-20 CVE-2012-2248: An issue was discovered in dhclient 4.3.1-6 due to an embedded path variable.
An issue was discovered in dhclient 4.3.1-6 due to an embedded path variable.
nvd
CVE-2021-36056P3HIGHCVSS 7.3v10.02021-09-01
CVE-2021-36056 [HIGH] CWE-122 CVE-2021-36056: XMP Toolkit SDK version 2020.1 (and earlier) is affected by a buffer overflow vulnerability potentia
XMP Toolkit SDK version 2020.1 (and earlier) is affected by a buffer overflow vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file.
nvd
CVE-2017-5396P3CRITICALCVSS 9.8v8.02018-06-11
CVE-2017-5396 [CRITICAL] CWE-416 CVE-2017-5396: A use-after-free vulnerability in the Media Decoder when working with media files when some events a
A use-after-free vulnerability in the Media Decoder when working with media files when some events are fired after the media elements are freed from memory. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
nvd
CVE-2020-27840P3HIGHCVSS 7.5v9.0v10.02021-05-12
CVE-2020-27840 [HIGH] CWE-125 CVE-2020-27840: A flaw was found in samba. Spaces used in a string around a domain name (DN), while supposed to be i
A flaw was found in samba. Spaces used in a string around a domain name (DN), while supposed to be ignored, can cause invalid DN strings with spaces to instead write a zero-byte into out-of-bounds memory, resulting in a crash. The highest threat from this vulnerability is to system availability.
nvd
CVE-2018-14348P3HIGHCVSS 8.1v8.02018-08-14
CVE-2018-14348 [HIGH] CWE-200 CVE-2018-14348: libcgroup up to and including 0.41 creates /var/log/cgred with mode 0666 regardless of the configure
libcgroup up to and including 0.41 creates /var/log/cgred with mode 0666 regardless of the configured umask, leading to disclosure of information.
nvd
CVE-2020-13625P3HIGHCVSS 7.5v8.0v9.02020-06-08
CVE-2020-13625 [HIGH] CWE-116 CVE-2020-13625: PHPMailer before 6.1.6 contains an output escaping bug when the name of a file attachment contains a
PHPMailer before 6.1.6 contains an output escaping bug when the name of a file attachment contains a double quote character. This can result in the file type being misinterpreted by the receiver or any mail relay processing the message.
nvd
CVE-2020-11741P3HIGHCVSS 8.8v10.02020-04-14
CVE-2020-11741 [HIGH] CWE-909 CVE-2020-11741: An issue was discovered in xenoprof in Xen through 4.13.x, allowing guest OS users (with active prof
An issue was discovered in xenoprof in Xen through 4.13.x, allowing guest OS users (with active profiling) to obtain sensitive information about other guests, cause a denial of service, or possibly gain privileges. For guests for which "active" profiling was enabled by the administrator, the xenoprof code uses the standard Xen shared ring structure. U
nvd
CVE-2016-9560P3HIGHCVSS 7.8v8.02017-02-15
CVE-2016-9560 [HIGH] CWE-787 CVE-2016-9560: Stack-based buffer overflow in the jpc_tsfb_getbands2 function in jpc_tsfb.c in JasPer before 1.900.
Stack-based buffer overflow in the jpc_tsfb_getbands2 function in jpc_tsfb.c in JasPer before 1.900.30 allows remote attackers to have unspecified impact via a crafted image.
nvd
CVE-2018-19134P3HIGHCVSS 7.8v8.02018-12-20
CVE-2018-19134 [HIGH] CWE-704 CVE-2018-19134: In Artifex Ghostscript through 9.25, the setpattern operator did not properly validate certain types
In Artifex Ghostscript through 9.25, the setpattern operator did not properly validate certain types. A specially crafted PostScript document could exploit this to crash Ghostscript or, possibly, execute arbitrary code in the context of the Ghostscript process. This is a type confusion issue because of failure to check whether the Implementation of a
nvd
CVE-2018-3710P3HIGHCVSS 7.8v9.02018-03-21
CVE-2018-3710 [HIGH] CWE-377 CVE-2018-3710: Gitlab Community and Enterprise Editions version 10.3.3 is vulnerable to an Insecure Temporary File
Gitlab Community and Enterprise Editions version 10.3.3 is vulnerable to an Insecure Temporary File in the project import component resulting remote code execution.
nvd
CVE-2018-20021P3HIGHCVSS 7.5v8.0v9.02018-12-19
CVE-2018-20021 [HIGH] CWE-835 CVE-2018-20021: LibVNC before commit c3115350eb8bb635d0fdb4dbbb0d0541f38ed19c contains a CWE-835: Infinite loop vuln
LibVNC before commit c3115350eb8bb635d0fdb4dbbb0d0541f38ed19c contains a CWE-835: Infinite loop vulnerability in VNC client code. Vulnerability allows attacker to consume excessive amount of resources like CPU and RAM
nvd
CVE-2017-5398P3CRITICALCVSS 9.8v8.0v9.02018-06-11
CVE-2017-5398 [CRITICAL] CWE-119 CVE-2017-5398: Memory safety bugs were reported in Thunderbird 45.7. Some of these bugs showed evidence of memory c
Memory safety bugs were reported in Thunderbird 45.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
nvd
CVE-2015-2318P3HIGHCVSS 8.1v6.02018-01-08
CVE-2015-2318 [HIGH] CWE-295 CVE-2015-2318: The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping a
The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequently impersonate clients by leveraging missing handshake state validation, aka a "SMACK SKIP-TLS" issue.
nvd
CVE-2017-3738P3MEDIUMCVSS 5.9v8.0v9.02017-12-07
CVE-2017-3738 [MEDIUM] CVE-2017-3738: There is an overflow bug in the AVX2 Montgomery multiplication procedure used in exponentiation with
There is an overflow bug in the AVX2 Montgomery multiplication procedure used in exponentiation with 1024-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH1024 are considered just feasible, because most of t
nvd
CVE-2020-15166P3HIGHCVSS 7.5v9.02020-09-11
CVE-2020-15166 [HIGH] CWE-400 CVE-2020-15166: In ZeroMQ before version 4.3.3, there is a denial-of-service vulnerability. Users with TCP transport
In ZeroMQ before version 4.3.3, there is a denial-of-service vulnerability. Users with TCP transport public endpoints, even with CURVE/ZAP enabled, are impacted. If a raw TCP socket is opened and connected to an endpoint that is fully configured with CURVE/ZAP, legitimate clients will not be able to exchange any message. Handshakes complete successful
nvd
CVE-2020-6575P3HIGHCVSS 8.3v10.02020-09-21
CVE-2020-6575 [HIGH] CWE-362 CVE-2020-6575: Race in Mojo in Google Chrome prior to 85.0.4183.102 allowed a remote attacker who had compromised t
Race in Mojo in Google Chrome prior to 85.0.4183.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2020-29361P3HIGHCVSS 7.5v9.0v10.02020-12-16
CVE-2020-29361 [HIGH] CWE-190 CVE-2020-29361: An issue was discovered in p11-kit 0.21.1 through 0.23.21. Multiple integer overflows have been disc
An issue was discovered in p11-kit 0.21.1 through 0.23.21. Multiple integer overflows have been discovered in the array allocations in the p11-kit library and the p11-kit list command, where overflow checks are missing before calling realloc or calloc.
nvd
CVE-2022-1619P3HIGHCVSS 7.8v9.0v10.02022-05-08
CVE-2022-1619 [HIGH] CWE-122 CVE-2022-1619: Heap-based Buffer Overflow in function cmdline_erase_chars in GitHub repository vim/vim prior to 8.2
Heap-based Buffer Overflow in function cmdline_erase_chars in GitHub repository vim/vim prior to 8.2.4899. This vulnerabilities are capable of crashing software, modify memory, and possible remote execution
nvd