Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 170 of 498
CVE-2018-5155P3CRITICALCVSS 9.8v7.0v8.0+1 more2018-06-11
CVE-2018-5155 [CRITICAL] CWE-416 CVE-2018-5155: A use-after-free vulnerability can occur while adjusting layout during SVG animations with text path
A use-after-free vulnerability can occur while adjusting layout during SVG animations with text paths. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.
nvd
CVE-2017-13004P3CRITICALCVSS 9.8v8.0v9.0+1 more2017-09-14
CVE-2017-13004 [CRITICAL] CWE-125 CVE-2017-13004: The Juniper protocols parser in tcpdump before 4.9.2 has a buffer over-read in print-juniper.c:junip
The Juniper protocols parser in tcpdump before 4.9.2 has a buffer over-read in print-juniper.c:juniper_parse_header().
nvd
CVE-2016-1000343P3HIGHCVSS 7.5v8.02018-06-04
CVE-2016-1000343 [HIGH] CWE-310 CVE-2016-1000343: In the Bouncy Castle JCE Provider version 1.55 and earlier the DSA key pair generator generates a we
In the Bouncy Castle JCE Provider version 1.55 and earlier the DSA key pair generator generates a weak private key if used with default values. If the JCA key pair generator is not explicitly initialised with DSA parameters, 1.55 and earlier generates a private value assuming a 1024 bit key size. In earlier releases this can be dealt with by expli
nvd
CVE-2017-7819P3CRITICALCVSS 9.8v7.0v8.0+1 more2018-06-11
CVE-2017-7819 [CRITICAL] CWE-416 CVE-2017-7819: A use-after-free vulnerability can occur in design mode when image objects are resized if objects re
A use-after-free vulnerability can occur in design mode when image objects are resized if objects referenced during the resizing have been freed from memory. This results in a potentially exploitable crash. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.
nvd
CVE-2009-1890P3HIGHCVSS 7.1v4.0v5.0+1 more2009-07-05
CVE-2009-1890 [HIGH] CWE-400 CVE-2009-1890: The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server
The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured, does not properly handle an amount of streamed data that exceeds the Content-Length value, which allows remote attackers to cause a denial of service (CPU consumption) via crafted requests.
nvd
CVE-2019-17673P3HIGHCVSS 7.5v9.0v10.02019-10-17
CVE-2019-17673 [HIGH] CVE-2019-17673: WordPress before 5.2.4 is vulnerable to poisoning of the cache of JSON GET requests because certain
WordPress before 5.2.4 is vulnerable to poisoning of the cache of JSON GET requests because certain requests lack a Vary: Origin header.
nvd
CVE-2020-27216P3HIGHCVSS 7.0v9.0v10.02020-10-23
CVE-2020-27216 [HIGH] CWE-378 CVE-2020-27216: In Eclipse Jetty versions 1.0 thru 9.4.32.v20200930, 10.0.0.alpha1 thru 10.0.0.beta2, and 11.0.0.alp
In Eclipse Jetty versions 1.0 thru 9.4.32.v20200930, 10.0.0.alpha1 thru 10.0.0.beta2, and 11.0.0.alpha1 thru 11.0.0.beta2O, on Unix like systems, the system's temporary directory is shared between all users on that system. A collocated user can observe the process of creating a temporary sub directory in the shared temporary directory and race to comp
nvd
CVE-2017-7826P3CRITICALCVSS 9.8v7.0v8.0+1 more2018-06-11
CVE-2017-7826 [CRITICAL] CWE-119 CVE-2017-7826: Memory safety bugs were reported in Firefox 56 and Firefox ESR 52.4. Some of these bugs showed evide
Memory safety bugs were reported in Firefox 56 and Firefox ESR 52.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 57, Firefox ESR < 52.5, and Thunderbird < 52.5.
nvd
CVE-2018-5089P3CRITICALCVSS 9.8v8.0v9.02018-06-11
CVE-2018-5089 [CRITICAL] CWE-119 CVE-2018-5089: Memory safety bugs were reported in Firefox 57 and Firefox ESR 52.5. Some of these bugs showed evide
Memory safety bugs were reported in Firefox 57 and Firefox ESR 52.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.
nvd
CVE-2020-8622P3MEDIUMCVSS 6.5v9.0v10.02020-08-21
CVE-2020-8622 [MEDIUM] CWE-617 CVE-2020-8622: In BIND 9.0.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.3-S1 -> 9.11.21-S1 of
In BIND 9.0.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker on the network path for a TSIG-signed request, or operating the server receiving the TSIG-signed request, could send a truncated response to that request, triggering an assertion failure, causing the se
nvd
CVE-2018-16949P3HIGHCVSS 7.5v8.0v9.02018-09-12
CVE-2018-16949 [HIGH] CWE-400 CVE-2018-16949: An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. Several data types used as
An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. Several data types used as RPC input variables were implemented as unbounded array types, limited only by the inherent 32-bit length field to 4 GB. An unauthenticated attacker could send, or claim to send, large input values and consume server resources waiting for those inputs, d
nvd
CVE-2018-10911P3HIGHCVSS 7.5v8.0v9.02018-09-04
CVE-2018-10911 [HIGH] CWE-190 CVE-2018-10911: A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key lengt
A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacker could use this flaw to read memory from other locations into the stored dict value.
nvd
CVE-2018-18541P3HIGHCVSS 7.5v9.02018-10-20
CVE-2018-18541 [HIGH] CWE-20 CVE-2018-18541: In Teeworlds before 0.6.5, connection packets could be forged. There was no challenge-response invol
In Teeworlds before 0.6.5, connection packets could be forged. There was no challenge-response involved in the connection build up. A remote attacker could send connection packets from a spoofed IP address and occupy all server slots, or even use them for a reflection attack using map download packets.
nvd
CVE-2017-7843P3HIGHCVSS 7.5v7.0v8.0+1 more2018-06-11
CVE-2017-7843 [HIGH] CWE-200 CVE-2017-7843: When Private Browsing mode is used, it is possible for a web worker to write persistent data to Inde
When Private Browsing mode is used, it is possible for a web worker to write persistent data to IndexedDB and fingerprint a user uniquely. IndexedDB should not be available in Private Browsing mode and this stored data will persist across multiple private browsing mode sessions because it is not cleared when exiting. This vulnerability affects Firefox E
nvd
CVE-2024-26581P3HIGHCVSS 7.8v10.02024-02-20
CVE-2024-26581 [HIGH] CVE-2024-26581: In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_rbtree: skip
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nft_set_rbtree: skip end interval element from gc
rbtree lazy gc on insert might collect an end interval element that has
been just added in this transactions, skip end interval elements that
are not yet active.
nvd
CVE-2021-21205P3HIGHCVSS 8.1v10.02021-04-26
CVE-2021-21205 [HIGH] CVE-2021-21205: Insufficient policy enforcement in navigation in Google Chrome on iOS prior to 90.0.4430.72 allowed
Insufficient policy enforcement in navigation in Google Chrome on iOS prior to 90.0.4430.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2021-41819P3HIGHCVSS 7.5v9.0v10.0+1 more2022-01-01
CVE-2021-41819 [HIGH] CWE-565 CVE-2021-41819: CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affe
CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.
nvd
CVE-2018-12376P3CRITICALCVSS 9.8v8.0v9.02018-10-18
CVE-2018-12376 [CRITICAL] CWE-119 CVE-2018-12376: Memory safety bugs present in Firefox 61 and Firefox ESR 60.1. Some of these bugs showed evidence of
Memory safety bugs present in Firefox 61 and Firefox ESR 60.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.
nvd
CVE-2019-13304P3HIGHCVSS 7.8v8.0v9.0+1 more2019-07-05
CVE-2019-13304 [HIGH] CWE-787 CVE-2019-13304: ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because
ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because of a misplaced assignment.
nvd
CVE-2019-13306P3HIGHCVSS 7.8v8.0v9.02019-07-05
CVE-2019-13306 [HIGH] CWE-193 CVE-2019-13306: ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because
ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because of off-by-one errors.
nvd