Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 173 of 498
CVE-2017-14040P3HIGHCVSS 8.8v8.0v9.02017-08-30
CVE-2017-14040 [HIGH] CWE-787 CVE-2017-14040: An invalid write access was discovered in bin/jp2/convert.c in OpenJPEG 2.2.0, triggering a crash in
An invalid write access was discovered in bin/jp2/convert.c in OpenJPEG 2.2.0, triggering a crash in the tgatoimage function. The vulnerability may lead to remote denial of service or possibly unspecified other impact.
nvd
CVE-2013-1809P3HIGHCVSS 7.5v8.0v9.0+1 more2019-11-07
CVE-2013-1809 [HIGH] CWE-59 CVE-2013-1809: Gambas before 3.4.0 allows remote attackers to move or manipulate directory contents or perform syml
Gambas before 3.4.0 allows remote attackers to move or manipulate directory contents or perform symlink attacks due to the creation of insecure temporary directories.
nvd
CVE-2015-3427P3HIGHCVSS 7.5v8.02015-05-14
CVE-2015-3427 [HIGH] CVE-2015-3427: Quassel before 0.12.2 does not properly re-initialize the database session when the PostgreSQL datab
Quassel before 0.12.2 does not properly re-initialize the database session when the PostgreSQL database is restarted, which allows remote attackers to conduct SQL injection attacks via a \ (backslash) in a message. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4422.
nvd
CVE-2013-5589P3HIGHCVSS 7.5v7.02013-08-29
CVE-2013-5589 [HIGH] CWE-89 CVE-2013-5589: SQL injection vulnerability in cacti/host.php in Cacti 0.8.8b and earlier allows remote attackers to
SQL injection vulnerability in cacti/host.php in Cacti 0.8.8b and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
nvd
CVE-2016-1762P3HIGHCVSS 8.1v8.02016-03-24
CVE-2016-1762 [HIGH] CWE-119 CVE-2016-1762: The xmlNextChar function in libxml2 before 2.9.4 allows remote attackers to cause a denial of servic
The xmlNextChar function in libxml2 before 2.9.4 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document.
nvd
CVE-2019-16770P3HIGHCVSS 7.5v9.02019-12-05
CVE-2019-16770 [HIGH] CWE-770 CVE-2019-16770: In Puma before versions 3.12.2 and 4.3.1, a poorly-behaved client could use keepalive requests to mo
In Puma before versions 3.12.2 and 4.3.1, a poorly-behaved client could use keepalive requests to monopolize Puma's reactor and create a denial of service attack. If more keepalive connections to Puma are opened than there are threads available, additional connections will wait permanently if the attacker sends requests frequently enough. This vulnera
nvd
CVE-2023-44488P3HIGHCVSS 7.5v10.0v11.0+1 more2023-09-30
CVE-2023-44488 [HIGH] CWE-755 CVE-2023-44488: VP9 in libvpx before 1.13.1 mishandles widths, leading to a crash related to encoding.
VP9 in libvpx before 1.13.1 mishandles widths, leading to a crash related to encoding.
nvd
CVE-2018-12601P3CRITICALCVSS 9.8v8.02018-06-20
CVE-2018-12601 [CRITICAL] CWE-787 CVE-2018-12601: There is a heap-based buffer overflow in ReadImage in input-tga.ci in sam2p 0.49.4 that leads to a d
There is a heap-based buffer overflow in ReadImage in input-tga.ci in sam2p 0.49.4 that leads to a denial of service or possibly unspecified other impact.
nvd
CVE-2020-29661P3HIGHCVSS 7.8v9.0v10.02020-12-09
CVE-2020-29661 [HIGH] CWE-416 CVE-2020-29661: A locking issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/
A locking issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_jobctrl.c allows a use-after-free attack against TIOCSPGRP, aka CID-54ffccbf053b.
nvd
CVE-2016-7966P3HIGHCVSS 7.3v8.02016-12-23
CVE-2016-7966 [HIGH] CWE-94 CVE-2016-7966: Through a malicious URL that contained a quote character it was possible to inject HTML code in KMai
Through a malicious URL that contained a quote character it was possible to inject HTML code in KMail's plaintext viewer. Due to the parser used on the URL it was not possible to include the equal sign (=) or a space into the injected HTML, which greatly reduces the available HTML functionality. Although it is possible to include an HTML comment indicato
nvd
CVE-2022-31002P3HIGHCVSS 7.5v10.02022-05-31
CVE-2022-31002 [HIGH] CWE-125 CVE-2022-31002: Sofia-SIP is an open-source Session Initiation Protocol (SIP) User-Agent library. Prior to version 1
Sofia-SIP is an open-source Session Initiation Protocol (SIP) User-Agent library. Prior to version 1.13.8, an attacker can send a message with evil sdp to FreeSWITCH, which may cause a crash. This type of crash may be caused by a URL ending with `%`. Version 1.13.8 contains a patch for this issue.
nvd
CVE-2017-11424P3HIGHCVSS 7.5v8.0v9.02017-08-24
CVE-2017-11424 [HIGH] CVE-2017-11424: In PyJWT 1.5.0 and below the `invalid_strings` check in `HMACAlgorithm.prepare_key` does not account
In PyJWT 1.5.0 and below the `invalid_strings` check in `HMACAlgorithm.prepare_key` does not account for all PEM encoded public keys. Specifically, the PKCS1 PEM encoded format would be allowed because it is prefaced with the string `-----BEGIN RSA PUBLIC KEY-----` which is not accounted for. This enables symmetric/asymmetric key confusion attacks against use
nvd
CVE-2021-20299P3HIGHCVSS 7.5v10.02022-03-16
CVE-2021-20299 [HIGH] CWE-476 CVE-2021-20299: A flaw was found in OpenEXR's Multipart input file functionality. A crafted multi-part input file wi
A flaw was found in OpenEXR's Multipart input file functionality. A crafted multi-part input file with no actual parts can trigger a NULL pointer dereference. The highest threat from this vulnerability is to system availability.
nvd
CVE-2021-38562P3HIGHCVSS 7.5v9.02021-10-18
CVE-2021-38562 [HIGH] CWE-203 CVE-2021-38562: Best Practical Request Tracker (RT) 4.2 before 4.2.17, 4.4 before 4.4.5, and 5.0 before 5.0.2 allows
Best Practical Request Tracker (RT) 4.2 before 4.2.17, 4.4 before 4.4.5, and 5.0 before 5.0.2 allows sensitive information disclosure via a timing attack against lib/RT/REST2/Middleware/Auth.pm.
nvd
CVE-2022-29581P3HIGHCVSS 7.8v10.02022-05-17
CVE-2022-29581 [HIGH] CWE-911 CVE-2022-29581: Improper Update of Reference Count vulnerability in net/sched of Linux Kernel allows local attacker
Improper Update of Reference Count vulnerability in net/sched of Linux Kernel allows local attacker to cause privilege escalation to root. This issue affects: Linux Kernel versions prior to 5.18; version 4.14 and later versions.
nvd
CVE-2012-6111P3HIGHCVSS 7.5v8.0v9.02019-12-20
CVE-2012-6111 [HIGH] CWE-20 CVE-2012-6111: gnome-keyring does not discard stored secrets when using gnome_keyring_lock_all_sync function
gnome-keyring does not discard stored secrets when using gnome_keyring_lock_all_sync function
nvd
CVE-2016-1238P3HIGHCVSS 7.8v8.02016-08-02
CVE-2016-1238 [HIGH] CWE-264 CVE-2016-1238: (1) cpan/Archive-Tar/bin/ptar, (2) cpan/Archive-Tar/bin/ptardiff, (3) cpan/Archive-Tar/bin/ptargrep,
(1) cpan/Archive-Tar/bin/ptar, (2) cpan/Archive-Tar/bin/ptardiff, (3) cpan/Archive-Tar/bin/ptargrep, (4) cpan/CPAN/scripts/cpan, (5) cpan/Digest-SHA/shasum, (6) cpan/Encode/bin/enc2xs, (7) cpan/Encode/bin/encguess, (8) cpan/Encode/bin/piconv, (9) cpan/Encode/bin/ucmlint, (10) cpan/Encode/bin/unidump, (11) cpan/ExtUtils-MakeMaker/bin/instmodsh, (12) cpan
nvd
CVE-2018-1087P3HIGHCVSS 7.8v8.0v9.02018-05-15
CVE-2018-1087 [HIGH] CWE-250 CVE-2018-1087: kernel KVM before versions kernel 4.16, kernel 4.16-rc7, kernel 4.17-rc1, kernel 4.17-rc2 and kernel
kernel KVM before versions kernel 4.16, kernel 4.16-rc7, kernel 4.17-rc1, kernel 4.17-rc2 and kernel 4.17-rc3 is vulnerable to a flaw in the way the Linux kernel's KVM hypervisor handled exceptions delivered after a stack switch operation via Mov SS or Pop SS instructions. During the stack switch operation, the processor did not deliver interrupts and e
nvd
CVE-2021-28116P3MEDIUMCVSS 5.3v10.0v11.02021-03-09
CVE-2021-28116 [MEDIUM] CWE-125 CVE-2021-28116: Squid through 4.14 and 5.x through 5.0.5, in some configurations, allows information disclosure beca
Squid through 4.14 and 5.x through 5.0.5, in some configurations, allows information disclosure because of an out-of-bounds read in WCCP protocol data. This can be leveraged as part of a chain for remote code execution as nobody.
nvd
CVE-2016-9775P3HIGHCVSS 7.8v7.0v8.02017-03-23
CVE-2016-9775 [HIGH] CWE-264 CVE-2016-9775: The postrm script in the tomcat6 package before 6.0.45+dfsg-1~deb7u3 on Debian wheezy, before 6.0.45
The postrm script in the tomcat6 package before 6.0.45+dfsg-1~deb7u3 on Debian wheezy, before 6.0.45+dfsg-1~deb8u1 on Debian jessie, before 6.0.35-1ubuntu3.9 on Ubuntu 12.04 LTS and on Ubuntu 14.04 LTS; the tomcat7 package before 7.0.28-4+deb7u7 on Debian wheezy, before 7.0.56-3+deb8u6 on Debian jessie, before 7.0.52-1ubuntu0.8 on Ubuntu 14.04 LTS, and
nvd