Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 178 of 498
CVE-2025-39790P3HIGHCVSS 7.8v11.02025-09-11
CVE-2025-39790 [HIGH] CWE-415 CVE-2025-39790: In the Linux kernel, the following vulnerability has been resolved: bus: mhi: host: Detect events p
In the Linux kernel, the following vulnerability has been resolved:
bus: mhi: host: Detect events pointing to unexpected TREs
When a remote device sends a completion event to the host, it contains a
pointer to the consumed TRE. The host uses this pointer to process all of
the TREs between it and the host's local copy of the ring's read pointer.
This
nvd
CVE-2023-39534P3HIGHCVSS 7.5v11.0v12.02023-08-11
CVE-2023-39534 [HIGH] CWE-617 CVE-2023-39534: eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Ma
eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.10.0, 2.9.2, and 2.6.5, a malformed GAP submessage can trigger assertion failure, crashing FastDDS. Version 2.10.0, 2.9.2, and 2.6.5 contain a patch for this issue.
nvd
CVE-2025-39881P3HIGHCVSS 7.8v11.02025-09-23
CVE-2025-39881 [HIGH] CWE-416 CVE-2025-39881: In the Linux kernel, the following vulnerability has been resolved: kernfs: Fix UAF in polling when
In the Linux kernel, the following vulnerability has been resolved:
kernfs: Fix UAF in polling when open file is released
A use-after-free (UAF) vulnerability was identified in the PSI (Pressure
Stall Information) monitoring mechanism:
BUG: KASAN: slab-use-after-free in psi_trigger_poll+0x3c/0x140
Read of size 8 at addr ffff3de3d50bd308 by task syst
nvd
CVE-2019-19949P3CRITICALCVSS 9.1v8.0v9.0+1 more2019-12-24
CVE-2019-19949 [CRITICAL] CWE-125 CVE-2019-19949: In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer over-read in the function WritePNGImage of
In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer over-read in the function WritePNGImage of coders/png.c, related to Magick_png_write_raw_profile and LocaleNCompare.
nvd
CVE-2023-39947P3HIGHCVSS 7.5v11.0v12.02023-08-11
CVE-2023-39947 [HIGH] CWE-122 CVE-2023-39947: eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Ma
eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.11.1, 2.10.2, 2.9.2, and 2.6.6, even after the fix at commit 3492270, malformed `PID_PROPERTY_LIST` parameters cause heap overflow at a different program counter. This can remotely crash any Fast-DDS process. Versions
nvd
CVE-2018-13139P3HIGHCVSS 8.8v8.02018-07-04
CVE-2018-13139 [HIGH] CWE-787 CVE-2018-13139: A stack-based buffer overflow in psf_memset in common.c in libsndfile 1.0.28 allows remote attackers
A stack-based buffer overflow in psf_memset in common.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted audio file. The vulnerability can be triggered by the executable sndfile-deinterleave.
nvd
CVE-2007-3387P3MEDIUMCVSS 6.8v3.1v4.02007-07-30
CVE-2007-3387 [MEDIUM] CWE-190 CVE-2007-3387: Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3.02, as used in (1) poppl
Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3.02, as used in (1) poppler before 0.5.91, (2) gpdf before 2.8.2, (3) kpdf, (4) kdegraphics, (5) CUPS, (6) PDFedit, and other products, might allow remote attackers to execute arbitrary code via a crafted PDF file that triggers a stack-based buffer overflow in the StreamPredict
nvd
CVE-2019-19923P3HIGHCVSS 7.5v9.0v10.02019-12-24
CVE-2019-19923 [HIGH] CWE-476 CVE-2019-19923: flattenSubquery in select.c in SQLite 3.30.1 mishandles certain uses of SELECT DISTINCT involving a
flattenSubquery in select.c in SQLite 3.30.1 mishandles certain uses of SELECT DISTINCT involving a LEFT JOIN in which the right-hand side is a view. This can cause a NULL pointer dereference (or incorrect results).
nvd
CVE-2011-4625P3HIGHCVSS 7.5v8.0v9.0+1 more2019-11-06
CVE-2011-4625 [HIGH] CWE-755 CVE-2011-4625: simplesamlphp before 1.6.3 (squeeze) and before 1.8.2 (sid) incorrectly handles XML encryption which
simplesamlphp before 1.6.3 (squeeze) and before 1.8.2 (sid) incorrectly handles XML encryption which could allow remote attackers to decrypt or forge messages.
nvd
CVE-2008-2371P3HIGHCVSS 7.5v4.02008-07-07
CVE-2008-2371 [HIGH] CWE-787 CVE-2008-2371: Heap-based buffer overflow in pcre_compile.c in the Perl-Compatible Regular Expression (PCRE) librar
Heap-based buffer overflow in pcre_compile.c in the Perl-Compatible Regular Expression (PCRE) library 7.7 allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a regular expression that begins with an option and contains multiple branches.
nvd
CVE-2020-8927P3MEDIUMCVSS 6.5v9.0v10.02020-09-15
CVE-2020-8927 [MEDIUM] CWE-130 CVE-2020-8927: A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling
A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recomm
nvd
CVE-2022-2255P3HIGHCVSS 7.5v10.02022-08-25
CVE-2022-2255 [HIGH] CWE-348 CVE-2022-2255: A vulnerability was found in mod_wsgi. The X-Client-IP header is not removed from a request from an
A vulnerability was found in mod_wsgi. The X-Client-IP header is not removed from a request from an untrusted proxy, allowing an attacker to pass the X-Client-IP header to the target WSGI application because the condition to remove it is missing.
nvd
CVE-2024-1936P3HIGHCVSS 7.5v10.02024-03-04
CVE-2024-1936 [HIGH] CWE-922 CVE-2024-1936: The encrypted subject of an email message could be incorrectly and permanently assigned to an arbitr
The encrypted subject of an email message could be incorrectly and permanently assigned to an arbitrary other email message in Thunderbird's local cache. Consequently, when replying to the contaminated email message, the user might accidentally leak the confidential subject to a third-party. While this update fixes the bug and avoids future message cont
nvd
CVE-2026-23490P3HIGHCVSS 7.5v11.02026-01-16
CVE-2026-23490 [HIGH] CWE-770 CVE-2026-23490: pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been fou
pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to memory exhaustion from malformed RELATIVE-OID with excessive continuation octets. This vulnerability is fixed in 0.6.2.
nvd
CVE-2017-16669P3HIGHCVSS 8.8v7.0v8.0+1 more2017-11-09
CVE-2017-16669 [HIGH] CWE-119 CVE-2017-16669: coders/wpg.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (heap-bas
coders/wpg.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file, related to the AcquireCacheNexus function in magick/pixel_cache.c.
nvd
CVE-2008-4302P4MEDIUMCVSS 5.5PoCv4.02008-09-29
CVE-2008-4302 [MEDIUM] CWE-667 CVE-2008-4302: fs/splice.c in the splice subsystem in the Linux kernel before 2.6.22.2 does not properly handle a f
fs/splice.c in the splice subsystem in the Linux kernel before 2.6.22.2 does not properly handle a failure of the add_to_page_cache_lru function, and subsequently attempts to unlock a page that was not locked, which allows local users to cause a denial of service (kernel BUG and system crash), as demonstrated by the fio I/O tool.
nvd
CVE-2024-33601P3HIGHCVSS 7.3v10.02024-05-06
CVE-2024-33601 [HIGH] CWE-617 CVE-2024-33601: nscd: netgroup cache may terminate daemon on memory allocation failure The Name Service Cache Daemo
nscd: netgroup cache may terminate daemon on memory allocation failure
The Name Service Cache Daemon's (nscd) netgroup cache uses xmalloc or
xrealloc and these functions may terminate the process due to a memory
allocation failure resulting in a denial of service to the clients. The
flaw was introduced in glibc 2.15 when the cache was added to nscd.
nvd
CVE-2012-3489P3MEDIUMCVSS 6.5v6.02012-10-03
CVE-2012-3489 [MEDIUM] CWE-611 CVE-2012-3489: The xml_parse function in the libxml2 support in the core server component in PostgreSQL 8.3 before
The xml_parse function in the libxml2 support in the core server component in PostgreSQL 8.3 before 8.3.20, 8.4 before 8.4.13, 9.0 before 9.0.9, and 9.1 before 9.1.5 allows remote authenticated users to determine the existence of arbitrary files or URLs, and possibly obtain file or URL content that triggers a parsing error, via an XML value that refers
nvd
CVE-2016-5300P3HIGHCVSS 7.5v8.02016-06-16
CVE-2016-5300 [HIGH] CVE-2016-5300: The XML parser in Expat does not use sufficient entropy for hash initialization, which allows contex
The XML parser in Expat does not use sufficient entropy for hash initialization, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted identifiers in an XML document. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0876.
nvd
CVE-2024-35235P3MEDIUMCVSS 6.7v10.02024-06-11
CVE-2024-35235 [MEDIUM] CWE-59 CVE-2024-35235: OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems.
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.8 and earlier, when starting the cupsd server with a Listen configuration item pointing to a symbolic link, the cupsd process can be caused to perform an arbitrary chmod of the provided argument, providing world-writable access to the
nvd