Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 186 of 498
CVE-2020-7919P3HIGHCVSS 7.5v10.02020-03-16
CVE-2020-7919 [HIGH] CWE-295 CVE-2020-7919: Go before 1.12.16 and 1.13.x before 1.13.7 (and the crypto/cryptobyte package before 0.0.0-202001242
Go before 1.12.16 and 1.13.x before 1.13.7 (and the crypto/cryptobyte package before 0.0.0-20200124225646-8b5121be2f68 for Go) allows attacks on clients (resulting in a panic) via a malformed X.509 certificate.
nvd
CVE-2016-9190P3HIGHCVSS 7.8v8.02016-11-04
CVE-2016-9190 [HIGH] CWE-284 CVE-2016-9190: Pillow before 3.3.2 allows context-dependent attackers to execute arbitrary code by using the "craft
Pillow before 3.3.2 allows context-dependent attackers to execute arbitrary code by using the "crafted image file" approach, related to an "Insecure Sign Extension" issue affecting the ImagingNew in Storage.c component.
nvd
CVE-2016-1572P3HIGHCVSS 8.4v7.0v8.02016-01-22
CVE-2016-1572 [HIGH] CWE-269 CVE-2016-1572: mount.ecryptfs_private.c in eCryptfs-utils does not validate mount destination filesystem types, whi
mount.ecryptfs_private.c in eCryptfs-utils does not validate mount destination filesystem types, which allows local users to gain privileges by mounting over a nonstandard filesystem, as demonstrated by /proc/$pid.
nvd
CVE-2015-8776P3CRITICALCVSS 9.1v8.02016-04-19
CVE-2015-8776 [CRITICAL] CWE-189 CVE-2015-8776: The strftime function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent
The strftime function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly obtain sensitive information via an out-of-range time value.
nvd
CVE-2020-29394P3HIGHCVSS 7.8v10.02020-11-30
CVE-2020-29394 [HIGH] CWE-787 CVE-2020-29394: A buffer overflow in the dlt_filter_load function in dlt_common.c from dlt-daemon through 2.18.5 (GE
A buffer overflow in the dlt_filter_load function in dlt_common.c from dlt-daemon through 2.18.5 (GENIVI Diagnostic Log and Trace) allows arbitrary code execution because fscanf is misused (no limit on the number of characters to be read in the format argument).
nvd
CVE-2021-46828P3HIGHCVSS 7.5v10.0v11.02022-07-20
CVE-2021-46828 [HIGH] CWE-755 CVE-2021-46828: In libtirpc before 1.3.3rc1, remote attackers could exhaust the file descriptors of a process that u
In libtirpc before 1.3.3rc1, remote attackers could exhaust the file descriptors of a process that uses libtirpc because idle TCP connections are mishandled. This can, in turn, lead to an svc_run infinite loop without accepting new connections.
nvd
CVE-2017-18122P3HIGHCVSS 8.1v7.0v8.0+1 more2018-02-02
CVE-2017-18122 [HIGH] CWE-347 CVE-2017-18122: A signature-validation bypass issue was discovered in SimpleSAMLphp through 1.14.16. A SimpleSAMLphp
A signature-validation bypass issue was discovered in SimpleSAMLphp through 1.14.16. A SimpleSAMLphp Service Provider using SAML 1.1 will regard as valid any unsigned SAML response containing more than one signed assertion, provided that the signature of at least one of the assertions is valid. Attributes contained in all the assertions received will
nvd
CVE-2022-27781P3HIGHCVSS 7.5v10.0v11.02022-06-02
CVE-2022-27781 [HIGH] CWE-400 CVE-2022-27781: libcurl provides the `CURLOPT_CERTINFO` option to allow applications torequest details to be returne
libcurl provides the `CURLOPT_CERTINFO` option to allow applications torequest details to be returned about a server's certificate chain.Due to an erroneous function, a malicious server could make libcurl built withNSS get stuck in a never-ending busy-loop when trying to retrieve thatinformation.
nvd
CVE-2017-7810P3CRITICALCVSS 9.8v7.0v8.0+1 more2018-06-11
CVE-2017-7810 [CRITICAL] CWE-119 CVE-2017-7810: Memory safety bugs were reported in Firefox 55 and Firefox ESR 52.3. Some of these bugs showed evide
Memory safety bugs were reported in Firefox 55 and Firefox ESR 52.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.
nvd
CVE-2020-5247P3HIGHCVSS 7.5v9.02020-02-28
CVE-2020-5247 [HIGH] CWE-113 CVE-2020-5247: In Puma (RubyGem) before 4.3.2 and before 3.12.3, if an application using Puma allows untrusted inpu
In Puma (RubyGem) before 4.3.2 and before 3.12.3, if an application using Puma allows untrusted input in a response header, an attacker can use newline characters (i.e. `CR`, `LF` or`/r`, `/n`) to end the header and inject malicious content, such as additional headers or an entirely new response body. This vulnerability is known as HTTP Response Splitti
nvd
CVE-2020-16303P3HIGHCVSS 7.8v9.0v10.02020-08-13
CVE-2020-16303 [HIGH] CWE-416 CVE-2020-16303: A use-after-free vulnerability in xps_finish_image_path() in devices/vector/gdevxps.c of Artifex Sof
A use-after-free vulnerability in xps_finish_image_path() in devices/vector/gdevxps.c of Artifex Software GhostScript v9.50 allows a remote attacker to escalate privileges via a crafted PDF file. This is fixed in v9.51.
nvd
CVE-2018-19490P3HIGHCVSS 7.8v8.02018-11-23
CVE-2018-19490 [HIGH] CWE-787 CVE-2018-19490: An issue was discovered in datafile.c in Gnuplot 5.2.5. This issue allows an attacker to conduct a h
An issue was discovered in datafile.c in Gnuplot 5.2.5. This issue allows an attacker to conduct a heap-based buffer overflow with an arbitrary amount of data in df_generate_ascii_array_entry. To exploit this vulnerability, an attacker must pass an overlong string as the right bound of the range argument that is passed to the plot function.
nvd
CVE-2018-19491P3HIGHCVSS 7.8v8.02018-11-23
CVE-2018-19491 [HIGH] CWE-119 CVE-2018-19491: An issue was discovered in post.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a buf
An issue was discovered in post.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a buffer overflow with an arbitrary amount of data in the PS_options function. This flaw is caused by a missing size check of an argument passed to the "set font" function. This issue occurs when the Gnuplot postscript terminal is used as a backend.
nvd
CVE-2018-19492P3HIGHCVSS 7.8v8.02018-11-23
CVE-2018-19492 [HIGH] CWE-119 CVE-2018-19492: An issue was discovered in cairo.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a bu
An issue was discovered in cairo.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a buffer overflow with an arbitrary amount of data in the cairotrm_options function. This flaw is caused by a missing size check of an argument passed to the "set font" function. This issue occurs when the Gnuplot pngcairo terminal is used as a backend.
nvd
CVE-2021-21775P3HIGHCVSS 8.0v10.02021-07-07
CVE-2021-21775 [HIGH] CWE-416 CVE-2021-21775: A use-after-free vulnerability exists in the way certain events are processed for ImageLoader object
A use-after-free vulnerability exists in the way certain events are processed for ImageLoader objects of Webkit WebKitGTK 2.30.4. A specially crafted web page can lead to a potential information leak and further memory corruption. In order to trigger the vulnerability, a victim must be tricked into visiting a malicious webpage.
nvd
CVE-2018-10753P3CRITICALCVSS 9.8v9.02018-05-05
CVE-2018-10753 [CRITICAL] CWE-787 CVE-2018-10753: Stack-based buffer overflow in the delayed_output function in music.c in abcm2ps through 8.13.20 all
Stack-based buffer overflow in the delayed_output function in music.c in abcm2ps through 8.13.20 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
nvd
CVE-2016-9578P3HIGHCVSS 7.5v8.02018-07-27
CVE-2016-9578 [HIGH] CWE-20 CVE-2016-9578: A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An attacke
A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An attacker able to connect to the SPICE server could send crafted messages which would cause the process to crash.
nvd
CVE-2020-25862P3HIGHCVSS 7.5v9.02020-10-06
CVE-2020-25862 [HIGH] CWE-354 CVE-2020-25862: In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the TCP dissector could crash. Th
In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the TCP dissector could crash. This was addressed in epan/dissectors/packet-tcp.c by changing the handling of the invalid 0xFFFF checksum.
nvd
CVE-2020-2601P3MEDIUMCVSS 6.8v8.0v9.0+1 more2020-01-15
CVE-2020-2601 [MEDIUM] CVE-2020-2601: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Security). Supp
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Security). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1; Java SE Embedded: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Kerberos to compromise Java SE, Java SE Embedded. While the vulner
nvd
CVE-2017-7809P3CRITICALCVSS 9.8v8.0v9.02018-06-11
CVE-2017-7809 [CRITICAL] CWE-416 CVE-2017-7809: A use-after-free vulnerability can occur when an editor DOM node is deleted prematurely during tree
A use-after-free vulnerability can occur when an editor DOM node is deleted prematurely during tree traversal while still bound to the document. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
nvd