Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 187 of 498
CVE-2022-27378P3HIGHCVSS 7.5v10.02022-04-12
CVE-2022-27378 [HIGH] CWE-89 CVE-2022-27378: An issue in the component Create_tmp_table::finalize of MariaDB Server v10.7 and below was discovere
An issue in the component Create_tmp_table::finalize of MariaDB Server v10.7 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.
nvd
CVE-2020-19667P3HIGHCVSS 7.8v9.02020-11-20
CVE-2020-19667 [HIGH] CWE-787 CVE-2020-19667: Stack-based buffer overflow and unconditional jump in ReadXPMImage in coders/xpm.c in ImageMagick 7.
Stack-based buffer overflow and unconditional jump in ReadXPMImage in coders/xpm.c in ImageMagick 7.0.10-7.
nvd
CVE-2018-18898P3HIGHCVSS 7.5v8.0v10.02019-03-21
CVE-2018-18898 [HIGH] CWE-400 CVE-2018-18898: The email-ingestion feature in Best Practical Request Tracker 4.1.13 through 4.4 allows denial of se
The email-ingestion feature in Best Practical Request Tracker 4.1.13 through 4.4 allows denial of service by remote attackers via an algorithmic complexity attack on email address parsing.
nvd
CVE-2014-0207P3MEDIUMCVSS 6.5v7.0v8.02014-07-09
CVE-2014-0207 [MEDIUM] CWE-119 CVE-2014-0207: The cdf_read_short_sector function in cdf.c in file before 5.19, as used in the Fileinfo component i
The cdf_read_short_sector function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted CDF file.
nvd
CVE-2021-39242P3HIGHCVSS 7.5v11.02021-08-17
CVE-2021-39242 [HIGH] CWE-755 CVE-2021-39242: An issue was discovered in HAProxy 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3. It ca
An issue was discovered in HAProxy 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3. It can lead to a situation with an attacker-controlled HTTP Host header, because a mismatch between Host and authority is mishandled.
nvd
CVE-2022-29901P3MEDIUMCVSS 6.5v10.0v11.02022-07-12
CVE-2022-29901 [MEDIUM] CWE-200 CVE-2022-29901: Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass
Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass their retpoline mitigation in the kernel to leak arbitrary data. An attacker with unprivileged user access can hijack return instructions to achieve arbitrary speculative code execution under certain microarchitecture-dependent conditions.
nvd
CVE-2022-2048P3HIGHCVSS 7.5v10.0v11.02022-07-07
CVE-2022-2048 [HIGH] CWE-410 CVE-2022-2048: In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the erro
In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug that can wind up not properly cleaning up the active connections and associated resources. This can lead to a Denial of Service scenario where there are no enough resources left to process good requests.
nvd
CVE-2015-2735P3CRITICALCVSS 9.3v8.02015-07-06
CVE-2015-2735 [CRITICAL] CWE-17 CVE-2015-2735: nsZipArchive.cpp in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1,
nsZipArchive.cpp in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 accesses unintended memory locations, which allows remote attackers to have an unspecified impact via a crafted ZIP archive.
nvd
CVE-2022-27380P3HIGHCVSS 7.5v10.02022-04-12
CVE-2022-27380 [HIGH] CWE-89 CVE-2022-27380: An issue in the component my_decimal::operator= of MariaDB Server v10.6.3 and below was discovered t
An issue in the component my_decimal::operator= of MariaDB Server v10.6.3 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.
nvd
CVE-2022-27379P3HIGHCVSS 7.5v10.02022-04-12
CVE-2022-27379 [HIGH] CWE-89 CVE-2022-27379: An issue in the component Arg_comparator::compare_real_fixed of MariaDB Server v10.6.2 and below was
An issue in the component Arg_comparator::compare_real_fixed of MariaDB Server v10.6.2 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.
nvd
CVE-2022-43680P3HIGHCVSS 7.5v10.0v11.02022-10-24
CVE-2022-43680 [HIGH] CWE-416 CVE-2022-43680: In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD
In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.
nvd
CVE-2018-7553P3CRITICALCVSS 9.8v7.02018-02-28
CVE-2018-7553 [CRITICAL] CWE-787 CVE-2018-7553: There is a heap-based buffer overflow in the pcxLoadRaster function of in_pcx.cpp in sam2p 0.49.4. A
There is a heap-based buffer overflow in the pcxLoadRaster function of in_pcx.cpp in sam2p 0.49.4. A crafted input will lead to a denial of service or possibly unspecified other impact.
nvd
CVE-2022-23947P3HIGHCVSS 7.8v9.0v10.0+1 more2022-02-04
CVE-2022-23947 [HIGH] CWE-121 CVE-2022-23947: A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon DCodeNum
A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon DCodeNumber parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or excellon file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
nvd
CVE-2022-27384P3HIGHCVSS 7.5v10.02022-04-12
CVE-2022-27384 [HIGH] CWE-89 CVE-2022-27384: An issue in the component Item_subselect::init_expr_cache_tracker of MariaDB Server v10.6 and below
An issue in the component Item_subselect::init_expr_cache_tracker of MariaDB Server v10.6 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.
nvd
CVE-2018-0734P3MEDIUMCVSS 5.9v9.02018-10-30
CVE-2018-0734 [MEDIUM] CWE-327 CVE-2018-0734: The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack.
The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.1a (Affected 1.1.1). Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.0.2q (Affected 1.0.2-1.0.2p).
nvd
CVE-2018-7053P3CRITICALCVSS 9.8v9.02018-02-15
CVE-2018-7053 [CRITICAL] CWE-416 CVE-2018-7053: An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a use-after-free when
An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a use-after-free when SASL messages are received in an unexpected order.
nvd
CVE-2021-4207P3HIGHCVSS 8.2v10.0v11.02022-04-29
CVE-2021-4207 [HIGH] CWE-362 CVE-2021-4207: A flaw was found in the QXL display device emulation in QEMU. A double fetch of guest controlled val
A flaw was found in the QXL display device emulation in QEMU. A double fetch of guest controlled values `cursor->header.width` and `cursor->header.height` can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. A malicious privileged guest user could use this flaw to crash the QEMU process on the host or
nvd
CVE-2017-7526P3MEDIUMCVSS 6.8v8.0v9.02018-07-26
CVE-2017-7526 [MEDIUM] CWE-200 CVE-2017-7526: libgcrypt before version 1.7.8 is vulnerable to a cache side-channel attack resulting into a complet
libgcrypt before version 1.7.8 is vulnerable to a cache side-channel attack resulting into a complete break of RSA-1024 while using the left-to-right method for computing the sliding-window expansion. The same attack is believed to work on RSA-2048 with moderately more computation. This side-channel requires that attacker can run arbitrary software on
nvd
CVE-2019-25041P3HIGHCVSS 7.5v9.02021-04-27
CVE-2019-25041 [HIGH] CWE-617 CVE-2019-25041: Unbound before 1.9.5 allows an assertion failure via a compressed name in dname_pkt_copy. NOTE: The
Unbound before 1.9.5 allows an assertion failure via a compressed name in dname_pkt_copy. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
nvd
CVE-2021-32918P3HIGHCVSS 7.5v10.02021-05-13
CVE-2021-32918 [HIGH] CWE-400 CVE-2021-32918: An issue was discovered in Prosody before 0.11.9. Default settings are susceptible to remote unauthe
An issue was discovered in Prosody before 0.11.9. Default settings are susceptible to remote unauthenticated denial-of-service (DoS) attacks via memory exhaustion when running under Lua 5.2 or Lua 5.3.
nvd