cbcvebase.

Debian Linux vulnerabilities

9,953 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358

Vulnerabilities

Page 188 of 498
CVE-2022-24763P3HIGHCVSS 7.5v9.0v10.0+1 more2022-03-30
CVE-2022-24763 [HIGH] CWE-835 CVE-2022-24763: PJSIP is a free and open source multimedia communication library written in the C language. Versions PJSIP is a free and open source multimedia communication library written in the C language. Versions 2.12 and prior contain a denial-of-service vulnerability that affects PJSIP users that consume PJSIP's XML parsing in their apps. Users are advised to update. There are no known workarounds.
nvd
CVE-2018-16948P3HIGHCVSS 7.5v8.0v9.02018-09-12
CVE-2018-16948 [HIGH] CWE-200 CVE-2018-16948: An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. Several RPC server routines An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. Several RPC server routines did not fully initialize their output variables before returning, leaking memory contents from both the stack and the heap. Because the OpenAFS cache manager functions as an Rx server for the AFSCB service, clients are also susceptible to information l
nvd
CVE-2019-25040P3HIGHCVSS 7.5v9.02021-04-27
CVE-2019-25040 [HIGH] CWE-835 CVE-2019-25040: Unbound before 1.9.5 allows an infinite loop via a compressed name in dname_pkt_copy. NOTE: The vend Unbound before 1.9.5 allows an infinite loop via a compressed name in dname_pkt_copy. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
nvd
CVE-2021-35063P3HIGHCVSS 7.5v9.0v10.02021-07-22
CVE-2021-35063 [HIGH] CVE-2021-35063: Suricata before 5.0.7 and 6.x before 6.0.3 has a "critical evasion." Suricata before 5.0.7 and 6.x before 6.0.3 has a "critical evasion."
nvd
CVE-2020-36332P3HIGHCVSS 7.5v10.02021-05-21
CVE-2020-36332 [HIGH] CWE-20 CVE-2020-36332: A flaw was found in libwebp in versions before 1.0.1. When reading a file libwebp allocates an exces A flaw was found in libwebp in versions before 1.0.1. When reading a file libwebp allocates an excessive amount of memory. The highest threat from this vulnerability is to the service availability.
nvd
CVE-2021-20273P3HIGHCVSS 7.5v9.02021-03-09
CVE-2021-20273 [HIGH] CWE-20 CVE-2021-20273: A flaw was found in privoxy before 3.0.32. A crash can occur via a crafted CGI request if Privoxy is A flaw was found in privoxy before 3.0.32. A crash can occur via a crafted CGI request if Privoxy is toggled off.
nvd
CVE-2016-2806P3HIGHCVSS 8.8v8.02016-04-30
CVE-2016-2806 [HIGH] CWE-119 CVE-2016-2806: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 46.0 and Firefo Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 46.0 and Firefox ESR 45.x before 45.1 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2016-1902P3HIGHCVSS 7.5v8.02016-06-01
CVE-2016-1902 [HIGH] CWE-310 CVE-2016-1902: The nextBytes function in the SecureRandom class in Symfony before 2.3.37, 2.6.x before 2.6.13, and The nextBytes function in the SecureRandom class in Symfony before 2.3.37, 2.6.x before 2.6.13, and 2.7.x before 2.7.9 does not properly generate random numbers when used with PHP 5.x without the paragonie/random_compat library and the openssl_random_pseudo_bytes function fails, which makes it easier for attackers to defeat cryptographic protection mecha
nvd
CVE-2012-5577P3HIGHCVSS 7.5v7.02019-10-28
CVE-2012-5577 [HIGH] CWE-276 CVE-2012-5577: Python keyring lib before 0.10 created keyring files with world-readable permissions. Python keyring lib before 0.10 created keyring files with world-readable permissions.
nvd
CVE-2020-4031P3HIGHCVSS 7.5v10.02020-06-22
CVE-2020-4031 [HIGH] CWE-416 CVE-2020-4031: In FreeRDP before version 2.1.2, there is a use-after-free in gdi_SelectObject. All FreeRDP clients In FreeRDP before version 2.1.2, there is a use-after-free in gdi_SelectObject. All FreeRDP clients using compatibility mode with /relax-order-checks are affected. This is fixed in version 2.1.2.
nvd
CVE-2018-20721P3CRITICALCVSS 9.8v8.0v9.02019-01-16
CVE-2018-20721 [CRITICAL] CWE-125 CVE-2018-20721: URI_FUNC() in UriParse.c in uriparser before 0.9.1 has an out-of-bounds read (in uriParse*Ex* functi URI_FUNC() in UriParse.c in uriparser before 0.9.1 has an out-of-bounds read (in uriParse*Ex* functions) for an incomplete URI with an IPv6 address containing an embedded IPv4 address, such as a "//[::44.1" address.
nvd
CVE-2017-5386P3HIGHCVSS 7.3v8.02018-06-11
CVE-2017-5386 [HIGH] CVE-2017-5386: WebExtension scripts can use the "data:" protocol to affect pages loaded by other web extensions usi WebExtension scripts can use the "data:" protocol to affect pages loaded by other web extensions using this protocol, leading to potential data disclosure or privilege escalation in affected extensions. This vulnerability affects Firefox ESR < 45.7 and Firefox < 51.
nvd
CVE-2020-3811P3HIGHCVSS 7.5v9.0v10.02020-05-26
CVE-2020-3811 [HIGH] CWE-665 CVE-2020-3811: qmail-verify as used in netqmail 1.06 is prone to a mail-address verification bypass vulnerability. qmail-verify as used in netqmail 1.06 is prone to a mail-address verification bypass vulnerability.
nvd
CVE-2022-39028P3HIGHCVSS 7.5v10.02022-08-30
CVE-2022-39028 [HIGH] CWE-476 CVE-2022-39028: telnetd in GNU Inetutils through 2.3, MIT krb5-appl through 1.0.3, and derivative works has a NULL p telnetd in GNU Inetutils through 2.3, MIT krb5-appl through 1.0.3, and derivative works has a NULL pointer dereference via 0xff 0xf7 or 0xff 0xf8. In a typical installation, the telnetd application would crash but the telnet service would remain available through inetd. However, if the telnetd application has many crashes within a short time interval,
nvd
CVE-2016-0753P3MEDIUMCVSS 5.3v8.02016-02-16
CVE-2016-0753 [MEDIUM] CVE-2016-0753: Active Model in Ruby on Rails 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta Active Model in Ruby on Rails 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 supports the use of instance-level writers for class accessors, which allows remote attackers to bypass intended validation steps via crafted parameters.
nvd
CVE-2016-2147P3HIGHCVSS 7.5v8.0v9.02017-02-09
CVE-2016-2147 [HIGH] CWE-190 CVE-2016-2147: Integer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to cau Integer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to cause a denial of service (crash) via a malformed RFC1035-encoded domain name, which triggers an out-of-bounds heap write.
nvd
CVE-2022-40617P3HIGHCVSS 7.5v10.0v11.02022-10-31
CVE-2022-40617 [HIGH] CWE-400 CVE-2022-40617: strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugi strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and intermediate CA) certificate that contains a CRL/OCSP URL that points to a server (under the attacker's control) that doesn't properly respond but (for example) just does nothing after the initial TCP handshake, or
nvd
CVE-2019-5108P3MEDIUMCVSS 6.5v8.0v9.02019-12-23
CVE-2019-5108 [MEDIUM] CWE-440 CVE-2019-5108: An exploitable denial-of-service vulnerability exists in the Linux kernel prior to mainline 5.3. An An exploitable denial-of-service vulnerability exists in the Linux kernel prior to mainline 5.3. An attacker could exploit this vulnerability by triggering AP to send IAPP location updates for stations before the required authentication process has completed. This could lead to different denial-of-service scenarios, either by causing CAM table attacks,
nvd
CVE-2020-25708P3HIGHCVSS 7.5v10.02020-11-27
CVE-2020-25708 [HIGH] CWE-369 CVE-2020-25708: A divide by zero issue was found to occur in libvncserver-0.9.12. A malicious client could use this A divide by zero issue was found to occur in libvncserver-0.9.12. A malicious client could use this flaw to send a specially crafted message that, when processed by the VNC server, would lead to a floating point exception, resulting in a denial of service.
nvd
CVE-2016-5178P3CRITICALCVSS 9.8v8.02017-05-23
CVE-2016-5178 [CRITICAL] CWE-20 CVE-2016-5178: Multiple unspecified vulnerabilities in Google Chrome before 53.0.2785.143 allow remote attackers to Multiple unspecified vulnerabilities in Google Chrome before 53.0.2785.143 allow remote attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
Debian Linux vulnerabilities | cvebase