Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 19 of 498
CVE-2025-68615P2CRITICALCVSS 9.8v11.02025-12-23
CVE-2025-68615 [CRITICAL] CWE-119 CVE-2025-68615: net-snmp is a SNMP application library, tools and daemon. Prior to versions 5.9.5 and 5.10.pre2, a s
net-snmp is a SNMP application library, tools and daemon. Prior to versions 5.9.5 and 5.10.pre2, a specially crafted packet to an net-snmp snmptrapd daemon can cause a buffer overflow and the daemon to crash. This issue has been patched in versions 5.9.5 and 5.10.pre2.
nvd
CVE-2022-33980P2CRITICALCVSS 9.8v11.02022-07-06
CVE-2022-33980 [CRITICAL] CVE-2022-33980: Apache Commons Configuration performs variable interpolation, allowing properties to be dynamically
Apache Commons Configuration performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.configuration2.interpol.Lookup that performs the interpolation. Starting with version 2.4 and continuing thr
nvd
CVE-2021-21342P2CRITICALCVSS 9.1v9.0v10.0+1 more2021-03-23
CVE-2021-21342 [CRITICAL] CWE-502 CVE-2021-21342: XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time contains type information to recreate the formerly written objects. XStream creates therefore new instances based on these type information. An attacker can manipulate the
nvd
CVE-2020-8625P2HIGHCVSS 8.1v9.0v10.02021-02-17
CVE-2020-8625 [HIGH] CWE-120 CVE-2020-8625: BIND servers are vulnerable if they are running an affected version and are configured to use GSS-TS
BIND servers are vulnerable if they are running an affected version and are configured to use GSS-TSIG features. In a configuration which uses BIND's default settings the vulnerable code path is not exposed, but a server can be rendered vulnerable by explicitly setting valid values for the tkey-gssapi-keytab or tkey-gssapi-credentialconfiguration option
nvd
CVE-2008-1721P3HIGHCVSS 7.5PoCv4.02008-04-10
CVE-2008-1721 [HIGH] CWE-681 CVE-2008-1721: Integer signedness error in the zlib extension module in Python 2.5.2 and earlier allows remote atta
Integer signedness error in the zlib extension module in Python 2.5.2 and earlier allows remote attackers to execute arbitrary code via a negative signed integer, which triggers insufficient memory allocation and a buffer overflow.
nvd
CVE-2016-5118P2CRITICALCVSS 9.8v8.02016-06-10
CVE-2016-5118 [CRITICAL] CVE-2016-5118: The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attack
The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename.
nvd
CVE-2022-31626P2HIGHCVSS 8.8v10.0v11.02022-06-16
CVE-2022-31626 [HIGH] CWE-120 CVE-2022-31626: In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when pdo_mysql extens
In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when pdo_mysql extension with mysqlnd driver, if the third party is allowed to supply host to connect to and the password for the connection, password of excessive length can trigger a buffer overflow in PHP, which can lead to a remote code execution vulnerability.
nvd
CVE-2020-25682P2HIGHCVSS 8.1v9.0v10.02021-01-20
CVE-2020-25682 [HIGH] CWE-122 CVE-2020-25682: A flaw was found in dnsmasq before 2.83. A buffer overflow vulnerability was discovered in the way d
A flaw was found in dnsmasq before 2.83. A buffer overflow vulnerability was discovered in the way dnsmasq extract names from DNS packets before validating them with DNSSEC data. An attacker on the network, who can create valid DNS replies, could use this flaw to cause an overflow with arbitrary data in a heap-allocated memory, possibly executing code
nvd
CVE-2013-2227P3HIGHCVSS 7.5PoCv8.02019-11-01
CVE-2013-2227 [HIGH] CWE-20 CVE-2013-2227: GLPI 0.83.7 has Local File Inclusion in common.tabs.php.
GLPI 0.83.7 has Local File Inclusion in common.tabs.php.
nvd
CVE-2016-2510P2HIGHCVSS 8.1v7.0v8.02016-04-07
CVE-2016-2510 [HIGH] CWE-19 CVE-2016-2510: BeanShell (bsh) before 2.0b6, when included on the classpath by an application that uses Java serial
BeanShell (bsh) before 2.0b6, when included on the classpath by an application that uses Java serialization or XStream, allows remote attackers to execute arbitrary code via crafted serialized data, related to XThis.Handler.
nvd
CVE-2014-5119P3HIGHCVSS 7.5PoCv7.02014-08-29
CVE-2014-5119 [HIGH] CWE-189 CVE-2014-5119: Off-by-one error in the __gconv_translit_find function in gconv_trans.c in GNU C Library (aka glibc)
Off-by-one error in the __gconv_translit_find function in gconv_trans.c in GNU C Library (aka glibc) allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via vectors related to the CHARSET environment variable and gconv transliteration modules.
nvd
CVE-2018-10900P2HIGHCVSS 7.8PoCv8.0v9.02018-07-26
CVE-2018-10900 [HIGH] CWE-78 CVE-2018-10900: Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privil
Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attack. A new line character can be used to inject a Password helper parameter into the configuration data passed to VPNC, allowing an attacker to execute arbitrary commands as root.
nvd
CVE-2024-31309P2HIGHCVSS 7.5v10.02024-04-10
CVE-2024-31309 [HIGH] CWE-20 CVE-2024-31309: HTTP/2 CONTINUATION DoS attack can cause Apache Traffic Server to consume more resources on the serv
HTTP/2 CONTINUATION DoS attack can cause Apache Traffic Server to consume more resources on the server. Version from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.3 are affected.
Users can set a new setting (proxy.config.http2.max_continuation_frames_per_minute) to limit the number of CONTINUATION frames per minute. ATS does have a fixed amount of memor
nvd
CVE-2020-25695P2HIGHCVSS 8.8v9.02020-11-16
CVE-2020-25695 [HIGH] CWE-89 CVE-2020-25695: A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before
A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. An attacker having permission to create non-temporary objects in at least one schema can execute arbitrary SQL functions under the identity of a superuser. The highest threat from this vulnerability is to data confidentiality a
nvd
CVE-2019-17570P2CRITICALCVSS 9.8v8.0v9.0+1 more2020-01-23
CVE-2019-17570 [CRITICAL] CWE-502 CVE-2019-17570: An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResul
An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) library. A malicious XML-RPC server could target a XML-RPC client causing it to execute arbitrary code. Apache XML-RPC is no longer maintained and this issue will not be fixed.
nvd
CVE-2018-17961P3HIGHCVSS 8.6PoCv8.0v9.02018-10-15
CVE-2018-17961 [HIGH] CVE-2018-17961: Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via v
Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving errorhandler setup. NOTE: this issue exists because of an incomplete fix for CVE-2018-17183.
nvd
CVE-2018-7286P3MEDIUMCVSS 6.5PoCv9.02018-02-22
CVE-2018-7286 [MEDIUM] CVE-2018-7286: An issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, a
An issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert2. res_pjsip allows remote authenticated users to crash Asterisk (segmentation fault) by sending a number of SIP INVITE messages on a TCP or TLS connection and then suddenly closing the connection.
nvd
CVE-2011-2189P3HIGHCVSS 7.5PoCv5.0v6.0+1 more2011-10-10
CVE-2011-2189 [HIGH] CWE-400 CVE-2011-2189: net/core/net_namespace.c in the Linux kernel 2.6.32 and earlier does not properly handle a high rate
net/core/net_namespace.c in the Linux kernel 2.6.32 and earlier does not properly handle a high rate of creation and cleanup of network namespaces, which makes it easier for remote attackers to cause a denial of service (memory consumption) via requests to a daemon that requires a separate namespace per connection, as demonstrated by vsftpd.
nvd
CVE-2014-3566P3LOWCVSS 3.4PoCv7.0v8.02014-10-15
CVE-2014-3566 [LOW] CWE-310 CVE-2014-3566: The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CB
The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.
nvd
CVE-2011-3596P3HIGHCVSS 7.5PoCv8.0v9.0+1 more2019-11-26
CVE-2011-3596 [HIGH] CWE-617 CVE-2011-3596: Polipo before 1.0.4.1 suffers from a DoD vulnerability via specially-crafted HTTP POST / PUT request
Polipo before 1.0.4.1 suffers from a DoD vulnerability via specially-crafted HTTP POST / PUT request.
nvd