Debian Linux vulnerabilities
9,954 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358
Vulnerabilities
Page 202 of 498
CVE-2018-14363P3HIGHCVSS 7.5v8.0v9.02018-07-17
CVE-2018-14363 [HIGH] CWE-22 CVE-2018-14363: An issue was discovered in NeoMutt before 2018-07-16. newsrc.c does not properly restrict '/' charac
An issue was discovered in NeoMutt before 2018-07-16. newsrc.c does not properly restrict '/' characters that may have unsafe interaction with cache pathnames.
nvd
CVE-2018-3064P3HIGHCVSS 7.1v8.0v9.02018-07-18
CVE-2018-3064 [HIGH] CVE-2018-3064: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versio
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.6.40 and prior, 5.7.22 and prior and 8.0.11 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can r
nvd
CVE-2022-27381P3HIGHCVSS 7.5v10.02022-04-12
CVE-2022-27381 [HIGH] CWE-89 CVE-2022-27381: An issue in the component Field::set_default of MariaDB Server v10.6 and below was discovered to all
An issue in the component Field::set_default of MariaDB Server v10.6 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.
nvd
CVE-2019-19583P3HIGHCVSS 7.5v9.0v10.02019-12-11
CVE-2019-19583 [HIGH] CVE-2019-19583: An issue was discovered in Xen through 4.12.x allowing x86 HVM/PVH guest OS users to cause a denial
An issue was discovered in Xen through 4.12.x allowing x86 HVM/PVH guest OS users to cause a denial of service (guest OS crash) because VMX VMEntry checks mishandle a certain case. Please see XSA-260 for background on the MovSS shadow. Please see XSA-156 for background on the need for #DB interception. The VMX VMEntry checks do not like the exact combination o
nvd
CVE-2018-16472P3HIGHCVSS 7.5v10.02018-11-06
CVE-2018-16472 [HIGH] CWE-400 CVE-2018-16472: A prototype pollution attack in cached-path-relative versions <=1.0.1 allows an attacker to inject p
A prototype pollution attack in cached-path-relative versions <=1.0.1 allows an attacker to inject properties on Object.prototype which are then inherited by all the JS objects through the prototype chain causing a DoS attack.
nvd
CVE-2019-14496P3HIGHCVSS 7.8v8.0v9.02019-08-01
CVE-2019-14496 [HIGH] CWE-787 CVE-2019-14496: LoaderXM::load in LoaderXM.cpp in milkyplay in MilkyTracker 1.02.00 has a stack-based buffer overflo
LoaderXM::load in LoaderXM.cpp in milkyplay in MilkyTracker 1.02.00 has a stack-based buffer overflow.
nvd
CVE-2008-5021P3CRITICALCVSS 9.3v4.02008-11-13
CVE-2008-5021 [CRITICAL] CWE-362 CVE-2008-5021: nsFrameManager in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.
nsFrameManager in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by modifying properties of a file input element while it is still being initialized, then using the blur method to a
nvd
CVE-2020-27813P3HIGHCVSS 7.5v9.02020-12-02
CVE-2020-27813 [HIGH] CWE-190 CVE-2020-27813: An integer overflow vulnerability exists with the length of websocket frames received via a websocke
An integer overflow vulnerability exists with the length of websocket frames received via a websocket connection. An attacker would use this flaw to cause a denial of service attack on an HTTP Server allowing websocket connections.
nvd
CVE-2017-14120P3HIGHCVSS 7.5v9.02017-09-03
CVE-2017-14120 [HIGH] CWE-22 CVE-2017-14120: unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a directory traversal vulnerability for RAR v
unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a directory traversal vulnerability for RAR v2 archives: pathnames of the form ../[filename] are unpacked into the upper directory.
nvd
CVE-2021-20272P3HIGHCVSS 7.5v9.02021-03-09
CVE-2021-20272 [HIGH] CWE-617 CVE-2021-20272: A flaw was found in privoxy before 3.0.32. An assertion failure could be triggered with a crafted CG
A flaw was found in privoxy before 3.0.32. An assertion failure could be triggered with a crafted CGI request leading to server crash.
nvd
CVE-2018-16841P3MEDIUMCVSS 6.5v9.02018-11-28
CVE-2018-16841 [MEDIUM] CWE-416 CVE-2018-16841: Samba from version 4.3.0 and before versions 4.7.12, 4.8.7 and 4.9.3 are vulnerable to a denial of s
Samba from version 4.3.0 and before versions 4.7.12, 4.8.7 and 4.9.3 are vulnerable to a denial of service. When configured to accept smart-card authentication, Samba's KDC will call talloc_free() twice on the same memory if the principal in a validly signed certificate does not match the principal in the AS-REQ. This is only possible after authenti
nvd
CVE-2018-8037P3MEDIUMCVSS 5.9v9.02018-08-02
CVE-2018-8037 [MEDIUM] CWE-362 CVE-2018-8037: If an async request was completed by the application at the same time as the container triggered the
If an async request was completed by the application at the same time as the container triggered the async timeout, a race condition existed that could result in a user seeing a response intended for a different user. An additional issue was present in the NIO and NIO2 connectors that did not correctly track the closure of the connection when an async
nvd
CVE-2016-10746P3HIGHCVSS 7.5v8.02019-04-18
CVE-2016-10746 [HIGH] CWE-254 CVE-2016-10746: libvirt-domain.c in libvirt before 1.3.1 supports virDomainGetTime API calls by guest agents with an
libvirt-domain.c in libvirt before 1.3.1 supports virDomainGetTime API calls by guest agents with an RO connection, even though an RW connection was supposed to be required, a different vulnerability than CVE-2019-3886.
nvd
CVE-2019-12474P3HIGHCVSS 7.5v9.02019-07-10
CVE-2019-12474 [HIGH] CVE-2019-12474: Wikimedia MediaWiki 1.23.0 through 1.32.1 has an information leak. Privileged API responses that inc
Wikimedia MediaWiki 1.23.0 through 1.32.1 has an information leak. Privileged API responses that include whether a recent change has been patrolled may be cached publicly. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
nvd
CVE-2022-0586P3HIGHCVSS 7.5v9.02022-02-14
CVE-2022-0586 [HIGH] CWE-835 CVE-2022-0586: Infinite loop in RTMPT protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows den
Infinite loop in RTMPT protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file
nvd
CVE-2020-8177P3HIGHCVSS 7.8v10.02020-12-14
CVE-2020-8177 [HIGH] CWE-99 CVE-2020-8177: curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for files and other resour
curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for files and other resources that can lead too overwriting a local file when the -J flag is used.
nvd
CVE-2022-29536P3HIGHCVSS 7.5v10.0v11.02022-04-20
CVE-2022-29536 [HIGH] CWE-787 CVE-2022-29536: In GNOME Epiphany before 41.4 and 42.x before 42.2, an HTML document can trigger a client buffer ove
In GNOME Epiphany before 41.4 and 42.x before 42.2, an HTML document can trigger a client buffer overflow (in ephy_string_shorten in the UI process) via a long page title. The issue occurs because the number of bytes for a UTF-8 ellipsis character is not properly considered.
nvd
CVE-2020-36658P3HIGHCVSS 8.1v10.02023-01-27
CVE-2020-36658 [HIGH] CVE-2020-36658: In Apache::Session::LDAP before 0.5, validity of the X.509 certificate is not checked by default whe
In Apache::Session::LDAP before 0.5, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used. NOTE: this can, for example, be fixed in conjunction with the CVE-2020-16093 fix.
nvd
CVE-2020-36659P3HIGHCVSS 8.1v10.02023-01-27
CVE-2020-36659 [HIGH] CVE-2020-36659: In Apache::Session::Browseable before 1.3.6, validity of the X.509 certificate is not checked by def
In Apache::Session::Browseable before 1.3.6, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used. NOTE: this can, for example, be fixed in conjunction with the CVE-2020-16093 fix.
nvd
CVE-2010-4654P3HIGHCVSS 7.8v8.0v9.0+1 more2019-11-13
CVE-2010-4654 [HIGH] CWE-74 CVE-2010-4654: poppler before 0.16.3 has malformed commands that may cause corruption of the internal stack.
poppler before 0.16.3 has malformed commands that may cause corruption of the internal stack.
nvd