cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 203 of 498
CVE-2018-5206P3CRITICALCVSS 9.8v9.02018-01-06
CVE-2018-5206 [CRITICAL] CWE-476 CVE-2018-5206: When the channel topic is set without specifying a sender, Irssi before 1.0.6 may dereference a NULL When the channel topic is set without specifying a sender, Irssi before 1.0.6 may dereference a NULL pointer.
nvd
CVE-2022-2509P3HIGHCVSS 7.5v10.0v11.02022-08-01
CVE-2022-2509 [HIGH] CWE-415 CVE-2022-2509: A vulnerability found in gnutls. This security flaw happens because of a double free error occurs du A vulnerability found in gnutls. This security flaw happens because of a double free error occurs during verification of pkcs7 signatures in gnutls_pkcs7_verify function.
nvd
CVE-2020-27823P3HIGHCVSS 7.8v9.0v10.02021-05-13
CVE-2020-27823 [HIGH] CWE-20 CVE-2020-27823: A flaw was found in OpenJPEG’s encoder. This flaw allows an attacker to pass specially crafted x,y o A flaw was found in OpenJPEG’s encoder. This flaw allows an attacker to pass specially crafted x,y offset input to OpenJPEG to use during encoding. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
nvd
CVE-2019-2949P3MEDIUMCVSS 6.8v8.0v9.0+1 more2019-10-16
CVE-2019-2949 [MEDIUM] CVE-2019-2949: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Kerberos). Supp Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Kerberos). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Kerberos to compromise Java SE, Java SE Embedded. While the vulnerabil
nvd
CVE-2021-45844P3HIGHCVSS 7.8v9.0v10.0+1 more2022-01-25
CVE-2021-45844 [HIGH] CWE-78 CVE-2021-45844: Improper sanitization in the invocation of ODA File Converter from FreeCAD 0.19 allows an attacker t Improper sanitization in the invocation of ODA File Converter from FreeCAD 0.19 allows an attacker to inject OS commands via a crafted filename.
nvd
CVE-2022-0583P3HIGHCVSS 7.5v9.02022-02-14
CVE-2022-0583 [HIGH] CWE-787 CVE-2022-0583: Crash in the PVFS protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial o Crash in the PVFS protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file
nvd
CVE-2020-14929P3HIGHCVSS 7.5v8.02020-06-19
CVE-2020-14929 [HIGH] CVE-2020-14929: Alpine before 2.23 silently proceeds to use an insecure connection after a /tls is sent in certain c Alpine before 2.23 silently proceeds to use an insecure connection after a /tls is sent in certain circumstances involving PREAUTH, which is a less secure behavior than the alternative of closing the connection and letting the user decide what they would like to do.
nvd
CVE-2018-18281P3HIGHCVSS 7.8v8.02018-10-30
CVE-2018-18281 [HIGH] CWE-459 CVE-2018-18281: Since Linux kernel version 3.2, the mremap() syscall performs TLB flushes after dropping pagetable l Since Linux kernel version 3.2, the mremap() syscall performs TLB flushes after dropping pagetable locks. If a syscall such as ftruncate() removes entries from the pagetables of a task that is in the middle of mremap(), a stale TLB entry can remain for a short time that permits access to a physical page after it has been released back to the page allo
nvd
CVE-2016-1000342P3HIGHCVSS 7.5v8.02018-06-04
CVE-2016-1000342 [HIGH] CWE-347 CVE-2016-1000342: In the Bouncy Castle JCE Provider version 1.55 and earlier ECDSA does not fully validate ASN.1 encod In the Bouncy Castle JCE Provider version 1.55 and earlier ECDSA does not fully validate ASN.1 encoding of signature on verification. It is possible to inject extra elements in the sequence making up the signature and still have it validate, which in some cases may allow the introduction of 'invisible' data into a signed structure.
nvd
CVE-2022-48560P3HIGHCVSS 7.5v10.02023-08-22
CVE-2022-48560 [HIGH] CWE-416 CVE-2022-48560: A use-after-free exists in Python through 3.9 via heappushpop in heapq. A use-after-free exists in Python through 3.9 via heappushpop in heapq.
nvd
CVE-2019-12098P3HIGHCVSS 7.4v9.02019-05-15
CVE-2019-12098 [HIGH] CWE-295 CVE-2019-12098: In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT PA-PKINIT-KX key exch In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT PA-PKINIT-KX key exchange permits a man-in-the-middle attack. This issue is in krb5_init_creds_step in lib/krb5/init_creds_pw.c.
nvd
CVE-2020-14356P3HIGHCVSS 7.8v9.02020-08-19
CVE-2020-14356 [HIGH] CWE-476 CVE-2020-14356: A flaw null pointer dereference in the Linux kernel cgroupv2 subsystem in versions before 5.7.10 was A flaw null pointer dereference in the Linux kernel cgroupv2 subsystem in versions before 5.7.10 was found in the way when reboot the system. A local user could use this flaw to crash the system or escalate their privileges on the system.
nvd
CVE-2019-14513P3HIGHCVSS 7.5v8.02019-08-01
CVE-2019-14513 [HIGH] CVE-2019-14513: Improper bounds checking in Dnsmasq before 2.76 allows an attacker controlled DNS server to send lar Improper bounds checking in Dnsmasq before 2.76 allows an attacker controlled DNS server to send large DNS packets that result in a read operation beyond the buffer allocated for the packet, a different vulnerability than CVE-2017-14491.
nvd
CVE-2016-10159P3HIGHCVSS 7.5v8.02017-01-24
CVE-2016-10159 [HIGH] CWE-190 CVE-2016-10159: Integer overflow in the phar_parse_pharfile function in ext/phar/phar.c in PHP before 5.6.30 and 7.0 Integer overflow in the phar_parse_pharfile function in ext/phar/phar.c in PHP before 5.6.30 and 7.0.x before 7.0.15 allows remote attackers to cause a denial of service (memory consumption or application crash) via a truncated manifest entry in a PHAR archive.
nvd
CVE-2024-32465P3HIGHCVSS 7.8v10.0v11.02024-05-14
CVE-2024-32465 [HIGH] CVE-2024-32465: Git is a revision control system. The Git project recommends to avoid working in untrusted repositor Git is a revision control system. The Git project recommends to avoid working in untrusted repositories, and instead to clone it first with `git clone --no-local` to obtain a clean copy. Git has specific protections to make that a safe operation even with an untrusted source repository, but vulnerabilities allow those protections to be bypassed. In the contex
nvd
CVE-2022-36440P3HIGHCVSS 7.5v10.0v11.0+1 more2023-04-03
CVE-2022-36440 [HIGH] CWE-617 CVE-2022-36440: A reachable assertion was found in Frrouting frr-bgpd 8.3.0 in the peek_for_as4_capability function. A reachable assertion was found in Frrouting frr-bgpd 8.3.0 in the peek_for_as4_capability function. Attackers can maliciously construct BGP open packets and send them to BGP peers running frr-bgpd, resulting in DoS.
nvd
CVE-2014-7810P3MEDIUMCVSS 5.0v7.02015-06-07
CVE-2014-7810 [MEDIUM] CWE-284 CVE-2014-7810: The Expression Language (EL) implementation in Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.58, a The Expression Language (EL) implementation in Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.58, and 8.x before 8.0.16 does not properly consider the possibility of an accessible interface implemented by an inaccessible class, which allows attackers to bypass a SecurityManager protection mechanism via a web application that leverages use of incorrec
nvd
CVE-2021-45910P3HIGHCVSS 7.8v9.02021-12-28
CVE-2021-45910 [HIGH] CWE-787 CVE-2021-45910: An issue was discovered in gif2apng 1.9. There is a heap-based buffer overflow within the main funct An issue was discovered in gif2apng 1.9. There is a heap-based buffer overflow within the main function. It allows an attacker to write data outside of the allocated buffer. The attacker has control over a part of the address that data is written to, control over the written data, and (to some extent) control over the amount of data that is written.
nvd
CVE-2021-29509P3HIGHCVSS 7.5v10.02021-05-11
CVE-2021-29509 [HIGH] CVE-2021-29509: Puma is a concurrent HTTP 1.1 server for Ruby/Rack applications. The fix for CVE-2019-16770 was inco Puma is a concurrent HTTP 1.1 server for Ruby/Rack applications. The fix for CVE-2019-16770 was incomplete. The original fix only protected existing connections that had already been accepted from having their requests starved by greedy persistent-connections saturating all threads in the same process. However, new connections may still be starved by greedy p
nvd
CVE-2023-2879P3HIGHCVSS 7.5v10.0v12.02023-05-26
CVE-2023-2879 [HIGH] CWE-835 CVE-2023-2879: GDSDB infinite loop in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via pac GDSDB infinite loop in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via packet injection or crafted capture file
nvd
Debian Linux vulnerabilities | cvebase