Debian Linux vulnerabilities
9,954 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358
Vulnerabilities
Page 204 of 498
CVE-2023-5724P3HIGHCVSS 7.5v10.0v11.02023-10-25
CVE-2023-5724 [HIGH] CWE-400 CVE-2023-5724: Drivers are not always robust to extremely large draw calls and in some cases this scenario could ha
Drivers are not always robust to extremely large draw calls and in some cases this scenario could have led to a crash. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
nvd
CVE-2020-35475P3HIGHCVSS 7.5v10.02020-12-18
CVE-2020-35475 [HIGH] CWE-79 CVE-2020-35475: In MediaWiki before 1.35.1, the messages userrights-expiry-current and userrights-expiry-none can co
In MediaWiki before 1.35.1, the messages userrights-expiry-current and userrights-expiry-none can contain raw HTML. XSS can happen when a user visits Special:UserRights but does not have rights to change all userrights, and the table on the left side has unchangeable groups in it. (The right column with the changeable groups is not affected and is esca
nvd
CVE-2007-2583P4MEDIUMCVSS 4.0PoCv3.1v4.02007-05-10
CVE-2007-2583 [MEDIUM] CVE-2007-2583: The in_decimal::set function in item_cmpfunc.cc in MySQL before 5.0.40, and 5.1 before 5.1.18-beta,
The in_decimal::set function in item_cmpfunc.cc in MySQL before 5.0.40, and 5.1 before 5.1.18-beta, allows context-dependent attackers to cause a denial of service (crash) via a crafted IF clause that results in a divide-by-zero error and a NULL pointer dereference.
nvd
CVE-2022-45934P3HIGHCVSS 7.8v11.02022-11-27
CVE-2022-45934 [HIGH] CWE-190 CVE-2022-45934: An issue was discovered in the Linux kernel through 6.0.10. l2cap_config_req in net/bluetooth/l2cap_
An issue was discovered in the Linux kernel through 6.0.10. l2cap_config_req in net/bluetooth/l2cap_core.c has an integer wraparound via L2CAP_CONF_REQ packets.
nvd
CVE-2016-9774P3HIGHCVSS 7.8v7.0v8.02017-03-23
CVE-2016-9774 [HIGH] CWE-59 CVE-2016-9774: The postinst script in the tomcat6 package before 6.0.45+dfsg-1~deb7u4 on Debian wheezy, before 6.0.
The postinst script in the tomcat6 package before 6.0.45+dfsg-1~deb7u4 on Debian wheezy, before 6.0.35-1ubuntu3.9 on Ubuntu 12.04 LTS and on Ubuntu 14.04 LTS; the tomcat7 package before 7.0.28-4+deb7u8 on Debian wheezy, before 7.0.56-3+deb8u6 on Debian jessie, before 7.0.52-1ubuntu0.8 on Ubuntu 14.04 LTS, and on Ubuntu 12.04 LTS, 16.04 LTS, and 16.10; an
nvd
CVE-2019-11487P3HIGHCVSS 7.8v8.02019-04-23
CVE-2019-11487 [HIGH] CWE-416 CVE-2019-11487: The Linux kernel before 5.1-rc5 allows page->_refcount reference count overflow, with resultant use-
The Linux kernel before 5.1-rc5 allows page->_refcount reference count overflow, with resultant use-after-free issues, if about 140 GiB of RAM exists. This is related to fs/fuse/dev.c, fs/pipe.c, fs/splice.c, include/linux/mm.h, include/linux/pipe_fs_i.h, kernel/trace/trace.c, mm/gup.c, and mm/hugetlb.c. It can occur with FUSE requests.
nvd
CVE-2016-5126P3HIGHCVSS 7.8v8.02016-06-01
CVE-2016-5126 [HIGH] CWE-787 CVE-2016-5126: Heap-based buffer overflow in the iscsi_aio_ioctl function in block/iscsi.c in QEMU allows local gue
Heap-based buffer overflow in the iscsi_aio_ioctl function in block/iscsi.c in QEMU allows local guest OS users to cause a denial of service (QEMU process crash) or possibly execute arbitrary code via a crafted iSCSI asynchronous I/O ioctl call.
nvd
CVE-2017-1000363P3HIGHCVSS 7.8v8.02017-07-17
CVE-2017-1000363 [HIGH] CVE-2017-1000363: Linux drivers/char/lp.c Out-of-Bounds Write. Due to a missing bounds check, and the fact that parpor
Linux drivers/char/lp.c Out-of-Bounds Write. Due to a missing bounds check, and the fact that parport_ptr integer is static, a 'secure boot' kernel command line adversary (can happen due to bootloader vulns, e.g. Google Nexus 6's CVE-2016-10277, where due to a vulnerability the adversary has partial control over the command line) can overflow the parport_
nvd
CVE-2014-4344P3HIGHCVSS 7.8v7.02014-08-14
CVE-2014-4344 [HIGH] CWE-476 CVE-2014-4344: The acc_ctx_cont function in the SPNEGO acceptor in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos
The acc_ctx_cont function in the SPNEGO acceptor in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.5.x through 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty continuation token at a certain point during a SPNEGO negotiation.
nvd
CVE-2015-8325P3HIGHCVSS 7.8v7.0v8.02016-05-01
CVE-2015-8325 [HIGH] CWE-264 CVE-2015-8325: The do_setup_env function in session.c in sshd in OpenSSH through 7.2p2, when the UseLogin feature i
The do_setup_env function in session.c in sshd in OpenSSH through 7.2p2, when the UseLogin feature is enabled and PAM is configured to read .pam_environment files in user home directories, allows local users to gain privileges by triggering a crafted environment for the /bin/login program, as demonstrated by an LD_PRELOAD environment variable.
nvd
CVE-2000-0508P4MEDIUMCVSS 5.0PoCv2.1v2.21994-12-19
CVE-2000-0508 [MEDIUM] CVE-2000-0508: rpc.lockd in Red Hat Linux 6.1 and 6.2 allows remote attackers to cause a denial of service via a ma
rpc.lockd in Red Hat Linux 6.1 and 6.2 allows remote attackers to cause a denial of service via a malformed request.
nvd
CVE-2015-7692P3HIGHCVSS 7.5v7.0v8.0+1 more2017-08-07
CVE-2015-7692 [HIGH] CVE-2015-7692: The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote
The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash). NOTE: This vulnerability exists due to an incomplete fix for CVE-2014-9750.
nvd
CVE-2022-38784P3HIGHCVSS 7.8v10.0v11.02022-08-30
CVE-2022-38784 [HIGH] CVE-2022-38784: Poppler prior to and including 22.08.0 contains an integer overflow in the JBIG2 decoder (JBIG2Strea
Poppler prior to and including 22.08.0 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIGStream.cc). Processing a specially crafted PDF file or JBIG2 image could lead to a crash or the execution of arbitrary code. This is similar to the vulnerability described by CVE-2022-38171 in Xpdf.
nvd
CVE-2010-5108P3HIGHCVSS 7.5v8.0v9.0+1 more2019-11-13
CVE-2010-5108 [HIGH] CWE-276 CVE-2010-5108: Trac 0.11.6 does not properly check workflow permissions before modifying a ticket. This can be expl
Trac 0.11.6 does not properly check workflow permissions before modifying a ticket. This can be exploited by an attacker to change the status and resolution of tickets without having proper permissions.
nvd
CVE-2019-25051P3HIGHCVSS 7.8v9.0v10.02021-07-20
CVE-2019-25051 [HIGH] CWE-787 CVE-2019-25051: objstack in GNU Aspell 0.60.8 has a heap-based buffer overflow in acommon::ObjStack::dup_top (called
objstack in GNU Aspell 0.60.8 has a heap-based buffer overflow in acommon::ObjStack::dup_top (called from acommon::StringMap::add and acommon::Config::lookup_list).
nvd
CVE-2019-13164P3HIGHCVSS 7.8v8.0v9.0+1 more2019-07-03
CVE-2019-13164 [HIGH] CVE-2019-13164: qemu-bridge-helper.c in QEMU 3.1 and 4.0.0 does not ensure that a network interface name (obtained f
qemu-bridge-helper.c in QEMU 3.1 and 4.0.0 does not ensure that a network interface name (obtained from bridge.conf or a --br=bridge option) is limited to the IFNAMSIZ size, which can lead to an ACL bypass.
nvd
CVE-2019-14846P3HIGHCVSS 7.8v8.0v9.0+1 more2019-10-08
CVE-2019-14846 [HIGH] CWE-117 CVE-2019-14846: In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-e
In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG level which lead to a disclosure of credentials if a plugin used a library that logged credentials at the DEBUG level. This flaw does not affect Ansible modules, as those are executed in a separate process.
nvd
CVE-2021-46790P3HIGHCVSS 7.8v10.0v11.02022-05-02
CVE-2021-46790 [HIGH] CWE-787 CVE-2021-46790: ntfsck in NTFS-3G through 2021.8.22 has a heap-based buffer overflow involving buffer+512*3-2. NOTE:
ntfsck in NTFS-3G through 2021.8.22 has a heap-based buffer overflow involving buffer+512*3-2. NOTE: the upstream position is that ntfsck is deprecated; however, it is shipped by some Linux distributions.
nvd
CVE-2019-3466P3HIGHCVSS 7.8v9.0v10.02019-11-20
CVE-2019-3466 [HIGH] CWE-269 CVE-2019-3466: The pg_ctlcluster script in postgresql-common in versions prior to 210 didn't drop privileges when c
The pg_ctlcluster script in postgresql-common in versions prior to 210 didn't drop privileges when creating socket/statistics temporary directories, which could result in local privilege escalation.
nvd
CVE-2022-1785P3HIGHCVSS 7.8v10.02022-05-19
CVE-2022-1785 [HIGH] CWE-787 CVE-2022-1785: Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.4977.
Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.4977.
nvd