Debian Linux vulnerabilities
9,954 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358
Vulnerabilities
Page 205 of 498
CVE-2021-35266P3HIGHCVSS 7.8v9.0v10.0+1 more2021-09-07
CVE-2021-35266 [HIGH] CWE-787 CVE-2021-35266: In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS inode pathname is supplied in an NTFS
In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS inode pathname is supplied in an NTFS image a heap buffer overflow can occur resulting in memory disclosure, denial of service and even code execution.
nvd
CVE-2011-2187P3HIGHCVSS 7.8v8.0v9.0+1 more2019-11-27
CVE-2011-2187 [HIGH] CWE-306 CVE-2011-2187: xscreensaver before 5.14 crashes during activation and leaves the screen unlocked when in Blank Only
xscreensaver before 5.14 crashes during activation and leaves the screen unlocked when in Blank Only Mode and when DPMS is disabled, which allows local attackers to access resources without authentication.
nvd
CVE-2017-7482P3HIGHCVSS 7.8v8.0v9.02018-07-30
CVE-2017-7482 [HIGH] CWE-190 CVE-2017-7482: In the Linux kernel before version 4.12, Kerberos 5 tickets decoded when using the RXRPC keys incorr
In the Linux kernel before version 4.12, Kerberos 5 tickets decoded when using the RXRPC keys incorrectly assumes the size of a field. This could lead to the size-remaining variable wrapping and the data pointer going over the end of the buffer. This could possibly lead to memory corruption and possible privilege escalation.
nvd
CVE-2020-1712P3HIGHCVSS 7.8v9.02020-03-31
CVE-2020-1712 [HIGH] CWE-416 CVE-2020-1712: A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous
A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse this flaw to crash systemd services or potentially execute code and elevate their privileges, by sending specially crafted dbus messages.
nvd
CVE-2021-39263P3HIGHCVSS 7.8v9.0v10.0+1 more2021-09-07
CVE-2021-39263 [HIGH] CWE-787 CVE-2021-39263: A crafted NTFS image can trigger a heap-based buffer overflow, caused by an unsanitized attribute in
A crafted NTFS image can trigger a heap-based buffer overflow, caused by an unsanitized attribute in ntfs_get_attribute_value, in NTFS-3G < 2021.8.22.
nvd
CVE-2021-39256P3HIGHCVSS 7.8v9.0v10.0+1 more2021-09-07
CVE-2021-39256 [HIGH] CWE-787 CVE-2021-39256: A crafted NTFS image can cause a heap-based buffer overflow in ntfs_inode_lookup_by_name in NTFS-3G
A crafted NTFS image can cause a heap-based buffer overflow in ntfs_inode_lookup_by_name in NTFS-3G < 2021.8.22.
nvd
CVE-2021-39261P3HIGHCVSS 7.8v9.0v10.0+1 more2021-09-07
CVE-2021-39261 [HIGH] CWE-787 CVE-2021-39261: A crafted NTFS image can cause a heap-based buffer overflow in ntfs_compressed_pwrite in NTFS-3G < 2
A crafted NTFS image can cause a heap-based buffer overflow in ntfs_compressed_pwrite in NTFS-3G < 2021.8.22.
nvd
CVE-2010-2450P3HIGHCVSS 7.5v8.0v9.02019-11-07
CVE-2010-2450 [HIGH] CWE-200 CVE-2010-2450: The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses Ope
The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which is placed in sp-key.pm. It relies on the root umask (default 22) instead of chmoding the resulting file itself, so the generated private key is world readable by default.
nvd
CVE-2019-18389P3HIGHCVSS 7.8v10.02019-12-23
CVE-2019-18389 [HIGH] CWE-787 CVE-2019-18389: A heap-based buffer overflow in the vrend_renderer_transfer_write_iov function in vrend_renderer.c i
A heap-based buffer overflow in the vrend_renderer_transfer_write_iov function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service, or QEMU guest-to-host escape and code execution, via VIRGL_CCMD_RESOURCE_INLINE_WRITE commands.
nvd
CVE-2021-39254P3HIGHCVSS 7.8v9.0v10.0+1 more2021-09-07
CVE-2021-39254 [HIGH] CWE-190 CVE-2021-39254: A crafted NTFS image can cause an integer overflow in memmove, leading to a heap-based buffer overfl
A crafted NTFS image can cause an integer overflow in memmove, leading to a heap-based buffer overflow in the function ntfs_attr_record_resize, in NTFS-3G < 2021.8.22.
nvd
CVE-2020-12653P3HIGHCVSS 7.8v8.0v9.02020-05-05
CVE-2020-12653 [HIGH] CWE-787 CVE-2020-12653: An issue was found in Linux kernel before 5.5.4. The mwifiex_cmd_append_vsie_tlv() function in drive
An issue was found in Linux kernel before 5.5.4. The mwifiex_cmd_append_vsie_tlv() function in drivers/net/wireless/marvell/mwifiex/scan.c allows local users to gain privileges or cause a denial of service because of an incorrect memcpy and buffer overflow, aka CID-b70261a288ea.
nvd
CVE-2019-20373P3HIGHCVSS 7.8v8.0v9.0+1 more2020-01-09
CVE-2019-20373 [HIGH] CVE-2019-20373: LTSP LDM through 2.18.06 allows fat-client root access because the LDM_USERNAME variable may have an
LTSP LDM through 2.18.06 allows fat-client root access because the LDM_USERNAME variable may have an empty value if the user's shell lacks support for Bourne shell syntax. This is related to a run-x-session script.
nvd
CVE-2012-4576P3HIGHCVSS 7.8v8.0v9.0+1 more2019-12-02
CVE-2012-4576 [HIGH] CWE-20 CVE-2012-4576: FreeBSD: Input Validation Flaw allows local users to gain elevated privileges
FreeBSD: Input Validation Flaw allows local users to gain elevated privileges
nvd
CVE-2017-15108P3HIGHCVSS 7.8v9.02018-01-20
CVE-2017-15108 [HIGH] CWE-78 CVE-2017-15108: spice-vdagent up to and including 0.17.0 does not properly escape save directory before passing to s
spice-vdagent up to and including 0.17.0 does not properly escape save directory before passing to shell, allowing local attacker with access to the session the agent runs in to inject arbitrary commands to be executed.
nvd
CVE-2021-39262P3HIGHCVSS 7.8v9.0v10.0+1 more2021-09-07
CVE-2021-39262 [HIGH] CWE-787 CVE-2021-39262: A crafted NTFS image can cause an out-of-bounds access in ntfs_decompress in NTFS-3G < 2021.8.22.
A crafted NTFS image can cause an out-of-bounds access in ntfs_decompress in NTFS-3G < 2021.8.22.
nvd
CVE-2021-39260P3HIGHCVSS 7.8v9.0v10.0+1 more2021-09-07
CVE-2021-39260 [HIGH] CWE-787 CVE-2021-39260: A crafted NTFS image can cause an out-of-bounds access in ntfs_inode_sync_standard_information in NT
A crafted NTFS image can cause an out-of-bounds access in ntfs_inode_sync_standard_information in NTFS-3G < 2021.8.22.
nvd
CVE-2020-25603P3HIGHCVSS 7.8v10.02020-09-23
CVE-2020-25603 [HIGH] CWE-670 CVE-2020-25603: An issue was discovered in Xen through 4.14.x. There are missing memory barriers when accessing/allo
An issue was discovered in Xen through 4.14.x. There are missing memory barriers when accessing/allocating an event channel. Event channels control structures can be accessed lockless as long as the port is considered to be valid. Such a sequence is missing an appropriate memory barrier (e.g., smp_*mb()) to prevent both the compiler and CPU from re-or
nvd
CVE-2019-9924P3HIGHCVSS 7.8v8.02019-03-22
CVE-2019-9924 [HIGH] CWE-862 CVE-2019-9924: rbash in Bash before 4.4-beta2 did not prevent the shell user from modifying BASH_CMDS, thus allowin
rbash in Bash before 4.4-beta2 did not prevent the shell user from modifying BASH_CMDS, thus allowing the user to execute any command with the permissions of the shell.
nvd
CVE-2018-16877P3HIGHCVSS 7.8v9.02019-04-18
CVE-2018-16877 [HIGH] CWE-287 CVE-2018-16877: A flaw was found in the way pacemaker's client-server authentication was implemented in versions up
A flaw was found in the way pacemaker's client-server authentication was implemented in versions up to and including 2.0.0. A local attacker could use this flaw, and combine it with other IPC weaknesses, to achieve local privilege escalation.
nvd
CVE-2023-31137P3HIGHCVSS 7.5v10.0v11.02023-05-09
CVE-2023-31137 [HIGH] CWE-191 CVE-2023-31137: MaraDNS is open-source software that implements the Domain Name System (DNS). In version 3.5.0024 an
MaraDNS is open-source software that implements the Domain Name System (DNS). In version 3.5.0024 and prior, a remotely exploitable integer underflow vulnerability in the DNS packet decompression function allows an attacker to cause a Denial of Service by triggering an abnormal program termination.
The vulnerability exists in the `decomp_get_rddata`
nvd