cbcvebase.

Debian Linux vulnerabilities

9,953 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358

Vulnerabilities

Page 21 of 498
CVE-2018-19627P3HIGHCVSS 7.5PoCv9.02018-11-29
CVE-2018-19627 [HIGH] CWE-125 CVE-2018-19627: In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the IxVeriWave file parser could crash. This was ad In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the IxVeriWave file parser could crash. This was addressed in wiretap/vwr.c by adjusting a buffer boundary.
nvd
CVE-2011-3389P3MEDIUMCVSS 4.3PoCv5.0v6.02011-09-06
CVE-2011-3389 [MEDIUM] CWE-326 CVE-2011-3389: The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Expl The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA)
nvd
CVE-2022-1292P2HIGHCVSS 7.3v9.0v10.0+1 more2022-05-03
CVE-2022-1292 [HIGH] CWE-78 CVE-2022-1292: The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. Th The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the c_rehash script is considered obsolete
nvd
CVE-2020-15803P3MEDIUMCVSS 6.1PoCv9.02020-07-17
CVE-2020-15803 [MEDIUM] CWE-79 CVE-2020-15803: Zabbix before 3.0.32rc1, 4.x before 4.0.22rc1, 4.1.x through 4.4.x before 4.4.10rc1, and 5.x before Zabbix before 3.0.32rc1, 4.x before 4.0.22rc1, 4.1.x through 4.4.x before 4.4.10rc1, and 5.x before 5.0.2rc1 allows stored XSS in the URL Widget.
nvd
CVE-2019-12815P2CRITICALCVSS 9.8v8.0v9.0+1 more2019-07-19
CVE-2019-12815 [CRITICAL] CVE-2019-12815: An arbitrary file copy vulnerability in mod_copy in ProFTPD up to 1.3.5b allows for remote code exec An arbitrary file copy vulnerability in mod_copy in ProFTPD up to 1.3.5b allows for remote code execution and information disclosure without authentication, a related issue to CVE-2015-3306.
nvd
CVE-1999-0046P3CRITICALCVSS 10.0PoCv0.931997-02-06
CVE-1999-0046 [CRITICAL] CWE-120 CVE-1999-0046: Buffer overflow of rlogin program using TERM environmental variable. Buffer overflow of rlogin program using TERM environmental variable.
nvd
CVE-1999-0368P3CRITICALCVSS 10.0PoCv2.01999-02-09
CVE-1999-0368 [CRITICAL] CVE-1999-0368: Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto.
nvd
CVE-2019-15605P2CRITICALCVSS 9.8v10.02020-02-07
CVE-2019-15605 [CRITICAL] CWE-444 CVE-2019-15605: HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-enc HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed
nvd
CVE-2019-17361P2CRITICALCVSS 9.8v9.0v10.02020-01-17
CVE-2019-17361 [CRITICAL] CWE-77 CVE-2019-17361: In SaltStack Salt through 2019.2.0, the salt-api NET API with the ssh client enabled is vulnerable t In SaltStack Salt through 2019.2.0, the salt-api NET API with the ssh client enabled is vulnerable to command injection. This allows an unauthenticated attacker with network access to the API endpoint to execute arbitrary code on the salt-api host.
nvd
CVE-2018-7489P2CRITICALCVSS 9.8v8.0v9.02018-02-26
CVE-2018-7489 [CRITICAL] CVE-2018-7489: FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unaut FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input to the readValue method of the ObjectMapper, bypassing a blacklist that is ineffective if t
nvd
CVE-2018-0494P3MEDIUMCVSS 6.5PoCv7.0v8.0+1 more2018-05-06
CVE-2018-0494 [MEDIUM] CWE-20 CVE-2018-0494: GNU Wget before 1.19.5 is prone to a cookie injection vulnerability in the resp_new function in http GNU Wget before 1.19.5 is prone to a cookie injection vulnerability in the resp_new function in http.c via a \r\n sequence in a continuation line.
nvd
CVE-2004-0594P3MEDIUMCVSS 5.1PoCv3.02004-07-27
CVE-2004-0594 [MEDIUM] CWE-367 CVE-2004-0594: The memory_limit functionality in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, under certain conditi The memory_limit functionality in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, under certain conditions such as when register_globals is enabled, allows remote attackers to execute arbitrary code by triggering a memory_limit abort during execution of the zend_hash_init function and overwriting a HashTable destructor pointer before the initialization o
nvd
CVE-2018-6794P3MEDIUMCVSS 5.3PoCv8.02018-02-07
CVE-2018-6794 [MEDIUM] CWE-693 CVE-2018-6794: Suricata before 4.0.4 is prone to an HTTP detection bypass vulnerability in detect.c and stream-tcp. Suricata before 4.0.4 is prone to an HTTP detection bypass vulnerability in detect.c and stream-tcp.c. If a malicious server breaks a normal TCP flow and sends data before the 3-way handshake is complete, then the data sent by the malicious server will be accepted by web clients such as a web browser or Linux CLI utilities, but ignored by Suricata IDS
nvd
CVE-2020-9490P2HIGHCVSS 7.5v10.02020-08-07
CVE-2020-9490 [HIGH] CWE-444 CVE-2020-9490: Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' heade Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resource afterwards. Configuring the HTTP/2 feature via "H2Push off" will mitigate this vulnerability for unpatched servers.
nvd
CVE-2016-4997P3HIGHCVSS 7.8PoCv8.02016-07-03
CVE-2016-4997 [HIGH] CWE-264 CVE-2016-4997: The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter su The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter subsystem in the Linux kernel before 4.6.3 allow local users to gain privileges or cause a denial of service (memory corruption) by leveraging in-container root access to provide a crafted offset value that triggers an unintended decrement.
nvd
CVE-2020-9274P3HIGHCVSS 7.5PoCv8.02020-02-26
CVE-2020-9274 [HIGH] CWE-824 CVE-2020-9274: An issue was discovered in Pure-FTPd 1.0.49. An uninitialized pointer vulnerability has been detecte An issue was discovered in Pure-FTPd 1.0.49. An uninitialized pointer vulnerability has been detected in the diraliases linked list. When the *lookup_alias(const char alias) or print_aliases(void) function is called, they fail to correctly detect the end of the linked list and try to access a non-existent list member. This is related to init_aliases in
nvd
CVE-2021-39275P2CRITICALCVSS 9.8v9.0v10.0+1 more2021-09-16
CVE-2021-39275 [CRITICAL] CWE-787 CVE-2021-39275: ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modu ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but third-party / external modules may. This issue affects Apache HTTP Server 2.4.48 and earlier.
nvd
CVE-2020-13936P2HIGHCVSS 8.8v9.02021-03-10
CVE-2020-13936 [HIGH] CVE-2020-13936: An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitra An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. This applies to applications that allow untrusted users to upload/modify velocity templates running Apache Velocity Engine versions up to 2.2.
nvd
CVE-2021-21349P2HIGHCVSS 8.6v9.0v10.0+1 more2021-03-23
CVE-2021-21349 [HIGH] CWE-502 CVE-2021-21349: XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4. XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream
nvd
CVE-2017-7178P3HIGHCVSS 8.8PoCv8.02017-03-18
CVE-2017-7178 [HIGH] CWE-352 CVE-2017-7178: CSRF was discovered in the web UI in Deluge before 1.3.14. The exploitation methodology involves (1) CSRF was discovered in the web UI in Deluge before 1.3.14. The exploitation methodology involves (1) hosting a crafted plugin that executes an arbitrary program from its __init__.py file and (2) causing the victim to download, install, and enable this plugin.
nvd
Debian Linux vulnerabilities | cvebase