Debian Linux vulnerabilities
9,954 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358
Vulnerabilities
Page 218 of 498
CVE-2021-3634P3MEDIUMCVSS 6.5v10.0v11.02021-08-31
CVE-2021-3634 [MEDIUM] CWE-787 CVE-2021-3634: A flaw has been found in libssh in versions prior to 0.9.6. The SSH protocol keeps track of two shar
A flaw has been found in libssh in versions prior to 0.9.6. The SSH protocol keeps track of two shared secrets during the lifetime of the session. One of them is called secret_hash and the other session_id. Initially, both of them are the same, but after key re-exchange, previous session_id is kept and used as an input to new secret_hash. Historically
nvd
CVE-2020-27778P3HIGHCVSS 7.5v10.02020-12-03
CVE-2020-27778 [HIGH] CWE-824 CVE-2020-27778: A flaw was found in Poppler in the way certain PDF files were converted into HTML. A remote attacker
A flaw was found in Poppler in the way certain PDF files were converted into HTML. A remote attacker could exploit this flaw by providing a malicious PDF file that, when processed by the 'pdftohtml' program, would crash the application causing a denial of service.
nvd
CVE-2018-20763P3HIGHCVSS 7.8v8.02019-02-06
CVE-2018-20763 [HIGH] CWE-787 CVE-2018-20763: In GPAC 0.7.1 and earlier, gf_text_get_utf8_line in media_tools/text_import.c in libgpac_static.a al
In GPAC 0.7.1 and earlier, gf_text_get_utf8_line in media_tools/text_import.c in libgpac_static.a allows an out-of-bounds write because of missing szLineConv bounds checking.
nvd
CVE-2017-18076P3HIGHCVSS 7.5v8.0v9.02018-01-26
CVE-2017-18076 [HIGH] CVE-2017-18076: In strategy.rb in OmniAuth before 1.3.2, the authenticity_token value is improperly protected becaus
In strategy.rb in OmniAuth before 1.3.2, the authenticity_token value is improperly protected because POST (in addition to GET) parameters are stored in the session and become available in the environment of the callback phase.
nvd
CVE-2019-25037P3HIGHCVSS 7.5v9.02021-04-27
CVE-2019-25037 [HIGH] CWE-617 CVE-2019-25037: Unbound before 1.9.5 allows an assertion failure and denial of service in dname_pkt_copy via an inva
Unbound before 1.9.5 allows an assertion failure and denial of service in dname_pkt_copy via an invalid packet. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
nvd
CVE-2022-2129P3HIGHCVSS 7.8v10.02022-06-19
CVE-2022-2129 [HIGH] CWE-787 CVE-2022-2129: Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.
Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.
nvd
CVE-2018-6594P3HIGHCVSS 7.5v7.02018-02-03
CVE-2018-6594 [HIGH] CWE-326 CVE-2018-6594: lib/Crypto/PublicKey/ElGamal.py in PyCrypto through 2.6.1 generates weak ElGamal key parameters, whi
lib/Crypto/PublicKey/ElGamal.py in PyCrypto through 2.6.1 generates weak ElGamal key parameters, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic security in face of a ciphertext-only attack). The Decisional Diffie-Hellman (DDH) assumption does not hold for PyCrypto's ElGamal implementati
nvd
CVE-2020-21041P3HIGHCVSS 7.5v9.0v10.02021-05-24
CVE-2020-21041 [HIGH] CWE-120 CVE-2020-21041: Buffer Overflow vulnerability exists in FFmpeg 4.1 via apng_do_inverse_blend in libavcodec/pngenc.c,
Buffer Overflow vulnerability exists in FFmpeg 4.1 via apng_do_inverse_blend in libavcodec/pngenc.c, which could let a remote malicious user cause a Denial of Service
nvd
CVE-2016-3822P3HIGHCVSS 7.8v8.0v9.02016-08-05
CVE-2016-3822 [HIGH] CWE-119 CVE-2016-3822: exif.c in Matthias Wandel jhead 2.87, as used in libjhead in Android 4.x before 4.4.4, 5.0.x before
exif.c in Matthias Wandel jhead 2.87, as used in libjhead in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01, allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds access) via crafted EXIF data, aka internal bug 28868315.
nvd
CVE-2022-32084P3HIGHCVSS 7.5v10.02022-07-01
CVE-2022-32084 [HIGH] CVE-2022-32084: MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component sub_select.
MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component sub_select.
nvd
CVE-2019-25036P3HIGHCVSS 7.5v9.02021-04-27
CVE-2019-25036 [HIGH] CWE-617 CVE-2019-25036: Unbound before 1.9.5 allows an assertion failure and denial of service in synth_cname. NOTE: The ven
Unbound before 1.9.5 allows an assertion failure and denial of service in synth_cname. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
nvd
CVE-2019-14586P3HIGHCVSS 8.0v9.02020-11-23
CVE-2019-14586 [HIGH] CWE-416 CVE-2019-14586: Use after free vulnerability in EDK II may allow an authenticated user to potentially enable escalat
Use after free vulnerability in EDK II may allow an authenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via adjacent access.
nvd
CVE-2018-5162P3HIGHCVSS 7.5v7.0v8.0+1 more2018-06-11
CVE-2018-5162 [HIGH] CWE-311 CVE-2018-5162: Plaintext of decrypted emails can leak through the src attribute of remote images, or links. This vu
Plaintext of decrypted emails can leak through the src attribute of remote images, or links. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
nvd
CVE-2020-36475P3HIGHCVSS 7.5v9.0v10.02021-08-23
CVE-2020-36475 [HIGH] CWE-131 CVE-2020-36475: An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). The
An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). The calculations performed by mbedtls_mpi_exp_mod are not limited; thus, supplying overly large parameters could lead to denial of service when generating Diffie-Hellman key pairs.
nvd
CVE-2021-3497P3HIGHCVSS 7.8v9.0v10.02021-04-19
CVE-2021-3497 [HIGH] CWE-416 CVE-2021-3497: GStreamer before 1.18.4 might access already-freed memory in error code paths when demuxing certain
GStreamer before 1.18.4 might access already-freed memory in error code paths when demuxing certain malformed Matroska files.
nvd
CVE-2012-6698P3HIGHCVSS 7.5v7.02016-04-11
CVE-2012-6698 [HIGH] CWE-119 CVE-2012-6698: The decode_search function in dhcp.c in dhcpcd 3.x allows remote DHCP servers to cause a denial of s
The decode_search function in dhcp.c in dhcpcd 3.x allows remote DHCP servers to cause a denial of service (out-of-bounds write) via a crafted response.
nvd
CVE-2016-3477P3HIGHCVSS 8.1v8.02016-07-21
CVE-2016-3477 [HIGH] CVE-2016-3477: Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and ear
Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and earlier and MariaDB before 5.5.50, 10.0.x before 10.0.26, and 10.1.x before 10.1.15 allows local users to affect confidentiality, integrity, and availability via vectors related to Server: Parser.
nvd
CVE-2021-20276P3HIGHCVSS 7.5v9.02021-03-09
CVE-2021-20276 [HIGH] CWE-119 CVE-2021-20276: A flaw was found in privoxy before 3.0.32. Invalid memory access with an invalid pattern passed to p
A flaw was found in privoxy before 3.0.32. Invalid memory access with an invalid pattern passed to pcre_compile() may lead to denial of service.
nvd
CVE-2020-27766P3HIGHCVSS 7.8v9.02020-12-04
CVE-2020-27766 [HIGH] CWE-190 CVE-2020-27766: A flaw was found in ImageMagick in MagickCore/statistic.c. An attacker who submits a crafted file th
A flaw was found in ImageMagick in MagickCore/statistic.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type `unsigned long`. This would most likely lead to an impact to application availability, but could potentially cause other problems related to
nvd
CVE-2014-8095P3MEDIUMCVSS 6.5v7.02014-12-10
CVE-2014-8095 [MEDIUM] CWE-119 CVE-2014-8095: The XInput extension in X.Org X Window System (aka X11 or X) X11R4 and X.Org Server (aka xserver and
The XInput extension in X.Org X Window System (aka X11 or X) X11R4 and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or write) or possibly execute arbitrary code via a crafted length or index value to the (1) SProcXChangeDeviceControl, (2) ProcXChangeDeviceCo
nvd