Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 22 of 498
CVE-2021-21341P2HIGHCVSS 7.5v9.0v10.0+1 more2021-03-23
CVE-2021-21341 [HIGH] CWE-400 CVE-2021-21341: XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is vulnerability which may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed input stream. N
nvd
CVE-2020-8450P2HIGHCVSS 7.3v9.0v10.02020-02-04
CVE-2020-8450 [HIGH] CWE-131 CVE-2020-8450: An issue was discovered in Squid before 4.10. Due to incorrect buffer management, a remote client ca
An issue was discovered in Squid before 4.10. Due to incorrect buffer management, a remote client can cause a buffer overflow in a Squid instance acting as a reverse proxy.
nvd
CVE-2020-6404P3HIGHCVSS 8.8PoCv9.0v10.02020-02-11
CVE-2020-6404 [HIGH] CWE-787 CVE-2020-6404: Inappropriate implementation in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attack
Inappropriate implementation in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-6339P2CRITICALCVSS 9.8v8.0v9.02019-01-22
CVE-2019-6339 [CRITICAL] CWE-20 CVE-2019-6339: In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; A remote c
In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; A remote code execution vulnerability exists in PHP's built-in phar stream wrapper when performing file operations on an untrusted phar:// URI. Some Drupal code (core, contrib, and custom) may be performing file operations on insufficiently validated user input,
nvd
CVE-2020-8865P3MEDIUMCVSS 6.3PoCv8.02020-03-23
CVE-2020-8865 [MEDIUM] CWE-23 CVE-2020-8865: This vulnerability allows remote attackers to execute local PHP files on affected installations of H
This vulnerability allows remote attackers to execute local PHP files on affected installations of Horde Groupware Webmail Edition 5.2.22. Authentication is required to exploit this vulnerability. The specific flaw exists within edit.php. When parsing the params[template] parameter, the process does not properly validate a user-supplied path prior to u
nvd
CVE-2009-0949P3HIGHCVSS 7.5PoCv4.0v5.0+1 more2009-06-09
CVE-2009-0949 [HIGH] CWE-908 CVE-2009-0949: The ippReadIO function in cups/ipp.c in cupsd in CUPS before 1.3.10 does not properly initialize mem
The ippReadIO function in cups/ipp.c in cupsd in CUPS before 1.3.10 does not properly initialize memory for IPP request packets, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a scheduler request with two consecutive IPP_TAG_UNSUPPORTED tags.
nvd
CVE-2017-15705P4MEDIUMCVSS 5.3Exploitedv8.02018-09-17
CVE-2017-15705 [MEDIUM] CWE-20 CVE-2017-15705: A denial of service vulnerability was identified that exists in Apache SpamAssassin before 3.4.2. Th
A denial of service vulnerability was identified that exists in Apache SpamAssassin before 3.4.2. The vulnerability arises with certain unclosed tags in emails that cause markup to be handled incorrectly leading to scan timeouts. In Apache SpamAssassin, using HTML::Parser, we setup an object and hook into the begin and end tag event handlers In both
nvd
CVE-2017-2885P2CRITICALCVSS 9.8v8.0v9.02018-04-24
CVE-2017-2885 [CRITICAL] CWE-787 CVE-2017-2885: An exploitable stack based buffer overflow vulnerability exists in the GNOME libsoup 2.58. A special
An exploitable stack based buffer overflow vulnerability exists in the GNOME libsoup 2.58. A specially crafted HTTP request can cause a stack overflow resulting in remote code execution. An attacker can send a special HTTP request to the vulnerable server to trigger this vulnerability.
nvd
CVE-2022-0778P2HIGHCVSS 7.5v9.0v10.0+1 more2022-03-15
CVE-2022-0778 [HIGH] CWE-835 CVE-2022-0778: The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it t
The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic curve public keys in compressed form or explicit elliptic curve parameters with a base point encoded in compressed form. It is possible t
nvd
CVE-2019-6799P3MEDIUMCVSS 5.9PoCv8.02019-01-26
CVE-2019-6799 [MEDIUM] CVE-2019-6799: An issue was discovered in phpMyAdmin before 4.8.5. When the AllowArbitraryServer configuration sett
An issue was discovered in phpMyAdmin before 4.8.5. When the AllowArbitraryServer configuration setting is set to true, with the use of a rogue MySQL server, an attacker can read any file on the server that the web server's user can access. This is related to the mysql.allow_local_infile PHP configuration, and the inadvertent ignoring of "options(MYSQLI_OPT_L
nvd
CVE-2019-12527P2HIGHCVSS 8.8v10.02019-07-11
CVE-2019-12527 [HIGH] CWE-787 CVE-2019-12527: An issue was discovered in Squid 4.0.23 through 4.7. When checking Basic Authentication with HttpHea
An issue was discovered in Squid 4.0.23 through 4.7. When checking Basic Authentication with HttpHeader::getAuth, Squid uses a global buffer to store the decoded data. Squid does not check that the decoded length isn't greater than the buffer, leading to a heap-based buffer overflow with user controlled data.
nvd
CVE-2022-0194P2CRITICALCVSS 9.8v10.0v11.02023-03-28
CVE-2022-0194 [CRITICAL] CWE-121 CVE-2022-0194: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ne
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the ad_addcomment function. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-l
nvd
CVE-2022-23122P2CRITICALCVSS 9.8v10.0v11.02023-03-28
CVE-2022-23122 [CRITICAL] CWE-121 CVE-2022-23122: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ne
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the setfilparams function. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-
nvd
CVE-2019-9515P3HIGHCVSS 7.5v9.0v10.02019-08-13
CVE-2019-9515 [HIGH] CWE-400 CVE-2019-9515: Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of s
Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RFC requires that the peer reply with one acknowledgement per SETTINGS frame, an empty SETTINGS frame is almost equivalent in behavior to a ping. Depending on how efficiently th
nvd
CVE-2017-14867P2HIGHCVSS 8.8v8.0v9.02017-09-29
CVE-2017-14867 [HIGH] CWE-78 CVE-2017-14867: Git before 2.10.5, 2.11.x before 2.11.4, 2.12.x before 2.12.5, 2.13.x before 2.13.6, and 2.14.x befo
Git before 2.10.5, 2.11.x before 2.11.4, 2.12.x before 2.12.5, 2.13.x before 2.13.6, and 2.14.x before 2.14.2 uses unsafe Perl scripts to support subcommands such as cvsserver, which allows attackers to execute arbitrary OS commands via shell metacharacters in a module name. The vulnerable code is reachable via git-shell even without CVS support.
nvd
CVE-2019-18610P2HIGHCVSS 8.8v8.0v9.02019-11-22
CVE-2019-18610 [HIGH] CWE-862 CVE-2019-18610: An issue was discovered in manager.c in Sangoma Asterisk through 13.x, 16.x, 17.x and Certified Aste
An issue was discovered in manager.c in Sangoma Asterisk through 13.x, 16.x, 17.x and Certified Asterisk 13.21 through 13.21-cert4. A remote authenticated Asterisk Manager Interface (AMI) user without system authorization could use a specially crafted Originate AMI request to execute arbitrary system commands.
nvd
CVE-2023-4357P2HIGHCVSS 8.8v11.0v12.02023-08-15
CVE-2023-4357 [HIGH] CWE-20 CVE-2023-4357: Insufficient validation of untrusted input in XML in Google Chrome prior to 116.0.5845.96 allowed a
Insufficient validation of untrusted input in XML in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to bypass file access restrictions via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2018-1126P3CRITICALCVSS 9.8PoCv7.0v8.0+1 more2018-05-23
CVE-2018-1126 [CRITICAL] CVE-2018-1126: procps-ng before version 3.3.15 is vulnerable to an incorrect integer size in proc/alloc.* leading t
procps-ng before version 3.3.15 is vulnerable to an incorrect integer size in proc/alloc.* leading to truncation/integer overflow issues. This flaw is related to CVE-2018-1124.
nvd
CVE-2011-4350P3MEDIUMCVSS 6.5PoCv8.0v9.0+1 more2019-11-26
CVE-2011-4350 [MEDIUM] CWE-22 CVE-2011-4350: Yaws 1.91 has a directory traversal vulnerability in the way certain URLs are processed. A remote au
Yaws 1.91 has a directory traversal vulnerability in the way certain URLs are processed. A remote authenticated user could use this flaw to obtain content of arbitrary local files via specially-crafted URL request.
nvd
CVE-2022-30287P2HIGHCVSS 8.0v10.02022-07-28
CVE-2022-30287 [HIGH] CWE-470 CVE-2022-30287: Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack through which an
Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack through which an attacker can instantiate a driver class. This then leads to arbitrary deserialization of PHP objects.
nvd