Debian Linux vulnerabilities
9,954 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358
Vulnerabilities
Page 220 of 498
CVE-2016-6185P3HIGHCVSS 7.8v8.02016-08-02
CVE-2016-6185 [HIGH] CVE-2016-6185: The XSLoader::load method in XSLoader in Perl does not properly locate .so files when called in a st
The XSLoader::load method in XSLoader in Perl does not properly locate .so files when called in a string eval, which might allow local users to execute arbitrary code via a Trojan horse library under the current working directory.
nvd
CVE-2010-4494P3HIGHCVSS 7.5v5.0v6.02010-12-07
CVE-2010-4494 [HIGH] CWE-415 CVE-2010-4494: Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.5
Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath handling.
nvd
CVE-2022-23517P3HIGHCVSS 7.5v10.02022-12-14
CVE-2022-23517 [HIGH] CWE-1333 CVE-2022-23517: rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Certain con
rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Certain configurations of rails-html-sanitizer < 1.4.4 use an inefficient regular expression that is susceptible to excessive backtracking when attempting to sanitize certain SVG attributes. This may lead to a denial of service through CPU resource consumption. T
nvd
CVE-2018-5735P3HIGHCVSS 7.5v8.0v9.0+1 more2019-10-30
CVE-2018-5735 [HIGH] CVE-2018-5735: The Debian backport of the fix for CVE-2017-3137 leads to assertion failure in validator.c:1858; Aff
The Debian backport of the fix for CVE-2017-3137 leads to assertion failure in validator.c:1858; Affects Debian versions 9.9.5.dfsg-9+deb8u15; 9.9.5.dfsg-9+deb8u18; 9.10.3.dfsg.P4-12.3+deb9u5; 9.11.5.P4+dfsg-5.1 No ISC releases are affected. Other packages from other distributions who did similar backports for the fix for 2017-3137 may also be affected.
nvd
CVE-2021-41141P3HIGHCVSS 7.5v9.02022-01-04
CVE-2021-41141 [HIGH] CWE-667 CVE-2021-41141: PJSIP is a free and open source multimedia communication library written in the C language implement
PJSIP is a free and open source multimedia communication library written in the C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In various parts of PJSIP, when error/failure occurs, it is found that the function returns without releasing the currently held locks. This could result in a system deadlock, whic
nvd
CVE-2022-0351P3HIGHCVSS 7.8v9.0v10.02022-01-25
CVE-2022-0351 [HIGH] CWE-786 CVE-2022-0351: Access of Memory Location Before Start of Buffer in GitHub repository vim/vim prior to 8.2.
Access of Memory Location Before Start of Buffer in GitHub repository vim/vim prior to 8.2.
nvd
CVE-2015-1276P3CRITICALCVSS 9.8v8.02015-07-23
CVE-2015-1276 [CRITICAL] CVE-2015-1276: Use-after-free vulnerability in content/browser/indexed_db/indexed_db_backing_store.cc in the Indexe
Use-after-free vulnerability in content/browser/indexed_db/indexed_db_backing_store.cc in the IndexedDB implementation in Google Chrome before 44.0.2403.89 allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging an abort action before a certain write operation.
nvd
CVE-2018-6061P3HIGHCVSS 7.5v9.02018-11-14
CVE-2018-6061 [HIGH] CWE-362 CVE-2018-6061: A race in the handling of SharedArrayBuffers in WebAssembly in Google Chrome prior to 65.0.3325.146
A race in the handling of SharedArrayBuffers in WebAssembly in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-3928P3HIGHCVSS 7.8v9.0v10.02021-11-05
CVE-2021-3928 [HIGH] CWE-457 CVE-2021-3928: vim is vulnerable to Use of Uninitialized Variable
vim is vulnerable to Use of Uninitialized Variable
nvd
CVE-2022-40149P3HIGHCVSS 7.5v10.0v11.02022-09-16
CVE-2022-40149 [HIGH] CWE-121 CVE-2022-40149: Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service atta
Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.
nvd
CVE-2023-2603P3HIGHCVSS 7.8v11.02023-06-06
CVE-2023-2603 [HIGH] CWE-190 CVE-2023-2603: A vulnerability was found in libcap. This issue occurs in the _libcap_strdup() function and can lead
A vulnerability was found in libcap. This issue occurs in the _libcap_strdup() function and can lead to an integer overflow if the input string is close to 4GiB.
nvd
CVE-2018-6158P3HIGHCVSS 7.5v9.02019-01-09
CVE-2018-6158 [HIGH] CWE-362 CVE-2018-6158: A race condition in Oilpan in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to poten
A race condition in Oilpan in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2012-1093P3HIGHCVSS 7.8v8.0v9.0+1 more2020-02-21
CVE-2012-1093 [HIGH] CWE-59 CVE-2012-1093: The init script in the Debian x11-common package before 1:7.6+12 is vulnerable to a symlink attack t
The init script in the Debian x11-common package before 1:7.6+12 is vulnerable to a symlink attack that can lead to a privilege escalation during package installation.
nvd
CVE-2022-40150P3HIGHCVSS 7.5v10.0v11.02022-09-16
CVE-2022-40150 [HIGH] CWE-400 CVE-2022-40150: Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service atta
Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by Out of memory. This effect may support a denial of service attack.
nvd
CVE-2018-7566P3HIGHCVSS 7.8v7.0v8.0+1 more2018-03-30
CVE-2018-7566 [HIGH] CWE-119 CVE-2018-7566: The Linux kernel 4.15 has a Buffer Overflow via an SNDRV_SEQ_IOCTL_SET_CLIENT_POOL ioctl write opera
The Linux kernel 4.15 has a Buffer Overflow via an SNDRV_SEQ_IOCTL_SET_CLIENT_POOL ioctl write operation to /dev/snd/seq by a local user.
nvd
CVE-2022-1920P3HIGHCVSS 7.8v10.0v11.02022-07-19
CVE-2022-1920 [HIGH] CWE-122 CVE-2022-1920: Integer overflow in matroskademux element in gst_matroska_demux_add_wvpk_header function which allow
Integer overflow in matroskademux element in gst_matroska_demux_add_wvpk_header function which allows a heap overwrite while parsing matroska files. Potential for arbitrary code execution through heap overwrite.
nvd
CVE-2022-1921P3HIGHCVSS 7.8v10.0v11.02022-07-19
CVE-2022-1921 [HIGH] CWE-190 CVE-2022-1921: Integer overflow in avidemux element in gst_avi_demux_invert function which allows a heap overwrite
Integer overflow in avidemux element in gst_avi_demux_invert function which allows a heap overwrite while parsing avi files. Potential for arbitrary code execution through heap overwrite.
nvd
CVE-2021-3761P3HIGHCVSS 7.5v11.02021-09-09
CVE-2021-3761 [HIGH] CWE-787 CVE-2021-3761: Any CA issuer in the RPKI can trick OctoRPKI prior to 1.3.0 into emitting an invalid VRP "MaxLength"
Any CA issuer in the RPKI can trick OctoRPKI prior to 1.3.0 into emitting an invalid VRP "MaxLength" value, causing RTR sessions to terminate. An attacker can use this to disable RPKI Origin Validation in a victim network (for example AS 13335 - Cloudflare) prior to launching a BGP hijack which during normal operations would be rejected as "RPKI invalid
nvd
CVE-2019-3813P3HIGHCVSS 7.5v8.0v9.02019-02-04
CVE-2019-3813 [HIGH] CWE-193 CVE-2019-3813: Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one e
Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a denial of service, or, in the worst case, code-execution by unauthenticated attackers.
nvd
CVE-2011-1145P3HIGHCVSS 7.8v8.0v9.0+1 more2019-11-14
CVE-2011-1145 [HIGH] CWE-120 CVE-2011-1145: The SQLDriverConnect() function in unixODBC before 2.2.14p2 have a possible buffer overflow conditio
The SQLDriverConnect() function in unixODBC before 2.2.14p2 have a possible buffer overflow condition when specifying a large value for SAVEFILE parameter in the connection string.
nvd