Debian Linux vulnerabilities
9,954 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358
Vulnerabilities
Page 226 of 498
CVE-2020-14350P3HIGHCVSS 7.3v9.02020-08-24
CVE-2020-14350 [HIGH] CWE-426 CVE-2020-14350: It was found that some PostgreSQL extensions did not use search_path safely in their installation sc
It was found that some PostgreSQL extensions did not use search_path safely in their installation script. An attacker with sufficient privileges could use this flaw to trick an administrator into executing a specially crafted script, during the installation or update of such extension. This affects PostgreSQL versions before 12.4, before 11.9, before
nvd
CVE-2016-2326P3HIGHCVSS 8.8v7.0v8.02016-02-12
CVE-2016-2326 [HIGH] CWE-190 CVE-2016-2326: Integer overflow in the asf_write_packet function in libavformat/asfenc.c in FFmpeg before 2.8.5 all
Integer overflow in the asf_write_packet function in libavformat/asfenc.c in FFmpeg before 2.8.5 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted PTS (aka presentation timestamp) value in a .mov file.
nvd
CVE-2021-3178P3MEDIUMCVSS 6.5v9.02021-01-19
CVE-2021-3178 [MEDIUM] CWE-22 CVE-2021-3178: fs/nfsd/nfs3xdr.c in the Linux kernel through 5.10.8, when there is an NFS export of a subdirectory
fs/nfsd/nfs3xdr.c in the Linux kernel through 5.10.8, when there is an NFS export of a subdirectory of a filesystem, allows remote attackers to traverse to other parts of the filesystem via READDIRPLUS. NOTE: some parties argue that such a subdirectory export is not intended to prevent this attack; see also the exports(5) no_subtree_check default behavi
nvd
CVE-2017-10379P3MEDIUMCVSS 6.5v8.02017-10-19
CVE-2017-10379 [MEDIUM] CWE-863 CVE-2017-10379: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs). Support
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs). Supported versions that are affected are 5.5.57 and earlier, 5.6.37 and earlier and 5.7.19 and earlier. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks
nvd
CVE-2018-6799P3HIGHCVSS 8.8v7.0v8.0+1 more2018-02-07
CVE-2018-6799 [HIGH] CWE-119 CVE-2018-6799: The AcquireCacheNexus function in magick/pixel_cache.c in GraphicsMagick before 1.3.28 allows remote
The AcquireCacheNexus function in magick/pixel_cache.c in GraphicsMagick before 1.3.28 allows remote attackers to cause a denial of service (heap overwrite) or possibly have unspecified other impact via a crafted image file, because a pixel staging area is not used.
nvd
CVE-2017-12640P3HIGHCVSS 8.8v8.0v9.02017-08-07
CVE-2017-12640 [HIGH] CWE-125 CVE-2017-12640: ImageMagick 7.0.6-1 has an out-of-bounds read vulnerability in ReadOneMNGImage in coders/png.c.
ImageMagick 7.0.6-1 has an out-of-bounds read vulnerability in ReadOneMNGImage in coders/png.c.
nvd
CVE-2018-10919P3MEDIUMCVSS 6.5v9.02018-08-22
CVE-2018-10919 [MEDIUM] CWE-203 CVE-2018-10919: The Samba Active Directory LDAP server was vulnerable to an information disclosure flaw because of m
The Samba Active Directory LDAP server was vulnerable to an information disclosure flaw because of missing access control checks. An authenticated attacker could use this flaw to extract confidential attribute values using LDAP search expressions. Samba versions before 4.6.16, 4.7.9 and 4.8.4 are vulnerable.
nvd
CVE-2022-31081P3MEDIUMCVSS 6.5v10.02022-06-27
CVE-2022-31081 [MEDIUM] CWE-444 CVE-2022-31081: HTTP::Daemon is a simple http server class written in perl. Versions prior to 6.15 are subject to a
HTTP::Daemon is a simple http server class written in perl. Versions prior to 6.15 are subject to a vulnerability which could potentially be exploited to gain privileged access to APIs or poison intermediate caches. It is uncertain how large the risks are, most Perl based applications are served on top of Nginx or Apache, not on the `HTTP::Daemon`. T
nvd
CVE-2018-10930P3MEDIUMCVSS 6.5v8.0v9.02018-09-04
CVE-2018-10930 [MEDIUM] CWE-20 CVE-2018-10930: A flaw was found in RPC request using gfs3_rename_req in glusterfs server. An authenticated attacker
A flaw was found in RPC request using gfs3_rename_req in glusterfs server. An authenticated attacker could use this flaw to write to a destination outside the gluster volume.
nvd
CVE-2017-12937P3HIGHCVSS 8.8v8.0v9.02017-08-18
CVE-2017-12937 [HIGH] CWE-125 CVE-2017-12937: The ReadSUNImage function in coders/sun.c in GraphicsMagick 1.3.26 has a colormap heap-based buffer
The ReadSUNImage function in coders/sun.c in GraphicsMagick 1.3.26 has a colormap heap-based buffer over-read.
nvd
CVE-2019-18790P3MEDIUMCVSS 6.5v8.0v9.02019-11-22
CVE-2019-18790 [MEDIUM] CWE-862 CVE-2019-18790: An issue was discovered in channels/chan_sip.c in Sangoma Asterisk 13.x before 13.29.2, 16.x before
An issue was discovered in channels/chan_sip.c in Sangoma Asterisk 13.x before 13.29.2, 16.x before 16.6.2, and 17.x before 17.0.1, and Certified Asterisk 13.21 before cert5. A SIP request can be sent to Asterisk that can change a SIP peer's IP address. A REGISTER does not need to occur, and calls can be hijacked as a result. The only thing that need
nvd
CVE-2016-5131P3HIGHCVSS 8.8v8.0v9.02016-07-23
CVE-2016-5131 [HIGH] CWE-416 CVE-2016-5131: Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82,
Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the XPointer range-to function.
nvd
CVE-2019-19956P3HIGHCVSS 7.5v8.0v9.02019-12-24
CVE-2019-19956 [HIGH] CWE-401 CVE-2019-19956: xmlParseBalancedChunkMemoryRecover in parser.c in libxml2 before 2.9.10 has a memory leak related to
xmlParseBalancedChunkMemoryRecover in parser.c in libxml2 before 2.9.10 has a memory leak related to newDoc->oldNs.
nvd
CVE-2018-7436P3HIGHCVSS 8.8v7.0v8.0+1 more2018-02-23
CVE-2018-7436 [HIGH] CWE-125 CVE-2018-7436: An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in a pointer
An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in a pointer dereference of the parse_SST function.
nvd
CVE-2019-19052P3HIGHCVSS 7.5v8.02019-11-18
CVE-2019-19052 [HIGH] CWE-401 CVE-2019-19052: A memory leak in the gs_can_open() function in drivers/net/can/usb/gs_usb.c in the Linux kernel befo
A memory leak in the gs_can_open() function in drivers/net/can/usb/gs_usb.c in the Linux kernel before 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering usb_submit_urb() failures, aka CID-fb5be6a7b486.
nvd
CVE-2015-7696P3MEDIUMCVSS 6.8v7.0v8.02015-11-06
CVE-2015-7696 [MEDIUM] CWE-119 CVE-2015-7696: Info-ZIP UnZip 6.0 allows remote attackers to cause a denial of service (heap-based buffer over-read
Info-ZIP UnZip 6.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly execute arbitrary code via a crafted password-protected ZIP archive, possibly related to an Extra-Field size value.
nvd
CVE-2014-6055P3MEDIUMCVSS 6.5v7.02014-09-30
CVE-2014-6055 [MEDIUM] CWE-119 CVE-2014-6055: Multiple stack-based buffer overflows in the File Transfer feature in rfbserver.c in LibVNCServer 0.
Multiple stack-based buffer overflows in the File Transfer feature in rfbserver.c in LibVNCServer 0.9.9 and earlier allow remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a (1) long file or (2) directory name or the (3) FileTime attribute in a rfbFileTransferOffer message.
nvd
CVE-2017-12599P3HIGHCVSS 8.8v8.0v9.02017-08-07
CVE-2017-12599 [HIGH] CWE-125 CVE-2017-12599: OpenCV (Open Source Computer Vision Library) through 3.3 has an out-of-bounds read error in the func
OpenCV (Open Source Computer Vision Library) through 3.3 has an out-of-bounds read error in the function icvCvt_BGRA2BGR_8u_C4C3R when reading an image file by using cv::imread.
nvd
CVE-2016-10197P3HIGHCVSS 7.5v8.02017-03-15
CVE-2016-10197 [HIGH] CWE-125 CVE-2016-10197: The search_make_new function in evdns.c in libevent before 2.1.6-beta allows attackers to cause a de
The search_make_new function in evdns.c in libevent before 2.1.6-beta allows attackers to cause a denial of service (out-of-bounds read) via an empty hostname.
nvd
CVE-2017-12935P3HIGHCVSS 8.8v8.0v9.02017-08-18
CVE-2017-12935 [HIGH] CWE-125 CVE-2017-12935: The ReadMNGImage function in coders/png.c in GraphicsMagick 1.3.26 mishandles large MNG images, lead
The ReadMNGImage function in coders/png.c in GraphicsMagick 1.3.26 mishandles large MNG images, leading to an invalid memory read in the SetImageColorCallBack function in magick/image.c.
nvd