cbcvebase.

Debian Linux vulnerabilities

9,953 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358

Vulnerabilities

Page 23 of 498
CVE-2013-4074P3MEDIUMCVSS 5.0PoCv7.02013-06-09
CVE-2013-4074 [MEDIUM] CWE-189 CVE-2013-4074: The dissect_capwap_data function in epan/dissectors/packet-capwap.c in the CAPWAP dissector in Wires The dissect_capwap_data function in epan/dissectors/packet-capwap.c in the CAPWAP dissector in Wireshark 1.6.x before 1.6.16 and 1.8.x before 1.8.8 incorrectly uses a -1 data value to represent an error condition, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
nvd
CVE-2017-16943P2CRITICALCVSS 9.8v9.02017-11-25
CVE-2017-16943 [CRITICAL] CWE-416 CVE-2017-16943: The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attacke The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via vectors involving BDAT commands.
nvd
CVE-2019-9513P3HIGHCVSS 7.5v9.0v10.02019-08-13
CVE-2019-9513 [HIGH] CWE-400 CVE-2019-9513: Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of ser Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request streams and continually shuffles the priority of the streams in a way that causes substantial churn to the priority tree. This can consume excess CPU.
nvd
CVE-2011-4107P3MEDIUMCVSS 6.5PoCv5.02011-11-17
CVE-2011-4107 [MEDIUM] CWE-611 CVE-2011-4107: The simplexml_load_string function in the XML import plug-in (libraries/import/xml.php) in phpMyAdmi The simplexml_load_string function in the XML import plug-in (libraries/import/xml.php) in phpMyAdmin 3.4.x before 3.4.7.1 and 3.3.x before 3.3.10.5 allows remote authenticated users to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack.
nvd
CVE-2018-14574P3MEDIUMCVSS 6.1PoCv9.02018-08-03
CVE-2018-14574 [MEDIUM] CWE-601 CVE-2018-14574: django.middleware.common.CommonMiddleware in Django 1.11.x before 1.11.15 and 2.0.x before 2.0.8 has django.middleware.common.CommonMiddleware in Django 1.11.x before 1.11.15 and 2.0.x before 2.0.8 has an Open Redirect.
nvd
CVE-2018-17182P3HIGHCVSS 7.8PoCv8.0v9.02018-09-19
CVE-2018-17182 [HIGH] CWE-416 CVE-2018-17182: An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vm An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles sequence number overflows. An attacker can trigger a use-after-free (and possibly gain privileges) via certain thread creation, map, unmap, invalidation, and dereference operations.
nvd
CVE-2017-7558P3HIGHCVSS 7.5PoCv8.0v9.02018-07-26
CVE-2017-7558 [HIGH] CWE-125 CVE-2017-7558: A kernel data leak due to an out-of-bound read was found in the Linux kernel in inet_diag_msg_sctp{, A kernel data leak due to an out-of-bound read was found in the Linux kernel in inet_diag_msg_sctp{,l}addr_fill() and sctp_get_sctp_info() functions present since version 4.7-rc1 through version 4.13. A data leak happens when these functions fill in sockaddr data structures used to export socket's diagnostic information. As a result, up to 100 bytes of
nvd
CVE-2017-3144P2HIGHCVSS 7.5v8.0v9.02019-01-16
CVE-2017-3144 [HIGH] CWE-400 CVE-2017-3144: A vulnerability stemming from failure to properly clean up closed OMAPI connections can lead to exha A vulnerability stemming from failure to properly clean up closed OMAPI connections can lead to exhaustion of the pool of socket descriptors available to the DHCP server. Affects ISC DHCP 4.1.0 to 4.1-ESV-R15, 4.2.0 to 4.2.8, 4.3.0 to 4.3.6. Older versions may also be affected but are well beyond their end-of-life (EOL). Releases prior to 4.1.0 have not
nvd
CVE-2017-6060P3HIGHCVSS 7.8PoCv9.02017-03-15
CVE-2017-6060 [HIGH] CWE-787 CVE-2017-6060: Stack-based buffer overflow in jstest_main.c in mujstest in Artifex Software, Inc. MuPDF 1.10a allow Stack-based buffer overflow in jstest_main.c in mujstest in Artifex Software, Inc. MuPDF 1.10a allows remote attackers to have unspecified impact via a crafted image.
nvd
CVE-2024-52316P2CRITICALCVSS 9.8v11.02024-11-18
CVE-2024-52316 [CRITICAL] CWE-391 CVE-2024-52316: Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Ja Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication (formerly JASPIC) ServerAuthContext component which may throw an exception during the authentication process without explicitly setting an HTTP status to indicate failure, the authentication may not fail, allowing the user to by
nvd
CVE-2017-6074P3HIGHCVSS 7.8PoCv8.02017-02-18
CVE-2017-6074 [HIGH] CWE-415 CVE-2017-6074: The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandle The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandles DCCP_PKT_REQUEST packet data structures in the LISTEN state, which allows local users to obtain root privileges or cause a denial of service (double free) via an application that makes an IPV6_RECVPKTINFO setsockopt system call.
nvd
CVE-2019-9512P3HIGHCVSS 7.5v10.02019-08-13
CVE-2019-9512 [HIGH] CWE-400 CVE-2019-9512: Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of servic Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service. The attacker sends continual pings to an HTTP/2 peer, causing the peer to build an internal queue of responses. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.
nvd
CVE-2019-9514P3HIGHCVSS 7.5v10.0v9.02019-08-13
CVE-2019-9514 [HIGH] CWE-400 CVE-2019-9514: Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of serv Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can consume excess memory, CPU, or both
nvd
CVE-2022-22720P2CRITICALCVSS 9.8v9.02022-03-14
CVE-2022-22720 [CRITICAL] CWE-444 CVE-2022-22720: Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling
nvd
CVE-2022-22721P2CRITICALCVSS 9.1v9.02022-03-14
CVE-2022-22721 [CRITICAL] CWE-190 CVE-2022-22721: If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit s If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier.
nvd
CVE-2022-22719P2HIGHCVSS 7.5v9.02022-03-14
CVE-2022-22719 [HIGH] CWE-665 CVE-2022-22719: A carefully crafted request body can cause a read to a random memory area which could cause the proc A carefully crafted request body can cause a read to a random memory area which could cause the process to crash. This issue affects Apache HTTP Server 2.4.52 and earlier.
nvd
CVE-2022-23121P2CRITICALCVSS 9.8v10.0v11.02023-03-28
CVE-2022-23121 [CRITICAL] CWE-755 CVE-2022-23121: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ne This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the parse_entries function. The issue results from the lack of proper error handling when parsing AppleDouble entries. An attacker can leverage thi
nvd
CVE-2018-1123P3HIGHCVSS 7.5PoCv7.0v8.0+1 more2018-05-23
CVE-2018-1123 [HIGH] CWE-122 CVE-2018-1123: procps-ng before version 3.3.15 is vulnerable to a denial of service in ps via mmap buffer overflow. procps-ng before version 3.3.15 is vulnerable to a denial of service in ps via mmap buffer overflow. Inbuilt protection in ps maps a guard page at the end of the overflowed buffer, ensuring that the impact of this flaw is limited to a crash (temporary denial of service).
nvd
CVE-2020-6519P3MEDIUMCVSS 6.5PoCv10.02020-07-22
CVE-2020-6519 [MEDIUM] CVE-2020-6519: Policy bypass in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass cont Policy bypass in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy via a crafted HTML page.
nvd
CVE-2017-8849P3HIGHCVSS 7.8PoCv8.02017-05-17
CVE-2017-8849 [HIGH] CWE-20 CVE-2017-8849: smb4k before 2.0.1 allows local users to gain root privileges by leveraging failure to verify argume smb4k before 2.0.1 allows local users to gain root privileges by leveraging failure to verify arguments to the mount helper DBUS service.
nvd
Debian Linux vulnerabilities | cvebase