cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 235 of 498
CVE-2021-31871P3HIGHCVSS 7.5v9.02021-04-30
CVE-2021-31871 [HIGH] CWE-190 CVE-2021-31871: An issue was discovered in klibc before 2.0.9. An integer overflow in the cpio command may result in An issue was discovered in klibc before 2.0.9. An integer overflow in the cpio command may result in a NULL pointer dereference on 64-bit systems.
nvd
CVE-2022-0581P3HIGHCVSS 7.5v9.02022-02-14
CVE-2022-0581 [HIGH] CWE-416 CVE-2022-0581: Crash in the CMS protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of Crash in the CMS protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file
nvd
CVE-2015-5214P3MEDIUMCVSS 6.8v7.0v8.02015-11-10
CVE-2015-5214 [MEDIUM] CWE-119 CVE-2015-5214: LibreOffice before 4.4.6 and 5.x before 5.0.1 and Apache OpenOffice before 4.1.2 allows remote attac LibreOffice before 4.4.6 and 5.x before 5.0.1 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via an index to a non-existent bookmark in a DOC file.
nvd
CVE-2018-5184P3HIGHCVSS 7.5v7.0v8.0+1 more2018-06-11
CVE-2018-5184 [HIGH] CWE-326 CVE-2018-5184: Using remote content in encrypted messages can lead to the disclosure of plaintext. This vulnerabili Using remote content in encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
nvd
CVE-2021-22222P3HIGHCVSS 7.5v10.0v11.02021-06-07
CVE-2021-22222 [HIGH] CWE-835 CVE-2021-22222: Infinite loop in DVB-S2-BB dissector in Wireshark 3.4.0 to 3.4.5 allows denial of service via packet Infinite loop in DVB-S2-BB dissector in Wireshark 3.4.0 to 3.4.5 allows denial of service via packet injection or crafted capture file
nvd
CVE-2008-3837P3CRITICALCVSS 9.3v4.02008-09-24
CVE-2008-3837 [CRITICAL] CVE-2008-3837: Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, and SeaMonkey before 1.1.12, allow user-assist Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, and SeaMonkey before 1.1.12, allow user-assisted remote attackers to move a window during a mouse click, and possibly force a file download or unspecified other drag-and-drop action, via a crafted onmousedown action that calls window.moveBy, a variant of CVE-2003-0823.
nvd
CVE-2022-3517P3HIGHCVSS 7.5v10.02022-10-17
CVE-2022-3517 [HIGH] CWE-400 CVE-2022-3517: A vulnerability was found in the minimatch package. This flaw allows a Regular Expression Denial of A vulnerability was found in the minimatch package. This flaw allows a Regular Expression Denial of Service (ReDoS) when calling the braceExpand function with specific arguments, resulting in a Denial of Service.
nvd
CVE-2017-9022P3HIGHCVSS 7.5v8.0v9.02017-06-08
CVE-2017-9022 [HIGH] CWE-20 CVE-2017-9022: The gmp plugin in strongSwan before 5.5.3 does not properly validate RSA public keys before calling The gmp plugin in strongSwan before 5.5.3 does not properly validate RSA public keys before calling mpz_powm_sec, which allows remote peers to cause a denial of service (floating point exception and process crash) via a crafted certificate.
nvd
CVE-2021-37969P3HIGHCVSS 7.8v10.0v11.02021-10-08
CVE-2021-37969 [HIGH] CWE-59 CVE-2021-37969: Inappropriate implementation in Google Updater in Google Chrome on Windows prior to 94.0.4606.54 all Inappropriate implementation in Google Updater in Google Chrome on Windows prior to 94.0.4606.54 allowed a remote attacker to perform local privilege escalation via a crafted file.
nvd
CVE-2011-4082P3HIGHCVSS 7.5v8.0v9.0+1 more2019-11-26
CVE-2011-4082 [HIGH] CWE-400 CVE-2011-4082: A local file inclusion flaw was found in the way the phpLDAPadmin before 0.9.8 processed certain val A local file inclusion flaw was found in the way the phpLDAPadmin before 0.9.8 processed certain values of the "Accept-Language" HTTP header. A remote attacker could use this flaw to cause a denial of service via specially-crafted request.
nvd
CVE-2020-36426P3HIGHCVSS 7.5v10.02021-07-19
CVE-2020-36426 [HIGH] CWE-125 CVE-2020-36426: An issue was discovered in Arm Mbed TLS before 2.24.0. mbedtls_x509_crl_parse_der has a buffer over- An issue was discovered in Arm Mbed TLS before 2.24.0. mbedtls_x509_crl_parse_der has a buffer over-read (of one byte).
nvd
CVE-2022-32087P3HIGHCVSS 7.5v10.02022-07-01
CVE-2022-32087 [HIGH] CVE-2022-32087: MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Item_args::w MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Item_args::walk_args.
nvd
CVE-2020-13881P3HIGHCVSS 7.5v8.0v9.02020-06-06
CVE-2020-13881 [HIGH] CWE-532 CVE-2020-13881: In support.c in pam_tacplus 1.3.8 through 1.5.1, the TACACS+ shared secret gets logged via syslog if In support.c in pam_tacplus 1.3.8 through 1.5.1, the TACACS+ shared secret gets logged via syslog if the DEBUG loglevel and journald are used.
nvd
CVE-2021-45911P3HIGHCVSS 7.8v9.02021-12-28
CVE-2021-45911 [HIGH] CWE-787 CVE-2021-45911: An issue was discovered in gif2apng 1.9. There is a heap-based buffer overflow in the main function. An issue was discovered in gif2apng 1.9. There is a heap-based buffer overflow in the main function. It allows an attacker to write 2 bytes outside the boundaries of the buffer.
nvd
CVE-2019-18602P3HIGHCVSS 7.5v8.02019-10-29
CVE-2019-18602 [HIGH] CWE-908 CVE-2019-18602: OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to an information disclosure vulnerability bec OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to an information disclosure vulnerability because uninitialized scalars are sent over the network to a peer.
nvd
CVE-2021-3909P3HIGHCVSS 7.5v11.02021-11-11
CVE-2021-3909 [HIGH] CWE-400 CVE-2021-3909: OctoRPKI does not limit the length of a connection, allowing for a slowloris DOS attack to take plac OctoRPKI does not limit the length of a connection, allowing for a slowloris DOS attack to take place which makes OctoRPKI wait forever. Specifically, the repository that OctoRPKI sends HTTP requests to will keep the connection open for a day before a response is returned, but does keep drip feeding new bytes to keep the connection alive.
nvd
CVE-2018-10878P3HIGHCVSS 7.8v8.02018-07-26
CVE-2018-10878 [HIGH] CWE-787 CVE-2018-10878: A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bounds writ A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bounds write and a denial of service or unspecified other impact is possible by mounting and operating a crafted ext4 filesystem image.
nvd
CVE-2016-6318P3HIGHCVSS 7.8v8.02016-09-07
CVE-2016-6318 [HIGH] CWE-787 CVE-2016-6318: Stack-based buffer overflow in the FascistGecosUser function in lib/fascist.c in cracklib allows loc Stack-based buffer overflow in the FascistGecosUser function in lib/fascist.c in cracklib allows local users to cause a denial of service (application crash) or gain privileges via a long GECOS field, involving longbuffer.
nvd
CVE-2018-2668P3MEDIUMCVSS 6.5v7.0v8.0+1 more2018-01-18
CVE-2018-2668 [MEDIUM] CVE-2018-2668: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Suppo Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.5.58 and prior, 5.6.38 and prior and 5.7.20 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulner
nvd
CVE-2018-2622P3MEDIUMCVSS 6.5v7.0v8.0+1 more2018-01-18
CVE-2018-2622 [MEDIUM] CVE-2018-2622: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported v Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.5.58 and prior, 5.6.38 and prior and 5.7.20 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerabilit
nvd
Debian Linux vulnerabilities | cvebase