cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 236 of 498
CVE-2018-2665P3MEDIUMCVSS 6.5v7.0v8.0+1 more2018-01-18
CVE-2018-2665 [MEDIUM] CVE-2018-2665: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Suppo Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.5.58 and prior, 5.6.38 and prior and 5.7.20 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulner
nvd
CVE-2018-2640P3MEDIUMCVSS 6.5v7.0v8.0+1 more2018-01-18
CVE-2018-2640 [MEDIUM] CVE-2018-2640: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Suppo Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.5.58 and prior, 5.6.38 and prior and 5.7.20 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulner
nvd
CVE-2022-0943P3HIGHCVSS 7.8v9.0v10.02022-03-14
CVE-2022-0943 [HIGH] CWE-122 CVE-2022-0943: Heap-based Buffer Overflow occurs in vim in GitHub repository vim/vim prior to 8.2.4563. Heap-based Buffer Overflow occurs in vim in GitHub repository vim/vim prior to 8.2.4563.
nvd
CVE-2022-41999P3HIGHCVSS 7.5v11.02022-12-22
CVE-2022-41999 [HIGH] CWE-476 CVE-2022-41999: A denial of service vulnerability exists in the DDS native tile reading functionality of OpenImageIO A denial of service vulnerability exists in the DDS native tile reading functionality of OpenImageIO Project OpenImageIO v2.3.19.0 and v2.4.4.2. A specially-crafted .dds can lead to denial of service. An attacker can provide a malicious file to trigger this vulnerability.
nvd
CVE-2011-1526P3MEDIUMCVSS 6.5v5.0v6.02011-07-11
CVE-2011-1526 [MEDIUM] CWE-269 CVE-2011-1526: ftpd.c in the GSS-API FTP daemon in MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.1 and ea ftpd.c in the GSS-API FTP daemon in MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.1 and earlier does not check the krb5_setegid return value, which allows remote authenticated users to bypass intended group access restrictions, and create, overwrite, delete, or read files, via standard FTP commands, related to missing autoconf tests in a con
nvd
CVE-2023-38802P3HIGHCVSS 7.5v10.0v11.0+1 more2023-08-29
CVE-2023-38802 [HIGH] CWE-354 CVE-2023-38802: FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of service via a crafted BGP update with a corrupted attribute 23 (Tunnel Encapsulation).
nvd
CVE-2022-45693P3HIGHCVSS 7.5v10.0v11.02022-12-13
CVE-2022-45693 [HIGH] CWE-787 CVE-2022-45693: Jettison before v1.5.2 was discovered to contain a stack overflow via the map parameter. This vulner Jettison before v1.5.2 was discovered to contain a stack overflow via the map parameter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted string.
nvd
CVE-2022-45939P3HIGHCVSS 7.8v10.0v11.02022-11-28
CVE-2022-45939 [HIGH] CWE-78 CVE-2022-45939: GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses the system C library function in its implementation of the ctags program. For example, a victim may use the "ctags *" command (suggested in the ctags documentation) in a situation where the current working
nvd
CVE-2005-4890P3HIGHCVSS 7.8v8.0v9.0+1 more2019-11-04
CVE-2005-4890 [HIGH] CWE-20 CVE-2005-4890: There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - use There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program". The user session can be escaped to the parent session by using the TIOCSTI ioctl to push characters into the input buffer to be read by the next process.
nvd
CVE-2019-16235P3HIGHCVSS 7.5v10.02019-09-11
CVE-2019-16235 [HIGH] CWE-346 CVE-2019-16235: Dino before 2019-09-10 does not properly check the source of a carbons message in module/xep/0280_me Dino before 2019-09-10 does not properly check the source of a carbons message in module/xep/0280_message_carbons.vala.
nvd
CVE-2017-7980P3HIGHCVSS 7.8v8.02017-07-25
CVE-2017-7980 [HIGH] CWE-119 CVE-2017-7980: Heap-based buffer overflow in Cirrus CLGD 54xx VGA Emulator in Quick Emulator (Qemu) 2.8 and earlier Heap-based buffer overflow in Cirrus CLGD 54xx VGA Emulator in Quick Emulator (Qemu) 2.8 and earlier allows local guest OS users to execute arbitrary code or cause a denial of service (crash) via vectors related to a VNC client updating its display after a VGA operation.
nvd
CVE-2015-5260P3HIGHCVSS 7.8v7.0v8.02016-06-07
CVE-2015-5260 [HIGH] CWE-119 CVE-2015-5260: Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to cause a denial of service Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host via QXL commands related to the surface_id parameter.
nvd
CVE-2020-13974P3HIGHCVSS 7.8v9.02020-06-09
CVE-2020-13974 [HIGH] CWE-190 CVE-2020-13974: An issue was discovered in the Linux kernel 4.4 through 5.7.1. drivers/tty/vt/keyboard.c has an inte An issue was discovered in the Linux kernel 4.4 through 5.7.1. drivers/tty/vt/keyboard.c has an integer overflow if k_ascii is called several times in a row, aka CID-b86dab054059. NOTE: Members in the community argue that the integer overflow does not lead to a security issue in this case.
nvd
CVE-2021-3410P3HIGHCVSS 7.8v9.02021-02-23
CVE-2021-3410 [HIGH] CWE-119 CVE-2021-3410: A flaw was found in libcaca v0.99.beta19. A buffer overflow issue in caca_resize function in libcaca A flaw was found in libcaca v0.99.beta19. A buffer overflow issue in caca_resize function in libcaca/caca/canvas.c may lead to local execution of arbitrary code in the user context.
nvd
CVE-2014-8369P3HIGHCVSS 7.8v7.02014-11-10
CVE-2014-8369 [HIGH] CVE-2014-8369: The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through 3.17.2 miscalculate The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through 3.17.2 miscalculates the number of pages during the handling of a mapping failure, which allows guest OS users to cause a denial of service (host OS page unpinning) or possibly have unspecified other impact by leveraging guest OS privileges. NOTE: this vulnerability exists because
nvd
CVE-2012-6071P3HIGHCVSS 7.5v8.0v9.0+1 more2019-11-19
CVE-2012-6071 [HIGH] CWE-295 CVE-2012-6071: nuSOAP before 0.7.3-5 does not properly check the hostname of a cert. nuSOAP before 0.7.3-5 does not properly check the hostname of a cert.
nvd
CVE-2020-7729P3HIGHCVSS 7.1v9.02020-09-03
CVE-2020-7729 [HIGH] CWE-1188 CVE-2020-7729: The package grunt before 1.3.0 are vulnerable to Arbitrary Code Execution due to the default usage o The package grunt before 1.3.0 are vulnerable to Arbitrary Code Execution due to the default usage of the function load() instead of its secure replacement safeLoad() of the package js-yaml inside grunt.file.readYAML.
nvd
CVE-2018-13406P3HIGHCVSS 7.8v8.02018-07-06
CVE-2018-13406 [HIGH] CWE-190 CVE-2018-13406: An integer overflow in the uvesafb_setcmap function in drivers/video/fbdev/uvesafb.c in the Linux ke An integer overflow in the uvesafb_setcmap function in drivers/video/fbdev/uvesafb.c in the Linux kernel before 4.17.4 could result in local attackers being able to crash the kernel or potentially elevate privileges because kmalloc_array is not used.
nvd
CVE-2021-36773P3HIGHCVSS 7.5v9.02021-07-18
CVE-2021-36773 [HIGH] CWE-674 CVE-2021-36773: uBlock Origin before 1.36.2 and nMatrix before 4.4.9 support an arbitrary depth of parameter nesting uBlock Origin before 1.36.2 and nMatrix before 4.4.9 support an arbitrary depth of parameter nesting for strict blocking, which allows crafted web sites to cause a denial of service (unbounded recursion that can trigger memory consumption and a loss of all blocking functionality).
nvd
CVE-2018-2794P3HIGHCVSS 7.7v8.0v9.02018-04-19
CVE-2018-2794 [HIGH] CVE-2018-2794: Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: Security). Supporte Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u181, 7u171, 8u162, 10 and JRockit: R28.3.17. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Java SE, JRockit executes to compromise Java SE, JRockit. Successful
nvd
Debian Linux vulnerabilities | cvebase