Debian Linux vulnerabilities
9,954 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358
Vulnerabilities
Page 237 of 498
CVE-2020-5390P3HIGHCVSS 7.5v8.0v9.0+1 more2020-01-13
CVE-2020-5390 [HIGH] CWE-347 CVE-2020-5390: PySAML2 before 5.0.0 does not check that the signature in a SAML document is enveloped and thus sign
PySAML2 before 5.0.0 does not check that the signature in a SAML document is enveloped and thus signature wrapping is effective, i.e., it is affected by XML Signature Wrapping (XSW). The signature information and the node/object that is signed can be in different places and thus the signature verification will succeed, but the wrong data will be used. T
nvd
CVE-2016-1659P3CRITICALCVSS 9.8v8.02016-04-18
CVE-2016-1659 [CRITICAL] CVE-2016-1659: Multiple unspecified vulnerabilities in Google Chrome before 50.0.2661.75 allow attackers to cause a
Multiple unspecified vulnerabilities in Google Chrome before 50.0.2661.75 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2018-4180P3HIGHCVSS 7.8v9.02019-01-11
CVE-2018-4180 [HIGH] CVE-2018-4180: In macOS High Sierra before 10.13.5, an issue existed in CUPS. This issue was addressed with improve
In macOS High Sierra before 10.13.5, an issue existed in CUPS. This issue was addressed with improved access restrictions.
nvd
CVE-2022-2122P3HIGHCVSS 7.8v10.0v11.02022-07-19
CVE-2022-2122 [HIGH] CWE-122 CVE-2022-2122: DOS / potential heap overwrite in qtdemux using zlib decompression. Integer overflow in qtdemux elem
DOS / potential heap overwrite in qtdemux using zlib decompression. Integer overflow in qtdemux element in qtdemux_inflate function which causes a segfault, or could cause a heap overwrite, depending on libc and OS. Depending on the libc used, and the underlying OS capabilities, it could be just a segfault or a heap overwrite.
nvd
CVE-2022-1922P3HIGHCVSS 7.8v10.0v11.02022-07-19
CVE-2022-1922 [HIGH] CWE-122 CVE-2022-1922: DOS / potential heap overwrite in mkv demuxing using zlib decompression. Integer overflow in matrosk
DOS / potential heap overwrite in mkv demuxing using zlib decompression. Integer overflow in matroskademux element in gst_matroska_decompress_data function which causes a segfault, or could cause a heap overwrite, depending on libc and OS. Depending on the libc used, and the underlying OS capabilities, it could be just a segfault or a heap overwrite. If
nvd
CVE-2020-36478P3HIGHCVSS 7.5v9.0v10.02021-08-23
CVE-2020-36478 [HIGH] CWE-295 CVE-2020-36478: An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). A N
An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). A NULL algorithm parameters entry looks identical to an array of REAL (size zero) and thus the certificate is considered valid. However, if the parameters do not match in any way, then the certificate should be considered invalid.
nvd
CVE-2017-17805P3HIGHCVSS 7.8v8.0v9.02017-12-20
CVE-2017-17805 [HIGH] CWE-20 CVE-2017-17805: The Salsa20 encryption algorithm in the Linux kernel before 4.14.8 does not correctly handle zero-le
The Salsa20 encryption algorithm in the Linux kernel before 4.14.8 does not correctly handle zero-length inputs, allowing a local attacker able to use the AF_ALG-based skcipher interface (CONFIG_CRYPTO_USER_API_SKCIPHER) to cause a denial of service (uninitialized-memory free and kernel crash) or have unspecified other impact by executing a crafted seq
nvd
CVE-2013-4251P3HIGHCVSS 7.8v8.0v9.0+1 more2019-11-04
CVE-2013-4251 [HIGH] CWE-269 CVE-2013-4251: The scipy.weave component in SciPy before 0.12.1 creates insecure temporary directories.
The scipy.weave component in SciPy before 0.12.1 creates insecure temporary directories.
nvd
CVE-2021-39252P3HIGHCVSS 7.8v9.0v10.0+1 more2021-09-07
CVE-2021-39252 [HIGH] CWE-125 CVE-2021-39252: A crafted NTFS image can cause an out-of-bounds read in ntfs_ie_lookup in NTFS-3G < 2021.8.22.
A crafted NTFS image can cause an out-of-bounds read in ntfs_ie_lookup in NTFS-3G < 2021.8.22.
nvd
CVE-2021-39253P3HIGHCVSS 7.8v9.0v10.0+1 more2021-09-07
CVE-2021-39253 [HIGH] CWE-125 CVE-2021-39253: A crafted NTFS image can cause an out-of-bounds read in ntfs_runlists_merge_i in NTFS-3G < 2021.8.22
A crafted NTFS image can cause an out-of-bounds read in ntfs_runlists_merge_i in NTFS-3G < 2021.8.22.
nvd
CVE-2022-1923P3HIGHCVSS 7.8v10.0v11.02022-07-19
CVE-2022-1923 [HIGH] CWE-122 CVE-2022-1923: DOS / potential heap overwrite in mkv demuxing using bzip decompression. Integer overflow in matrosk
DOS / potential heap overwrite in mkv demuxing using bzip decompression. Integer overflow in matroskademux element in bzip decompression function which causes a segfault, or could cause a heap overwrite, depending on libc and OS. Depending on the libc used, and the underlying OS capabilities, it could be just a segfault or a heap overwrite. If the libc
nvd
CVE-2022-1924P3HIGHCVSS 7.8v10.0v11.02022-07-19
CVE-2022-1924 [HIGH] CWE-122 CVE-2022-1924: DOS / potential heap overwrite in mkv demuxing using lzo decompression. Integer overflow in matroska
DOS / potential heap overwrite in mkv demuxing using lzo decompression. Integer overflow in matroskademux element in lzo decompression function which causes a segfault, or could cause a heap overwrite, depending on libc and OS. Depending on the libc used, and the underlying OS capabilities, it could be just a segfault or a heap overwrite. If the libc us
nvd
CVE-2021-37980P3HIGHCVSS 7.4v10.0v11.02021-11-02
CVE-2021-37980 [HIGH] CVE-2021-37980: Inappropriate implementation in Sandbox in Google Chrome prior to 94.0.4606.81 allowed a remote atta
Inappropriate implementation in Sandbox in Google Chrome prior to 94.0.4606.81 allowed a remote attacker to potentially bypass site isolation via Windows.
nvd
CVE-2021-33287P3HIGHCVSS 7.8v9.0v10.0+1 more2021-09-07
CVE-2021-33287 [HIGH] CWE-787 CVE-2021-33287: In NTFS-3G versions < 2021.8.22, when specially crafted NTFS attributes are read in the function ntf
In NTFS-3G versions < 2021.8.22, when specially crafted NTFS attributes are read in the function ntfs_attr_pread_i, a heap buffer overflow can occur and allow for writing to arbitrary memory or denial of service of the application.
nvd
CVE-2018-14678P3HIGHCVSS 7.8v8.0v9.02018-07-28
CVE-2018-14678 [HIGH] CWE-665 CVE-2018-14678: An issue was discovered in the Linux kernel through 4.17.11, as used in Xen through 4.11.x. The xen_
An issue was discovered in the Linux kernel through 4.17.11, as used in Xen through 4.11.x. The xen_failsafe_callback entry point in arch/x86/entry/entry_64.S does not properly maintain RBX, which allows local users to cause a denial of service (uninitialized memory usage and system crash). Within Xen, 64-bit x86 PV Linux guest OS users can trigger a
nvd
CVE-2022-27776P3MEDIUMCVSS 6.5v10.0v11.02022-06-02
CVE-2022-27776 [MEDIUM] CWE-522 CVE-2022-27776: A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authenticati
A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.
nvd
CVE-2019-16237P3HIGHCVSS 7.5v10.02019-09-11
CVE-2019-16237 [HIGH] CWE-346 CVE-2019-16237: Dino before 2019-09-10 does not properly check the source of an MAM message in module/xep/0313_messa
Dino before 2019-09-10 does not properly check the source of an MAM message in module/xep/0313_message_archive_management.vala.
nvd
CVE-2019-9735P3MEDIUMCVSS 6.5v9.02019-03-13
CVE-2019-9735 [MEDIUM] CWE-755 CVE-2019-9735: An issue was discovered in the iptables firewall module in OpenStack Neutron before 10.0.8, 11.x bef
An issue was discovered in the iptables firewall module in OpenStack Neutron before 10.0.8, 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By setting a destination port in a security group rule along with a protocol that doesn't support that option (for example, VRRP), an authenticated user may block further application of security gr
nvd
CVE-2015-5723P3HIGHCVSS 7.8v7.0v8.02016-06-07
CVE-2015-5723 [HIGH] CWE-264 CVE-2015-5723: Doctrine Annotations before 1.2.7, Cache before 1.3.2 and 1.4.x before 1.4.2, Common before 2.4.3 an
Doctrine Annotations before 1.2.7, Cache before 1.3.2 and 1.4.x before 1.4.2, Common before 2.4.3 and 2.5.x before 2.5.1, ORM before 2.4.8 or 2.5.x before 2.5.1, MongoDB ODM before 1.0.2, and MongoDB ODM Bundle before 3.0.1 use world-writable permissions for cache directories, which allows local users to execute arbitrary PHP code with additional privil
nvd
CVE-2017-1000111P3HIGHCVSS 7.8v8.0v9.02017-10-05
CVE-2017-1000111 [HIGH] CVE-2017-1000111: Linux kernel: heap out-of-bounds in AF_PACKET sockets. This new issue is analogous to previously dis
Linux kernel: heap out-of-bounds in AF_PACKET sockets. This new issue is analogous to previously disclosed CVE-2016-8655. In both cases, a socket option that changes socket state may race with safety checks in packet_set_ring. Previously with PACKET_VERSION. This time with PACKET_RESERVE. The solution is similar: lock the socket for the update. This issue
nvd