Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 24 of 498
CVE-2022-21449P2HIGHCVSS 7.5v10.0v11.02022-04-19
CVE-2022-21449 [HIGH] CVE-2022-21449: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (co
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 17.0.2 and 18; Oracle GraalVM Enterprise Edition: 21.3.1 and 22.0.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to c
nvd
CVE-2020-36221P3HIGHCVSS 7.5v9.0v10.02021-01-26
CVE-2020-36221 [HIGH] CWE-191 CVE-2020-36221: An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd crashes in the Certif
An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd crashes in the Certificate Exact Assertion processing, resulting in denial of service (schema_init.c serialNumberAndIssuerCheck).
nvd
CVE-2018-5740P2HIGHCVSS 7.5v8.0v9.02019-01-16
CVE-2018-5740 [HIGH] CWE-617 CVE-2018-5740: "deny-answer-aliases" is a little-used feature intended to help recursive server operators protect e
"deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS rebinding attacks, a potential method of circumventing the security model used by client browsers. However, a defect in this feature makes it easy, when the feature is in use, to experience an assertion failure in name.c. Affects BIND
nvd
CVE-2017-7376P2CRITICALCVSS 9.8v8.0v9.02018-02-19
CVE-2017-7376 [CRITICAL] CWE-119 CVE-2017-7376: Buffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorr
Buffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorrect limit for port values when handling redirects.
nvd
CVE-2017-16353P3MEDIUMCVSS 6.5PoCv7.0v8.0+1 more2017-11-01
CVE-2017-16353 [MEDIUM] CWE-125 CVE-2017-16353: GraphicsMagick 1.3.26 is vulnerable to a memory information disclosure vulnerability found in the De
GraphicsMagick 1.3.26 is vulnerable to a memory information disclosure vulnerability found in the DescribeImage function of the magick/describe.c file, because of a heap-based buffer over-read. The portion of the code containing the vulnerability is responsible for printing the IPTC Profile information contained in the image. This vulnerability can
nvd
CVE-2021-40346P2HIGHCVSS 7.5v11.02021-09-08
CVE-2021-40346 [HIGH] CWE-190 CVE-2021-40346: An integer overflow exists in HAProxy 2.0 through 2.5 in htx_add_header that can be exploited to per
An integer overflow exists in HAProxy 2.0 through 2.5 in htx_add_header that can be exploited to perform an HTTP request smuggling attack, allowing an attacker to bypass all configured http-request HAProxy ACLs and possibly other ACLs.
nvd
CVE-2023-6112P2HIGHCVSS 8.8v11.0v12.02023-11-15
CVE-2023-6112 [HIGH] CWE-416 CVE-2023-6112: Use after free in Navigation in Google Chrome prior to 119.0.6045.159 allowed a remote attacker to p
Use after free in Navigation in Google Chrome prior to 119.0.6045.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2021-21350P2CRITICALCVSS 9.8v9.0v10.0+1 more2021-03-23
CVE-2021-21350 [CRITICAL] CWE-434 CVE-2021-21350: XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to execute arbitrary code only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist lim
nvd
CVE-2021-36160P2HIGHCVSS 7.5v9.0v10.0+1 more2021-09-16
CVE-2021-36160 [HIGH] CWE-125 CVE-2021-36160: A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory an
A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory and crash (DoS). This issue affects Apache HTTP Server versions 2.4.30 to 2.4.48 (inclusive).
nvd
CVE-2020-26259P3MEDIUMCVSS 6.8v9.0v10.02020-12-16
CVE-2020-26259 [MEDIUM] CWE-78 CVE-2020-26259: XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling. The vulnerability may allow a remote attacker to delete arbitrary know files on the host as log as the executing process has sufficient rights only by manipulating th
nvd
CVE-2018-18820P2HIGHCVSS 8.1v8.0v9.02018-11-05
CVE-2018-18820 [HIGH] CWE-119 CVE-2018-18820: A buffer overflow was discovered in the URL-authentication backend of the Icecast before 2.4.4. If t
A buffer overflow was discovered in the URL-authentication backend of the Icecast before 2.4.4. If the backend is enabled, then any malicious HTTP client can send a request for that specific resource including a crafted header, leading to denial of service and potentially remote code execution.
nvd
CVE-2021-3712P2HIGHCVSS 7.4v9.0v10.0+1 more2021-08-24
CVE-2021-3712 [HIGH] CWE-125 CVE-2021-3712: ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which contains a
ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which contains a buffer holding the string data and a field holding the buffer length. This contrasts with normal C strings which are repesented as a buffer for the string data which is terminated with a NUL (0) byte. Although not a strict requirement, ASN.1 strings that
nvd
CVE-2007-4476P3HIGHCVSS 7.5PoCv3.1v4.02007-09-05
CVE-2007-4476 [HIGH] CWE-119 CVE-2007-4476: Buffer overflow in the safer_name_suffix function in GNU tar has unspecified attack vectors and impa
Buffer overflow in the safer_name_suffix function in GNU tar has unspecified attack vectors and impact, resulting in a "crashing stack."
nvd
CVE-2021-32626P2HIGHCVSS 8.8v10.0v11.02021-10-04
CVE-2021-32626 [HIGH] CWE-122 CVE-2021-32626: Redis is an open source, in-memory database that persists on disk. In affected versions specially cr
Redis is an open source, in-memory database that persists on disk. In affected versions specially crafted Lua scripts executing in Redis can cause the heap-based Lua stack to be overflowed, due to incomplete checks for this condition. This can result with heap corruption and potentially remote code execution. This problem exists in all versions of Red
nvd
CVE-2023-34966P2HIGHCVSS 7.5v11.0v12.02023-07-20
CVE-2023-34966 [HIGH] CWE-835 CVE-2023-34966: An infinite loop vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing S
An infinite loop vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC packets sent by the client, the core unmarshalling function sl_unpack_loop() did not validate a field in the network packet that contains the count of elements in an array-like structure. By passing 0 as the count value, the attacked
nvd
CVE-2017-12379P2CRITICALCVSS 9.8v7.02018-01-26
CVE-2017-12379 [CRITICAL] CWE-119 CVE-2017-12379: ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unau
ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or potentially execute arbitrary code on an affected device. The vulnerability is due to improper input validation checking mechanisms in the message parsing function on an af
nvd
CVE-2021-22930P2CRITICALCVSS 9.8v10.02021-10-07
CVE-2021-22930 [CRITICAL] CWE-416 CVE-2021-22930: Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to a use after free attack where an attack
Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to a use after free attack where an attacker might be able to exploit the memory corruption, to change process behavior.
nvd
CVE-2020-13933P2HIGHCVSS 7.5v9.02020-08-17
CVE-2020-13933 [HIGH] CVE-2020-13933: Apache Shiro before 1.6.0, when using Apache Shiro, a specially crafted HTTP request may cause an au
Apache Shiro before 1.6.0, when using Apache Shiro, a specially crafted HTTP request may cause an authentication bypass.
nvd
CVE-2020-36228P3HIGHCVSS 7.5v9.0v10.02021-01-26
CVE-2020-36228 [HIGH] CWE-191 CVE-2020-36228: An integer underflow was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Certif
An integer underflow was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Certificate List Exact Assertion processing, resulting in denial of service.
nvd
CVE-2016-5385P2HIGHCVSS 8.1v8.02016-07-19
CVE-2016-5385 [HIGH] CWE-601 CVE-2016-5385: PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and theref
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy hea
nvd