cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 240 of 498
CVE-2020-14765P3MEDIUMCVSS 6.5v9.02020-10-21
CVE-2020-14765 [MEDIUM] CVE-2020-14765: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: FTS). Supported versio Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: FTS). Supported versions that are affected are 5.6.49 and prior, 5.7.31 and prior and 8.0.21 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability c
nvd
CVE-2015-7701P3HIGHCVSS 7.5v7.0v8.0+1 more2017-08-07
CVE-2015-7701 [HIGH] CWE-772 CVE-2015-7701: Memory leak in the CRYPTO_ASSOC function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.7 Memory leak in the CRYPTO_ASSOC function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (memory consumption).
nvd
CVE-2021-20181P3HIGHCVSS 7.5v9.0v10.02021-05-13
CVE-2021-20181 [HIGH] CWE-367 CVE-2021-20181: A race condition flaw was found in the 9pfs server implementation of QEMU up to and including 5.2.0. A race condition flaw was found in the 9pfs server implementation of QEMU up to and including 5.2.0. This flaw allows a malicious 9p client to cause a use-after-free error, potentially escalating their privileges on the system. The highest threat from this vulnerability is to confidentiality, integrity as well as system availability.
nvd
CVE-2018-19935P3HIGHCVSS 7.5v8.0v9.02018-12-07
CVE-2018-19935 [HIGH] CWE-476 CVE-2018-19935: ext/imap/php_imap.c in PHP 5.x and 7.x before 7.3.0 allows remote attackers to cause a denial of ser ext/imap/php_imap.c in PHP 5.x and 7.x before 7.3.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty string in the message argument to the imap_mail function.
nvd
CVE-2022-2996P3HIGHCVSS 7.4v10.02022-09-01
CVE-2022-2996 [HIGH] CWE-295 CVE-2022-2996: A flaw was found in the python-scciclient when making an HTTPS connection to a server where the serv A flaw was found in the python-scciclient when making an HTTPS connection to a server where the server's certificate would not be verified. This issue opens up the connection to possible Man-in-the-middle (MITM) attacks.
nvd
CVE-2020-36158P3MEDIUMCVSS 6.7v9.0v10.02021-01-05
CVE-2020-36158 [MEDIUM] CWE-120 CVE-2020-36158: mwifiex_cmd_802_11_ad_hoc_start in drivers/net/wireless/marvell/mwifiex/join.c in the Linux kernel t mwifiex_cmd_802_11_ad_hoc_start in drivers/net/wireless/marvell/mwifiex/join.c in the Linux kernel through 5.10.4 might allow remote attackers to execute arbitrary code via a long SSID value, aka CID-5c455c5ab332.
nvd
CVE-2020-12108P3MEDIUMCVSS 6.5v9.0v10.02020-05-06
CVE-2020-12108 [MEDIUM] CWE-74 CVE-2020-12108: /options/mailman in GNU Mailman before 2.1.31 allows Arbitrary Content Injection. /options/mailman in GNU Mailman before 2.1.31 allows Arbitrary Content Injection.
nvd
CVE-2016-4483P3HIGHCVSS 7.5v8.02017-04-11
CVE-2016-4483 [HIGH] CWE-502 CVE-2016-4483: The xmlBufAttrSerializeTxtContent function in xmlsave.c in libxml2 allows context-dependent attacker The xmlBufAttrSerializeTxtContent function in xmlsave.c in libxml2 allows context-dependent attackers to cause a denial of service (out-of-bounds read and application crash) via a non-UTF-8 attribute value, related to serialization. NOTE: this vulnerability may be a duplicate of CVE-2016-3627.
nvd
CVE-2014-0460P3MEDIUMCVSS 5.8v6.0v7.0+1 more2014-04-16
CVE-2014-0460 [MEDIUM] CVE-2014-0460: Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality and integrity via vectors related to JNDI.
nvd
CVE-2021-21703P3HIGHCVSS 7.0v9.0v10.0+1 more2021-10-25
CVE-2021-21703 [HIGH] CWE-284 CVE-2021-21703: In PHP versions 7.3.x up to and including 7.3.31, 7.4.x below 7.4.25 and 8.0.x below 8.0.12, when ru In PHP versions 7.3.x up to and including 7.3.31, 7.4.x below 7.4.25 and 8.0.x below 8.0.12, when running PHP FPM SAPI with main FPM daemon process running as root and child worker processes running as lower-privileged users, it is possible for the child processes to access memory shared with the main process and write to it, modifying it in a way tha
nvd
CVE-2014-1497P3HIGHCVSS 8.8v7.0v8.02014-03-19
CVE-2014-1497 [HIGH] CWE-125 CVE-2014-1497: The mozilla::WaveReader::DecodeAudioData function in Mozilla Firefox before 28.0, Firefox ESR 24.x b The mozilla::WaveReader::DecodeAudioData function in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive information from process heap memory, cause a denial of service (out-of-bounds read and application crash), or possibly have unspecified other impac
nvd
CVE-2015-8567P3HIGHCVSS 7.7v8.02017-04-13
CVE-2015-8567 [HIGH] CWE-401 CVE-2015-8567: Memory leak in net/vmxnet3.c in QEMU allows remote attackers to cause a denial of service (memory co Memory leak in net/vmxnet3.c in QEMU allows remote attackers to cause a denial of service (memory consumption).
nvd
CVE-2017-3138P3MEDIUMCVSS 5.3v8.02019-01-16
CVE-2017-3138 [MEDIUM] CWE-617 CVE-2017-3138: named contains a feature which allows operators to issue commands to a running server by communicati named contains a feature which allows operators to issue commands to a running server by communicating with the server process over a control channel, using a utility program such as rndc. A regression introduced in a recent feature change has created a situation under which some versions of named can be caused to exit with a REQUIRE assertion failure
nvd
CVE-2020-28473P3MEDIUMCVSS 6.8v9.02021-01-18
CVE-2020-28473 [MEDIUM] CWE-444 CVE-2020-28473: The package bottle from 0 and before 0.12.19 are vulnerable to Web Cache Poisoning by using a vector The package bottle from 0 and before 0.12.19 are vulnerable to Web Cache Poisoning by using a vector called parameter cloaking. When the attacker can separate query parameters using a semicolon (;), they can cause a difference in the interpretation of the request between the proxy (running with default configuration) and the server. This can result
nvd
CVE-2017-5507P3HIGHCVSS 7.5v8.0v9.02017-03-24
CVE-2017-5507 [HIGH] CWE-772 CVE-2017-5507: Memory leak in coders/mpc.c in ImageMagick before 6.9.7-4 and 7.x before 7.0.4-4 allows remote attac Memory leak in coders/mpc.c in ImageMagick before 6.9.7-4 and 7.x before 7.0.4-4 allows remote attackers to cause a denial of service (memory consumption) via vectors involving a pixel cache.
nvd
CVE-2020-10730P3MEDIUMCVSS 6.5v9.0v10.02020-07-07
CVE-2020-10730 [MEDIUM] CWE-416 CVE-2020-10730: A NULL pointer dereference, or possible use-after-free flaw was found in Samba AD LDAP server in ver A NULL pointer dereference, or possible use-after-free flaw was found in Samba AD LDAP server in versions before 4.10.17, before 4.11.11 and before 4.12.4. Although some versions of Samba shipped with Red Hat Enterprise Linux do not support Samba in AD mode, the affected code is shipped with the libldb package. This flaw allows an authenticated user
nvd
CVE-2024-24795P3MEDIUMCVSS 6.3v10.02024-04-04
CVE-2024-24795 [MEDIUM] CWE-113 CVE-2024-24795: HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications to cause an HTTP desynchronization attack. Users are recommended to upgrade to version 2.4.59, which fixes this issue.
nvd
CVE-2019-8980P3HIGHCVSS 7.5v8.02019-02-21
CVE-2019-8980 [HIGH] CWE-401 CVE-2019-8980: A memory leak in the kernel_read_file function in fs/exec.c in the Linux kernel through 4.20.11 allo A memory leak in the kernel_read_file function in fs/exec.c in the Linux kernel through 4.20.11 allows attackers to cause a denial of service (memory consumption) by triggering vfs_read failures.
nvd
CVE-2021-22960P3MEDIUMCVSS 6.5v11.02021-11-03
CVE-2021-22960 [MEDIUM] CWE-444 CVE-2021-22960: The parse function in llhttp < 2.1.4 and < 6.0.6. ignores chunk extensions when parsing the body of The parse function in llhttp < 2.1.4 and < 6.0.6. ignores chunk extensions when parsing the body of chunked requests. This leads to HTTP Request Smuggling (HRS) under certain conditions.
nvd
CVE-2021-3482P3MEDIUMCVSS 6.5v9.0v10.02021-04-08
CVE-2021-3482 [MEDIUM] CWE-20 CVE-2021-3482: A flaw was found in Exiv2 in versions before and including 0.27.4-RC1. Improper input validation of A flaw was found in Exiv2 in versions before and including 0.27.4-RC1. Improper input validation of the rawData.size property in Jp2Image::readMetadata() in jp2image.cpp can lead to a heap-based buffer overflow via a crafted JPG image containing malicious EXIF data.
nvd
Debian Linux vulnerabilities | cvebase