cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 242 of 498
CVE-2019-19783P3MEDIUMCVSS 6.5v9.0v10.02019-12-16
CVE-2019-19783 [MEDIUM] CWE-269 CVE-2019-19783: An issue was discovered in Cyrus IMAP before 2.5.15, 3.0.x before 3.0.13, and 3.1.x through 3.1.8. I An issue was discovered in Cyrus IMAP before 2.5.15, 3.0.x before 3.0.13, and 3.1.x through 3.1.8. If sieve script uploading is allowed (3.x) or certain non-default sieve options are enabled (2.x), a user with a mail account on the service can use a sieve script containing a fileinto directive to create any mailbox with administrator privileges, bec
nvd
CVE-2021-2161P3MEDIUMCVSS 5.9v9.0v10.02021-04-22
CVE-2021-2161 [MEDIUM] CVE-2021-2161: Vulnerability in the Java SE, Java SE Embedded, Oracle GraalVM Enterprise Edition product of Oracle Vulnerability in the Java SE, Java SE Embedded, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u291, 8u281, 11.0.10, 16; Java SE Embedded: 8u281; Oracle GraalVM Enterprise Edition: 19.3.5, 20.3.1.2 and 21.0.0.2. Difficult to exploit vulnerability allows unauthenticated atta
nvd
CVE-2021-36740P3MEDIUMCVSS 6.5v10.0v11.02021-07-14
CVE-2021-36740 [MEDIUM] CWE-444 CVE-2021-36740: Varnish Cache, with HTTP/2 enabled, allows request smuggling and VCL authorization bypass via a larg Varnish Cache, with HTTP/2 enabled, allows request smuggling and VCL authorization bypass via a large Content-Length header for a POST request. This affects Varnish Enterprise 6.0.x before 6.0.8r3, and Varnish Cache 5.x and 6.x before 6.5.2, 6.6.x before 6.6.1, and 6.0 LTS before 6.0.8.
nvd
CVE-2014-9658P3HIGHCVSS 7.5v7.02015-02-08
CVE-2014-9658 [HIGH] CWE-125 CVE-2014-9658: The tt_face_load_kern function in sfnt/ttkern.c in FreeType before 2.5.4 enforces an incorrect minim The tt_face_load_kern function in sfnt/ttkern.c in FreeType before 2.5.4 enforces an incorrect minimum table length, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted TrueType font.
nvd
CVE-2021-22947P3MEDIUMCVSS 5.9v9.0v10.0+1 more2021-09-29
CVE-2021-22947 [MEDIUM] CWE-310 CVE-2021-22947: When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS security, the server can respond and send back multiple responses at once that curl caches. curl would then upgrade to TLS but not flush the in-queue of cached responses but instead continue using and trustingthe responses it got *b
nvd
CVE-2017-15238P3HIGHCVSS 8.8v9.02017-10-11
CVE-2017-15238 [HIGH] CWE-416 CVE-2017-15238: ReadOneJNGImage in coders/png.c in GraphicsMagick 1.3.26 has a use-after-free issue when the height ReadOneJNGImage in coders/png.c in GraphicsMagick 1.3.26 has a use-after-free issue when the height or width is zero, related to ReadJNGImage.
nvd
CVE-2019-16391P3MEDIUMCVSS 6.5v8.0v9.0+1 more2019-09-17
CVE-2019-16391 [MEDIUM] CVE-2019-16391: SPIP before 3.1.11 and 3.2 before 3.2.5 allows authenticated visitors to modify any published conten SPIP before 3.1.11 and 3.2 before 3.2.5 allows authenticated visitors to modify any published content and execute other modifications in the database. This is related to ecrire/inc/meta.php and ecrire/inc/securiser_action.php.
nvd
CVE-2016-1231P3MEDIUMCVSS 5.9v7.0v8.02016-01-12
CVE-2016-1231 [MEDIUM] CWE-22 CVE-2016-1231: Directory traversal vulnerability in the HTTP file-serving module (mod_http_files) in Prosody 0.9.x Directory traversal vulnerability in the HTTP file-serving module (mod_http_files) in Prosody 0.9.x before 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) in an unspecified path.
nvd
CVE-2015-3415P3HIGHCVSS 7.5v8.02015-04-24
CVE-2015-3415 [HIGH] CWE-404 CVE-2015-3415: The sqlite3VdbeExec function in vdbe.c in SQLite before 3.8.9 does not properly implement comparison The sqlite3VdbeExec function in vdbe.c in SQLite before 3.8.9 does not properly implement comparison operators, which allows context-dependent attackers to cause a denial of service (invalid free operation) or possibly have unspecified other impact via a crafted CHECK clause, as demonstrated by CHECK(0&O>O) in a CREATE TABLE statement.
nvd
CVE-2017-5356P3HIGHCVSS 7.5v7.02017-03-03
CVE-2017-5356 [HIGH] CWE-125 CVE-2017-5356: Irssi before 0.8.21 allows remote attackers to cause a denial of service (out-of-bounds read and cra Irssi before 0.8.21 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a string containing a formatting sequence (%[) without a closing bracket (]).
nvd
CVE-2020-15157P3MEDIUMCVSS 6.1v10.02020-10-16
CVE-2020-15157 [MEDIUM] CWE-522 CVE-2020-15157: In containerd (an industry-standard container runtime) before version 1.2.14 there is a credential l In containerd (an industry-standard container runtime) before version 1.2.14 there is a credential leaking vulnerability. If a container image manifest in the OCI Image format or Docker Image V2 Schema 2 format includes a URL for the location of a specific image layer (otherwise known as a “foreign layer”), the default containerd resolver will follo
nvd
CVE-2022-24808P3MEDIUMCVSS 6.5v10.0v11.02024-04-16
CVE-2022-24808 [MEDIUM] CWE-476 CVE-2022-24808: net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can use a malformed OID in a `SET` request to `NET-SNMP-AGENT-MIB::nsLogTable` to cause a NULL pointer dereference. Version 5.9.2 contains a patch. Users should use strong SNMPv3 credentials and avoid sharing
nvd
CVE-2010-2519P3MEDIUMCVSS 6.8v5.02010-08-19
CVE-2010-2519 [MEDIUM] CWE-787 CVE-2010-2519: Heap-based buffer overflow in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType befor Heap-based buffer overflow in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.4.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted length value in a POST fragment header in a font file.
nvd
CVE-2008-2726P3HIGHCVSS 7.8v4.02008-06-24
CVE-2008-2726 [HIGH] CWE-189 CVE-2008-2726: Integer overflow in the (1) rb_ary_splice function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p23 Integer overflow in the (1) rb_ary_splice function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 before 1.8.7-p22, and 1.9.0 before 1.9.0-2; and (2) the rb_ary_replace function in 1.6.x allows context-dependent attackers to trigger memory corruption, aka the "beg + rlen" issue. NOTE: as of 20080624, there has been in
nvd
CVE-2021-41183P3MEDIUMCVSS 6.1v9.02021-10-26
CVE-2021-41183 [MEDIUM] CWE-79 CVE-2021-41183: jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the valu jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The values passed to various `*Text` options are now always treated as pure text, not HTML. A workaround is
nvd
CVE-2019-19074P3HIGHCVSS 7.5v9.02019-11-18
CVE-2019-19074 [HIGH] CWE-401 CVE-2019-19074: A memory leak in the ath9k_wmi_cmd() function in drivers/net/wireless/ath/ath9k/wmi.c in the Linux k A memory leak in the ath9k_wmi_cmd() function in drivers/net/wireless/ath/ath9k/wmi.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption), aka CID-728c1e2a05e4.
nvd
CVE-2021-32728P3MEDIUMCVSS 6.5v10.0v11.02021-08-18
CVE-2021-32728 [MEDIUM] CWE-295 CVE-2021-32728: The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with a computer. C The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with a computer. Clients using the Nextcloud end-to-end encryption feature download the public and private key via an API endpoint. In versions prior to 3.3.0, the Nextcloud Desktop client fails to check if a private key belongs to previously downloaded public certific
nvd
CVE-2008-4359P3HIGHCVSS 7.5v4.02008-10-03
CVE-2008-4359 [HIGH] CWE-200 CVE-2008-4359: lighttpd before 1.4.20 compares URIs to patterns in the (1) url.redirect and (2) url.rewrite configu lighttpd before 1.4.20 compares URIs to patterns in the (1) url.redirect and (2) url.rewrite configuration settings before performing URL decoding, which might allow remote attackers to bypass intended access restrictions, and obtain sensitive information or possibly modify data.
nvd
CVE-2020-11655P3HIGHCVSS 7.5v8.0v9.02020-04-09
CVE-2020-11655 [HIGH] CWE-665 CVE-2020-11655: SQLite through 3.31.1 allows attackers to cause a denial of service (segmentation fault) via a malfo SQLite through 3.31.1 allows attackers to cause a denial of service (segmentation fault) via a malformed window-function query because the AggInfo object's initialization is mishandled.
nvd
CVE-2015-8917P3HIGHCVSS 7.5v7.0v8.02016-09-20
CVE-2015-8917 [HIGH] CWE-476 CVE-2015-8917: bsdtar in libarchive before 3.2.0 allows remote attackers to cause a denial of service (NULL pointer bsdtar in libarchive before 3.2.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an invalid character in the name of a cab file.
nvd
Debian Linux vulnerabilities | cvebase