Debian Linux vulnerabilities
9,954 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358
Vulnerabilities
Page 250 of 498
CVE-2016-6794P3MEDIUMCVSS 5.3v8.02017-08-10
CVE-2016-6794 [MEDIUM] CVE-2016-6794: When a SecurityManager is configured, a web application's ability to read system properties should b
When a SecurityManager is configured, a web application's ability to read system properties should be controlled by the SecurityManager. In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70, 6.0.0 to 6.0.45 the system property replacement feature for configuration files could be used by a malicious web application to byp
nvd
CVE-2014-0237P4MEDIUMCVSS 5.0v7.0v8.02014-06-01
CVE-2014-0237 [MEDIUM] CWE-399 CVE-2014-0237: The cdf_unpack_summary_info function in cdf.c in the Fileinfo component in PHP before 5.4.29 and 5.5
The cdf_unpack_summary_info function in cdf.c in the Fileinfo component in PHP before 5.4.29 and 5.5.x before 5.5.13 allows remote attackers to cause a denial of service (performance degradation) by triggering many file_printf calls.
nvd
CVE-2021-3624P3HIGHCVSS 7.8v9.0v10.0+1 more2022-04-18
CVE-2021-3624 [HIGH] CWE-20 CVE-2021-3624: There is an integer overflow vulnerability in dcraw. When the victim runs dcraw with a maliciously c
There is an integer overflow vulnerability in dcraw. When the victim runs dcraw with a maliciously crafted X3F input image, arbitrary code may be executed in the victim's system.
nvd
CVE-2004-1175P3HIGHCVSS 7.5v3.02005-04-14
CVE-2004-1175 [HIGH] CVE-2004-1175: fish.c in midnight commander allows remote attackers to execute arbitrary programs via "insecure fil
fish.c in midnight commander allows remote attackers to execute arbitrary programs via "insecure filename quoting," possibly using shell metacharacters.
nvd
CVE-2017-15577P3HIGHCVSS 7.5v9.02017-10-18
CVE-2017-15577 [HIGH] CWE-200 CVE-2017-15577: Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles the rendering of wiki links, which allows rem
Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles the rendering of wiki links, which allows remote attackers to obtain sensitive information.
nvd
CVE-2017-15576P3HIGHCVSS 7.5v9.02017-10-18
CVE-2017-15576 [HIGH] CWE-200 CVE-2017-15576: Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles Time Entry rendering in activity views, which
Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles Time Entry rendering in activity views, which allows remote attackers to obtain sensitive information.
nvd
CVE-2022-40188P3HIGHCVSS 7.5v10.02022-09-23
CVE-2022-40188 [HIGH] CWE-407 CVE-2022-40188: Knot Resolver before 5.5.3 allows remote attackers to cause a denial of service (CPU consumption) be
Knot Resolver before 5.5.3 allows remote attackers to cause a denial of service (CPU consumption) because of algorithmic complexity. During an attack, an authoritative server must return large NS sets or address sets.
nvd
CVE-2013-2900P3HIGHCVSS 7.5v7.02013-08-21
CVE-2013-2900 [HIGH] CWE-22 CVE-2013-2900: The FilePath::ReferencesParent function in files/file_path.cc in Google Chrome before 29.0.1547.57 o
The FilePath::ReferencesParent function in files/file_path.cc in Google Chrome before 29.0.1547.57 on Windows does not properly handle pathname components composed entirely of . (dot) and whitespace characters, which allows remote attackers to conduct directory traversal attacks via a crafted directory name.
nvd
CVE-2010-4657P3HIGHCVSS 7.5v8.02019-11-13
CVE-2010-4657 [HIGH] CWE-772 CVE-2010-4657: PHP5 before 5.4.4 allows passing invalid utf-8 strings via the xmlTextWriterWriteAttribute, which ar
PHP5 before 5.4.4 allows passing invalid utf-8 strings via the xmlTextWriterWriteAttribute, which are then misparsed by libxml2. This results in memory leak into the resulting output.
nvd
CVE-2021-39923P3HIGHCVSS 7.5v10.0v11.0+1 more2021-11-19
CVE-2021-39923 [HIGH] CWE-834 CVE-2021-39923: Large loop in the PNRP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of se
Large loop in the PNRP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
nvd
CVE-2020-4047P3MEDIUMCVSS 6.8v8.0v9.0+1 more2020-06-12
CVE-2020-4047 [MEDIUM] CWE-80 CVE-2020-4047: In affected versions of WordPress, authenticated users with upload permissions (like authors) are ab
In affected versions of WordPress, authenticated users with upload permissions (like authors) are able to inject JavaScript into some media file attachment pages in a certain way. This can lead to script execution in the context of a higher privileged user when the file is viewed by them. This has been patched in version 5.4.2, along with all the previ
nvd
CVE-2017-8819P3HIGHCVSS 7.5v8.0v9.02017-12-03
CVE-2017-8819 [HIGH] CVE-2017-8819: In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3
In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, the replay-cache protection mechanism is ineffective for v2 onion services, aka TROVE-2017-009. An attacker can send many INTRODUCE2 cells to trigger this issue.
nvd
CVE-2016-3163P3HIGHCVSS 7.5v7.0v8.02016-04-12
CVE-2016-3163 [HIGH] CWE-254 CVE-2016-3163: The XML-RPC system in Drupal 6.x before 6.38 and 7.x before 7.43 might make it easier for remote att
The XML-RPC system in Drupal 6.x before 6.38 and 7.x before 7.43 might make it easier for remote attackers to conduct brute-force attacks via a large number of calls made at once to the same method.
nvd
CVE-2022-45685P3HIGHCVSS 7.5v10.0v11.02022-12-13
CVE-2022-45685 [HIGH] CWE-787 CVE-2022-45685: A stack overflow in Jettison before v1.5.2 allows attackers to cause a Denial of Service (DoS) via c
A stack overflow in Jettison before v1.5.2 allows attackers to cause a Denial of Service (DoS) via crafted JSON data.
nvd
CVE-2018-2755P3HIGHCVSS 7.7v7.0v8.0+1 more2018-04-19
CVE-2018-2755 [HIGH] CVE-2018-2755: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Sup
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 5.5.59 and prior, 5.6.39 and prior and 5.7.21 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful a
nvd
CVE-2020-13396P3HIGHCVSS 7.1v9.0v10.02020-05-22
CVE-2020-13396 [HIGH] CWE-125 CVE-2020-13396: An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) read vulnerability has been
An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) read vulnerability has been detected in ntlm_read_ChallengeMessage in winpr/libwinpr/sspi/NTLM/ntlm_message.c.
nvd
CVE-2018-14734P3HIGHCVSS 7.8v8.0v9.02018-07-29
CVE-2018-14734 [HIGH] CWE-416 CVE-2018-14734: drivers/infiniband/core/ucma.c in the Linux kernel through 4.17.11 allows ucma_leave_multicast to ac
drivers/infiniband/core/ucma.c in the Linux kernel through 4.17.11 allows ucma_leave_multicast to access a certain data structure after a cleanup step in ucma_process_join, which allows attackers to cause a denial of service (use-after-free).
nvd
CVE-2018-17470P3HIGHCVSS 7.4v9.02019-01-09
CVE-2018-17470 [HIGH] CWE-119 CVE-2018-17470: A heap buffer overflow in GPU in Google Chrome prior to 70.0.3538.67 allowed a remote attacker who h
A heap buffer overflow in GPU in Google Chrome prior to 70.0.3538.67 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2012-2350P3HIGHCVSS 7.5v8.0v9.0+1 more2019-11-21
CVE-2012-2350 [HIGH] CWE-20 CVE-2012-2350: pam_shield before 0.9.4: Default configuration does not perform protective action
pam_shield before 0.9.4: Default configuration does not perform protective action
nvd
CVE-2022-29900P3MEDIUMCVSS 6.5v11.02022-07-12
CVE-2022-29900 [MEDIUM] CWE-212 CVE-2022-29900: Mis-trained branch predictions for return instructions may allow arbitrary speculative code executio
Mis-trained branch predictions for return instructions may allow arbitrary speculative code execution under certain microarchitecture-dependent conditions.
nvd