cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 250 of 498
CVE-2016-6794P3MEDIUMCVSS 5.3v8.02017-08-10
CVE-2016-6794 [MEDIUM] CVE-2016-6794: When a SecurityManager is configured, a web application's ability to read system properties should b When a SecurityManager is configured, a web application's ability to read system properties should be controlled by the SecurityManager. In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70, 6.0.0 to 6.0.45 the system property replacement feature for configuration files could be used by a malicious web application to byp
nvd
CVE-2014-0237P4MEDIUMCVSS 5.0v7.0v8.02014-06-01
CVE-2014-0237 [MEDIUM] CWE-399 CVE-2014-0237: The cdf_unpack_summary_info function in cdf.c in the Fileinfo component in PHP before 5.4.29 and 5.5 The cdf_unpack_summary_info function in cdf.c in the Fileinfo component in PHP before 5.4.29 and 5.5.x before 5.5.13 allows remote attackers to cause a denial of service (performance degradation) by triggering many file_printf calls.
nvd
CVE-2021-3624P3HIGHCVSS 7.8v9.0v10.0+1 more2022-04-18
CVE-2021-3624 [HIGH] CWE-20 CVE-2021-3624: There is an integer overflow vulnerability in dcraw. When the victim runs dcraw with a maliciously c There is an integer overflow vulnerability in dcraw. When the victim runs dcraw with a maliciously crafted X3F input image, arbitrary code may be executed in the victim's system.
nvd
CVE-2004-1175P3HIGHCVSS 7.5v3.02005-04-14
CVE-2004-1175 [HIGH] CVE-2004-1175: fish.c in midnight commander allows remote attackers to execute arbitrary programs via "insecure fil fish.c in midnight commander allows remote attackers to execute arbitrary programs via "insecure filename quoting," possibly using shell metacharacters.
nvd
CVE-2017-15577P3HIGHCVSS 7.5v9.02017-10-18
CVE-2017-15577 [HIGH] CWE-200 CVE-2017-15577: Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles the rendering of wiki links, which allows rem Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles the rendering of wiki links, which allows remote attackers to obtain sensitive information.
nvd
CVE-2017-15576P3HIGHCVSS 7.5v9.02017-10-18
CVE-2017-15576 [HIGH] CWE-200 CVE-2017-15576: Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles Time Entry rendering in activity views, which Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles Time Entry rendering in activity views, which allows remote attackers to obtain sensitive information.
nvd
CVE-2022-40188P3HIGHCVSS 7.5v10.02022-09-23
CVE-2022-40188 [HIGH] CWE-407 CVE-2022-40188: Knot Resolver before 5.5.3 allows remote attackers to cause a denial of service (CPU consumption) be Knot Resolver before 5.5.3 allows remote attackers to cause a denial of service (CPU consumption) because of algorithmic complexity. During an attack, an authoritative server must return large NS sets or address sets.
nvd
CVE-2013-2900P3HIGHCVSS 7.5v7.02013-08-21
CVE-2013-2900 [HIGH] CWE-22 CVE-2013-2900: The FilePath::ReferencesParent function in files/file_path.cc in Google Chrome before 29.0.1547.57 o The FilePath::ReferencesParent function in files/file_path.cc in Google Chrome before 29.0.1547.57 on Windows does not properly handle pathname components composed entirely of . (dot) and whitespace characters, which allows remote attackers to conduct directory traversal attacks via a crafted directory name.
nvd
CVE-2010-4657P3HIGHCVSS 7.5v8.02019-11-13
CVE-2010-4657 [HIGH] CWE-772 CVE-2010-4657: PHP5 before 5.4.4 allows passing invalid utf-8 strings via the xmlTextWriterWriteAttribute, which ar PHP5 before 5.4.4 allows passing invalid utf-8 strings via the xmlTextWriterWriteAttribute, which are then misparsed by libxml2. This results in memory leak into the resulting output.
nvd
CVE-2021-39923P3HIGHCVSS 7.5v10.0v11.0+1 more2021-11-19
CVE-2021-39923 [HIGH] CWE-834 CVE-2021-39923: Large loop in the PNRP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of se Large loop in the PNRP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
nvd
CVE-2020-4047P3MEDIUMCVSS 6.8v8.0v9.0+1 more2020-06-12
CVE-2020-4047 [MEDIUM] CWE-80 CVE-2020-4047: In affected versions of WordPress, authenticated users with upload permissions (like authors) are ab In affected versions of WordPress, authenticated users with upload permissions (like authors) are able to inject JavaScript into some media file attachment pages in a certain way. This can lead to script execution in the context of a higher privileged user when the file is viewed by them. This has been patched in version 5.4.2, along with all the previ
nvd
CVE-2017-8819P3HIGHCVSS 7.5v8.0v9.02017-12-03
CVE-2017-8819 [HIGH] CVE-2017-8819: In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3 In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, the replay-cache protection mechanism is ineffective for v2 onion services, aka TROVE-2017-009. An attacker can send many INTRODUCE2 cells to trigger this issue.
nvd
CVE-2016-3163P3HIGHCVSS 7.5v7.0v8.02016-04-12
CVE-2016-3163 [HIGH] CWE-254 CVE-2016-3163: The XML-RPC system in Drupal 6.x before 6.38 and 7.x before 7.43 might make it easier for remote att The XML-RPC system in Drupal 6.x before 6.38 and 7.x before 7.43 might make it easier for remote attackers to conduct brute-force attacks via a large number of calls made at once to the same method.
nvd
CVE-2022-45685P3HIGHCVSS 7.5v10.0v11.02022-12-13
CVE-2022-45685 [HIGH] CWE-787 CVE-2022-45685: A stack overflow in Jettison before v1.5.2 allows attackers to cause a Denial of Service (DoS) via c A stack overflow in Jettison before v1.5.2 allows attackers to cause a Denial of Service (DoS) via crafted JSON data.
nvd
CVE-2018-2755P3HIGHCVSS 7.7v7.0v8.0+1 more2018-04-19
CVE-2018-2755 [HIGH] CVE-2018-2755: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Sup Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 5.5.59 and prior, 5.6.39 and prior and 5.7.21 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful a
nvd
CVE-2020-13396P3HIGHCVSS 7.1v9.0v10.02020-05-22
CVE-2020-13396 [HIGH] CWE-125 CVE-2020-13396: An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) read vulnerability has been An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) read vulnerability has been detected in ntlm_read_ChallengeMessage in winpr/libwinpr/sspi/NTLM/ntlm_message.c.
nvd
CVE-2018-14734P3HIGHCVSS 7.8v8.0v9.02018-07-29
CVE-2018-14734 [HIGH] CWE-416 CVE-2018-14734: drivers/infiniband/core/ucma.c in the Linux kernel through 4.17.11 allows ucma_leave_multicast to ac drivers/infiniband/core/ucma.c in the Linux kernel through 4.17.11 allows ucma_leave_multicast to access a certain data structure after a cleanup step in ucma_process_join, which allows attackers to cause a denial of service (use-after-free).
nvd
CVE-2018-17470P3HIGHCVSS 7.4v9.02019-01-09
CVE-2018-17470 [HIGH] CWE-119 CVE-2018-17470: A heap buffer overflow in GPU in Google Chrome prior to 70.0.3538.67 allowed a remote attacker who h A heap buffer overflow in GPU in Google Chrome prior to 70.0.3538.67 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2012-2350P3HIGHCVSS 7.5v8.0v9.0+1 more2019-11-21
CVE-2012-2350 [HIGH] CWE-20 CVE-2012-2350: pam_shield before 0.9.4: Default configuration does not perform protective action pam_shield before 0.9.4: Default configuration does not perform protective action
nvd
CVE-2022-29900P3MEDIUMCVSS 6.5v11.02022-07-12
CVE-2022-29900 [MEDIUM] CWE-212 CVE-2022-29900: Mis-trained branch predictions for return instructions may allow arbitrary speculative code executio Mis-trained branch predictions for return instructions may allow arbitrary speculative code execution under certain microarchitecture-dependent conditions.
nvd
Debian Linux vulnerabilities | cvebase