cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 251 of 498
CVE-2019-18848P3HIGHCVSS 7.5v9.02019-11-12
CVE-2019-18848 [HIGH] CWE-287 CVE-2019-18848: The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string. The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string.
nvd
CVE-2018-2612P3MEDIUMCVSS 6.5v8.0v9.02018-01-18
CVE-2018-2612 [MEDIUM] CVE-2018-2612: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versio Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.6.38 and prior and 5.7.20 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauth
nvd
CVE-2016-5338P3HIGHCVSS 7.8v8.02016-06-14
CVE-2016-5338 [HIGH] CVE-2016-5338: The (1) esp_reg_read and (2) esp_reg_write functions in hw/scsi/esp.c in QEMU allow local guest OS a The (1) esp_reg_read and (2) esp_reg_write functions in hw/scsi/esp.c in QEMU allow local guest OS administrators to cause a denial of service (QEMU process crash) or execute arbitrary code on the QEMU host via vectors related to the information transfer buffer.
nvd
CVE-2009-0115P3HIGHCVSS 7.8v4.0v5.02009-03-30
CVE-2009-0115 [HIGH] CWE-732 CVE-2009-0115: The Device Mapper multipathing driver (aka multipath-tools or device-mapper-multipath) 0.4.8, as use The Device Mapper multipathing driver (aka multipath-tools or device-mapper-multipath) 0.4.8, as used in SUSE openSUSE, SUSE Linux Enterprise Server (SLES), Fedora, and possibly other operating systems, uses world-writable permissions for the socket file (aka /var/run/multipathd.sock), which allows local users to send arbitrary commands to the multipath
nvd
CVE-2017-15115P3HIGHCVSS 7.8v7.02017-11-15
CVE-2017-15115 [HIGH] CWE-416 CVE-2017-15115: The sctp_do_peeloff function in net/sctp/socket.c in the Linux kernel before 4.14 does not check whe The sctp_do_peeloff function in net/sctp/socket.c in the Linux kernel before 4.14 does not check whether the intended netns is used in a peel-off action, which allows local users to cause a denial of service (use-after-free and system crash) or possibly have unspecified other impact via crafted system calls.
nvd
CVE-2018-3143P3MEDIUMCVSS 6.5v8.0v9.02018-10-17
CVE-2018-3143 [MEDIUM] CVE-2018-3143: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versio Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.6.41 and prior, 5.7.23 and prior and 8.0.12 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can
nvd
CVE-2018-3156P3MEDIUMCVSS 6.5v8.0v9.02018-10-17
CVE-2018-3156 [MEDIUM] CVE-2018-3156: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versio Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.6.41 and prior, 5.7.23 and prior and 8.0.12 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can
nvd
CVE-2017-0361P3HIGHCVSS 7.8v7.02018-04-13
CVE-2017-0361 [HIGH] CWE-200 CVE-2017-0361: Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains an information disclosure flaw, where the api.lo Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains an information disclosure flaw, where the api.log might contain passwords in plaintext.
nvd
CVE-2022-28203P3HIGHCVSS 7.5v10.0v11.02022-09-19
CVE-2022-28203 [HIGH] CWE-763 CVE-2022-28203: A denial-of-service issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37. A denial-of-service issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. When many files exist, requesting Special:NewFiles with actor as a condition can result in a very long running query.
nvd
CVE-2017-17847P3HIGHCVSS 7.5v8.0v9.02017-12-27
CVE-2017-17847 [HIGH] CWE-347 CVE-2017-17847: An issue was discovered in Enigmail before 1.9.9. Signature spoofing is possible because the UI does An issue was discovered in Enigmail before 1.9.9. Signature spoofing is possible because the UI does not properly distinguish between an attachment signature, and a signature that applies to the entire containing message, aka TBE-01-021. This is demonstrated by an e-mail message with an attachment that is a signed e-mail message in message/rfc822 form
nvd
CVE-2017-13723P3HIGHCVSS 7.8v8.0v9.02017-10-10
CVE-2017-13723 [HIGH] CWE-119 CVE-2017-13723: In X.Org Server (aka xserver and xorg-server) before 1.19.4, a local attacker authenticated to the X In X.Org Server (aka xserver and xorg-server) before 1.19.4, a local attacker authenticated to the X server could overflow a global buffer, causing crashes of the X server or potentially other problems by injecting large or malformed XKB related atoms and accessing them via xkbcomp.
nvd
CVE-2022-0367P3HIGHCVSS 7.8v10.02022-08-29
CVE-2022-0367 [HIGH] CWE-119 CVE-2022-0367: A heap-based buffer overflow flaw was found in libmodbus in function modbus_reply() in src/modbus.c. A heap-based buffer overflow flaw was found in libmodbus in function modbus_reply() in src/modbus.c.
nvd
CVE-2021-39255P3HIGHCVSS 7.8v9.0v10.0+1 more2021-09-07
CVE-2021-39255 [HIGH] CWE-125 CVE-2021-39255: A crafted NTFS image can trigger an out-of-bounds read, caused by an invalid attribute in ntfs_attr_ A crafted NTFS image can trigger an out-of-bounds read, caused by an invalid attribute in ntfs_attr_find_in_attrdef, in NTFS-3G < 2021.8.22.
nvd
CVE-2021-39251P3HIGHCVSS 7.8v9.0v10.0+1 more2021-09-07
CVE-2021-39251 [HIGH] CWE-476 CVE-2021-39251: A crafted NTFS image can cause a NULL pointer dereference in ntfs_extent_inode_open in NTFS-3G < 202 A crafted NTFS image can cause a NULL pointer dereference in ntfs_extent_inode_open in NTFS-3G < 2021.8.22.
nvd
CVE-2022-24958P3HIGHCVSS 7.8v9.02022-02-11
CVE-2022-24958 [HIGH] CWE-763 CVE-2022-24958: drivers/usb/gadget/legacy/inode.c in the Linux kernel through 5.16.8 mishandles dev->buf release. drivers/usb/gadget/legacy/inode.c in the Linux kernel through 5.16.8 mishandles dev->buf release.
nvd
CVE-2019-14563P3HIGHCVSS 7.8v9.02020-11-23
CVE-2019-14563 [HIGH] CWE-681 CVE-2019-14563: Integer truncation in EDK II may allow an authenticated user to potentially enable escalation of pri Integer truncation in EDK II may allow an authenticated user to potentially enable escalation of privilege via local access.
nvd
CVE-2018-12379P3HIGHCVSS 7.8v8.0v9.02018-10-18
CVE-2018-12379 [HIGH] CWE-787 CVE-2018-12379: When the Mozilla Updater opens a MAR format file which contains a very long item filename, an out-of When the Mozilla Updater opens a MAR format file which contains a very long item filename, an out-of-bounds write can be triggered, leading to a potentially exploitable crash. This requires running the Mozilla Updater manually on the local system with the malicious MAR file in order to occur. This vulnerability affects Firefox < 62, Firefox ESR < 60.2
nvd
CVE-2018-20152P3MEDIUMCVSS 6.5v8.0v9.02018-12-14
CVE-2018-20152 [MEDIUM] CWE-20 CVE-2018-20152: In WordPress before 4.9.9 and 5.x before 5.0.1, authors could bypass intended restrictions on post t In WordPress before 4.9.9 and 5.x before 5.0.1, authors could bypass intended restrictions on post types via crafted input.
nvd
CVE-2018-11506P3HIGHCVSS 7.8v8.02018-05-28
CVE-2018-11506 [HIGH] CWE-787 CVE-2018-11506: The sr_do_ioctl function in drivers/scsi/sr_ioctl.c in the Linux kernel through 4.16.12 allows local The sr_do_ioctl function in drivers/scsi/sr_ioctl.c in the Linux kernel through 4.16.12 allows local users to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact because sense buffers have different sizes at the CDROM layer and the SCSI layer, as demonstrated by a CDROMREADMODE2 ioctl call.
nvd
CVE-2023-24038P3HIGHCVSS 7.5v10.02023-01-21
CVE-2023-24038 [HIGH] CWE-1333 CVE-2023-24038: The HTML-StripScripts module through 1.06 for Perl allows _hss_attval_style ReDoS because of catastr The HTML-StripScripts module through 1.06 for Perl allows _hss_attval_style ReDoS because of catastrophic backtracking for HTML content with certain style attributes.
nvd
Debian Linux vulnerabilities | cvebase