Debian Linux vulnerabilities
9,954 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358
Vulnerabilities
Page 253 of 498
CVE-2015-1821P3MEDIUMCVSS 6.5v7.02015-04-16
CVE-2015-1821 [MEDIUM] CWE-119 CVE-2015-1821: Heap-based buffer overflow in chrony before 1.31.1 allows remote authenticated users to cause a deni
Heap-based buffer overflow in chrony before 1.31.1 allows remote authenticated users to cause a denial of service (chronyd crash) or possibly execute arbitrary code by configuring the (1) NTP or (2) cmdmon access with a subnet size that is indivisible by four and an address with a nonzero bit in the subnet remainder.
nvd
CVE-2023-52696P3HIGHCVSS 7.5v10.02024-05-17
CVE-2023-52696 [HIGH] CWE-476 CVE-2023-52696: In the Linux kernel, the following vulnerability has been resolved: powerpc/powernv: Add a null poi
In the Linux kernel, the following vulnerability has been resolved:
powerpc/powernv: Add a null pointer check in opal_powercap_init()
kasprintf() returns a pointer to dynamically allocated memory
which can be NULL upon failure.
nvd
CVE-2016-6128P3HIGHCVSS 7.5v8.02016-08-07
CVE-2016-6128 [HIGH] CWE-20 CVE-2016-6128: The gdImageCropThreshold function in gd_crop.c in the GD Graphics Library (aka libgd) before 2.2.3,
The gdImageCropThreshold function in gd_crop.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 7.0.9, allows remote attackers to cause a denial of service (application crash) via an invalid color index.
nvd
CVE-2025-26699P3HIGHCVSS 7.5v11.02025-03-06
CVE-2025-26699 [HIGH] CWE-770 CVE-2025-26699: An issue was discovered in Django 5.1 before 5.1.7, 5.0 before 5.0.13, and 4.2 before 4.2.20. The dj
An issue was discovered in Django 5.1 before 5.1.7, 5.0 before 5.0.13, and 4.2 before 4.2.20. The django.utils.text.wrap() method and wordwrap template filter are subject to a potential denial-of-service attack when used with very long strings.
nvd
CVE-2017-15575P3HIGHCVSS 7.3v9.02017-10-18
CVE-2017-15575 [HIGH] CVE-2017-15575: In Redmine before 3.2.6 and 3.3.x before 3.3.3, Redmine.pm lacks a check for whether the Repository
In Redmine before 3.2.6 and 3.3.x before 3.3.3, Redmine.pm lacks a check for whether the Repository module is enabled in a project's settings, which might allow remote attackers to obtain sensitive differences information or possibly have unspecified other impact.
nvd
CVE-2017-10378P3MEDIUMCVSS 6.5v8.0v9.02017-10-19
CVE-2017-10378 [MEDIUM] CVE-2017-10378: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Suppo
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.5.57 and earlier, 5.6.37 and earlier and 5.7.11 and earlier. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of thi
nvd
CVE-2018-2618P3MEDIUMCVSS 5.9v7.0v8.0+1 more2018-01-18
CVE-2018-2618 [MEDIUM] CVE-2018-2618: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: J
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JCE). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE
nvd
CVE-2021-3908P3HIGHCVSS 7.5v11.02021-11-11
CVE-2021-3908 [HIGH] CWE-400 CVE-2021-3908: OctoRPKI does not limit the depth of a certificate chain, allowing for a CA to create children in an
OctoRPKI does not limit the depth of a certificate chain, allowing for a CA to create children in an ad-hoc fashion, thereby making tree traversal never end.
nvd
CVE-2018-2819P3MEDIUMCVSS 6.5v7.0v8.0+1 more2018-04-19
CVE-2018-2819 [MEDIUM] CVE-2018-2819: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versio
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.5.59 and prior, 5.6.39 and prior and 5.7.21 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can
nvd
CVE-2018-2817P3MEDIUMCVSS 6.5v7.0v8.0+1 more2018-04-19
CVE-2018-2817 [MEDIUM] CVE-2018-2817: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported v
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.5.59 and prior, 5.6.39 and prior and 5.7.21 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerabilit
nvd
CVE-2019-9371P3MEDIUMCVSS 6.5v9.0v10.02019-09-27
CVE-2019-9371 [MEDIUM] CWE-20 CVE-2019-9371: In libvpx, there is a possible resource exhaustion due to improper input validation. This could lead
In libvpx, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-132783254
nvd
CVE-2018-4117P3MEDIUMCVSS 6.5v9.02018-04-03
CVE-2018-4117 [MEDIUM] CWE-200 CVE-2018-4117: An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 i
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. watchOS before 4.3 is affected. The issue involves the fetch API in the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy an
nvd
CVE-2018-20147P3MEDIUMCVSS 6.5v8.0v9.02018-12-14
CVE-2018-20147 [MEDIUM] CWE-863 CVE-2018-20147: In WordPress before 4.9.9 and 5.x before 5.0.1, authors could modify metadata to bypass intended res
In WordPress before 4.9.9 and 5.x before 5.0.1, authors could modify metadata to bypass intended restrictions on deleting files.
nvd
CVE-2018-2782P3MEDIUMCVSS 6.5v8.0v9.02018-04-19
CVE-2018-2782 [MEDIUM] CVE-2018-2782: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versio
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.6.39 and prior and 5.7.21 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unautho
nvd
CVE-2024-27355P3HIGHCVSS 7.5v10.02024-03-01
CVE-2024-27355 [HIGH] CWE-400 CVE-2024-27355: An issue was discovered in phpseclib 1.x before 1.0.23, 2.x before 2.0.47, and 3.x before 3.0.36. Wh
An issue was discovered in phpseclib 1.x before 1.0.23, 2.x before 2.0.47, and 3.x before 3.0.36. When processing the ASN.1 object identifier of a certificate, a sub identifier may be provided that leads to a denial of service (CPU consumption for decodeOID).
nvd
CVE-2020-13920P3MEDIUMCVSS 5.9v9.02020-09-10
CVE-2020-13920 [MEDIUM] CWE-306 CVE-2020-13920: Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX RMI registry and binds the se
Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX RMI registry and binds the server to the "jmxrmi" entry. It is possible to connect to the registry without authentication and call the rebind method to rebind jmxrmi to something else. If an attacker creates another server to proxy the original, and bound that, he effectively bec
nvd
CVE-2018-16845P4MEDIUMCVSS 6.1v8.0v9.02018-11-07
CVE-2018-16845 [MEDIUM] CWE-400 CVE-2018-16845: nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might all
nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted mp4 file. The issue only affects nginx if it is built with the ngx_http_mp4_modul
nvd
CVE-2019-11779P3MEDIUMCVSS 6.5v8.0v10.02019-09-19
CVE-2019-11779 [MEDIUM] CWE-754 CVE-2019-11779: In Eclipse Mosquitto 1.5.0 to 1.6.5 inclusive, if a malicious MQTT client sends a SUBSCRIBE packet c
In Eclipse Mosquitto 1.5.0 to 1.6.5 inclusive, if a malicious MQTT client sends a SUBSCRIBE packet containing a topic that consists of approximately 65400 or more '/' characters, i.e. the topic hierarchy separator, then a stack overflow will occur.
nvd
CVE-2021-31799P3HIGHCVSS 7.0v9.0v10.02021-07-30
CVE-2021-31799 [HIGH] CWE-78 CVE-2021-31799: In RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby through 3.0.1, it is possible to exe
In RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby through 3.0.1, it is possible to execute arbitrary code via | and tags in a filename.
nvd
CVE-2021-43797P3MEDIUMCVSS 6.5v10.0v11.02021-12-09
CVE-2021-43797 [MEDIUM] CWE-444 CVE-2021-43797: Netty is an asynchronous event-driven network application framework for rapid development of maintai
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. Netty prior to version 4.1.71.Final skips control chars when they are present at the beginning / end of the header name. It should instead fail fast as these are not allowed by the spec and could lead
nvd