Debian Linux vulnerabilities
9,954 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358
Vulnerabilities
Page 254 of 498
CVE-2017-0925P3HIGHCVSS 7.2v9.02018-03-21
CVE-2017-0925 [HIGH] CWE-522 CVE-2017-0925: Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently protected credential iss
Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently protected credential issue in the project service integration API endpoint resulting in an information disclosure of plaintext password.
nvd
CVE-2004-0981P4CRITICALCVSS 10.0v3.02005-02-09
CVE-2004-0981 [CRITICAL] CVE-2004-0981: Buffer overflow in the EXIF parsing routine in ImageMagick before 6.1.0 allows remote attackers to e
Buffer overflow in the EXIF parsing routine in ImageMagick before 6.1.0 allows remote attackers to execute arbitrary code via a certain image file.
nvd
CVE-2019-12418P3HIGHCVSS 7.0v8.0v9.0+1 more2019-12-23
CVE-2019-12418 [HIGH] CVE-2019-12418: When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX
When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files is able to manipulate the RMI registry to perform a man-in-the-middle attack to capture user names and passwords used to access the JMX interface. The attacke
nvd
CVE-2016-1653P4HIGHCVSS 8.8v8.02016-04-18
CVE-2016-1653 [HIGH] CWE-119 CVE-2016-1653: The LoadBuffer implementation in Google V8, as used in Google Chrome before 50.0.2661.75, mishandles
The LoadBuffer implementation in Google V8, as used in Google Chrome before 50.0.2661.75, mishandles data types, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that triggers an out-of-bounds write operation, related to compiler/pipeline.cc and compiler/simplified-lowering.
nvd
CVE-2022-42258P3HIGHCVSS 7.3v10.02022-12-30
CVE-2022-42258 [HIGH] CWE-190 CVE-2022-42258: NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), w
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an integer overflow may lead to denial of service, data tampering, or information disclosure.
nvd
CVE-2022-42257P3HIGHCVSS 7.3v10.02022-12-30
CVE-2022-42257 [HIGH] CWE-190 CVE-2022-42257: NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), w
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an integer overflow may lead to information disclosure, data tampering or denial of service.
nvd
CVE-2020-26137P3MEDIUMCVSS 6.5v9.02020-09-30
CVE-2020-26137 [MEDIUM] CVE-2020-26137: urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as dem
urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116.
nvd
CVE-2016-0505P4MEDIUMCVSS 6.8v8.02016-01-21
CVE-2016-0505 [MEDIUM] CVE-2016-0505: Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and Mari
Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via unknown vectors related to Options.
nvd
CVE-2018-6315P4HIGHCVSS 8.8v7.02018-01-25
CVE-2018-6315 [HIGH] CWE-125 CVE-2018-6315: The outputSWF_TEXT_RECORD function (util/outputscript.c) in libming through 0.4.8 is vulnerable to a
The outputSWF_TEXT_RECORD function (util/outputscript.c) in libming through 0.4.8 is vulnerable to an integer overflow and resultant out-of-bounds read, which may allow attackers to cause a denial of service or unspecified other impact via a crafted SWF file.
nvd
CVE-2020-8244P3MEDIUMCVSS 6.5v9.02020-08-30
CVE-2020-8244 [MEDIUM] CWE-126 CVE-2020-8244: A buffer over-read vulnerability exists in bl <4.0.3, <3.0.1, <2.2.1, and <1.2.3 which could allow a
A buffer over-read vulnerability exists in bl <4.0.3, <3.0.1, <2.2.1, and <1.2.3 which could allow an attacker to supply user input (even typed) that if it ends up in consume() argument and can become negative, the BufferList state can be corrupted, tricking it into exposing uninitialized memory via regular .slice() calls.
nvd
CVE-2017-5610P3MEDIUMCVSS 5.3v8.0v9.02017-01-30
CVE-2017-5610 [MEDIUM] CWE-200 CVE-2017-5610: wp-admin/includes/class-wp-press-this.php in Press This in WordPress before 4.7.2 does not properly
wp-admin/includes/class-wp-press-this.php in Press This in WordPress before 4.7.2 does not properly restrict visibility of a taxonomy-assignment user interface, which allows remote attackers to bypass intended access restrictions by reading terms.
nvd
CVE-2020-7069P3MEDIUMCVSS 6.5v10.02020-10-02
CVE-2020-7069 [MEDIUM] CWE-20 CVE-2020-7069: In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when AES-CCM mode is
In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when AES-CCM mode is used with openssl_encrypt() function with 12 bytes IV, only first 7 bytes of the IV is actually used. This can lead to both decreased security and incorrect encryption data.
nvd
CVE-2023-6931P3HIGHCVSS 7.0v10.02023-12-19
CVE-2023-6931 [HIGH] CWE-787 CVE-2023-6931: A heap out-of-bounds write vulnerability in the Linux kernel's Performance Events system component c
A heap out-of-bounds write vulnerability in the Linux kernel's Performance Events system component can be exploited to achieve local privilege escalation.
A perf_event's read_size can overflow, leading to an heap out-of-bounds increment or write in perf_read_group().
We recommend upgrading past commit 382c27f4ed28f803b1f1473ac2d8db0afc795a1b.
nvd
CVE-2013-6668P3HIGHCVSS 7.5v7.0v8.02014-03-05
CVE-2013-6668 [HIGH] CVE-2013-6668: Multiple unspecified vulnerabilities in Google V8 before 3.24.35.10, as used in Google Chrome before
Multiple unspecified vulnerabilities in Google V8 before 3.24.35.10, as used in Google Chrome before 33.0.1750.146, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2021-37533P3MEDIUMCVSS 6.5v10.0v11.02022-12-03
CVE-2021-37533 [MEDIUM] CWE-20 CVE-2021-37533: Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default. A
Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default. A malicious server can redirect the Commons Net code to use a different host, but the user has to connect to the malicious server in the first place. This may lead to leakage of information about services running on the private network of the client. Th
nvd
CVE-2023-4622P3HIGHCVSS 7.0v10.0v12.02023-09-06
CVE-2023-4622 [HIGH] CWE-416 CVE-2023-4622: A use-after-free vulnerability in the Linux kernel's af_unix component can be exploited to achieve l
A use-after-free vulnerability in the Linux kernel's af_unix component can be exploited to achieve local privilege escalation.
The unix_stream_sendpage() function tries to add data to the last skb in the peer's recv queue without locking the queue. Thus there is a race where unix_stream_sendpage() could access an skb locklessly that is being released b
nvd
CVE-2011-1002P4MEDIUMCVSS 5.0v5.0v6.0+1 more2011-02-22
CVE-2011-1002 [MEDIUM] CVE-2011-1002: avahi-core/socket.c in avahi-daemon in Avahi before 0.6.29 allows remote attackers to cause a denial
avahi-core/socket.c in avahi-daemon in Avahi before 0.6.29 allows remote attackers to cause a denial of service (infinite loop) via an empty mDNS (1) IPv4 or (2) IPv6 UDP packet to port 5353. NOTE: this vulnerability exists because of an incorrect fix for CVE-2010-2244.
nvd
CVE-2020-28242P3MEDIUMCVSS 6.5v9.02020-11-06
CVE-2020-28242 [MEDIUM] CWE-674 CVE-2020-28242: An issue was discovered in Asterisk Open Source 13.x before 13.37.1, 16.x before 16.14.1, 17.x befor
An issue was discovered in Asterisk Open Source 13.x before 13.37.1, 16.x before 16.14.1, 17.x before 17.8.1, and 18.x before 18.0.1 and Certified Asterisk before 16.8-cert5. If Asterisk is challenged on an outbound INVITE and the nonce is changed in each response, Asterisk will continually send INVITEs in a loop. This causes Asterisk to consume mor
nvd
CVE-2008-2664P3HIGHCVSS 7.8v4.02008-06-24
CVE-2008-2664 [HIGH] CVE-2008-2664: The rb_str_format function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p2
The rb_str_format function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 before 1.8.7-p22, and 1.9.0 before 1.9.0-2 allows context-dependent attackers to trigger memory corruption via unspecified vectors related to alloca, a different issue than CVE-2008-2662, CVE-2008-2663, and CVE-2008-2725. NOTE: as of 20080624, there has
nvd
CVE-2017-12197P3MEDIUMCVSS 6.5v7.0v8.0+1 more2018-01-18
CVE-2017-12197 [MEDIUM] CWE-863 CVE-2017-12197: It was found that libpam4j up to and including 1.8 did not properly validate user accounts when auth
It was found that libpam4j up to and including 1.8 did not properly validate user accounts when authenticating. A user with a valid password for a disabled account would be able to bypass security restrictions and possibly access sensitive information.
nvd