cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 255 of 498
CVE-2016-2860P3MEDIUMCVSS 6.5v8.02016-05-13
CVE-2016-2860 [MEDIUM] CWE-284 CVE-2016-2860: The newEntry function in ptserver/ptprocs.c in OpenAFS before 1.6.17 allows remote authenticated use The newEntry function in ptserver/ptprocs.c in OpenAFS before 1.6.17 allows remote authenticated users from foreign Kerberos realms to bypass intended access restrictions and create arbitrary groups as administrators by leveraging mishandling of the creator ID.
nvd
CVE-2015-8806P3HIGHCVSS 7.5v8.02016-04-13
CVE-2015-8806 [HIGH] CVE-2015-8806: dict.c in libxml2 allows remote attackers to cause a denial of service (heap-based buffer over-read dict.c in libxml2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via an unexpected character immediately after the "<!DOCTYPE html" substring in a crafted HTML document.
nvd
CVE-2008-4068P4HIGHCVSS 7.8v4.02008-09-24
CVE-2008-4068 [HIGH] CWE-22 CVE-2008-4068: Directory traversal vulnerability in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbi Directory traversal vulnerability in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to bypass "restrictions imposed on local HTML files," and obtain sensitive information and prompt users to write this information into a file, via directory traversal sequences in a re
nvd
CVE-2019-14824P3MEDIUMCVSS 6.5v8.02019-11-08
CVE-2019-14824 [MEDIUM] CWE-732 CVE-2019-14824: A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.
nvd
CVE-2019-10868P3MEDIUMCVSS 6.5v9.02019-04-05
CVE-2019-10868 [MEDIUM] CWE-862 CVE-2019-10868: In trytond/model/modelstorage.py in Tryton 4.2 before 4.2.21, 4.4 before 4.4.19, 4.6 before 4.6.14, In trytond/model/modelstorage.py in Tryton 4.2 before 4.2.21, 4.4 before 4.4.19, 4.6 before 4.6.14, 4.8 before 4.8.10, and 5.0 before 5.0.6, an authenticated user can order records based on a field for which he has no access right. This may allow the user to guess values.
nvd
CVE-2012-1610P3HIGHCVSS 7.5v6.02012-06-05
CVE-2012-1610 [HIGH] CVE-2012-1610: Integer overflow in the GetEXIFProperty function in magick/property.c in ImageMagick before 6.7.6-4 Integer overflow in the GetEXIFProperty function in magick/property.c in ImageMagick before 6.7.6-4 allows remote attackers to cause a denial of service (out-of-bounds read) via a large component count for certain EXIF tags in a JPEG image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0259.
nvd
CVE-2022-2553P3MEDIUMCVSS 6.5v10.0v11.02022-07-28
CVE-2022-2553 [MEDIUM] CWE-287 CVE-2022-2553: The authfile directive in the booth config file is ignored, preventing use of authentication in comm The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node to node. As a result, nodes that do not have the correct authentication key are not prevented from communicating with other nodes in the cluster.
nvd
CVE-2022-24809P3MEDIUMCVSS 6.5v10.0v11.02024-04-16
CVE-2022-24809 [MEDIUM] CWE-476 CVE-2022-24809: net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-only credentials can use a malformed OID in a `GET-NEXT` to the `nsVacmAccessTable` to cause a NULL pointer dereference. Version 5.9.2 contains a patch. Users should use strong SNMPv3 credentials and avoid sharing the credenti
nvd
CVE-2022-21541P3MEDIUMCVSS 5.9v10.0v11.02022-07-19
CVE-2022-21541 [MEDIUM] CVE-2022-21541: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (co Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 7u343, 8u333, 11.0.15.1, 17.0.3.1, 18.0.1.1; Oracle GraalVM Enterprise Edition: 20.3.6, 21.3.2 and 22.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with netw
nvd
CVE-2017-8309P4HIGHCVSS 7.5v8.02017-05-23
CVE-2017-8309 [HIGH] CWE-772 CVE-2017-8309: Memory leak in the audio/audio.c in QEMU (aka Quick Emulator) allows remote attackers to cause a den Memory leak in the audio/audio.c in QEMU (aka Quick Emulator) allows remote attackers to cause a denial of service (memory consumption) by repeatedly starting and stopping audio capture.
nvd
CVE-2016-1680P3HIGHCVSS 8.8v8.02016-06-05
CVE-2016-1680 [HIGH] CWE-119 CVE-2016-1680: Use-after-free vulnerability in ports/SkFontHost_FreeType.cpp in Skia, as used in Google Chrome befo Use-after-free vulnerability in ports/SkFontHost_FreeType.cpp in Skia, as used in Google Chrome before 51.0.2704.63, allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2019-14466P3MEDIUMCVSS 6.5v8.02019-12-31
CVE-2019-14466 [MEDIUM] CWE-502 CVE-2019-14466: The GOsa_Filter_Settings cookie in GONICUS GOsa 2.7.5.2 is vulnerable to PHP objection injection, wh The GOsa_Filter_Settings cookie in GONICUS GOsa 2.7.5.2 is vulnerable to PHP objection injection, which allows a remote authenticated attacker to perform file deletions (in the context of the user account that runs the web server) via a crafted cookie value, because unserialize is used to restore filter settings from a cookie.
nvd
CVE-2024-3044P3MEDIUMCVSS 6.5v10.02024-05-14
CVE-2024-3044 [MEDIUM] CWE-356 CVE-2024-3044: Unchecked script execution in Graphic on-click binding in affected LibreOffice versions allows an at Unchecked script execution in Graphic on-click binding in affected LibreOffice versions allows an attacker to create a document which without prompt will execute scripts built-into LibreOffice on clicking a graphic. Such scripts were previously deemed trusted but are now deemed untrusted.
nvd
CVE-2008-2725P4HIGHCVSS 7.8v4.02008-06-24
CVE-2008-2725 [HIGH] CVE-2008-2725: Integer overflow in the (1) rb_ary_splice function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p23 Integer overflow in the (1) rb_ary_splice function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, and 1.8.7 before 1.8.7-p22; and (2) the rb_ary_replace function in 1.6.x allows context-dependent attackers to trigger memory corruption via unspecified vectors, aka the "REALLOC_N" variant, a different issue than CVE-2008-2662, CVE-20
nvd
CVE-2010-2499P4MEDIUMCVSS 6.8v5.02010-08-19
CVE-2010-2499 [MEDIUM] CWE-120 CVE-2010-2499: Buffer overflow in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.4.0 all Buffer overflow in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.4.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted LaserWriter PS font file with an embedded PFB fragment.
nvd
CVE-2005-0005P4HIGHCVSS 7.5v3.02005-05-02
CVE-2005-0005 [HIGH] CVE-2005-0005: Heap-based buffer overflow in psd.c for ImageMagick 6.1.0, 6.1.7, and possibly earlier versions allo Heap-based buffer overflow in psd.c for ImageMagick 6.1.0, 6.1.7, and possibly earlier versions allows remote attackers to execute arbitrary code via a .PSD image file with a large number of layers.
nvd
CVE-2020-8492P4MEDIUMCVSS 6.5v9.02020-01-30
CVE-2020-8492 [MEDIUM] CWE-400 CVE-2020-8492: Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTTP server to conduct Regular Expression Denial of Service (ReDoS) attacks against a client because of urllib.request.AbstractBasicAuthHandler catastrophic backtracking.
nvd
CVE-2016-1246P4HIGHCVSS 7.5v8.02016-10-05
CVE-2016-1246 [HIGH] CWE-119 CVE-2016-1246: Buffer overflow in the DBD::mysql module before 4.037 for Perl allows context-dependent attackers to Buffer overflow in the DBD::mysql module before 4.037 for Perl allows context-dependent attackers to cause a denial of service (crash) via vectors related to an error message.
nvd
CVE-2010-3705P4HIGHCVSS 8.3v5.02010-11-26
CVE-2010-3705 [HIGH] CWE-400 CVE-2010-3705: The sctp_auth_asoc_get_hmac function in net/sctp/auth.c in the Linux kernel before 2.6.36 does not p The sctp_auth_asoc_get_hmac function in net/sctp/auth.c in the Linux kernel before 2.6.36 does not properly validate the hmac_ids array of an SCTP peer, which allows remote attackers to cause a denial of service (memory corruption and panic) via a crafted value in the last element of this array.
nvd
CVE-2019-11009P4HIGHCVSS 8.1v8.02019-04-08
CVE-2019-11009 [HIGH] CWE-125 CVE-2019-11009: In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the function R In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the function ReadXWDImage of coders/xwd.c, which allows attackers to cause a denial of service or information disclosure via a crafted image file.
nvd
Debian Linux vulnerabilities | cvebase