Debian Linux vulnerabilities
9,954 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358
Vulnerabilities
Page 256 of 498
CVE-2016-8734P3MEDIUMCVSS 6.5v8.0v9.02017-10-16
CVE-2016-8734 [MEDIUM] CWE-400 CVE-2016-8734: Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 through 1
Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 through 1.9.4 are vulnerable to a denial-of-service attack caused by exponential XML entity expansion. The attack can cause the targeted process to consume an excessive amount of CPU resources or memory.
nvd
CVE-2021-44533P4MEDIUMCVSS 5.3v11.02022-02-24
CVE-2021-44533 [MEDIUM] CWE-295 CVE-2021-44533: Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle multi-value Relative Distinguis
Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle multi-value Relative Distinguished Names correctly. Attackers could craft certificate subjects containing a single-value Relative Distinguished Name that would be interpreted as a multi-value Relative Distinguished Name, for example, in order to inject a Common Name that would allo
nvd
CVE-2017-14607P4HIGHCVSS 8.1v8.0v9.02017-09-20
CVE-2017-14607 [HIGH] CWE-125 CVE-2017-14607: In ImageMagick 7.0.7-4 Q16, an out of bounds read flaw related to ReadTIFFImage has been reported in
In ImageMagick 7.0.7-4 Q16, an out of bounds read flaw related to ReadTIFFImage has been reported in coders/tiff.c. An attacker could possibly exploit this flaw to disclose potentially sensitive memory or cause an application crash.
nvd
CVE-2004-1052P4CRITICALCVSS 10.0v3.02005-03-01
CVE-2004-1052 [CRITICAL] CVE-2004-1052: Buffer overflow in the getnickuserhost function in BNC 2.8.9, and possibly other versions, allows re
Buffer overflow in the getnickuserhost function in BNC 2.8.9, and possibly other versions, allows remote IRC servers to execute arbitrary code via an IRC server response that contains many (1) ! (exclamation) or (2) @ (at sign) characters.
nvd
CVE-2016-1526P4HIGHCVSS 8.1v7.0v8.02016-02-13
CVE-2016-1526 [HIGH] CWE-119 CVE-2016-1526: The TtfUtil:LocaLookup function in TtfUtil.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozill
The TtfUtil:LocaLookup function in TtfUtil.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, incorrectly validates a size value, which allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash) via a crafted Graphite smar
nvd
CVE-2023-27535P3MEDIUMCVSS 5.9v10.02023-03-30
CVE-2023-27535 [MEDIUM] CWE-305 CVE-2023-27535: An authentication bypass vulnerability exists in libcurl <8.0.0 in the FTP connection reuse feature
An authentication bypass vulnerability exists in libcurl <8.0.0 in the FTP connection reuse feature that can result in wrong credentials being used during subsequent transfers. Previously created connections are kept in a connection pool for reuse if they match the current setup. However, certain FTP settings such as CURLOPT_FTP_ACCOUNT, CURLOPT_FTP_
nvd
CVE-2015-5312P4HIGHCVSS 7.1v7.0v8.02015-12-15
CVE-2015-5312 [HIGH] CVE-2015-5312: The xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.3 does not properly preven
The xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.3 does not properly prevent entity expansion, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data, a different vulnerability than CVE-2014-3660.
nvd
CVE-2017-9726P4HIGHCVSS 7.8v8.0v9.02017-07-26
CVE-2017-9726 [HIGH] CWE-125 CVE-2017-9726: The Ins_MDRP function in base/ttinterp.c in Artifex Ghostscript GhostXPS 9.21 allows remote attacker
The Ins_MDRP function in base/ttinterp.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted document.
nvd
CVE-2019-7659P3HIGHCVSS 8.1v8.02019-02-09
CVE-2019-7659 [HIGH] CWE-787 CVE-2019-7659: Genivia gSOAP 2.7.x and 2.8.x before 2.8.75 allows attackers to cause a denial of service (applicati
Genivia gSOAP 2.7.x and 2.8.x before 2.8.75 allows attackers to cause a denial of service (application abort) or possibly have unspecified other impact if a server application is built with the -DWITH_COOKIES flag. This affects the C/C++ libgsoapck/libgsoapck++ and libgsoapssl/libgsoapssl++ libraries, as these are built with that flag.
nvd
CVE-2021-29425P4MEDIUMCVSS 4.8v9.02021-04-13
CVE-2021-29425 [MEDIUM] CWE-20 CVE-2021-29425: In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper i
In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to constru
nvd
CVE-2019-11007P3HIGHCVSS 8.1v8.0v9.0+1 more2019-04-08
CVE-2019-11007 [HIGH] CWE-125 CVE-2019-11007: In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the ReadMNGIma
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the ReadMNGImage function of coders/png.c, which allows attackers to cause a denial of service or information disclosure via an image colormap.
nvd
CVE-2016-9453P4HIGHCVSS 7.8v8.0v9.02017-01-27
CVE-2016-9453 [HIGH] CWE-787 CVE-2016-9453: The t2p_readwrite_pdf_image_tile function in LibTIFF allows remote attackers to cause a denial of se
The t2p_readwrite_pdf_image_tile function in LibTIFF allows remote attackers to cause a denial of service (out-of-bounds write and crash) or possibly execute arbitrary code via a JPEG file with a TIFFTAG_JPEGTABLES of length one.
nvd
CVE-2016-9897P3HIGHCVSS 7.5v8.02018-06-11
CVE-2016-9897 [HIGH] CWE-119 CVE-2016-9897: Memory corruption resulting in a potentially exploitable crash during WebGL functions using a vector
Memory corruption resulting in a potentially exploitable crash during WebGL functions using a vector constructor with a varying array within libGLES. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
nvd
CVE-2018-1084P4HIGHCVSS 7.5v9.02018-04-12
CVE-2018-1084 [HIGH] CWE-190 CVE-2018-1084: corosync before version 2.4.4 is vulnerable to an integer overflow in exec/totemcrypto.c.
corosync before version 2.4.4 is vulnerable to an integer overflow in exec/totemcrypto.c.
nvd
CVE-2007-1667P4CRITICALCVSS 9.3v3.1v4.02007-03-24
CVE-2007-1667 [CRITICAL] CWE-189 CVE-2007-1667: Multiple integer overflows in (1) the XGetPixel function in ImUtil.c in X.Org libx11 before 1.0.3, a
Multiple integer overflows in (1) the XGetPixel function in ImUtil.c in X.Org libx11 before 1.0.3, and (2) XInitImage function in xwd.c for ImageMagick, allow user-assisted remote attackers to cause a denial of service (crash) or obtain sensitive information via crafted images with large or negative values that trigger a buffer overflow.
nvd
CVE-2019-12979P4HIGHCVSS 7.8v9.0v10.02019-06-26
CVE-2019-12979 [HIGH] CWE-665 CVE-2019-12979: ImageMagick 7.0.8-34 has a "use of uninitialized value" vulnerability in the SyncImageSettings funct
ImageMagick 7.0.8-34 has a "use of uninitialized value" vulnerability in the SyncImageSettings function in MagickCore/image.c. This is related to AcquireImage in magick/image.c.
nvd
CVE-2017-17935P4HIGHCVSS 7.5v8.02017-12-27
CVE-2017-17935 [HIGH] CWE-125 CVE-2017-17935: The File_read_line function in epan/wslua/wslua_file.c in Wireshark through 2.2.11 does not properly
The File_read_line function in epan/wslua/wslua_file.c in Wireshark through 2.2.11 does not properly strip '\n' characters, which allows remote attackers to cause a denial of service (buffer underflow and application crash) via a crafted packet that triggers the attempted processing of an empty line.
nvd
CVE-2019-7310P4HIGHCVSS 7.8v8.0v9.02019-02-03
CVE-2019-7310 [HIGH] CWE-125 CVE-2019-7310: In Poppler 0.73.0, a heap-based buffer over-read (due to an integer signedness error in the XRef::ge
In Poppler 0.73.0, a heap-based buffer over-read (due to an integer signedness error in the XRef::getEntry function in XRef.cc) allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PDF document, as demonstrated by pdftocairo.
nvd
CVE-2018-5345P4HIGHCVSS 7.8v9.02018-01-12
CVE-2018-5345 [HIGH] CWE-787 CVE-2018-5345: A stack-based buffer overflow within GNOME gcab through 0.7.4 can be exploited by malicious attacker
A stack-based buffer overflow within GNOME gcab through 0.7.4 can be exploited by malicious attackers to cause a crash or, potentially, execute arbitrary code via a crafted .cab file.
nvd
CVE-2020-13959P4MEDIUMCVSS 6.1v9.02021-03-10
CVE-2020-13959 [MEDIUM] CWE-79 CVE-2020-13959: The default error page for VelocityView in Apache Velocity Tools prior to 3.1 reflects back the vm f
The default error page for VelocityView in Apache Velocity Tools prior to 3.1 reflects back the vm file that was entered as part of the URL. An attacker can set an XSS payload file as this vm file in the URL which results in this payload being executed. XSS vulnerabilities allow attackers to execute arbitrary JavaScript in the context of the attacked
nvd