Debian Linux vulnerabilities
9,954 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358
Vulnerabilities
Page 260 of 498
CVE-2021-43818P3HIGHCVSS 7.1v9.0v10.0+1 more2021-12-13
CVE-2021-43818 [HIGH] CWE-74 CVE-2021-43818: lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HT
lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HTML Cleaner in lxml.html lets certain crafted script content pass through, as well as script content in SVG files embedded using data URIs. Users that employ the HTML cleaner in a security relevant context should upgrade to lxml 4.6.5 to receive a patch.
nvd
CVE-2022-3109P4HIGHCVSS 7.5v10.0v11.02022-12-16
CVE-2022-3109 [HIGH] CWE-476 CVE-2022-3109: An issue was discovered in the FFmpeg package, where vp3_decode_frame in libavcodec/vp3.c lacks chec
An issue was discovered in the FFmpeg package, where vp3_decode_frame in libavcodec/vp3.c lacks check of the return value of av_malloc() and will cause a null pointer dereference, impacting availability.
nvd
CVE-2018-8005P4MEDIUMCVSS 5.3v9.02018-08-29
CVE-2018-8005 [MEDIUM] CWE-400 CVE-2018-8005: When there are multiple ranges in a range request, Apache Traffic Server (ATS) will read the entire
When there are multiple ranges in a range request, Apache Traffic Server (ATS) will read the entire object from cache. This can cause performance problems with large objects in cache. This affects versions 6.0.0 to 6.2.2 and 7.0.0 to 7.1.3. To resolve this issue users running 6.x users should upgrade to 6.2.3 or later versions and 7.x users should upgr
nvd
CVE-2018-14337P4HIGHCVSS 7.5v9.02018-07-17
CVE-2018-14337 [HIGH] CWE-190 CVE-2018-14337: The CHECK macro in mrbgems/mruby-sprintf/src/sprintf.c in mruby 1.4.1 contains a signed integer over
The CHECK macro in mrbgems/mruby-sprintf/src/sprintf.c in mruby 1.4.1 contains a signed integer overflow, possibly leading to out-of-bounds memory access because the mrb_str_resize function in string.c does not check for a negative length.
nvd
CVE-2021-35565P4MEDIUMCVSS 5.3v9.0v10.0+1 more2021-10-20
CVE-2021-35565 [MEDIUM] CVE-2021-35565: Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component
Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Java SE, Oracle
nvd
CVE-2023-4781P3HIGHCVSS 7.8v10.02023-09-05
CVE-2023-4781 [HIGH] CWE-122 CVE-2023-4781: Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1873.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1873.
nvd
CVE-2020-20451P4HIGHCVSS 7.5v9.02021-05-25
CVE-2020-20451 [HIGH] CWE-401 CVE-2020-20451: Denial of Service issue in FFmpeg 4.2 due to resource management errors via fftools/cmdutils.c.
Denial of Service issue in FFmpeg 4.2 due to resource management errors via fftools/cmdutils.c.
nvd
CVE-2014-1936P4HIGHCVSS 7.5v8.0v9.0+1 more2019-11-21
CVE-2014-1936 [HIGH] CWE-20 CVE-2014-1936: rc before 1.7.1-5 insecurely creates temporary files.
rc before 1.7.1-5 insecurely creates temporary files.
nvd
CVE-2023-4752P4HIGHCVSS 7.8v10.02023-09-04
CVE-2023-4752 [HIGH] CWE-416 CVE-2023-4752: Use After Free in GitHub repository vim/vim prior to 9.0.1858.
Use After Free in GitHub repository vim/vim prior to 9.0.1858.
nvd
CVE-2011-0529P4HIGHCVSS 7.5v8.0v9.0+1 more2019-11-20
CVE-2011-0529 [HIGH] CWE-20 CVE-2011-0529: Weborf before 0.12.5 is affected by a Denial of Service (DOS) due to malformed fields in HTTP.
Weborf before 0.12.5 is affected by a Denial of Service (DOS) due to malformed fields in HTTP.
nvd
CVE-2017-12874P4HIGHCVSS 7.5v7.0v8.0+1 more2017-09-01
CVE-2017-12874 [HIGH] CWE-20 CVE-2017-12874: The InfoCard module 1.0 for SimpleSAMLphp allows attackers to spoof XML messages by leveraging an in
The InfoCard module 1.0 for SimpleSAMLphp allows attackers to spoof XML messages by leveraging an incorrect check of return values in signature validation utilities.
nvd
CVE-2021-3910P4HIGHCVSS 7.5v11.02021-11-11
CVE-2021-3910 [HIGH] CWE-20 CVE-2021-3910: OctoRPKI crashes when encountering a repository that returns an invalid ROA (just an encoded NUL (\0
OctoRPKI crashes when encountering a repository that returns an invalid ROA (just an encoded NUL (\0) character).
nvd
CVE-2022-3324P4HIGHCVSS 7.8v10.02022-09-27
CVE-2022-3324 [HIGH] CWE-121 CVE-2022-3324: Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0598.
Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0598.
nvd
CVE-2018-6555P4HIGHCVSS 7.8v8.0v9.02018-09-04
CVE-2018-6555 [HIGH] CWE-416 CVE-2018-6555: The irda_setsockopt function in net/irda/af_irda.c and later in drivers/staging/irda/net/af_irda.c i
The irda_setsockopt function in net/irda/af_irda.c and later in drivers/staging/irda/net/af_irda.c in the Linux kernel before 4.17 allows local users to cause a denial of service (ias_object use-after-free and system crash) or possibly have unspecified other impact via an AF_IRDA socket.
nvd
CVE-2022-29824P4MEDIUMCVSS 6.5v9.0v10.0+1 more2022-05-03
CVE-2022-29824 [MEDIUM] CWE-190 CVE-2022-29824: In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer
In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows. This can result in out-of-bounds memory writes. Exploitation requires a victim to open a crafted, multi-gigabyte XML file. Other software using libxml2's buffer functions, for example libxslt through 1.1.35, is af
nvd
CVE-2016-4565P4HIGHCVSS 7.8v8.02016-05-23
CVE-2016-4565 [HIGH] CWE-264 CVE-2016-4565: The InfiniBand (aka IB) stack in the Linux kernel before 4.5.3 incorrectly relies on the write syste
The InfiniBand (aka IB) stack in the Linux kernel before 4.5.3 incorrectly relies on the write system call, which allows local users to cause a denial of service (kernel memory write operation) or possibly have unspecified other impact via a uAPI interface.
nvd
CVE-2022-1925P4HIGHCVSS 7.8v10.0v11.02022-07-19
CVE-2022-1925 [HIGH] CWE-122 CVE-2022-1925: DOS / potential heap overwrite in mkv demuxing using HEADERSTRIP decompression. Integer overflow in
DOS / potential heap overwrite in mkv demuxing using HEADERSTRIP decompression. Integer overflow in matroskaparse element in gst_matroska_decompress_data function which causes a heap overflow. Due to restrictions on chunk sizes in the matroskademux element, the overflow can't be triggered, however the matroskaparse element has no size checks.
nvd
CVE-2012-1572P4HIGHCVSS 7.5v8.0v9.0+1 more2019-11-12
CVE-2012-1572 [HIGH] CWE-400 CVE-2012-1572: OpenStack Keystone: extremely long passwords can crash Keystone by exhausting stack space
OpenStack Keystone: extremely long passwords can crash Keystone by exhausting stack space
nvd
CVE-2016-5828P4HIGHCVSS 7.8v8.02016-06-27
CVE-2016-5828 [HIGH] CWE-20 CVE-2016-5828: The start_thread function in arch/powerpc/kernel/process.c in the Linux kernel through 4.6.3 on powe
The start_thread function in arch/powerpc/kernel/process.c in the Linux kernel through 4.6.3 on powerpc platforms mishandles transactional state, which allows local users to cause a denial of service (invalid process state or TM Bad Thing exception, and system crash) or possibly have unspecified other impact by starting and suspending a transaction befor
nvd
CVE-2018-10380P4HIGHCVSS 7.8v9.02018-05-08
CVE-2018-10380 [HIGH] CWE-59 CVE-2018-10380: kwallet-pam in KDE KWallet before 5.12.6 allows local users to obtain ownership of arbitrary files v
kwallet-pam in KDE KWallet before 5.12.6 allows local users to obtain ownership of arbitrary files via a symlink attack.
nvd