Debian Linux vulnerabilities
9,954 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358
Vulnerabilities
Page 261 of 498
CVE-2017-3244P4MEDIUMCVSS 6.5v8.02017-01-27
CVE-2017-3244 [MEDIUM] CVE-2017-3244: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML). Supported v
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML). Supported versions that are affected are 5.5.53 and earlier, 5.6.34 and earlier and 5.7.16 and earlier. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulner
nvd
CVE-2021-34055P4HIGHCVSS 7.8v10.0v11.02022-11-04
CVE-2021-34055 [HIGH] CWE-120 CVE-2021-34055: jhead 3.06 is vulnerable to Buffer Overflow via exif.c in function Put16u.
jhead 3.06 is vulnerable to Buffer Overflow via exif.c in function Put16u.
nvd
CVE-2020-24977P4MEDIUMCVSS 6.5v9.02020-09-04
CVE-2020-24977 [MEDIUM] CWE-125 CVE-2020-24977: GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesIntern
GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c. The issue has been fixed in commit 50f06b3e.
nvd
CVE-2018-18718P4HIGHCVSS 7.8v8.02018-10-29
CVE-2018-18718 [HIGH] CWE-415 CVE-2018-18718: An issue was discovered in gThumb through 3.6.2. There is a double-free vulnerability in the add_the
An issue was discovered in gThumb through 3.6.2. There is a double-free vulnerability in the add_themes_from_dir method in dlg-contact-sheet.c because of two successive calls of g_free, each of which frees the same buffer.
nvd
CVE-2011-3618P4HIGHCVSS 7.8v8.0v9.0+1 more2019-11-12
CVE-2011-3618 [HIGH] CWE-59 CVE-2011-3618: atop: symlink attack possible due to insecure tempfile handling
atop: symlink attack possible due to insecure tempfile handling
nvd
CVE-2016-5384P4HIGHCVSS 7.8v8.02016-08-13
CVE-2016-5384 [HIGH] CWE-415 CVE-2016-5384: fontconfig before 2.12.1 does not validate offsets, which allows local users to trigger arbitrary fr
fontconfig before 2.12.1 does not validate offsets, which allows local users to trigger arbitrary free calls and consequently conduct double free attacks and execute arbitrary code via a crafted cache file.
nvd
CVE-2022-28893P3HIGHCVSS 7.8v11.02022-04-11
CVE-2022-28893 [HIGH] CWE-416 CVE-2022-28893: The SUNRPC subsystem in the Linux kernel through 5.17.2 can call xs_xprt_free before ensuring that s
The SUNRPC subsystem in the Linux kernel through 5.17.2 can call xs_xprt_free before ensuring that sockets are in the intended state.
nvd
CVE-2019-5819P4HIGHCVSS 7.8v10.02019-06-27
CVE-2019-5819 [HIGH] CWE-20 CVE-2019-5819: Insufficient data validation in developer tools in Google Chrome on OS X prior to 74.0.3729.108 allo
Insufficient data validation in developer tools in Google Chrome on OS X prior to 74.0.3729.108 allowed a local attacker to execute arbitrary code via a crafted string copied to clipboard.
nvd
CVE-2018-3070P4MEDIUMCVSS 6.5v8.02018-07-18
CVE-2018-3070 [MEDIUM] CVE-2018-3070: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client mysqldump). Suppor
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client mysqldump). Supported versions that are affected are 5.5.60 and prior, 5.6.40 and prior and 5.7.22 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnera
nvd
CVE-2011-1070P4HIGHCVSS 7.8v8.0v9.0+1 more2019-11-14
CVE-2011-1070 [HIGH] CWE-863 CVE-2011-1070: v86d before 0.1.10 do not verify if received netlink messages are sent by the kernel. This could all
v86d before 0.1.10 do not verify if received netlink messages are sent by the kernel. This could allow unprivileged users to manipulate the video mode and potentially other consequences.
nvd
CVE-2019-14575P3HIGHCVSS 7.8v9.02020-11-23
CVE-2019-14575 [HIGH] CVE-2019-14575: Logic issue in DxeImageVerificationHandler() for EDK II may allow an authenticated user to potential
Logic issue in DxeImageVerificationHandler() for EDK II may allow an authenticated user to potentially enable escalation of privilege via local access.
nvd
CVE-2019-3500P4HIGHCVSS 7.8v8.0v9.02019-01-02
CVE-2019-3500 [HIGH] CWE-532 CVE-2019-3500: aria2c in aria2 1.33.1, when --log is used, can store an HTTP Basic Authentication username and pass
aria2c in aria2 1.33.1, when --log is used, can store an HTTP Basic Authentication username and password in a file, which might allow local users to obtain sensitive information by reading this file.
nvd
CVE-2013-2859P3HIGHCVSS 7.5v7.0v8.02013-06-05
CVE-2013-2859 [HIGH] CVE-2013-2859: Google Chrome before 27.0.1453.110 allows remote attackers to bypass the Same Origin Policy and trig
Google Chrome before 27.0.1453.110 allows remote attackers to bypass the Same Origin Policy and trigger namespace pollution via unspecified vectors.
nvd
CVE-2022-32205P4MEDIUMCVSS 4.3v11.02022-07-07
CVE-2022-32205 [MEDIUM] CWE-770 CVE-2022-32205: A malicious server can serve excessive amounts of `Set-Cookie:` headers in a HTTP response to curl a
A malicious server can serve excessive amounts of `Set-Cookie:` headers in a HTTP response to curl and curl < 7.84.0 stores all of them. A sufficiently large amount of (big) cookies make subsequent HTTP requests to this, or other servers to which the cookies match, create requests that become larger than the threshold that curl uses internally to av
nvd
CVE-2023-33204P4HIGHCVSS 7.8v10.02023-05-18
CVE-2023-33204 [HIGH] CVE-2023-33204: sysstat through 12.7.2 allows a multiplication integer overflow in check_overflow in common.c. NOTE:
sysstat through 12.7.2 allows a multiplication integer overflow in check_overflow in common.c. NOTE: this issue exists because of an incomplete fix for CVE-2022-39377.
nvd
CVE-2021-30130P4HIGHCVSS 7.5v10.02021-04-06
CVE-2021-30130 [HIGH] CWE-347 CVE-2021-30130: phpseclib before 2.0.31 and 3.x before 3.0.7 mishandles RSA PKCS#1 v1.5 signature verification.
phpseclib before 2.0.31 and 3.x before 3.0.7 mishandles RSA PKCS#1 v1.5 signature verification.
nvd
CVE-2018-8032P4MEDIUMCVSS 6.1v9.02018-08-02
CVE-2018-8032 [MEDIUM] CWE-79 CVE-2018-8032: Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the
Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services.
nvd
CVE-2016-10937P4HIGHCVSS 7.5v8.02019-09-08
CVE-2016-10937 [HIGH] CWE-295 CVE-2016-10937: IMAPFilter through 2.6.12 does not validate the hostname in an SSL certificate.
IMAPFilter through 2.6.12 does not validate the hostname in an SSL certificate.
nvd
CVE-2014-3495P4HIGHCVSS 7.5v8.0v9.0+1 more2019-12-13
CVE-2014-3495 [HIGH] CWE-295 CVE-2014-3495: duplicity 0.6.24 has improper verification of SSL certificates
duplicity 0.6.24 has improper verification of SSL certificates
nvd
CVE-2023-41909P4HIGHCVSS 7.5v10.02023-09-05
CVE-2023-41909 [HIGH] CWE-476 CVE-2023-41909: An issue was discovered in FRRouting FRR through 9.0. bgp_nlri_parse_flowspec in bgpd/bgp_flowspec.c
An issue was discovered in FRRouting FRR through 9.0. bgp_nlri_parse_flowspec in bgpd/bgp_flowspec.c processes malformed requests with no attributes, leading to a NULL pointer dereference.
nvd