cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 263 of 498
CVE-2020-25269P4MEDIUMCVSS 6.5v9.0v10.02020-09-11
CVE-2020-25269 [MEDIUM] CWE-416 CVE-2020-25269: An issue was discovered in InspIRCd 2 before 2.0.29 and 3 before 3.6.0. The pgsql module contains a An issue was discovered in InspIRCd 2 before 2.0.29 and 3 before 3.6.0. The pgsql module contains a use after free vulnerability. When combined with the sqlauth or sqloper modules, this vulnerability can be used for remote crashing of an InspIRCd server by any user able to connect to a server.
nvd
CVE-2022-35256P3MEDIUMCVSS 6.5v11.02022-12-05
CVE-2022-35256 [MEDIUM] CWE-444 CVE-2022-35256: The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that ar The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF. This may result in HTTP Request Smuggling.
nvd
CVE-2019-9325P3MEDIUMCVSS 6.5v9.0v10.02019-09-27
CVE-2019-9325 [MEDIUM] CWE-125 CVE-2019-9325: In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112001302
nvd
CVE-2020-27617P4MEDIUMCVSS 6.5v9.0v10.02020-11-06
CVE-2020-27617 [MEDIUM] CWE-617 CVE-2020-27617: eth_get_gso_type in net/eth.c in QEMU 4.2.1 allows guest OS users to trigger an assertion failure. A eth_get_gso_type in net/eth.c in QEMU 4.2.1 allows guest OS users to trigger an assertion failure. A guest can crash the QEMU process via packet data that lacks a valid Layer 3 protocol.
nvd
CVE-2018-14660P4MEDIUMCVSS 6.5v9.02018-11-01
CVE-2018-14660 [MEDIUM] CWE-400 CVE-2018-14660: A flaw was found in glusterfs server through versions 4.1.4 and 3.1.2 which allowed repeated usage o A flaw was found in glusterfs server through versions 4.1.4 and 3.1.2 which allowed repeated usage of GF_META_LOCK_KEY xattr. A remote, authenticated attacker could use this flaw to create multiple locks for single inode by using setxattr repetitively resulting in memory exhaustion of glusterfs server node.
nvd
CVE-2013-4245P4HIGHCVSS 7.3v8.0v9.02019-12-11
CVE-2013-4245 [HIGH] CWE-20 CVE-2013-4245: Orca has arbitrary code execution due to insecure Python module load Orca has arbitrary code execution due to insecure Python module load
nvd
CVE-2024-32021P3HIGHCVSS 7.1v10.0v11.02024-05-14
CVE-2024-32021 [HIGH] CVE-2024-32021: Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, when cloning a local source repository that contains symlinks via the filesystem, Git may create hardlinks to arbitrary user-readable files on the same filesystem as the target repository in the `objects/` directory. Cloning a local repository over t
nvd
CVE-2018-15587P4MEDIUMCVSS 6.5v8.02019-02-11
CVE-2018-15587 [MEDIUM] CWE-347 CVE-2018-15587: GNOME Evolution through 3.28.2 is prone to OpenPGP signatures being spoofed for arbitrary messages u GNOME Evolution through 3.28.2 is prone to OpenPGP signatures being spoofed for arbitrary messages using a specially crafted email that contains a valid signature from the entity to be impersonated as an attachment.
nvd
CVE-2013-2012P4HIGHCVSS 7.3v8.0v9.0+1 more2019-10-31
CVE-2013-2012 [HIGH] CWE-269 CVE-2013-2012: autojump before 21.5.8 allows local users to gain privileges via a Trojan horse custom_install direc autojump before 21.5.8 allows local users to gain privileges via a Trojan horse custom_install directory in the current working directory.
nvd
CVE-2021-4160P4MEDIUMCVSS 5.9v9.0v10.0+1 more2022-01-28
CVE-2021-4160 [MEDIUM] CVE-2021-4160: There is a carry propagation bug in the MIPS32 and MIPS64 squaring procedure. Many EC algorithms are There is a carry propagation bug in the MIPS32 and MIPS64 squaring procedure. Many EC algorithms are affected, including some of the TLS 1.3 default curves. Impact was not analyzed in detail, because the pre-requisites for attack are considered unlikely and include reusing private keys. Analysis suggests that attacks against RSA and DSA as a result of this de
nvd
CVE-2020-25668P4HIGHCVSS 7.0v9.02021-05-26
CVE-2020-25668 [HIGH] CWE-362 CVE-2020-25668: A flaw was found in Linux Kernel because access to the global variable fg_console is not properly sy A flaw was found in Linux Kernel because access to the global variable fg_console is not properly synchronized leading to a use after free in con_font_op.
nvd
CVE-2023-0668P4MEDIUMCVSS 6.5v12.02023-06-07
CVE-2023-0668 [MEDIUM] CWE-125 CVE-2023-0668: Due to failure in validating the length provided by an attacker-crafted IEEE-C37.118 packet, Wiresha Due to failure in validating the length provided by an attacker-crafted IEEE-C37.118 packet, Wireshark version 4.0.5 and prior, by default, is susceptible to a heap-based buffer overflow, and possibly code execution in the context of the process running Wireshark.
nvd
CVE-2023-0666P3MEDIUMCVSS 6.5v12.02023-06-07
CVE-2023-0666 [MEDIUM] CWE-122 CVE-2023-0666: Due to failure in validating the length provided by an attacker-crafted RTPS packet, Wireshark versi Due to failure in validating the length provided by an attacker-crafted RTPS packet, Wireshark version 4.0.5 and prior, by default, is susceptible to a heap-based buffer overflow, and possibly code execution in the context of the process running Wireshark.
nvd
CVE-2021-35564P4MEDIUMCVSS 5.3v9.0v10.0+1 more2021-10-20
CVE-2021-35564 [MEDIUM] CVE-2021-35564: Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Keytool). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compr
nvd
CVE-2016-2047P4MEDIUMCVSS 5.9v8.0v9.02016-01-27
CVE-2016-2047 [MEDIUM] CWE-254 CVE-2016-2047: The ssl_verify_server_cert function in sql-common/client.c in MariaDB before 5.5.47, 10.0.x before 1 The ssl_verify_server_cert function in sql-common/client.c in MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10; Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier; and Percona Server do not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName
nvd
CVE-2020-11521P3MEDIUMCVSS 6.6v9.02020-05-15
CVE-2020-11521 [MEDIUM] CWE-125 CVE-2020-11521: libfreerdp/codec/planar.c in FreeRDP version > 1.0 through 2.0.0-rc4 has an Out-of-bounds Write. libfreerdp/codec/planar.c in FreeRDP version > 1.0 through 2.0.0-rc4 has an Out-of-bounds Write.
nvd
CVE-2024-0741P3MEDIUMCVSS 6.5v10.02024-01-23
CVE-2024-0741 [MEDIUM] CWE-787 CVE-2024-0741: An out of bounds write in ANGLE could have allowed an attacker to corrupt memory leading to a potent An out of bounds write in ANGLE could have allowed an attacker to corrupt memory leading to a potentially exploitable crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
nvd
CVE-2018-10913P4MEDIUMCVSS 6.5v8.0v9.02018-09-04
CVE-2018-10913 [MEDIUM] CWE-209 CVE-2018-10913: An information disclosure vulnerability was discovered in glusterfs server. An attacker could issue An information disclosure vulnerability was discovered in glusterfs server. An attacker could issue a xattr request via glusterfs FUSE to determine the existence of any file.
nvd
CVE-2021-3671P3MEDIUMCVSS 6.5v10.0v11.02021-10-12
CVE-2021-3671 [MEDIUM] CWE-476 CVE-2021-3671: A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS- A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS-REQ (Ticket Granting Server - Request). An authenticated user could use this flaw to crash the samba server.
nvd
CVE-2016-2120P4MEDIUMCVSS 6.5v8.02018-11-01
CVE-2016-2120 [MEDIUM] CWE-190 CVE-2016-2120: An issue has been found in PowerDNS Authoritative Server versions up to and including 3.4.10, 4.0.1 An issue has been found in PowerDNS Authoritative Server versions up to and including 3.4.10, 4.0.1 allowing an authorized user to crash the server by inserting a specially crafted record in a zone under their control then sending a DNS query for that record. The issue is due to an integer overflow when checking if the content of the record matches the
nvd
Debian Linux vulnerabilities | cvebase