Debian Linux vulnerabilities
9,954 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358
Vulnerabilities
Page 265 of 498
CVE-2020-15707P4MEDIUMCVSS 6.4v10.02020-07-29
CVE-2020-15707 [MEDIUM] CWE-362 CVE-2020-15707: Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efili
Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red Hat, and Ubuntu (the functionality is not included in GRUB2 upstream), leading to a heap-based buffer overflow. These could be triggered by an extremely large number of arguments to the initrd command
nvd
CVE-2014-1705P4HIGHCVSS 7.5v7.0v8.02014-03-16
CVE-2014-1705 [HIGH] CWE-787 CVE-2014-1705: Google V8, as used in Google Chrome before 33.0.1750.152 on OS X and Linux and before 33.0.1750.154
Google V8, as used in Google Chrome before 33.0.1750.152 on OS X and Linux and before 33.0.1750.154 on Windows, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2013-2625P4MEDIUMCVSS 6.5v8.0v9.0+1 more2019-11-27
CVE-2013-2625 [MEDIUM] CWE-269 CVE-2013-2625: An Access Bypass issue exists in OTRS Help Desk before 3.2.4, 3.1.14, and 3.0.19, OTRS ITSM before 3
An Access Bypass issue exists in OTRS Help Desk before 3.2.4, 3.1.14, and 3.0.19, OTRS ITSM before 3.2.3, 3.1.8, and 3.0.7, and FAQ before 2.2.3, 2.1.4, and 2.0.8. Access rights by the object linking mechanism is not verified
nvd
CVE-2019-19830P4MEDIUMCVSS 6.5v9.0v10.02019-12-17
CVE-2019-19830 [MEDIUM] CVE-2019-19830: _core_/plugins/medias in SPIP 3.2.x before 3.2.7 allows remote authenticated authors to inject conte
_core_/plugins/medias in SPIP 3.2.x before 3.2.7 allows remote authenticated authors to inject content into the database.
nvd
CVE-2020-9498P4MEDIUMCVSS 6.7v9.02020-07-02
CVE-2020-9498 [MEDIUM] CWE-787 CVE-2020-9498: Apache Guacamole 1.1.0 and older may mishandle pointers involved inprocessing data received via RDP
Apache Guacamole 1.1.0 and older may mishandle pointers involved inprocessing data received via RDP static virtual channels. If a userconnects to a malicious or compromised RDP server, a series ofspecially-crafted PDUs could result in memory corruption, possiblyallowing arbitrary code to be executed with the privileges of therunning guacd process.
nvd
CVE-2017-11104P4MEDIUMCVSS 5.9v8.0v9.0+1 more2017-07-08
CVE-2017-11104 [MEDIUM] CWE-20 CVE-2017-11104: Knot DNS before 2.4.5 and 2.5.x before 2.5.2 contains a flaw within the TSIG protocol implementation
Knot DNS before 2.4.5 and 2.5.x before 2.5.2 contains a flaw within the TSIG protocol implementation that would allow an attacker with a valid key name and algorithm to bypass TSIG authentication if no additional ACL restrictions are set, because of an improper TSIG validity period check.
nvd
CVE-2016-2831P4HIGHCVSS 8.8v8.02016-06-13
CVE-2016-2831 [HIGH] CWE-254 CVE-2016-2831: Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 do not ensure that the user approves th
Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 do not ensure that the user approves the fullscreen and pointerlock settings, which allows remote attackers to cause a denial of service (UI outage), or conduct clickjacking or spoofing attacks, via a crafted web site.
nvd
CVE-2021-38165P4MEDIUMCVSS 5.3v9.0v10.02021-08-07
CVE-2021-38165 [MEDIUM] CWE-522 CVE-2021-38165: Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to d
Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may appear in SNI data.
nvd
CVE-2016-3994P4HIGHCVSS 8.2v7.0v8.02016-05-13
CVE-2016-3994 [HIGH] CWE-119 CVE-2016-3994: The GIF loader in imlib2 before 1.4.9 allows remote attackers to cause a denial of service (applicat
The GIF loader in imlib2 before 1.4.9 allows remote attackers to cause a denial of service (application crash) or obtain sensitive information via a crafted image, which triggers an out-of-bounds read.
nvd
CVE-2010-0434P4MEDIUMCVSS 4.3v5.0v6.02010-03-05
CVE-2010-0434 [MEDIUM] CWE-200 CVE-2010-0434: The ap_read_request function in server/protocol.c in the Apache HTTP Server 2.2.x before 2.2.15, whe
The ap_read_request function in server/protocol.c in the Apache HTTP Server 2.2.x before 2.2.15, when a multithreaded MPM is used, does not properly handle headers in subrequests in certain circumstances involving a parent request that has a body, which might allow remote attackers to obtain sensitive information via a crafted request that triggers ac
nvd
CVE-2019-8921P4MEDIUMCVSS 6.5v10.02021-11-29
CVE-2019-8921 [MEDIUM] CWE-345 CVE-2019-8921: An issue was discovered in bluetoothd in BlueZ through 5.48. The vulnerability lies in the handling
An issue was discovered in bluetoothd in BlueZ through 5.48. The vulnerability lies in the handling of a SVC_ATTR_REQ by the SDP implementation. By crafting a malicious CSTATE, it is possible to trick the server into returning more bytes than the buffer actually holds, resulting in leaking arbitrary heap data. The root cause can be found in the functio
nvd
CVE-2017-5848P4HIGHCVSS 7.5v8.0v9.02017-02-09
CVE-2017-5848 [HIGH] CWE-125 CVE-2017-5848: The gst_ps_demux_parse_psm function in gst/mpegdemux/gstmpegdemux.c in gst-plugins-bad in GStreamer
The gst_ps_demux_parse_psm function in gst/mpegdemux/gstmpegdemux.c in gst-plugins-bad in GStreamer allows remote attackers to cause a denial of service (invalid memory read and crash) via vectors involving PSM parsing.
nvd
CVE-2016-1695P4HIGHCVSS 8.8v8.02016-06-05
CVE-2016-1695 [HIGH] CVE-2016-1695: Multiple unspecified vulnerabilities in Google Chrome before 51.0.2704.63 allow attackers to cause a
Multiple unspecified vulnerabilities in Google Chrome before 51.0.2704.63 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2016-1703P4HIGHCVSS 8.8v8.02016-06-05
CVE-2016-1703 [HIGH] CVE-2016-1703: Multiple unspecified vulnerabilities in Google Chrome before 51.0.2704.79 allow attackers to cause a
Multiple unspecified vulnerabilities in Google Chrome before 51.0.2704.79 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2022-26491P4MEDIUMCVSS 5.9v9.02022-06-02
CVE-2022-26491 [MEDIUM] CVE-2022-26491: An issue was discovered in Pidgin before 2.14.9. A remote attacker who can spoof DNS responses can r
An issue was discovered in Pidgin before 2.14.9. A remote attacker who can spoof DNS responses can redirect a client connection to a malicious server. The client will perform TLS certificate verification of the malicious domain name instead of the original XMPP service domain, allowing the attacker to take over control over the XMPP connection and to obtain
nvd
CVE-2022-41915P4MEDIUMCVSS 6.5v10.0v11.02022-12-13
CVE-2022-41915 [MEDIUM] CWE-113 CVE-2022-41915: Netty project is an event-driven asynchronous network application framework. Starting in version 4.1
Netty project is an event-driven asynchronous network application framework. Starting in version 4.1.83.Final and prior to 4.1.86.Final, when calling `DefaultHttpHeadesr.set` with an _iterator_ of values, header value validation was not performed, allowing malicious header values in the iterator to perform HTTP Response Splitting. This issue has bee
nvd
CVE-2021-28658P4MEDIUMCVSS 5.3v9.02021-04-06
CVE-2021-28658 [MEDIUM] CWE-22 CVE-2021-28658: In Django 2.2 before 2.2.20, 3.0 before 3.0.14, and 3.1 before 3.1.8, MultiPartParser allowed direct
In Django 2.2 before 2.2.20, 3.0 before 3.0.14, and 3.1 before 3.1.8, MultiPartParser allowed directory traversal via uploaded files with suitably crafted file names. Built-in upload handlers were not affected by this vulnerability.
nvd
CVE-2018-19143P4MEDIUMCVSS 6.5v8.02018-11-11
CVE-2018-19143 [MEDIUM] CWE-425 CVE-2018-19143: Open Ticket Request System (OTRS) 4.0.x before 4.0.33, 5.0.x before 5.0.31, and 6.0.x before 6.0.13
Open Ticket Request System (OTRS) 4.0.x before 4.0.33, 5.0.x before 5.0.31, and 6.0.x before 6.0.13 allows an authenticated user to delete files via a modified submission form because upload caching is mishandled.
nvd
CVE-2023-5388P4MEDIUMCVSS 6.5v10.02024-03-19
CVE-2023-5388 [MEDIUM] CWE-203 CVE-2023-5388: NSS was susceptible to a timing side-channel attack when performing RSA decryption. This attack coul
NSS was susceptible to a timing side-channel attack when performing RSA decryption. This attack could potentially allow an attacker to recover the private data. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
nvd
CVE-2019-13377P4MEDIUMCVSS 5.9v10.02019-08-15
CVE-2019-13377 [MEDIUM] CWE-203 CVE-2019-13377: The implementations of SAE and EAP-pwd in hostapd and wpa_supplicant 2.x through 2.8 are vulnerable
The implementations of SAE and EAP-pwd in hostapd and wpa_supplicant 2.x through 2.8 are vulnerable to side-channel attacks as a result of observable timing differences and cache access patterns when Brainpool curves are used. An attacker may be able to gain leaked information from a side-channel attack that can be used for full password recovery.
nvd