Debian Linux vulnerabilities
9,954 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358
Vulnerabilities
Page 266 of 498
CVE-2015-5395P4HIGHCVSS 8.8v7.0v8.0+1 more2017-09-20
CVE-2015-5395 [HIGH] CWE-352 CVE-2015-5395: Cross-site request forgery (CSRF) vulnerability in SOGo before 3.1.0.
Cross-site request forgery (CSRF) vulnerability in SOGo before 3.1.0.
nvd
CVE-2008-5018P4CRITICALCVSS 10.0v4.02008-11-13
CVE-2008-5018 [CRITICAL] CWE-399 CVE-2008-5018: The JavaScript engine in Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird
The JavaScript engine in Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via vectors related to "insufficient class checking" in the Date class.
nvd
CVE-2024-12426P4MEDIUMCVSS 6.5v11.02025-01-07
CVE-2024-12426 [MEDIUM] CWE-200 CVE-2024-12426: Exposure of Environmental Variables and arbitrary INI file values to an Unauthorized Actor vulnerabi
Exposure of Environmental Variables and arbitrary INI file values to an Unauthorized Actor vulnerability in The Document Foundation LibreOffice.
URLs could be constructed which expanded environmental variables or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening a document containing such link
nvd
CVE-2017-0362P4HIGHCVSS 8.8v7.02018-04-13
CVE-2017-0362 [HIGH] CWE-352 CVE-2017-0362: Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw where the "Mark all pages visited" on the
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw where the "Mark all pages visited" on the watchlist does not require a CSRF token.
nvd
CVE-2024-35853P4MEDIUMCVSS 6.4v10.02024-05-17
CVE-2024-35853 [MEDIUM] CWE-401 CVE-2024-35853: In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_acl_tcam: Fix m
In the Linux kernel, the following vulnerability has been resolved:
mlxsw: spectrum_acl_tcam: Fix memory leak during rehash
The rehash delayed work migrates filters from one region to another.
This is done by iterating over all chunks (all the filters with the same
priority) in the region and in each chunk iterating over all the
filters.
If the mi
nvd
CVE-2010-2527P4MEDIUMCVSS 6.8v5.02010-08-19
CVE-2010-2527 [MEDIUM] CWE-120 CVE-2010-2527: Multiple buffer overflows in demo programs in FreeType before 2.4.0 allow remote attackers to cause
Multiple buffer overflows in demo programs in FreeType before 2.4.0 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.
nvd
CVE-2010-2498P4MEDIUMCVSS 6.8v5.02010-08-19
CVE-2010-2498 [MEDIUM] CWE-787 CVE-2010-2498: The psh_glyph_find_strong_points function in pshinter/pshalgo.c in FreeType before 2.4.0 does not pr
The psh_glyph_find_strong_points function in pshinter/pshalgo.c in FreeType before 2.4.0 does not properly implement hinting masks, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via a crafted font file that triggers an invalid free operation.
nvd
CVE-2012-2750P4CRITICALCVSS 10.0v6.02012-08-17
CVE-2012-2750 [CRITICAL] CVE-2012-2750: Unspecified vulnerability in MySQL 5.5.x before 5.5.23 has unknown impact and attack vectors related
Unspecified vulnerability in MySQL 5.5.x before 5.5.23 has unknown impact and attack vectors related to a "Security Fix", aka Bug #59533. NOTE: this might be a duplicate of CVE-2012-1689, but as of 20120816, Oracle has not commented on this possibility.
nvd
CVE-2016-7448P3HIGHCVSS 7.5v8.02017-02-06
CVE-2016-7448 [HIGH] CWE-399 CVE-2016-7448: The Utah RLE reader in GraphicsMagick before 1.3.25 allows remote attackers to cause a denial of ser
The Utah RLE reader in GraphicsMagick before 1.3.25 allows remote attackers to cause a denial of service (CPU consumption or large memory allocations) via vectors involving the header information and the file size.
nvd
CVE-2018-19662P4HIGHCVSS 8.1v8.02018-11-29
CVE-2018-19662 [HIGH] CWE-125 CVE-2018-19662: An issue was discovered in libsndfile 1.0.28. There is a buffer over-read in the function i2alaw_arr
An issue was discovered in libsndfile 1.0.28. There is a buffer over-read in the function i2alaw_array in alaw.c that will lead to a denial of service.
nvd
CVE-2011-4566P3MEDIUMCVSS 6.4v5.0v6.0+1 more2011-11-29
CVE-2011-4566 [MEDIUM] CVE-2011-4566: Integer overflow in the exif_process_IFD_TAG function in exif.c in the exif extension in PHP 5.4.0be
Integer overflow in the exif_process_IFD_TAG function in exif.c in the exif extension in PHP 5.4.0beta2 on 32-bit platforms allows remote attackers to read the contents of arbitrary memory locations or cause a denial of service via a crafted offset_val value in an EXIF header in a JPEG file, a different vulnerability than CVE-2011-0708.
nvd
CVE-2017-10810P4HIGHCVSS 7.5v8.0v9.02017-07-04
CVE-2017-10810 [HIGH] CWE-772 CVE-2017-10810: Memory leak in the virtio_gpu_object_create function in drivers/gpu/drm/virtio/virtgpu_object.c in t
Memory leak in the virtio_gpu_object_create function in drivers/gpu/drm/virtio/virtgpu_object.c in the Linux kernel through 4.11.8 allows attackers to cause a denial of service (memory consumption) by triggering object-initialization failures.
nvd
CVE-2015-3451P4MEDIUMCVSS 5.0v7.0v8.02015-05-12
CVE-2015-3451 [MEDIUM] CWE-611 CVE-2015-3451: The _clone function in XML::LibXML before 2.0119 does not properly set the expand_entities option, w
The _clone function in XML::LibXML before 2.0119 does not properly set the expand_entities option, which allows remote attackers to conduct XML external entity (XXE) attacks via crafted XML data to the (1) new or (2) load_xml function.
nvd
CVE-2019-7398P4HIGHCVSS 7.5v10.02019-02-05
CVE-2019-7398 [HIGH] CWE-401 CVE-2019-7398: In ImageMagick before 7.0.8-25, a memory leak exists in WriteDIBImage in coders/dib.c.
In ImageMagick before 7.0.8-25, a memory leak exists in WriteDIBImage in coders/dib.c.
nvd
CVE-2017-12608P4HIGHCVSS 7.8v7.0v8.02017-11-20
CVE-2017-12608 [HIGH] CWE-787 CVE-2017-12608: A vulnerability in Apache OpenOffice Writer DOC file parser before 4.1.4, and specifically in Import
A vulnerability in Apache OpenOffice Writer DOC file parser before 4.1.4, and specifically in ImportOldFormatStyles, allows attackers to craft malicious documents that cause denial of service (memory corruption and application crash) potentially resulting in arbitrary code execution.
nvd
CVE-2023-27536P4MEDIUMCVSS 5.9v10.02023-03-30
CVE-2023-27536 [MEDIUM] CWE-305 CVE-2023-27536: An authentication bypass vulnerability exists libcurl <8.0.0 in the connection reuse feature which c
An authentication bypass vulnerability exists libcurl <8.0.0 in the connection reuse feature which can reuse previously established connections with incorrect user permissions due to a failure to check for changes in the CURLOPT_GSSAPI_DELEGATION option. This vulnerability affects krb5/kerberos/negotiate/GSSAPI transfers and could potentially result
nvd
CVE-2019-14870P3MEDIUMCVSS 5.4v9.0v10.02019-12-10
CVE-2019-14870 [MEDIUM] CWE-285 CVE-2019-14870: All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue
All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the S4U (MS-SFU) Kerberos delegation model includes a feature allowing for a subset of clients to be opted out of constrained delegation in any way, either S4U2Self or regular Kerberos authentication, by forcing all tickets for these clients t
nvd
CVE-2016-7449P4HIGHCVSS 7.5v8.02017-02-06
CVE-2016-7449 [HIGH] CWE-125 CVE-2016-7449: The TIFFGetField function in coders/tiff.c in GraphicsMagick 1.3.24 allows remote attackers to cause
The TIFFGetField function in coders/tiff.c in GraphicsMagick 1.3.24 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a file containing an "unterminated" string.
nvd
CVE-2019-7396P4HIGHCVSS 7.5v10.02019-02-05
CVE-2019-7396 [HIGH] CWE-401 CVE-2019-7396: In ImageMagick before 7.0.8-25, a memory leak exists in ReadSIXELImage in coders/sixel.c.
In ImageMagick before 7.0.8-25, a memory leak exists in ReadSIXELImage in coders/sixel.c.
nvd
CVE-2019-7395P4HIGHCVSS 7.5v10.02019-02-05
CVE-2019-7395 [HIGH] CWE-401 CVE-2019-7395: In ImageMagick before 7.0.8-25, a memory leak exists in WritePSDChannel in coders/psd.c.
In ImageMagick before 7.0.8-25, a memory leak exists in WritePSDChannel in coders/psd.c.
nvd