cbcvebase.

Debian Linux vulnerabilities

9,953 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358

Vulnerabilities

Page 27 of 498
CVE-2017-0358P3HIGHCVSS 7.8PoCv8.02018-04-13
CVE-2017-0358 [HIGH] CWE-269 CVE-2017-0358: Jann Horn of Google Project Zero discovered that NTFS-3G, a read-write NTFS driver for FUSE, does no Jann Horn of Google Project Zero discovered that NTFS-3G, a read-write NTFS driver for FUSE, does not scrub the environment before executing modprobe with elevated privileges. A local user can take advantage of this flaw for local root privilege escalation.
nvd
CVE-2019-15606P2CRITICALCVSS 9.8v10.02020-02-07
CVE-2019-15606 [CRITICAL] CWE-20 CVE-2019-15606: Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of autho Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons
nvd
CVE-2018-5390P3HIGHCVSS 7.5v8.0v9.02018-08-06
CVE-2018-5390 [HIGH] CWE-400 CVE-2018-5390: Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() an Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service.
nvd
CVE-2018-18065P3MEDIUMCVSS 6.5PoCv9.02018-10-08
CVE-2018-18065 [MEDIUM] CWE-476 CVE-2018-18065: _set_key in agent/helpers/table_container.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug _set_key in agent/helpers/table_container.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an authenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resulting in Denial of Service.
nvd
CVE-2018-1125P3HIGHCVSS 7.5PoCv7.0v8.0+1 more2018-05-23
CVE-2018-1125 [HIGH] CWE-121 CVE-2018-1125: procps-ng before version 3.3.15 is vulnerable to a stack buffer overflow in pgrep. This vulnerabilit procps-ng before version 3.3.15 is vulnerable to a stack buffer overflow in pgrep. This vulnerability is mitigated by FORTIFY, as it involves strncat() to a stack-allocated string. When pgrep is compiled with FORTIFY (as on Red Hat Enterprise Linux and Fedora), the impact is limited to a crash.
nvd
CVE-2021-32761P2HIGHCVSS 7.5v9.0v10.0+1 more2021-07-21
CVE-2021-32761 [HIGH] CWE-125 CVE-2021-32761: Redis is an in-memory database that persists on disk. A vulnerability involving out-of-bounds read a Redis is an in-memory database that persists on disk. A vulnerability involving out-of-bounds read and integer overflow to buffer overflow exists starting with version 2.2 and prior to versions 5.0.13, 6.0.15, and 6.2.5. On 32-bit systems, Redis `*BIT*` command are vulnerable to integer overflow that can potentially be exploited to corrupt the heap, l
nvd
CVE-2019-1999P3HIGHCVSS 7.8PoCv9.0v10.02019-02-28
CVE-2019-1999 [HIGH] CWE-415 CVE-2019-1999: In binder_alloc_free_page of binder_alloc.c, there is a possible double free due to improper locking In binder_alloc_free_page of binder_alloc.c, there is a possible double free due to improper locking. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-120025196.
nvd
CVE-2021-23450P2CRITICALCVSS 9.8v10.02021-12-17
CVE-2021-23450 [CRITICAL] CWE-1321 CVE-2021-23450: All versions of package dojo are vulnerable to Prototype Pollution via the setObject function. All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.
nvd
CVE-2023-4355P2HIGHCVSS 8.8v11.0v12.02023-08-15
CVE-2023-4355 [HIGH] CWE-787 CVE-2023-4355: Out of bounds memory access in V8 in Google Chrome prior to 116.0.5845.96 allowed a remote attacker Out of bounds memory access in V8 in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2022-25236P2CRITICALCVSS 9.8v10.0v11.02022-02-16
CVE-2022-25236 [CRITICAL] CWE-668 CVE-2022-25236: xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator chara xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.
nvd
CVE-2018-20148P2CRITICALCVSS 9.8v8.0v9.02018-12-14
CVE-2018-20148 [CRITICAL] CWE-502 CVE-2018-20148: In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection atta In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection attacks via crafted metadata in a wp.getMediaItem XMLRPC call. This is caused by mishandling of serialized data at phar:// URLs in the wp_get_attachment_thumb_file function in wp-includes/post.php.
nvd
CVE-2017-10661P3HIGHCVSS 7.0PoCv8.0v9.02017-08-19
CVE-2017-10661 [HIGH] CWE-416 CVE-2017-10661: Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local users to gain privile Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local users to gain privileges or cause a denial of service (list corruption or use-after-free) via simultaneous file-descriptor operations that leverage improper might_cancel queueing.
nvd
CVE-2023-24998P3HIGHCVSS 7.5v9.0v11.02023-02-20
CVE-2023-24998 [HIGH] CWE-770 CVE-2023-24998: Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resu Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads. Note that, like all of the file upload limits, the new configuration option (FileUploadBase#setFileCountMax) is not enabled by default and must be e
nvd
CVE-2022-25648P2CRITICALCVSS 9.8v10.02022-04-19
CVE-2022-25648 [CRITICAL] CWE-88 CVE-2022-25648: The package git before 1.11.0 are vulnerable to Command Injection via git argument injection. When c The package git before 1.11.0 are vulnerable to Command Injection via git argument injection. When calling the fetch(remote = 'origin', opts = {}) function, the remote parameter is passed to the git fetch subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection.
nvd
CVE-2021-27212P3HIGHCVSS 7.5v9.0v10.02021-02-14
CVE-2021-27212 [HIGH] CWE-617 CVE-2021-27212: In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in slapd can occur in In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in slapd can occur in the issuerAndThisUpdateCheck function via a crafted packet, resulting in a denial of service (daemon exit) via a short timestamp. This is related to schema_init.c and checkTime.
nvd
CVE-2017-7657P2CRITICALCVSS 9.8v9.02018-06-26
CVE-2017-7657 [CRITICAL] CWE-444 CVE-2017-7657: In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default confi In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), transfer-encoding chunks are handled poorly. The chunk length parsing was vulnerable to an integer overflow. Thus a large chunk size could be interpreted as a smaller chunk size and content sent as chunk body
nvd
CVE-2014-5008P2CRITICALCVSS 9.8v7.02017-03-31
CVE-2014-5008 [CRITICAL] CWE-77 CVE-2014-5008: Snoopy allows remote attackers to execute arbitrary commands. Snoopy allows remote attackers to execute arbitrary commands.
nvd
CVE-2017-10355P3MEDIUMCVSS 5.3PoCv7.0v8.0+1 more2017-10-19
CVE-2017-10355 [MEDIUM] CVE-2017-10355: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: N Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144; JRockit: R28.3.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java
nvd
CVE-2018-1312P2CRITICALCVSS 9.8v7.0v8.0+1 more2018-03-26
CVE-2018-1312 [CRITICAL] CWE-287 CVE-2018-1312: In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly generated using a pseudo-random seed. In a cluster of servers using a common Digest authentication configuration, HTTP requests could be replayed across servers by an attacker without detection.
nvd
CVE-2022-0547P2CRITICALCVSS 9.8v9.02022-03-18
CVE-2022-0547 [CRITICAL] CWE-305 CVE-2022-0547: OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plu OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials.
nvd
Debian Linux vulnerabilities | cvebase