Debian Linux vulnerabilities
9,954 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358
Vulnerabilities
Page 273 of 498
CVE-2004-0889P4CRITICALCVSS 10.0v3.02005-01-27
CVE-2004-0889 [CRITICAL] CVE-2004-0889: Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow re
Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0888.
nvd
CVE-2015-1822P4MEDIUMCVSS 6.5v7.02015-04-16
CVE-2015-1822 [MEDIUM] CWE-17 CVE-2015-1822: chrony before 1.31.1 does not initialize the last "next" pointer when saving unacknowledged replies
chrony before 1.31.1 does not initialize the last "next" pointer when saving unacknowledged replies to command requests, which allows remote authenticated users to cause a denial of service (uninitialized pointer dereference and daemon crash) or possibly execute arbitrary code via a large number of command requests.
nvd
CVE-2017-3600P4MEDIUMCVSS 6.6v8.02017-04-24
CVE-2017-3600 [MEDIUM] CVE-2017-3600: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client mysqldump). Suppor
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client mysqldump). Supported versions that are affected are 5.5.54 and earlier, 5.6.35 and earlier and 5.7.17 and earlier. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of thi
nvd
CVE-2020-6426P4MEDIUMCVSS 6.5v9.0v10.02020-03-23
CVE-2020-6426 [MEDIUM] CWE-787 CVE-2020-6426: Inappropriate implementation in V8 in Google Chrome prior to 80.0.3987.149 allowed a remote attacker
Inappropriate implementation in V8 in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2007-6170P4MEDIUMCVSS 6.5v3.1v4.02007-11-30
CVE-2007-6170 [MEDIUM] CWE-89 CVE-2007-6170: SQL injection vulnerability in the Call Detail Record Postgres logging engine (cdr_pgsql) in Asteris
SQL injection vulnerability in the Call Detail Record Postgres logging engine (cdr_pgsql) in Asterisk 1.4.x before 1.4.15, 1.2.x before 1.2.25, B.x before B.2.3.4, and C.x before C.1.0-beta6 allows remote authenticated users to execute arbitrary SQL commands via (1) ANI and (2) DNIS arguments.
nvd
CVE-2019-20917P4MEDIUMCVSS 6.5v9.0v10.02020-09-11
CVE-2019-20917 [MEDIUM] CWE-476 CVE-2019-20917: An issue was discovered in InspIRCd 2 before 2.0.28 and 3 before 3.3.0. The mysql module contains a
An issue was discovered in InspIRCd 2 before 2.0.28 and 3 before 3.3.0. The mysql module contains a NULL pointer dereference when built against mariadb-connector-c 3.0.5 or newer. When combined with the sqlauth or sqloper modules, this vulnerability can be used for remote crashing of an InspIRCd server by any user able to connect to a server.
nvd
CVE-2019-10247P4MEDIUMCVSS 5.3v9.0v10.02019-04-22
CVE-2019-10247 [MEDIUM] CWE-213 CVE-2019-10247: In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the ser
In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the server running on any OS and Jetty version combination will reveal the configured fully qualified directory base resource location on the output of the 404 error for not finding a Context that matches the requested path. The default server behavior on je
nvd
CVE-2017-17742P4MEDIUMCVSS 5.3v7.02018-04-03
CVE-2017-17742 [MEDIUM] CWE-113 CVE-2017-17742: Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1 a
Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1 allows an HTTP Response Splitting attack. An attacker can inject a crafted key and value into an HTTP response for the HTTP server of WEBrick.
nvd
CVE-2017-2666P4MEDIUMCVSS 6.5v9.0v10.02018-07-27
CVE-2017-2666 [MEDIUM] CWE-444 CVE-2017-2666: It was discovered in Undertow that the code that parsed the HTTP request line permitted invalid char
It was discovered in Undertow that the code that parsed the HTTP request line permitted invalid characters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the HTTP response. By manipulating the HTTP response the attacker could poison a web-cache,
nvd
CVE-2020-15389P4MEDIUMCVSS 6.5v9.0v10.02020-06-29
CVE-2020-15389 [MEDIUM] CWE-416 CVE-2020-15389: jp2/opj_decompress.c in OpenJPEG through 2.3.1 has a use-after-free that can be triggered if there i
jp2/opj_decompress.c in OpenJPEG through 2.3.1 has a use-after-free that can be triggered if there is a mix of valid and invalid files in a directory operated on by the decompressor. Triggering a double-free may also be possible. This is related to calling opj_image_destroy twice.
nvd
CVE-2017-3257P4MEDIUMCVSS 6.5v8.02017-01-27
CVE-2017-3257 [MEDIUM] CWE-269 CVE-2017-3257: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: InnoDB). Supporte
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: InnoDB). Supported versions that are affected are 5.6.34 and earlier5.7.16 and earlier. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can re
nvd
CVE-2018-2761P4MEDIUMCVSS 5.9v7.0v8.0+1 more2018-04-19
CVE-2018-2761 [MEDIUM] CVE-2018-2761: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs). Support
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs). Supported versions that are affected are 5.5.59 and prior, 5.6.39 and prior and 5.7.21 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulne
nvd
CVE-2017-14604P3MEDIUMCVSS 6.5v8.0v9.0+1 more2017-09-20
CVE-2017-14604 [MEDIUM] CWE-20 CVE-2017-14604: GNOME Nautilus before 3.23.90 allows attackers to spoof a file type by using the .desktop file exten
GNOME Nautilus before 3.23.90 allows attackers to spoof a file type by using the .desktop file extension, as demonstrated by an attack in which a .desktop file's Name field ends in .pdf but this file's Exec field launches a malicious "sh -c" command. In other words, Nautilus provides no UI indication that a file actually has the potentially unsafe .d
nvd
CVE-2021-22876P4MEDIUMCVSS 5.3v9.02021-04-01
CVE-2021-22876 [MEDIUM] CWE-359 CVE-2021-22876: curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to
curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in the HTTP Referer: header. libcurl does not strip off user credentials from the URL when automatically populating the Referer: HTTP request header field in outgoing HTTP requests, and therefore risks leak
nvd
CVE-2007-3278P4MEDIUMCVSS 6.9v3.1v4.02007-06-19
CVE-2007-3278 [MEDIUM] CWE-264 CVE-2007-3278: PostgreSQL 8.1 and probably later versions, when local trust authentication is enabled and the Datab
PostgreSQL 8.1 and probably later versions, when local trust authentication is enabled and the Database Link library (dblink) is installed, allows remote attackers to access arbitrary accounts and execute arbitrary SQL queries via a dblink host parameter that proxies the connection from 127.0.0.1.
nvd
CVE-2019-18683P3HIGHCVSS 7.0v8.02019-11-04
CVE-2019-18683 [HIGH] CWE-362 CVE-2019-18683: An issue was discovered in drivers/media/platform/vivid in the Linux kernel through 5.3.8. It is exp
An issue was discovered in drivers/media/platform/vivid in the Linux kernel through 5.3.8. It is exploitable for privilege escalation on some Linux distributions where local users have /dev/video0 access, but only if the driver happens to be loaded. There are multiple race conditions during streaming stopping in this driver (part of the V4L2 subsystem
nvd
CVE-2023-2002P4MEDIUMCVSS 6.8v10.0v11.02023-05-26
CVE-2023-2002 [MEDIUM] CWE-250 CVE-2023-2002: A vulnerability was found in the HCI sockets implementation due to a missing capability check in net
A vulnerability was found in the HCI sockets implementation due to a missing capability check in net/bluetooth/hci_sock.c in the Linux Kernel. This flaw allows an attacker to unauthorized execution of management commands, compromising the confidentiality, integrity, and availability of Bluetooth communication.
nvd
CVE-2019-13750P4MEDIUMCVSS 6.5v9.0v10.02019-12-10
CVE-2019-13750 [MEDIUM] CWE-20 CVE-2019-13750: Insufficient data validation in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attac
Insufficient data validation in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass defense-in-depth measures via a crafted HTML page.
nvd
CVE-2023-2460P4HIGHCVSS 7.1v11.02023-05-03
CVE-2023-2460 [HIGH] CVE-2023-2460: Insufficient validation of untrusted input in Extensions in Google Chrome prior to 113.0.5672.63 all
Insufficient validation of untrusted input in Extensions in Google Chrome prior to 113.0.5672.63 allowed an attacker who convinced a user to install a malicious extension to bypass file access checks via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2024-35899P4HIGHCVSS 7.3v10.02024-05-19
CVE-2024-35899 [HIGH] CWE-362 CVE-2024-35899: In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: flush pen
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: flush pending destroy work before exit_net release
Similar to 2c9f0293280e ("netfilter: nf_tables: flush pending destroy
work before netlink notifier") to address a race between exit_net and
the destroy workqueue.
The trace below shows an element to be released
nvd