cbcvebase.

Debian Linux vulnerabilities

9,953 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358

Vulnerabilities

Page 29 of 498
CVE-2021-21343P3HIGHCVSS 7.5v9.0v10.0+1 more2021-03-23
CVE-2021-21343 [HIGH] CWE-73 CVE-2021-21343: XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4. XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time contains type information to recreate the formerly written objects. XStream creates therefore new instances based on these type information. An attacker can manipulate the proc
nvd
CVE-2021-33193P3HIGHCVSS 7.5v10.02021-08-16
CVE-2021-33193 [HIGH] CVE-2021-33193: A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request splitting or cache poisoning. This issue affects Apache HTTP Server 2.4.17 to 2.4.48.
nvd
CVE-2018-25032P3HIGHCVSS 7.5v9.0v10.0+1 more2022-03-25
CVE-2018-25032 [HIGH] CWE-787 CVE-2018-25032: zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
nvd
CVE-2016-0742P3HIGHCVSS 7.5v7.0v8.0+1 more2016-02-15
CVE-2016-0742 [HIGH] CWE-476 CVE-2016-0742: The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 allows remote attackers to cause a denial The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (invalid pointer dereference and worker process crash) via a crafted UDP DNS response.
nvd
CVE-2022-31003P2CRITICALCVSS 9.8v10.02022-05-31
CVE-2022-31003 [CRITICAL] CWE-122 CVE-2022-31003: Sofia-SIP is an open-source Session Initiation Protocol (SIP) User-Agent library. Prior to version 1 Sofia-SIP is an open-source Session Initiation Protocol (SIP) User-Agent library. Prior to version 1.13.8, when parsing each line of a sdp message, `rest = record + 2` will access the memory behind `\0` and cause an out-of-bounds write. An attacker can send a message with evil sdp to FreeSWITCH, causing a crash or more serious consequence, such as
nvd
CVE-2022-23648P2HIGHCVSS 7.5v11.02022-03-03
CVE-2022-23648 [HIGH] CWE-200 CVE-2022-23648: containerd is a container runtime available as a daemon for Linux and Windows. A bug was found in co containerd is a container runtime available as a daemon for Linux and Windows. A bug was found in containerd prior to versions 1.6.1, 1.5.10, and 1.14.12 where containers launched through containerd’s CRI implementation on Linux with a specially-crafted image configuration could gain access to read-only copies of arbitrary files and directories on the
nvd
CVE-2018-4013P2CRITICALCVSS 9.8v8.0v9.02018-10-19
CVE-2018-4013 [CRITICAL] CWE-787 CVE-2018-4013: An exploitable code execution vulnerability exists in the HTTP packet-parsing functionality of the L An exploitable code execution vulnerability exists in the HTTP packet-parsing functionality of the LIVE555 RTSP server library version 0.92. A specially crafted packet can cause a stack-based buffer overflow, resulting in code execution. An attacker can send a packet to trigger this vulnerability.
nvd
CVE-2013-5123P3MEDIUMCVSS 5.9PoCv8.0v9.0+1 more2019-11-05
CVE-2013-5123 [MEDIUM] CWE-287 CVE-2013-5123: The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and au The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.
nvd
CVE-2020-11800P2CRITICALCVSS 9.8v9.02020-10-07
CVE-2020-11800 [CRITICAL] CVE-2020-11800: Zabbix Server 2.2.x and 3.0.x before 3.0.31, and 3.2 allows remote attackers to execute arbitrary co Zabbix Server 2.2.x and 3.0.x before 3.0.31, and 3.2 allows remote attackers to execute arbitrary code.
nvd
CVE-2016-2148P2CRITICALCVSS 9.8v8.0v9.02017-02-09
CVE-2016-2148 [CRITICAL] CWE-119 CVE-2016-2148: Heap-based buffer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attack Heap-based buffer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to have unspecified impact via vectors involving OPTION_6RD parsing.
nvd
CVE-2018-15127P2CRITICALCVSS 9.8v8.0v9.02018-12-19
CVE-2018-15127 [CRITICAL] CWE-787 CVE-2018-15127: LibVNC before commit 502821828ed00b4a2c4bef90683d0fd88ce495de contains heap out-of-bound write vulne LibVNC before commit 502821828ed00b4a2c4bef90683d0fd88ce495de contains heap out-of-bound write vulnerability in server code of file transfer extension that can result remote code execution
nvd
CVE-2017-7658P2CRITICALCVSS 9.8v9.02018-06-26
CVE-2017-7658 [CRITICAL] CWE-444 CVE-2017-7658: In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4. In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when presented with two content-lengths headers, Jetty ignored the second. When presented with a content-length and a chunked encoding header, the content-length was ignored (as per RFC 2616). If an intermediary decide
nvd
CVE-2018-4056P2CRITICALCVSS 9.8v8.0v9.02019-02-05
CVE-2018-4056 [CRITICAL] CWE-89 CVE-2018-4056: An exploitable SQL injection vulnerability exists in the administrator web portal function of coTURN An exploitable SQL injection vulnerability exists in the administrator web portal function of coTURN prior to version 4.5.0.9. A login message with a specially crafted username can cause an SQL injection, resulting in authentication bypass, which could give access to the TURN server administrator web portal. An attacker can log in via the external in
nvd
CVE-2011-2767P2CRITICALCVSS 9.8v8.02018-08-26
CVE-2011-2767 [CRITICAL] CWE-94 CVE-2011-2767: mod_perl 2.0 through 2.0.10 allows attackers to execute arbitrary Perl code by placing it in a user- mod_perl 2.0 through 2.0.10 allows attackers to execute arbitrary Perl code by placing it in a user-owned .htaccess file, because (contrary to the documentation) there is no configuration option that permits Perl code for the administrator's control of HTTP request processing without also permitting unprivileged users to run Perl code in the context
nvd
CVE-2020-6551P2HIGHCVSS 8.8v10.02020-09-21
CVE-2020-6551 [HIGH] CWE-416 CVE-2020-6551: Use after free in WebXR in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potenti Use after free in WebXR in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6550P2HIGHCVSS 8.8v10.02020-09-21
CVE-2020-6550 [HIGH] CWE-416 CVE-2020-6550: Use after free in IndexedDB in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to pot Use after free in IndexedDB in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2008-5183P3HIGHCVSS 7.5PoCv5.0v6.02008-11-21
CVE-2008-5183 [HIGH] CWE-476 CVE-2008-5183: cupsd in CUPS 1.3.9 and earlier allows local users, and possibly remote attackers, to cause a denial cupsd in CUPS 1.3.9 and earlier allows local users, and possibly remote attackers, to cause a denial of service (daemon crash) by adding a large number of RSS Subscriptions, which triggers a NULL pointer dereference. NOTE: this issue can be triggered remotely by leveraging CVE-2008-5184.
nvd
CVE-2023-28709P3HIGHCVSS 7.5v12.02023-05-22
CVE-2023-28709 [HIGH] CVE-2023-28709: The fix for CVE-2023-24998 was incomplete for Apache Tomcat 11.0.0-M2 to 11.0.0-M4, 10.1.5 to 10.1.7 The fix for CVE-2023-24998 was incomplete for Apache Tomcat 11.0.0-M2 to 11.0.0-M4, 10.1.5 to 10.1.7, 9.0.71 to 9.0.73 and 8.5.85 to 8.5.87. If non-default HTTP connector settings were used such that the maxParameterCount could be reached using query string parameters and a request was submitted that supplied exactly maxParameterCount parameters in the query
nvd
CVE-2016-1908P2CRITICALCVSS 9.8v8.02017-04-11
CVE-2016-1908 [CRITICAL] CWE-287 CVE-2016-1908: The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding an The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the local X11 server for access-control decisions, which allows remote X11 clients to trigger a fallback and obtain trusted X11 forwarding privileges by leveraging configuration issues on this X11 server, as demonstrated by lack of the SEC
nvd
CVE-2018-0732P3HIGHCVSS 7.5v8.02018-06-12
CVE-2018-0732 [HIGH] CWE-320 CVE-2018-0732: During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send a very large prime value to the client. This will cause the client to spend an unreasonably long period of time generating a key for this prime resulting in a hang until the client has finished. This could be exploited in a Denial Of Service attack. Fixed
nvd
Debian Linux vulnerabilities | cvebase