cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 295 of 498
CVE-2022-24302P4MEDIUMCVSS 5.9v9.0v10.02022-03-17
CVE-2022-24302 [MEDIUM] CWE-362 CVE-2022-24302: In Paramiko before 2.10.1, a race condition (between creation and chmod) in the write_private_key_fi In Paramiko before 2.10.1, a race condition (between creation and chmod) in the write_private_key_file function could allow unauthorized information disclosure.
nvd
CVE-2019-7282P4MEDIUMCVSS 5.9v9.02019-01-31
CVE-2019-7282 [MEDIUM] CVE-2019-7282: In NetKit through 0.17, rcp.c in the rcp client allows remote rsh servers to bypass intended access In NetKit through 0.17, rcp.c in the rcp client allows remote rsh servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side. This is similar to CVE-2018-20685.
nvd
CVE-2021-2163P4MEDIUMCVSS 5.3v9.0v10.02021-04-22
CVE-2021-2163 [MEDIUM] CVE-2021-2163: Vulnerability in the Java SE, Java SE Embedded, Oracle GraalVM Enterprise Edition product of Oracle Vulnerability in the Java SE, Java SE Embedded, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u291, 8u281, 11.0.10, 16; Java SE Embedded: 8u281; Oracle GraalVM Enterprise Edition: 19.3.5, 20.3.1.2 and 21.0.0.2. Difficult to exploit vulnerability allows unauthenticated atta
nvd
CVE-2008-4934P4HIGHCVSS 7.8v4.02008-11-05
CVE-2008-4934 [HIGH] CWE-20 CVE-2008-4934: The hfsplus_block_allocate function in fs/hfsplus/bitmap.c in the Linux kernel before 2.6.28-rc1 doe The hfsplus_block_allocate function in fs/hfsplus/bitmap.c in the Linux kernel before 2.6.28-rc1 does not check a certain return value from the read_mapping_page function before calling kmap, which allows attackers to cause a denial of service (system crash) via a crafted hfsplus filesystem image.
nvd
CVE-2019-7317P4MEDIUMCVSS 5.3v8.0v9.02019-02-04
CVE-2019-7317 [MEDIUM] CWE-416 CVE-2019-7317: png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_fu png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.
nvd
CVE-2017-15906P4MEDIUMCVSS 5.3v8.02017-10-26
CVE-2017-15906 [MEDIUM] CWE-732 CVE-2017-15906: The process_open function in sftp-server.c in OpenSSH before 7.6 does not properly prevent write ope The process_open function in sftp-server.c in OpenSSH before 7.6 does not properly prevent write operations in readonly mode, which allows attackers to create zero-length files.
nvd
CVE-2025-25474P4MEDIUMCVSS 6.5v11.02025-02-18
CVE-2025-25474 [MEDIUM] CWE-120 CVE-2025-25474: DCMTK v3.6.9+ DEV was discovered to contain a buffer overflow via the component /dcmimgle/diinpxt.h. DCMTK v3.6.9+ DEV was discovered to contain a buffer overflow via the component /dcmimgle/diinpxt.h.
nvd
CVE-2010-2497P4MEDIUMCVSS 6.8v5.02010-08-19
CVE-2010-2497 [MEDIUM] CWE-191 CVE-2010-2497: Integer underflow in glyph handling in FreeType before 2.4.0 allows remote attackers to cause a deni Integer underflow in glyph handling in FreeType before 2.4.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.
nvd
CVE-2016-6207P4MEDIUMCVSS 6.5v8.02016-08-12
CVE-2016-6207 [MEDIUM] CWE-119 CVE-2016-6207: Integer overflow in the _gdContributionsAlloc function in gd_interpolation.c in GD Graphics Library Integer overflow in the _gdContributionsAlloc function in gd_interpolation.c in GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds memory write or memory consumption) via unspecified vectors.
nvd
CVE-2020-8608P4MEDIUMCVSS 5.6v8.0v9.0+1 more2020-02-06
CVE-2020-8608 [MEDIUM] CWE-120 CVE-2020-8608: In libslirp 4.1.0, as used in QEMU 4.2.0, tcp_subr.c misuses snprintf return values, leading to a bu In libslirp 4.1.0, as used in QEMU 4.2.0, tcp_subr.c misuses snprintf return values, leading to a buffer overflow in later code.
nvd
CVE-2020-25651P4MEDIUMCVSS 6.4v9.02020-11-26
CVE-2020-25651 [MEDIUM] CWE-362 CVE-2020-25651: A flaw was found in the SPICE file transfer protocol. File data from the host system can end up in f A flaw was found in the SPICE file transfer protocol. File data from the host system can end up in full or in parts in the client connection of an illegitimate local user in the VM system. Active file transfers from other users could also be interrupted, resulting in a denial of service. The highest threat from this vulnerability is to data confiden
nvd
CVE-2007-3409P4HIGHCVSS 7.5v3.1v4.02007-06-26
CVE-2007-3409 [HIGH] CWE-674 CVE-2007-3409: Net::DNS before 0.60, a Perl module, allows remote attackers to cause a denial of service (stack con Net::DNS before 0.60, a Perl module, allows remote attackers to cause a denial of service (stack consumption) via a malformed compressed DNS packet with self-referencing pointers, which triggers an infinite loop.
nvd
CVE-2020-7071P4MEDIUMCVSS 5.3v9.0v10.02021-02-15
CVE-2020-7071 [MEDIUM] CWE-20 CVE-2020-7071: In PHP versions 7.3.x below 7.3.26, 7.4.x below 7.4.14 and 8.0.0, when validating URL with functions In PHP versions 7.3.x below 7.3.26, 7.4.x below 7.4.14 and 8.0.0, when validating URL with functions like filter_var($url, FILTER_VALIDATE_URL), PHP will accept an URL with invalid password as valid URL. This may lead to functions that rely on URL being valid to mis-parse the URL and produce wrong data as components of the URL.
nvd
CVE-2017-8314P4MEDIUMCVSS 5.5v7.02017-05-23
CVE-2017-8314 [MEDIUM] CWE-22 CVE-2017-8314: Directory Traversal in Zip Extraction built-in function in Kodi 17.1 and earlier allows arbitrary fi Directory Traversal in Zip Extraction built-in function in Kodi 17.1 and earlier allows arbitrary file write on disk via a Zip file as subtitles.
nvd
CVE-2008-5500P4CRITICALCVSS 10.0v4.0v5.02008-12-17
CVE-2008-5500 [CRITICAL] CWE-399 CVE-2008-5500: The layout engine in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x befor The layout engine in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to cause a denial of service (crash) and possibly trigger memory corruption via vectors related to (1) a reachable assertion or (2) an integer overflow.
nvd
CVE-2017-12872P4MEDIUMCVSS 5.9v7.0v8.02017-09-01
CVE-2017-12872 [MEDIUM] CWE-200 CVE-2017-12872: The (1) Htpasswd authentication source in the authcrypt module and (2) SimpleSAML_Session class in S The (1) Htpasswd authentication source in the authcrypt module and (2) SimpleSAML_Session class in SimpleSAMLphp 1.14.11 and earlier allow remote attackers to conduct timing side-channel attacks by leveraging use of the standard comparison operator to compare secret material against user input.
nvd
CVE-2022-21291P4MEDIUMCVSS 5.3v10.0v11.02022-01-19
CVE-2022-21291 [MEDIUM] CWE-284 CVE-2022-21291: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (co Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via m
nvd
CVE-2021-3426P4MEDIUMCVSS 5.7v9.02021-05-20
CVE-2021-3426 [MEDIUM] CWE-200 CVE-2021-3426: There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convinc There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convince another local or adjacent user to start a pydoc server could access the server and use it to disclose sensitive information belonging to the other user that they would not normally be able to access. The highest risk of this flaw is to data confidenti
nvd
CVE-2022-21282P4MEDIUMCVSS 5.3v9.0v10.0+1 more2022-01-19
CVE-2022-21282 [MEDIUM] CWE-611 CVE-2022-21282: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (co Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via mult
nvd
CVE-2012-5639P4MEDIUMCVSS 6.5v8.0v9.0+1 more2019-12-20
CVE-2012-5639 [MEDIUM] CWE-668 CVE-2012-5639: LibreOffice and OpenOffice automatically open embedded content LibreOffice and OpenOffice automatically open embedded content
nvd
Debian Linux vulnerabilities | cvebase