cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 296 of 498
CVE-2022-21296P4MEDIUMCVSS 5.3v9.0v10.0+1 more2022-01-19
CVE-2022-21296 [MEDIUM] CWE-200 CVE-2022-21296: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (co Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via mult
nvd
CVE-2022-21496P4MEDIUMCVSS 5.3v9.02022-04-19
CVE-2022-21496 [MEDIUM] CVE-2022-21496: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (co Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JNDI). Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle GraalVM Enterprise Edition: 20.3.5, 21.3.1 and 22.0.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access vi
nvd
CVE-2022-21305P4MEDIUMCVSS 5.3v9.0v10.0+1 more2022-01-19
CVE-2022-21305 [MEDIUM] CWE-284 CVE-2022-21305: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (co Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via m
nvd
CVE-2004-0456P4HIGHCVSS 7.6v3.02004-12-06
CVE-2004-0456 [HIGH] CVE-2004-0456: Stack-based buffer overflow in pavuk 0.9pl28, 0.9pl27, and possibly other versions allows remote web Stack-based buffer overflow in pavuk 0.9pl28, 0.9pl27, and possibly other versions allows remote web sites to execute arbitrary code via a long HTTP Location header.
nvd
CVE-2021-4189P4MEDIUMCVSS 5.3v10.0v11.02022-08-24
CVE-2021-4189 [MEDIUM] CWE-252 CVE-2021-4189: A flaw was found in Python, specifically in the FTP (File Transfer Protocol) client library in PASV A flaw was found in Python, specifically in the FTP (File Transfer Protocol) client library in PASV (passive) mode. The issue is how the FTP client trusts the host from the PASV response by default. This flaw allows an attacker to set up a malicious FTP server that can trick FTP clients into connecting back to a given IP address and port. This vulnerab
nvd
CVE-2022-43596P4MEDIUMCVSS 5.9v11.02022-12-22
CVE-2022-43596 [MEDIUM] CWE-125 CVE-2022-43596: An information disclosure vulnerability exists in the IFFOutput channel interleaving functionality o An information disclosure vulnerability exists in the IFFOutput channel interleaving functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to leaked heap data. An attacker can provide malicious input to trigger this vulnerability.
nvd
CVE-2022-43592P4MEDIUMCVSS 5.9v11.02022-12-22
CVE-2022-43592 [MEDIUM] CWE-125 CVE-2022-43592: An information disclosure vulnerability exists in the DPXOutput::close() functionality of OpenImageI An information disclosure vulnerability exists in the DPXOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to leaked heap data. An attacker can provide malicious input to trigger this vulnerability.
nvd
CVE-2011-4539P4MEDIUMCVSS 5.0v6.0v7.02011-12-08
CVE-2011-4539 [MEDIUM] CWE-20 CVE-2011-4539: dhcpd in ISC DHCP 4.x before 4.2.3-P1 and 4.1-ESV before 4.1-ESV-R4 does not properly handle regular dhcpd in ISC DHCP 4.x before 4.2.3-P1 and 4.1-ESV before 4.1-ESV-R4 does not properly handle regular expressions in dhcpd.conf, which allows remote attackers to cause a denial of service (daemon crash) via a crafted request packet.
nvd
CVE-2014-6275P4MEDIUMCVSS 5.9v8.02020-01-02
CVE-2014-6275 [MEDIUM] CWE-200 CVE-2014-6275: FusionForge before 5.3.2 use scripts that run under the shared Apache user, which is also used by pr FusionForge before 5.3.2 use scripts that run under the shared Apache user, which is also used by project homepages by default. If project webpages are hosted on the same server than FusionForge, it can allow users to incorrectly access on-disk private data in FusionForge.
nvd
CVE-2020-28896P4MEDIUMCVSS 5.3v9.02020-11-23
CVE-2020-28896 [MEDIUM] CWE-287 CVE-2020-28896: Mutt before 2.0.2 and NeoMutt before 2020-11-20 did not ensure that $ssl_force_tls was processed if Mutt before 2.0.2 and NeoMutt before 2020-11-20 did not ensure that $ssl_force_tls was processed if an IMAP server's initial server response was invalid. The connection was not properly closed, and the code could continue attempting to authenticate. This could result in authentication credentials being exposed on an unencrypted connection, or to a ma
nvd
CVE-2023-2255P4MEDIUMCVSS 5.3v11.02023-05-25
CVE-2023-2255 [MEDIUM] CWE-264 CVE-2023-2255: Improper access control in editor components of The Document Foundation LibreOffice allowed an attac Improper access control in editor components of The Document Foundation LibreOffice allowed an attacker to craft a document that would cause external links to be loaded without prompt. In the affected versions of LibreOffice documents that used "floating frames" linked to external files, would load the contents of those frames without prompting the us
nvd
CVE-2015-7702P4MEDIUMCVSS 6.5v7.0v8.0+1 more2017-08-07
CVE-2015-7702 [MEDIUM] CVE-2015-7702: The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash). NOTE: This vulnerability exists due to an incomplete fix for CVE-2014-9750.
nvd
CVE-2015-8241P4MEDIUMCVSS 6.4v7.0v8.02015-12-15
CVE-2015-8241 [MEDIUM] CWE-119 CVE-2015-8241: The xmlNextChar function in libxml2 2.9.2 does not properly check the state, which allows context-de The xmlNextChar function in libxml2 2.9.2 does not properly check the state, which allows context-dependent attackers to cause a denial of service (heap-based buffer over-read and application crash) or obtain sensitive information via crafted XML data.
nvd
CVE-2025-38562P4MEDIUMCVSS 5.5v11.02025-08-19
CVE-2025-38562 [MEDIUM] CWE-476 CVE-2025-38562: In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix null pointer derefer In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix null pointer dereference error in generate_encryptionkey If client send two session setups with krb5 authenticate to ksmbd, null pointer dereference error in generate_encryptionkey could happen. sess->Preauth_HashValue is set to NULL if session is valid. So this patch sk
nvd
CVE-2020-1935P4MEDIUMCVSS 4.8v8.0v9.0+1 more2020-02-24
CVE-2020-1935 [MEDIUM] CWE-444 CVE-2020-1935: In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing cod In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encodi
nvd
CVE-2014-9664P4MEDIUMCVSS 6.8v7.02015-02-08
CVE-2014-9664 [MEDIUM] CWE-119 CVE-2014-9664: FreeType before 2.5.4 does not check for the end of the data during certain parsing actions, which a FreeType before 2.5.4 does not check for the end of the data during certain parsing actions, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted Type42 font, related to type42/t42parse.c and type1/t1load.c.
nvd
CVE-2014-9666P4MEDIUMCVSS 6.8v7.02015-02-08
CVE-2014-9666 [MEDIUM] CWE-189 CVE-2014-9666: The tt_sbit_decoder_init function in sfnt/ttsbit.c in FreeType before 2.5.4 proceeds with a count-to The tt_sbit_decoder_init function in sfnt/ttsbit.c in FreeType before 2.5.4 proceeds with a count-to-size association without restricting the count value, which allows remote attackers to cause a denial of service (integer overflow and out-of-bounds read) or possibly have unspecified other impact via a crafted embedded bitmap.
nvd
CVE-2018-1000204P4MEDIUMCVSS 5.3v8.02018-06-26
CVE-2018-1000204 [MEDIUM] CVE-2018-1000204: Linux Kernel version 3.18 to 4.16 incorrectly handles an SG_IO ioctl on /dev/sg0 with dxfer_directio Linux Kernel version 3.18 to 4.16 incorrectly handles an SG_IO ioctl on /dev/sg0 with dxfer_direction=SG_DXFER_FROM_DEV and an empty 6-byte cmdp. This may lead to copying up to 1000 kernel heap pages to the userspace. This has been fixed upstream in https://github.com/torvalds/linux/commit/a45b599ad808c3c982fdcdc12b0b8611c2f92824 already. The problem ha
nvd
CVE-2018-9270P4HIGHCVSS 7.5v8.0v9.02018-04-04
CVE-2018-9270 [HIGH] CWE-772 CVE-2018-9270: In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/oids.c has a memory leak. In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/oids.c has a memory leak.
nvd
CVE-2018-9267P4HIGHCVSS 7.5v8.02018-04-04
CVE-2018-9267 [HIGH] CWE-772 CVE-2018-9267: In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-lapd.c has a memory leak. In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-lapd.c has a memory leak.
nvd
Debian Linux vulnerabilities | cvebase