cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 297 of 498
CVE-2018-9273P4HIGHCVSS 7.5v8.0v9.02018-04-04
CVE-2018-9273 [HIGH] CWE-772 CVE-2018-9273: In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-pcp.c has a memory leak. In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-pcp.c has a memory leak.
nvd
CVE-2018-9265P4HIGHCVSS 7.5v8.02018-04-04
CVE-2018-9265 [HIGH] CWE-772 CVE-2018-9265: In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-tn3270.c has a memory leak. In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-tn3270.c has a memory leak.
nvd
CVE-2015-8631P4MEDIUMCVSS 6.5v7.0v8.02016-02-13
CVE-2015-8631 [MEDIUM] CWE-772 CVE-2015-8631: Multiple memory leaks in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) before Multiple memory leaks in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x before 1.14.1 allow remote authenticated users to cause a denial of service (memory consumption) via a request specifying a NULL principal name.
nvd
CVE-2019-17569P4MEDIUMCVSS 4.8v9.0v10.02020-02-24
CVE-2019-17569 [MEDIUM] CWE-444 CVE-2019-17569: The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 int The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed leading to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the inval
nvd
CVE-2018-14432P4MEDIUMCVSS 5.3v9.02018-07-31
CVE-2018-14432 [MEDIUM] CWE-200 CVE-2018-14432: In the Federation component of OpenStack Keystone before 11.0.4, 12.0.0, and 13.0.0, an authenticate In the Federation component of OpenStack Keystone before 11.0.4, 12.0.0, and 13.0.0, an authenticated "GET /v3/OS-FEDERATION/projects" request may bypass intended access restrictions on listing projects. An authenticated user may discover projects they have no authority to access, leaking all projects in the deployment and their attributes. Only Key
nvd
CVE-2019-18860P4MEDIUMCVSS 6.1v9.0v10.02020-03-20
CVE-2019-18860 [MEDIUM] CWE-74 CVE-2019-18860: Squid before 4.9, when certain web browsers are used, mishandles HTML in the host (aka hostname) par Squid before 4.9, when certain web browsers are used, mishandles HTML in the host (aka hostname) parameter to cachemgr.cgi.
nvd
CVE-2014-9750P4MEDIUMCVSS 5.8v7.0v8.0+1 more2015-10-06
CVE-2014-9750 [MEDIUM] CWE-20 CVE-2014-9750: ntp_crypto.c in ntpd in NTP 4.x before 4.2.8p1, when Autokey Authentication is enabled, allows remot ntp_crypto.c in ntpd in NTP 4.x before 4.2.8p1, when Autokey Authentication is enabled, allows remote attackers to obtain sensitive information from process memory or cause a denial of service (daemon crash) via a packet containing an extension field with an invalid value for the length of its value field.
nvd
CVE-1999-0978P4HIGHCVSS 7.5v2.11999-12-09
CVE-1999-0978 [HIGH] CVE-1999-0978: htdig allows remote attackers to execute commands via filenames with shell metacharacters. htdig allows remote attackers to execute commands via filenames with shell metacharacters.
nvd
CVE-2024-22049P4MEDIUMCVSS 5.3v10.0v11.02024-01-04
CVE-2024-22049 [MEDIUM] CWE-472 CVE-2024-22049: httparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulnerability. A remote a httparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulnerability. A remote and unauthenticated attacker can provide a crafted filename parameter during multipart/form-data uploads which could result in attacker controlled filenames being written.
nvd
CVE-2004-1005P4HIGHCVSS 7.5v3.02005-04-14
CVE-2004-1005 [HIGH] CVE-2004-1005: Multiple buffer overflows in Midnight Commander (mc) 4.5.55 and earlier allow remote attackers to ha Multiple buffer overflows in Midnight Commander (mc) 4.5.55 and earlier allow remote attackers to have an unknown impact.
nvd
CVE-2009-2408P4MEDIUMCVSS 5.9v5.02009-07-30
CVE-2009-2408 [MEDIUM] CWE-295 CVE-2009-2408: Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before 2.0 Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before 2.0.0.23, and SeaMonkey before 1.1.18 do not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificat
nvd
CVE-2015-1250P4HIGHCVSS 7.5v8.02015-05-01
CVE-2015-1250 [HIGH] CVE-2015-1250: Multiple unspecified vulnerabilities in Google Chrome before 42.0.2311.135 allow attackers to cause Multiple unspecified vulnerabilities in Google Chrome before 42.0.2311.135 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2021-31866P4MEDIUMCVSS 5.3v9.02021-04-28
CVE-2021-31866 [MEDIUM] CWE-203 CVE-2021-31866: Redmine before 4.0.9 and 4.1.x before 4.1.3 allows an attacker to learn the values of internal authe Redmine before 4.0.9 and 4.1.x before 4.1.3 allows an attacker to learn the values of internal authentication keys by observing timing differences in string comparison operations within SysController and MailHandlerController.
nvd
CVE-2013-2919P4HIGHCVSS 7.5v7.0v8.02013-10-02
CVE-2013-2919 [HIGH] CWE-119 CVE-2013-2919: Google V8, as used in Google Chrome before 30.0.1599.66, allows remote attackers to cause a denial o Google V8, as used in Google Chrome before 30.0.1599.66, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2010-4492P4HIGHCVSS 7.5v6.0v7.02010-12-07
CVE-2010-4492 [HIGH] CWE-416 CVE-2010-4492: Use-after-free vulnerability in Google Chrome before 8.0.552.215 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 8.0.552.215 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving SVG animations.
nvd
CVE-2015-1256P4HIGHCVSS 7.5v8.02015-05-20
CVE-2015-1256 [HIGH] CVE-2015-1256: Use-after-free vulnerability in the SVG implementation in Blink, as used in Google Chrome before 43. Use-after-free vulnerability in the SVG implementation in Blink, as used in Google Chrome before 43.0.2357.65, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document that leverages improper handling of a shadow tree for a use element.
nvd
CVE-2013-6646P4HIGHCVSS 7.5v7.0v8.02014-01-16
CVE-2013-6646 [HIGH] CWE-416 CVE-2013-6646: Use-after-free vulnerability in the Web Workers implementation in Google Chrome before 32.0.1700.76 Use-after-free vulnerability in the Web Workers implementation in Google Chrome before 32.0.1700.76 on Windows and before 32.0.1700.77 on Mac OS X and Linux allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the shutting down of a worker process.
nvd
CVE-2013-6649P4HIGHCVSS 7.5v7.0v8.02014-01-28
CVE-2013-6649 [HIGH] CWE-399 CVE-2013-6649: Use-after-free vulnerability in the RenderSVGImage::paint function in core/rendering/svg/RenderSVGIm Use-after-free vulnerability in the RenderSVGImage::paint function in core/rendering/svg/RenderSVGImage.cpp in Blink, as used in Google Chrome before 32.0.1700.102, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a zero-size SVG image.
nvd
CVE-2021-43784P4MEDIUMCVSS 5.0v9.02021-12-06
CVE-2021-43784 [MEDIUM] CWE-190 CVE-2021-43784: runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc, netlink is used internally as a serialization system for specifying the relevant container configuration to the `C` portion of the code (responsible for the based namespace setup of containers). In all versions of runc prior to 1.0.3, the enco
nvd
CVE-2017-6802P4HIGHCVSS 7.5v8.0v9.02017-03-10
CVE-2017-6802 [HIGH] CWE-125 CVE-2017-6802: An issue was discovered in ytnef before 1.9.2. There is a potential heap-based buffer over-read on i An issue was discovered in ytnef before 1.9.2. There is a potential heap-based buffer over-read on incoming Compressed RTF Streams, related to DecompressRTF() in libytnef.
nvd
Debian Linux vulnerabilities | cvebase