Debian Linux vulnerabilities
9,954 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358
Vulnerabilities
Page 308 of 498
CVE-2018-20149P4MEDIUMCVSS 5.4v8.0v9.02018-12-14
CVE-2018-20149 [MEDIUM] CWE-79 CVE-2018-20149: In WordPress before 4.9.9 and 5.x before 5.0.1, when the Apache HTTP Server is used, authors could u
In WordPress before 4.9.9 and 5.x before 5.0.1, when the Apache HTTP Server is used, authors could upload crafted files that bypass intended MIME type restrictions, leading to XSS, as demonstrated by a .jpg file without JPEG data.
nvd
CVE-2019-3835P4MEDIUMCVSS 5.5v8.0v9.02019-03-25
CVE-2019-3835 [MEDIUM] CWE-648 CVE-2019-3835: It was found that the superexec operator was available in the internal dictionary in ghostscript bef
It was found that the superexec operator was available in the internal dictionary in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER.
nvd
CVE-2019-3838P4MEDIUMCVSS 5.5v8.0v9.02019-03-25
CVE-2019-3838 [MEDIUM] CWE-648 CVE-2019-3838: It was found that the forceput operator could be extracted from the DefineResource method in ghostsc
It was found that the forceput operator could be extracted from the DefineResource method in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER.
nvd
CVE-2016-1000108P4MEDIUMCVSS 6.1v8.0v9.0+1 more2019-12-10
CVE-2016-1000108 [MEDIUM] CWE-601 CVE-2016-1000108: yaws before 2.0.4 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and theref
yaws before 2.0.4 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy server via a cr
nvd
CVE-2022-21277P4MEDIUMCVSS 5.3v10.0v11.02022-01-19
CVE-2022-21277 [MEDIUM] CWE-400 CVE-2022-21277: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (co
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Oracle Java SE: 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protoc
nvd
CVE-2023-21967P4MEDIUMCVSS 5.9v10.0v11.0+1 more2023-04-18
CVE-2023-21967 [MEDIUM] CVE-2023-21967: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (co
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6, 20; Oracle GraalVM Enterprise Edition: 20.3.9, 21.3.5 and 22.3.1. Difficult to exploit vulnerability allows unauthenticated attacker with network acce
nvd
CVE-2008-0063P4HIGHCVSS 7.5v3.1v4.02008-03-19
CVE-2008-0063 [HIGH] CWE-908 CVE-2008-0063: The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion
The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, which might allow remote attackers to obtain sensitive information, aka "Uninitialized stack values."
nvd
CVE-2019-16779P4MEDIUMCVSS 5.9v8.02019-12-16
CVE-2019-16779 [MEDIUM] CWE-664 CVE-2019-16779: In RubyGem excon before 0.71.0, there was a race condition around persistent connections, where a co
In RubyGem excon before 0.71.0, there was a race condition around persistent connections, where a connection which is interrupted (such as by a timeout) would leave data on the socket. Subsequent requests would then read this data, returning content from the previous response. The race condition window appears to be short, and it would be difficult
nvd
CVE-2019-25031P4MEDIUMCVSS 5.9v9.02021-04-27
CVE-2019-25031 [MEDIUM] CWE-74 CVE-2019-25031: Unbound before 1.9.5 allows configuration injection in create_unbound_ad_servers.sh upon a successfu
Unbound before 1.9.5 allows configuration injection in create_unbound_ad_servers.sh upon a successful man-in-the-middle attack against a cleartext HTTP session. NOTE: The vendor does not consider this a vulnerability of the Unbound software. create_unbound_ad_servers.sh is a contributed script from the community that facilitates automatic configurati
nvd
CVE-2022-1462P4MEDIUMCVSS 6.3v10.02022-06-02
CVE-2022-1462 [MEDIUM] CWE-362 CVE-2022-1462: An out-of-bounds read flaw was found in the Linux kernel’s TeleTYpe subsystem. The issue occurs in h
An out-of-bounds read flaw was found in the Linux kernel’s TeleTYpe subsystem. The issue occurs in how a user triggers a race condition using ioctls TIOCSPTLCK and TIOCGPTPEER and TIOCSTI and TCXONC with leakage of memory in the flush_to_ldisc function. This flaw allows a local user to crash the system or read unauthorized random data from memory.
nvd
CVE-2023-38745P4MEDIUMCVSS 6.3v10.02023-07-25
CVE-2023-38745 [MEDIUM] CVE-2023-38745: Pandoc before 3.1.6 allows arbitrary file write: this can be triggered by providing a crafted image
Pandoc before 3.1.6 allows arbitrary file write: this can be triggered by providing a crafted image element in the input when generating files via the --extract-media option or outputting to PDF format. This allows an attacker to create or overwrite arbitrary files, depending on the privileges of the process running Pandoc. It only affects systems that pass
nvd
CVE-2016-7073P4MEDIUMCVSS 5.9v8.02018-09-11
CVE-2016-7073 [MEDIUM] CWE-20 CVE-2016-7073: An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, all
An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, allowing an attacker in position of man-in-the-middle to alter the content of an AXFR because of insufficient validation of TSIG signatures. A missing check of the TSIG time and fudge values was found in AXFRRetriever, leading to a possible replay attack.
nvd
CVE-2016-3166P4MEDIUMCVSS 5.9v7.0v8.02016-04-12
CVE-2016-3166 [MEDIUM] CVE-2016-3166: CRLF injection vulnerability in the drupal_set_header function in Drupal 6.x before 6.38, when used
CRLF injection vulnerability in the drupal_set_header function in Drupal 6.x before 6.38, when used with PHP before 5.1.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks by leveraging a module that allows user-submitted data to appear in HTTP headers.
nvd
CVE-2014-9709P4MEDIUMCVSS 5.0v7.0v8.02015-03-30
CVE-2014-9709 [MEDIUM] CWE-119 CVE-2014-9709: The GetCode_ function in gd_gif_in.c in GD 2.1.1 and earlier, as used in PHP before 5.5.21 and 5.6.x
The GetCode_ function in gd_gif_in.c in GD 2.1.1 and earlier, as used in PHP before 5.5.21 and 5.6.x before 5.6.5, allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted GIF image that is improperly handled by the gdImageCreateFromGif function.
nvd
CVE-2021-28153P4MEDIUMCVSS 5.3v9.02021-03-11
CVE-2021-28153 [MEDIUM] CWE-59 CVE-2021-28153: An issue was discovered in GNOME GLib before 2.66.8. When g_file_replace() is used with G_FILE_CREAT
An issue was discovered in GNOME GLib before 2.66.8. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION to replace a path that is a dangling symlink, it incorrectly also creates the target of the symlink as an empty file, which could conceivably have security relevance if the symlink is attacker-controlled. (If the path is a symlink
nvd
CVE-2016-7142P4MEDIUMCVSS 5.9v8.02016-09-26
CVE-2016-7142 [MEDIUM] CWE-264 CVE-2016-7142: The m_sasl module in InspIRCd before 2.0.23, when used with a service that supports SASL_EXTERNAL au
The m_sasl module in InspIRCd before 2.0.23, when used with a service that supports SASL_EXTERNAL authentication, allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a crafted SASL message.
nvd
CVE-2022-21434P4MEDIUMCVSS 5.3v9.0v10.0+1 more2022-04-19
CVE-2022-21434 [MEDIUM] CVE-2022-21434: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (co
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle GraalVM Enterprise Edition: 20.3.5, 21.3.1 and 22.0.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network acce
nvd
CVE-2024-28219P4MEDIUMCVSS 5.9v10.02024-04-03
CVE-2024-28219 [MEDIUM] CWE-680 CVE-2024-28219: In _imagingcms.c in Pillow before 10.3.0, a buffer overflow exists because strcpy is used instead of
In _imagingcms.c in Pillow before 10.3.0, a buffer overflow exists because strcpy is used instead of strncpy.
nvd
CVE-2007-4657P4HIGHCVSS 7.5v3.1v4.02007-09-04
CVE-2007-4657 [HIGH] CVE-2007-4657: Multiple integer overflows in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, allow remote attackers to
Multiple integer overflows in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, allow remote attackers to obtain sensitive information (memory contents) or cause a denial of service (thread crash) via a large len value to the (1) strspn or (2) strcspn function, which triggers an out-of-bounds read. NOTE: this affects different product versions than CVE-2007-3996.
nvd
CVE-2023-21939P4MEDIUMCVSS 5.3v10.0v11.0+1 more2023-04-18
CVE-2023-21939 [MEDIUM] CVE-2023-21939: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (co
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing). Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6, 20; Oracle GraalVM Enterprise Edition: 20.3.9, 21.3.5 and 22.3.1. Easily exploitable vulnerability allows unauthenticated attacker with network acces
nvd