cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 309 of 498
CVE-2019-18978P4MEDIUMCVSS 5.3v8.0v9.0+1 more2019-11-14
CVE-2019-18978 [MEDIUM] CWE-22 CVE-2019-18978: An issue was discovered in the rack-cors (aka Rack CORS Middleware) gem before 1.0.4 for Ruby. It al An issue was discovered in the rack-cors (aka Rack CORS Middleware) gem before 1.0.4 for Ruby. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format.
nvd
CVE-2013-5653P4MEDIUMCVSS 5.5v8.02017-03-07
CVE-2013-5653 [MEDIUM] CWE-200 CVE-2013-5653: The getenv and filenameforall functions in Ghostscript 9.10 ignore the "-dSAFER" argument, which all The getenv and filenameforall functions in Ghostscript 9.10 ignore the "-dSAFER" argument, which allows remote attackers to read data via a crafted postscript file.
nvd
CVE-2011-5326P4HIGHCVSS 7.5v7.0v8.02016-05-13
CVE-2011-5326 [HIGH] CWE-189 CVE-2011-5326: imlib2 before 1.4.9 allows remote attackers to cause a denial of service (divide-by-zero error and a imlib2 before 1.4.9 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) by drawing a 2x1 ellipse.
nvd
CVE-2020-11026P4MEDIUMCVSS 5.4v8.0v9.0+1 more2020-04-30
CVE-2020-11026 [MEDIUM] CWE-707 CVE-2020-11026: In affected versions of WordPress, files with a specially crafted name when uploaded to the Media se In affected versions of WordPress, files with a specially crafted name when uploaded to the Media section can lead to script execution upon accessing the file. This requires an authenticated user with privileges to upload files. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6,
nvd
CVE-2022-21549P4MEDIUMCVSS 5.3v11.02022-07-19
CVE-2022-21549 [MEDIUM] CWE-502 CVE-2022-21549: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (co Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 17.0.3.1; Oracle GraalVM Enterprise Edition: 21.3.2 and 22.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols t
nvd
CVE-2001-0441P4HIGHCVSS 7.5≤ 2.22001-06-27
CVE-2001-0441 [HIGH] CVE-2001-0441: Buffer overflow in (1) wrapping and (2) unwrapping functions of slrn news reader before 0.9.7.0 allo Buffer overflow in (1) wrapping and (2) unwrapping functions of slrn news reader before 0.9.7.0 allows remote attackers to execute arbitrary commands via a long message header.
nvd
CVE-2021-32917P4MEDIUMCVSS 5.3v9.0v10.02021-05-13
CVE-2021-32917 [MEDIUM] CWE-862 CVE-2021-32917: An issue was discovered in Prosody before 0.11.9. The proxy65 component allows open access by defaul An issue was discovered in Prosody before 0.11.9. The proxy65 component allows open access by default, even if neither of the users has an XMPP account on the local server, allowing unrestricted use of the server's bandwidth.
nvd
CVE-2023-42795P4MEDIUMCVSS 5.3v10.0v11.0+1 more2023-10-10
CVE-2023-42795 [MEDIUM] CWE-459 CVE-2023-42795: Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various internal objects in Apache Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various internal objects in Apache Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.80 and from 8.5.0 through 8.5.93, an error could cause Tomcat to skip some parts of the recycling process leading to information leaking from the curren
nvd
CVE-2020-14402P4MEDIUMCVSS 5.4v8.0v9.02020-06-17
CVE-2020-14402 [MEDIUM] CWE-787 CVE-2020-14402: An issue was discovered in LibVNCServer before 0.9.13. libvncserver/corre.c allows out-of-bounds acc An issue was discovered in LibVNCServer before 0.9.13. libvncserver/corre.c allows out-of-bounds access via encodings.
nvd
CVE-2017-13079P4MEDIUMCVSS 5.3v8.0v9.02017-10-17
CVE-2017-13079 [MEDIUM] CWE-323 CVE-2017-13079: Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the Integr Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the Integrity Group Temporal Key (IGTK) during the four-way handshake, allowing an attacker within radio range to spoof frames from access points to clients.
nvd
CVE-2009-1721P4MEDIUMCVSS 6.8v4.0v5.02009-07-31
CVE-2009-1721 [MEDIUM] CWE-824 CVE-2009-1721: The decompression implementation in the Imf::hufUncompress function in OpenEXR 1.2.2 and 1.6.1 allow The decompression implementation in the Imf::hufUncompress function in OpenEXR 1.2.2 and 1.6.1 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger a free of an uninitialized pointer.
nvd
CVE-2022-47951P4MEDIUMCVSS 5.7v10.0v11.02023-01-26
CVE-2022-47951 [MEDIUM] CWE-22 CVE-2022-47951: An issue was discovered in OpenStack Cinder before 19.1.2, 20.x before 20.0.2, and 21.0.0; Glance be An issue was discovered in OpenStack Cinder before 19.1.2, 20.x before 20.0.2, and 21.0.0; Glance before 23.0.1, 24.x before 24.1.1, and 25.0.0; and Nova before 24.1.2, 25.x before 25.0.2, and 26.0.0. By supplying a specially created VMDK flat image that references a specific backing file path, an authenticated user may convince systems to return a c
nvd
CVE-2019-10156P4MEDIUMCVSS 5.4v8.0v9.02019-07-30
CVE-2019-10156 [MEDIUM] CWE-200 CVE-2019-10156: A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.1 A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing the possibility of information disclosure through unexpected variable substitution. By taking advantage of unintended variable substitution the content of any variable may be disclosed.
nvd
CVE-2018-14056P4MEDIUMCVSS 5.3v9.02018-07-15
CVE-2018-14056 [MEDIUM] CWE-22 CVE-2018-14056: ZNC before 1.7.1-rc1 is prone to a path traversal flaw via ../ in a web skin name to access files ou ZNC before 1.7.1-rc1 is prone to a path traversal flaw via ../ in a web skin name to access files outside of the intended skins directories.
nvd
CVE-2018-11212P4MEDIUMCVSS 6.5v8.02018-05-16
CVE-2018-11212 [MEDIUM] CWE-369 CVE-2018-11212: An issue was discovered in libjpeg 9a and 9d. The alloc_sarray function in jmemmgr.c allows remote a An issue was discovered in libjpeg 9a and 9d. The alloc_sarray function in jmemmgr.c allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted file.
nvd
CVE-2004-0833P4HIGHCVSS 7.5v3.02004-12-23
CVE-2004-0833 [HIGH] CVE-2004-0833: Sendmail before 8.12.3 on Debian GNU/Linux, when using sasl and sasl-bin, uses a Sendmail configurat Sendmail before 8.12.3 on Debian GNU/Linux, when using sasl and sasl-bin, uses a Sendmail configuration script with a fixed username and password, which could allow remote attackers to use Sendmail as an open mail relay and send spam messages.
nvd
CVE-2022-38648P4MEDIUMCVSS 5.3v10.02022-09-22
CVE-2022-38648 [MEDIUM] CWE-918 CVE-2022-38648: Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to fetch external resources. This issue affects Apache XML Graphics Batik 1.14.
nvd
CVE-2019-16780P4MEDIUMCVSS 5.4v9.0v10.02019-12-26
CVE-2019-16780 [MEDIUM] CWE-79 CVE-2019-16780: WordPress users with lower privileges (like contributors) can inject JavaScript code in the block ed WordPress users with lower privileges (like contributors) can inject JavaScript code in the block editor using a specific payload, which is executed within the dashboard. This can lead to XSS if an admin opens the post in the editor. Execution of this attack does require an authenticated user. This has been patched in WordPress 5.3.1, along with all
nvd
CVE-2013-5705P4MEDIUMCVSS 5.0v7.0v8.02014-04-15
CVE-2013-5705 [MEDIUM] CVE-2013-5705: apache2/modsecurity.c in ModSecurity before 2.7.6 allows remote attackers to bypass rules by using c apache2/modsecurity.c in ModSecurity before 2.7.6 allows remote attackers to bypass rules by using chunked transfer coding with a capitalized Chunked value in the Transfer-Encoding HTTP header.
nvd
CVE-2014-2497P4MEDIUMCVSS 4.3v7.0v8.02014-03-21
CVE-2014-2497 [MEDIUM] CWE-476 CVE-2014-2497: The gdImageCreateFromXpm function in gdxpm.c in libgd, as used in PHP 5.4.26 and earlier, allows rem The gdImageCreateFromXpm function in gdxpm.c in libgd, as used in PHP 5.4.26 and earlier, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted color table in an XPM file.
nvd
Debian Linux vulnerabilities | cvebase