cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 310 of 498
CVE-2017-13088P4MEDIUMCVSS 5.3v8.0v9.02017-10-17
CVE-2017-13088 [MEDIUM] CWE-323 CVE-2017-13088: Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Integrity Gr Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Integrity Group Temporal Key (IGTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame, allowing an attacker within radio range to replay frames from access points to clients.
nvd
CVE-2019-14902P4MEDIUMCVSS 5.4v9.02020-01-21
CVE-2019-14902 [MEDIUM] CWE-284 CVE-2019-14902: There is an issue in all samba 4.11.x versions before 4.11.5, all samba 4.10.x versions before 4.10. There is an issue in all samba 4.11.x versions before 4.11.5, all samba 4.10.x versions before 4.10.12 and all samba 4.9.x versions before 4.9.18, where the removal of the right to create or modify a subtree would not automatically be taken away on all domain controllers.
nvd
CVE-2021-39241P4MEDIUMCVSS 5.3v11.02021-08-17
CVE-2021-39241 [MEDIUM] CVE-2021-39241: An issue was discovered in HAProxy 2.0 before 2.0.24, 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 An issue was discovered in HAProxy 2.0 before 2.0.24, 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3. An HTTP method name may contain a space followed by the name of a protected resource. It is possible that a server would interpret this as a request for that protected resource, such as in the "GET /admin? HTTP/1.1 /static/images HTTP/1.1" exampl
nvd
CVE-2017-13087P4MEDIUMCVSS 5.3v8.0v9.02017-10-17
CVE-2017-13087 [MEDIUM] CWE-330 CVE-2017-13087: Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Group Tempor Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Group Temporal Key (GTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame, allowing an attacker within radio range to replay frames from access points to clients.
nvd
CVE-2019-12781P4MEDIUMCVSS 5.3v9.02019-07-01
CVE-2019-12781 [MEDIUM] CWE-319 CVE-2019-12781: An issue was discovered in Django 1.11 before 1.11.22, 2.1 before 2.1.10, and 2.2 before 2.2.3. An H An issue was discovered in Django 1.11 before 1.11.22, 2.1 before 2.1.10, and 2.2 before 2.2.3. An HTTP request is not redirected to HTTPS when the SECURE_PROXY_SSL_HEADER and SECURE_SSL_REDIRECT settings are used, and the proxy connects to Django via HTTPS. In other words, django.http.HttpRequest.scheme has incorrect behavior when a client uses HTT
nvd
CVE-2010-4040P4HIGHCVSS 7.8v6.0v7.02010-10-21
CVE-2010-4040 [HIGH] CWE-20 CVE-2010-4040: Google Chrome before 7.0.517.41 does not properly handle animated GIF images, which allows remote at Google Chrome before 7.0.517.41 does not properly handle animated GIF images, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted image.
nvd
CVE-2014-0453P4MEDIUMCVSS 4.0v6.0v7.0+1 more2014-04-16
CVE-2014-0453 [MEDIUM] CVE-2014-0453: Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Security.
nvd
CVE-2020-10803P4MEDIUMCVSS 5.4v8.02020-03-22
CVE-2020-10803 [MEDIUM] CWE-79 CVE-2020-10803: In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered wh In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered where malicious code could be used to trigger an XSS attack through retrieving and displaying results (in tbl_get_field.php and libraries/classes/Display/Results.php). The attacker must be able to insert crafted data into certain database tables, which w
nvd
CVE-2018-19132P4MEDIUMCVSS 5.9v8.02018-11-09
CVE-2018-19132 [MEDIUM] CWE-772 CVE-2018-19132: Squid before 4.4, when SNMP is enabled, allows a denial of service (Memory Leak) via an SNMP packet. Squid before 4.4, when SNMP is enabled, allows a denial of service (Memory Leak) via an SNMP packet.
nvd
CVE-2014-9669P4MEDIUMCVSS 6.8v7.02015-02-08
CVE-2014-9669 [MEDIUM] CWE-125 CVE-2014-9669: Multiple integer overflows in sfnt/ttcmap.c in FreeType before 2.5.4 allow remote attackers to cause Multiple integer overflows in sfnt/ttcmap.c in FreeType before 2.5.4 allow remote attackers to cause a denial of service (out-of-bounds read or memory corruption) or possibly have unspecified other impact via a crafted cmap SFNT table.
nvd
CVE-2004-0986P4HIGHCVSS 7.5v3.02005-03-01
CVE-2004-0986 [HIGH] CVE-2004-0986: Iptables before 1.2.11, under certain conditions, does not properly load the required modules at sys Iptables before 1.2.11, under certain conditions, does not properly load the required modules at system startup, which causes the firewall rules to fail to load and protect the system from remote attackers.
nvd
CVE-2022-26847P4MEDIUMCVSS 5.3v9.0v10.0+1 more2022-03-10
CVE-2022-26847 [MEDIUM] CWE-200 CVE-2022-26847: SPIP before 3.2.14 and 4.x before 4.0.5 allows unauthenticated access to information about editorial SPIP before 3.2.14 and 4.x before 4.0.5 allows unauthenticated access to information about editorial objects.
nvd
CVE-2019-13454P4MEDIUMCVSS 6.5v9.0v10.02019-07-09
CVE-2019-13454 [MEDIUM] CWE-369 CVE-2019-13454: ImageMagick 7.0.1-0 to 7.0.8-54 Q16 allows Division by Zero in RemoveDuplicateLayers in MagickCore/l ImageMagick 7.0.1-0 to 7.0.8-54 Q16 allows Division by Zero in RemoveDuplicateLayers in MagickCore/layer.c.
nvd
CVE-2023-34968P4MEDIUMCVSS 5.3v11.0v12.02023-07-20
CVE-2023-34968 [MEDIUM] CWE-201 CVE-2023-34968: A path disclosure vulnerability was found in Samba. As part of the Spotlight protocol, Samba disclos A path disclosure vulnerability was found in Samba. As part of the Spotlight protocol, Samba discloses the server-side absolute path of shares, files, and directories in the results for search queries. This flaw allows a malicious client or an attacker with a targeted RPC request to view the information that is part of the disclosed path.
nvd
CVE-2011-3892P4HIGHCVSS 7.5v6.02011-11-11
CVE-2011-3892 [HIGH] CWE-415 CVE-2011-3892: Double free vulnerability in the Theora decoder in Google Chrome before 15.0.874.120 allows remote a Double free vulnerability in the Theora decoder in Google Chrome before 15.0.874.120 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted stream.
nvd
CVE-2018-14567P4MEDIUMCVSS 6.5v8.02018-08-16
CVE-2018-14567 [MEDIUM] CVE-2018-14567: libxml2 2.9.8, if --with-lzma is used, allows remote attackers to cause a denial of service (infinit libxml2 2.9.8, if --with-lzma is used, allows remote attackers to cause a denial of service (infinite loop) via a crafted XML file that triggers LZMA_MEMLIMIT_ERROR, as demonstrated by xmllint, a different vulnerability than CVE-2015-8035 and CVE-2018-9251.
nvd
CVE-2012-2135P4MEDIUMCVSS 6.4v6.02012-08-14
CVE-2012-2135 [MEDIUM] CVE-2012-2135: The utf-16 decoder in Python 3.1 through 3.3 does not update the aligned_end variable after calling The utf-16 decoder in Python 3.1 through 3.3 does not update the aligned_end variable after calling the unicode_decode_call_errorhandler function, which allows remote attackers to obtain sensitive information (process memory) or cause a denial of service (memory corruption and crash) via unspecified vectors.
nvd
CVE-2016-3164P4HIGHCVSS 7.4v7.0v8.02016-04-12
CVE-2016-3164 [HIGH] CVE-2016-3164: Drupal 6.x before 6.38, 7.x before 7.43, and 8.x before 8.0.4 might allow remote attackers to conduc Drupal 6.x before 6.38, 7.x before 7.43, and 8.x before 8.0.4 might allow remote attackers to conduct open redirect attacks by leveraging (1) custom code or (2) a form shown on a 404 error page, related to path manipulation.
nvd
CVE-2010-4578P4HIGHCVSS 7.5v6.0v7.02010-12-22
CVE-2010-4578 [HIGH] CVE-2010-4578: Google Chrome before 8.0.552.224 and Chrome OS before 8.0.552.343 do not properly perform cursor han Google Chrome before 8.0.552.224 and Chrome OS before 8.0.552.343 do not properly perform cursor handling, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to "stale pointers."
nvd
CVE-2004-1004P4HIGHCVSS 7.5v3.02005-04-14
CVE-2004-1004 [HIGH] CVE-2004-1004: Multiple format string vulnerabilities in Midnight Commander (mc) 4.5.55 and earlier allow remote at Multiple format string vulnerabilities in Midnight Commander (mc) 4.5.55 and earlier allow remote attackers to have an unknown impact.
nvd
Debian Linux vulnerabilities | cvebase