cbcvebase.

Debian Linux vulnerabilities

9,953 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358

Vulnerabilities

Page 32 of 498
CVE-2018-14719P2CRITICALCVSS 9.8v8.0v9.02019-01-02
CVE-2018-14719 [CRITICAL] CWE-502 CVE-2018-14719: FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code b FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt and blaze-ds-core classes from polymorphic deserialization.
nvd
CVE-2022-41853P2CRITICALCVSS 9.8v10.0v11.02022-10-06
CVE-2022-41853 [CRITICAL] CWE-470 CVE-2022-41853: Those using java.sql.Statement or java.sql.PreparedStatement in hsqldb (HyperSQL DataBase) to proces Those using java.sql.Statement or java.sql.PreparedStatement in hsqldb (HyperSQL DataBase) to process untrusted input may be vulnerable to a remote code execution attack. By default it is allowed to call any static method of any Java class in the classpath resulting in code execution. The issue can be prevented by updating to 2.7.1 or by setting t
nvd
CVE-2018-1000140P2CRITICALCVSS 9.8v8.0v9.02018-03-23
CVE-2018-1000140 [CRITICAL] CWE-787 CVE-2018-1000140: rsyslog librelp version 1.2.14 and earlier contains a Buffer Overflow vulnerability in the checking rsyslog librelp version 1.2.14 and earlier contains a Buffer Overflow vulnerability in the checking of x509 certificates from a peer that can result in Remote code execution. This attack appear to be exploitable a remote attacker that can connect to rsyslog and trigger a stack buffer overflow by sending a specially crafted x509 certificate.
nvd
CVE-2020-11987P2HIGHCVSS 8.2v10.02021-02-24
CVE-2020-11987 [HIGH] CWE-20 CVE-2020-11987: Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
nvd
CVE-2017-11176P3HIGHCVSS 7.8PoCv8.0v9.02017-07-11
CVE-2017-11176 [HIGH] CWE-416 CVE-2017-11176: The mq_notify function in the Linux kernel through 4.11.9 does not set the sock pointer to NULL upon The mq_notify function in the Linux kernel through 4.11.9 does not set the sock pointer to NULL upon entry into the retry logic. During a user-space close of a Netlink socket, it allows attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact.
nvd
CVE-2018-20019P2CRITICALCVSS 9.8v8.0v9.02018-12-19
CVE-2018-20019 [CRITICAL] CWE-787 CVE-2018-20019: LibVNC before commit a83439b9fbe0f03c48eb94ed05729cb016f8b72f contains multiple heap out-of-bound wr LibVNC before commit a83439b9fbe0f03c48eb94ed05729cb016f8b72f contains multiple heap out-of-bound write vulnerabilities in VNC client code that can result remote code execution
nvd
CVE-2021-31618P3HIGHCVSS 7.5v9.0v10.02021-06-15
CVE-2021-31618 [HIGH] CWE-476 CVE-2021-31618: Apache HTTP Server protocol handler for the HTTP/2 protocol checks received request headers against Apache HTTP Server protocol handler for the HTTP/2 protocol checks received request headers against the size limitations as configured for the server and used for the HTTP/1 protocol as well. On violation of these restrictions and HTTP response is sent to the client with a status code indicating why the request was rejected. This rejection response was
nvd
CVE-2024-49369P2CRITICALCVSS 9.8v11.02024-11-12
CVE-2024-49369 [CRITICAL] CWE-295 CVE-2024-49369: Icinga is a monitoring system which checks the availability of network resources, notifies users of Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. The TLS certificate validation in all Icinga 2 versions starting from 2.4.0 was flawed, allowing an attacker to impersonate both trusted cluster nodes as well as any API users that use TLS client
nvd
CVE-2017-3737P3MEDIUMCVSS 5.9v9.02017-12-07
CVE-2017-3737 [MEDIUM] CWE-125 CVE-2017-3737: OpenSSL 1.0.2 (starting from version 1.0.2b) introduced an "error state" mechanism. The intent was t OpenSSL 1.0.2 (starting from version 1.0.2b) introduced an "error state" mechanism. The intent was that if a fatal error occurred during a handshake then OpenSSL would move into the error state and would immediately fail if you attempted to continue the handshake. This works as designed for the explicit handshake functions (SSL_do_handshake(), SSL_acc
nvd
CVE-2020-8840P3CRITICALCVSS 9.8v8.02020-02-10
CVE-2020-8840 [CRITICAL] CWE-502 CVE-2020-8840: FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demo FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiConverter.
nvd
CVE-2020-6541P3HIGHCVSS 8.8v10.02020-09-21
CVE-2020-6541 [HIGH] CWE-416 CVE-2020-6541: Use after free in WebUSB in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potent Use after free in WebUSB in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2006-3918P4MEDIUMCVSS 4.3PoCv3.12006-07-28
CVE-2006-3918 [MEDIUM] CWE-79 CVE-2006-3918: http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HT http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HTTP Server 1.3 before 1.3.35, 2.0 before 2.0.58, and 2.2 before 2.2.2, does not sanitize the Expect header from an HTTP request when it is reflected back in an error message, which might allow cross-site scripting (XSS) style attacks using web client comp
nvd
CVE-2013-2024P2HIGHCVSS 8.8v8.0v9.0+1 more2019-10-31
CVE-2013-2024 [HIGH] CWE-78 CVE-2013-2024: OS command injection vulnerability in the "qs" procedure from the "utils" module in Chicken before 4 OS command injection vulnerability in the "qs" procedure from the "utils" module in Chicken before 4.9.0.
nvd
CVE-2011-4120P2CRITICALCVSS 9.8v8.0v9.0+1 more2019-11-26
CVE-2011-4120 [CRITICAL] CWE-20 CVE-2011-4120: Yubico PAM Module before 2.10 performed user authentication when 'use_first_pass' PAM configuration Yubico PAM Module before 2.10 performed user authentication when 'use_first_pass' PAM configuration option was not used and the module was configured as 'sufficient' in the PAM configuration. A remote attacker could use this flaw to circumvent common authentication process and obtain access to the account in question by providing a NULL value (pressin
nvd
CVE-2019-11356P2CRITICALCVSS 9.8v9.02019-06-03
CVE-2019-11356 [CRITICAL] CWE-787 CVE-2019-11356: The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote attackers to execute arbitrary code via a crafted HTTP PUT operation for an event with a long iCalendar property name.
nvd
CVE-2023-24805P2HIGHCVSS 8.8v10.0v11.02023-05-17
CVE-2023-24805 [HIGH] CWE-78 CVE-2023-24805: cups-filters contains backends, filters, and other software required to get the cups printing servic cups-filters contains backends, filters, and other software required to get the cups printing service working on operating systems other than macos. If you use the Backend Error Handler (beh) to create an accessible network printer, this security vulnerability can cause remote code execution. `beh.c` contains the line `retval = system(cmdline) >> 8;` w
nvd
CVE-2016-10243P2CRITICALCVSS 9.8v7.0v8.02017-05-02
CVE-2016-10243 [CRITICAL] CWE-20 CVE-2016-10243: TeX Live allows remote attackers to execute arbitrary commands by leveraging inclusion of mpost in s TeX Live allows remote attackers to execute arbitrary commands by leveraging inclusion of mpost in shell_escape_commands in the texmf.cnf config file.
nvd
CVE-2021-30560P3HIGHCVSS 8.8v10.0v11.02021-08-03
CVE-2021-30560 [HIGH] CWE-416 CVE-2021-30560: Use after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to po Use after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2015-1265P3HIGHCVSS 7.5PoCv8.02015-05-20
CVE-2015-1265 [HIGH] CVE-2015-1265: Multiple unspecified vulnerabilities in Google Chrome before 43.0.2357.65 allow attackers to cause a Multiple unspecified vulnerabilities in Google Chrome before 43.0.2357.65 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2021-45079P2CRITICALCVSS 9.1v9.0v10.0+1 more2022-01-31
CVE-2021-45079 [CRITICAL] CWE-476 CVE-2021-45079: In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the case of EAP methods with mutual authentication and EAP-only authentication for IKEv2) even without server authentication.
nvd
Debian Linux vulnerabilities | cvebase