cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 322 of 498
CVE-2020-4046P4MEDIUMCVSS 5.4v8.0v9.02020-06-12
CVE-2020-4046 [MEDIUM] CWE-80 CVE-2020-4046: In affected versions of WordPress, users with low privileges (like contributors and authors) can use In affected versions of WordPress, users with low privileges (like contributors and authors) can use the embed block in a certain way to inject unfiltered HTML in the block editor. When affected posts are viewed by a higher privileged user, this could lead to script execution in the editor/wp-admin. This has been patched in version 5.4.2, along with al
nvd
CVE-2018-1000801P4MEDIUMCVSS 5.5v8.0v9.02018-09-06
CVE-2018-1000801 [MEDIUM] CWE-22 CVE-2018-1000801: okular version 18.08 and earlier contains a Directory Traversal vulnerability in function "unpackDoc okular version 18.08 and earlier contains a Directory Traversal vulnerability in function "unpackDocumentArchive(...)" in "core/document.cpp" that can result in Arbitrary file creation on the user workstation. This attack appear to be exploitable via he victim must open a specially crafted Okular archive. This issue appears to have been corrected
nvd
CVE-2014-9763P4HIGHCVSS 7.5v7.0v8.02016-05-13
CVE-2014-9763 [HIGH] CWE-189 CVE-2014-9763: imlib2 before 1.4.7 allows remote attackers to cause a denial of service (divide-by-zero error and a imlib2 before 1.4.7 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted PNM file.
nvd
CVE-2024-3859P4MEDIUMCVSS 5.9v10.02024-04-16
CVE-2024-3859 [MEDIUM] CWE-125 CVE-2024-3859: On 32-bit versions there were integer-overflows that led to an out-of-bounds-read that potentially c On 32-bit versions there were integer-overflows that led to an out-of-bounds-read that potentially could be triggered by a malformed OpenType font. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
nvd
CVE-2022-38398P4MEDIUMCVSS 5.3v10.02022-09-22
CVE-2022-38398 [MEDIUM] CWE-918 CVE-2022-38398: Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to load a url thru the jar protocol. This issue affects Apache XML Graphics Batik 1.14.
nvd
CVE-2017-13078P4MEDIUMCVSS 5.3v8.0v9.02017-10-17
CVE-2017-13078 [MEDIUM] CWE-323 CVE-2017-13078: Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during t Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the four-way handshake, allowing an attacker within radio range to replay frames from access points to clients.
nvd
CVE-2020-20739P4MEDIUMCVSS 5.3v9.02020-11-20
CVE-2020-20739 [MEDIUM] CWE-909 CVE-2020-20739: im_vips2dz in /libvips/libvips/deprecated/im_vips2dz.c in libvips before 8.8.2 has an uninitialized im_vips2dz in /libvips/libvips/deprecated/im_vips2dz.c in libvips before 8.8.2 has an uninitialized variable which may cause the leakage of remote server path or stack address.
nvd
CVE-2015-7850P4MEDIUMCVSS 6.5v7.0v8.0+1 more2017-08-07
CVE-2015-7850 [MEDIUM] CWE-835 CVE-2015-7850: ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote authenticated users to cause ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote authenticated users to cause a denial of service (infinite loop or crash) by pointing the key file at the log file.
nvd
CVE-2005-1527P4MEDIUMCVSS 5.0v3.0v3.12005-08-15
CVE-2005-1527 [MEDIUM] CWE-94 CVE-2005-1527: Eval injection vulnerability in awstats.pl in AWStats 6.4 and earlier, when a URLPlugin is enabled, Eval injection vulnerability in awstats.pl in AWStats 6.4 and earlier, when a URLPlugin is enabled, allows remote attackers to execute arbitrary Perl code via the HTTP Referrer, which is used in a $url parameter that is inserted into an eval function call.
nvd
CVE-2020-14403P4MEDIUMCVSS 5.4v8.0v9.02020-06-17
CVE-2020-14403 [MEDIUM] CWE-787 CVE-2020-14403: An issue was discovered in LibVNCServer before 0.9.13. libvncserver/hextile.c allows out-of-bounds a An issue was discovered in LibVNCServer before 0.9.13. libvncserver/hextile.c allows out-of-bounds access via encodings.
nvd
CVE-2020-14404P4MEDIUMCVSS 5.4v8.0v9.02020-06-17
CVE-2020-14404 [MEDIUM] CWE-787 CVE-2020-14404: An issue was discovered in LibVNCServer before 0.9.13. libvncserver/rre.c allows out-of-bounds acces An issue was discovered in LibVNCServer before 0.9.13. libvncserver/rre.c allows out-of-bounds access via encodings.
nvd
CVE-2023-27538P4MEDIUMCVSS 5.5v10.02023-03-30
CVE-2023-27538 [MEDIUM] CWE-305 CVE-2023-27538: An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previousl An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previously used connections to reuse them for subsequent transfers if the configurations match. However, two
nvd
CVE-2022-2795P4MEDIUMCVSS 5.3v10.0v11.02022-09-21
CVE-2022-2795 [MEDIUM] CVE-2022-2795: By flooding the target resolver with queries exploiting this flaw an attacker can significantly impa By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver's performance, effectively denying legitimate clients access to the DNS resolution service.
nvd
CVE-2020-7063P4MEDIUMCVSS 5.3v8.0v9.0+1 more2020-02-27
CVE-2020-7063 [MEDIUM] CWE-281 CVE-2020-7063: In PHP versions 7.2.x below 7.2.28, 7.3.x below 7.3.15 and 7.4.x below 7.4.3, when creating PHAR arc In PHP versions 7.2.x below 7.2.28, 7.3.x below 7.3.15 and 7.4.x below 7.4.3, when creating PHAR archive using PharData::buildFromIterator() function, the files are added with default permissions (0666, or all access) even if the original files on the filesystem were with more restrictive permissions. This may result in files having more lax permissio
nvd
CVE-2011-0983P4HIGHCVSS 7.5v6.0v7.02011-02-10
CVE-2011-0983 [HIGH] CWE-20 CVE-2011-0983: Google Chrome before 9.0.597.94 does not properly handle anonymous blocks, which allows remote attac Google Chrome before 9.0.597.94 does not properly handle anonymous blocks, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2020-11038P4MEDIUMCVSS 5.4v10.02020-05-29
CVE-2020-11038 [MEDIUM] CWE-680 CVE-2020-11038: In FreeRDP less than or equal to 2.0.0, an Integer Overflow to Buffer Overflow exists. When using /v In FreeRDP less than or equal to 2.0.0, an Integer Overflow to Buffer Overflow exists. When using /video redirection, a manipulated server can instruct the client to allocate a buffer with a smaller size than requested due to an integer overflow in size calculation. With later messages, the server can manipulate the client to write data out of bound
nvd
CVE-2011-0981P4HIGHCVSS 7.5v6.0v7.02011-02-10
CVE-2011-0981 [HIGH] CWE-20 CVE-2011-0981: Google Chrome before 9.0.597.94 does not properly perform event handling for animations, which allow Google Chrome before 9.0.597.94 does not properly perform event handling for animations, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2015-0382P4MEDIUMCVSS 4.3v7.02015-01-21
CVE-2015-0382 [MEDIUM] CVE-2015-0382: Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows re Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows remote attackers to affect availability via unknown vectors related to Server : Replication, a different vulnerability than CVE-2015-0381.
nvd
CVE-2011-2821P4HIGHCVSS 7.5v5.0v6.0+1 more2011-08-29
CVE-2011-2821 [HIGH] CWE-415 CVE-2011-2821: Double free vulnerability in libxml2, as used in Google Chrome before 13.0.782.215, allows remote at Double free vulnerability in libxml2, as used in Google Chrome before 13.0.782.215, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted XPath expression.
nvd
CVE-2014-1829P4MEDIUMCVSS 5.0v7.02014-10-15
CVE-2014-1829 [MEDIUM] CWE-200 CVE-2014-1829: Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by read Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by reading the Authorization header in a redirected request.
nvd
Debian Linux vulnerabilities | cvebase