Debian Linux vulnerabilities
9,954 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358
Vulnerabilities
Page 323 of 498
CVE-2014-9472P4HIGHCVSS 7.1v7.02015-03-09
CVE-2014-9472 [HIGH] CWE-399 CVE-2014-9472: The email gateway in RT (aka Request Tracker) 3.0.0 through 4.x before 4.0.23 and 4.2.x before 4.2.1
The email gateway in RT (aka Request Tracker) 3.0.0 through 4.x before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to cause a denial of service (CPU and disk consumption) via a crafted email.
nvd
CVE-2019-15523P4MEDIUMCVSS 5.3v9.02020-12-30
CVE-2019-15523 [MEDIUM] CWE-252 CVE-2019-15523: An issue was discovered in LINBIT csync2 through 2.0. It does not correctly check for the return val
An issue was discovered in LINBIT csync2 through 2.0. It does not correctly check for the return value GNUTLS_E_WARNING_ALERT_RECEIVED of the gnutls_handshake() function. It neglects to call this function again, as required by the design of the API.
nvd
CVE-2023-26049P4MEDIUMCVSS 5.3v10.0v11.0+1 more2023-04-18
CVE-2023-26049 [MEDIUM] CWE-200 CVE-2023-26049: Jetty is a java based web server and servlet engine. Nonstandard cookie parsing in Jetty may allow a
Jetty is a java based web server and servlet engine. Nonstandard cookie parsing in Jetty may allow an attacker to smuggle cookies within other cookies, or otherwise perform unintended behavior by tampering with the cookie parsing mechanism. If Jetty sees a cookie VALUE that starts with `"` (double quote), it will continue to read the cookie string u
nvd
CVE-2015-1782P4MEDIUMCVSS 6.8v7.02015-03-13
CVE-2015-1782 [MEDIUM] CWE-20 CVE-2015-1782: The kex_agree_methods function in libssh2 before 1.5.0 allows remote servers to cause a denial of se
The kex_agree_methods function in libssh2 before 1.5.0 allows remote servers to cause a denial of service (crash) or have other unspecified impact via crafted length values in an SSH_MSG_KEXINIT packet.
nvd
CVE-2015-3225P4MEDIUMCVSS 5.0v7.0v8.02015-07-26
CVE-2015-3225 [MEDIUM] CWE-19 CVE-2015-3225: lib/rack/utils.rb in Rack before 1.5.4 and 1.6.x before 1.6.2, as used with Ruby on Rails 3.x and 4.
lib/rack/utils.rb in Rack before 1.5.4 and 1.6.x before 1.6.2, as used with Ruby on Rails 3.x and 4.x and other products, allows remote attackers to cause a denial of service (SystemStackError) via a request with a large parameter depth.
nvd
CVE-2014-9667P4MEDIUMCVSS 6.8v7.02015-02-08
CVE-2014-9667 [MEDIUM] CWE-119 CVE-2014-9667: sfnt/ttload.c in FreeType before 2.5.4 proceeds with offset+length calculations without restricting
sfnt/ttload.c in FreeType before 2.5.4 proceeds with offset+length calculations without restricting the values, which allows remote attackers to cause a denial of service (integer overflow and out-of-bounds read) or possibly have unspecified other impact via a crafted SFNT table.
nvd
CVE-2019-14973P4MEDIUMCVSS 6.5v8.0v9.0+1 more2019-08-14
CVE-2019-14973 [MEDIUM] CWE-190 CVE-2019-14973: _TIFFCheckMalloc and _TIFFCheckRealloc in tif_aux.c in LibTIFF through 4.0.10 mishandle Integer Over
_TIFFCheckMalloc and _TIFFCheckRealloc in tif_aux.c in LibTIFF through 4.0.10 mishandle Integer Overflow checks because they rely on compiler behavior that is undefined by the applicable C standards. This can, for example, lead to an application crash.
nvd
CVE-2021-31864P4MEDIUMCVSS 5.3v9.02021-04-28
CVE-2021-31864 [MEDIUM] CVE-2021-31864: Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows attackers to bypass the add_
Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows attackers to bypass the add_issue_notes permission requirement by leveraging the incoming mail handler.
nvd
CVE-2021-36409P4HIGHCVSS 7.8v10.0v11.02022-01-10
CVE-2021-36409 [HIGH] CWE-617 CVE-2021-36409: There is an Assertion `scaling_list_pred_matrix_id_delta==1' failed at sps.cc:925 in libde265 v1.0.8
There is an Assertion `scaling_list_pred_matrix_id_delta==1' failed at sps.cc:925 in libde265 v1.0.8 when decoding file, which allows attackers to cause a Denial of Service (DoS) by running the application with a crafted file or possibly have unspecified other impact.
nvd
CVE-2018-16872P4MEDIUMCVSS 5.3v8.0v9.02018-12-13
CVE-2018-16872 [MEDIUM] CWE-367 CVE-2018-16872: A flaw was found in qemu Media Transfer Protocol (MTP). The code opening files in usb_mtp_get_object
A flaw was found in qemu Media Transfer Protocol (MTP). The code opening files in usb_mtp_get_object and usb_mtp_get_partial_object and directories in usb_mtp_object_readdir doesn't consider that the underlying filesystem may have changed since the time lstat(2) was called in usb_mtp_object_alloc, a classical TOCTTOU problem. An attacker with write
nvd
CVE-2017-6928P4MEDIUMCVSS 5.3v7.0v8.0+1 more2018-03-01
CVE-2017-6928 [MEDIUM] CWE-732 CVE-2017-6928: Drupal core 7.x versions before 7.57 when using Drupal's private file system, Drupal will check to m
Drupal core 7.x versions before 7.57 when using Drupal's private file system, Drupal will check to make sure a user has access to a file before allowing the user to view or download it. This check fails under certain conditions in which one module is trying to grant access to the file and another is trying to deny it, leading to an access bypass vulne
nvd
CVE-2013-4590P4MEDIUMCVSS 4.3v7.02014-02-26
CVE-2013-4590 [MEDIUM] CWE-200 CVE-2013-4590: Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 allows attackers to obtain
Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 allows attackers to obtain "Tomcat internals" information by leveraging the presence of an untrusted web application with a context.xml, web.xml, *.jspx, *.tagx, or *.tld XML document containing an external entity declaration in conjunction with an entity reference, related to a
nvd
CVE-2011-0985P4HIGHCVSS 7.5v6.0v7.02011-02-10
CVE-2011-0985 [HIGH] CWE-400 CVE-2011-0985: Google Chrome before 9.0.597.94 does not properly perform process termination upon memory exhaustion
Google Chrome before 9.0.597.94 does not properly perform process termination upon memory exhaustion, which has unspecified impact and remote attack vectors.
nvd
CVE-2022-21125P4MEDIUMCVSS 5.5v9.0v10.0+1 more2022-06-15
CVE-2022-21125 [MEDIUM] CWE-459 CVE-2022-21125: Incomplete cleanup of microarchitectural fill buffers on some Intel(R) Processors may allow an authe
Incomplete cleanup of microarchitectural fill buffers on some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
nvd
CVE-2016-1670P4MEDIUMCVSS 5.3v8.02016-05-14
CVE-2016-1670 [MEDIUM] CWE-362 CVE-2016-1670: Race condition in the ResourceDispatcherHostImpl::BeginRequest function in content/browser/loader/re
Race condition in the ResourceDispatcherHostImpl::BeginRequest function in content/browser/loader/resource_dispatcher_host_impl.cc in Google Chrome before 50.0.2661.102 allows remote attackers to make arbitrary HTTP requests by leveraging access to a renderer process and reusing a request ID.
nvd
CVE-2015-1259P4HIGHCVSS 7.5v8.02015-05-20
CVE-2015-1259 [HIGH] CWE-17 CVE-2015-1259: PDFium, as used in Google Chrome before 43.0.2357.65, does not properly initialize memory, which all
PDFium, as used in Google Chrome before 43.0.2357.65, does not properly initialize memory, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2018-17972P4MEDIUMCVSS 5.5v8.02018-10-03
CVE-2018-17972 [MEDIUM] CWE-362 CVE-2018-17972: An issue was discovered in the proc_pid_stack function in fs/proc/base.c in the Linux kernel through
An issue was discovered in the proc_pid_stack function in fs/proc/base.c in the Linux kernel through 4.18.11. It does not ensure that only root may inspect the kernel stack of an arbitrary task, allowing a local attacker to exploit racy stack unwinding and leak kernel task stack contents.
nvd
CVE-2023-40577P4MEDIUMCVSS 5.4v10.02023-08-25
CVE-2023-40577 [MEDIUM] CWE-79 CVE-2023-40577: Alertmanager handles alerts sent by client applications such as the Prometheus server. An attacker w
Alertmanager handles alerts sent by client applications such as the Prometheus server. An attacker with the permission to perform POST requests on the /api/v1/alerts endpoint could be able to execute arbitrary JavaScript code on the users of Prometheus Alertmanager. This issue has been fixed in Alertmanager version 0.2.51.
nvd
CVE-2014-3167P4HIGHCVSS 7.5v7.0v8.02014-08-13
CVE-2014-3167 [HIGH] CVE-2014-3167: Multiple unspecified vulnerabilities in Google Chrome before 36.0.1985.143 allow attackers to cause
Multiple unspecified vulnerabilities in Google Chrome before 36.0.1985.143 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2008-2812P4HIGHCVSS 7.8v4.02008-07-09
CVE-2008-2812 [HIGH] CWE-476 CVE-2008-2812: The Linux kernel before 2.6.25.10 does not properly perform tty operations, which allows local users
The Linux kernel before 2.6.25.10 does not properly perform tty operations, which allows local users to cause a denial of service (system crash) or possibly gain privileges via vectors involving NULL pointer dereference of function pointers in (1) hamradio/6pack.c, (2) hamradio/mkiss.c, (3) irda/irtty-sir.c, (4) ppp_async.c, (5) ppp_synctty.c, (6) slip.
nvd