cbcvebase.

Debian Linux vulnerabilities

9,953 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358

Vulnerabilities

Page 33 of 498
CVE-2022-26651P2CRITICALCVSS 9.8v10.0v11.02022-04-15
CVE-2022-26651 [CRITICAL] CWE-89 CVE-2022-26651: An issue was discovered in Asterisk through 19.x and Certified Asterisk through 16.8-cert13. The fun An issue was discovered in Asterisk through 19.x and Certified Asterisk through 16.8-cert13. The func_odbc module provides possibly inadequate escaping functionality for backslash characters in SQL queries, resulting in user-provided data creating a broken SQL query or possibly a SQL injection. This is fixed in 16.25.2, 18.11.2, and 19.3.2, and 16.
nvd
CVE-2019-14271P2CRITICALCVSS 9.8v10.02019-07-29
CVE-2019-14271 [CRITICAL] CWE-665 CVE-2019-14271: In Docker 19.03.x before 19.03.1 linked against the GNU C Library (aka glibc), code injection can oc In Docker 19.03.x before 19.03.1 linked against the GNU C Library (aka glibc), code injection can occur when the nsswitch facility dynamically loads a library inside a chroot that contains the contents of the container.
nvd
CVE-2021-32610P3HIGHCVSS 7.1v9.02021-07-30
CVE-2021-32610 [HIGH] CVE-2021-32610: In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a diff In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.
nvd
CVE-2020-25074P2CRITICALCVSS 9.8v9.0v10.02020-11-10
CVE-2020-25074 [CRITICAL] CWE-22 CVE-2020-25074: The cache action in action/cache.py in MoinMoin through 1.9.10 allows directory traversal through a The cache action in action/cache.py in MoinMoin through 1.9.10 allows directory traversal through a crafted HTTP request. An attacker who can upload attachments to the wiki can use this to achieve remote code execution.
nvd
CVE-2019-5482P3CRITICALCVSS 9.8v9.0v10.02019-09-16
CVE-2019-5482 [CRITICAL] CWE-122 CVE-2019-5482: Heap buffer overflow in the TFTP protocol handler in cURL 7.19.4 to 7.65.3. Heap buffer overflow in the TFTP protocol handler in cURL 7.19.4 to 7.65.3.
nvd
CVE-2021-33620P3MEDIUMCVSS 6.5v9.02021-05-28
CVE-2021-33620 [MEDIUM] CWE-20 CVE-2021-33620: Squid before 4.15 and 5.x before 5.0.6 allows remote servers to cause a denial of service (affecting Squid before 4.15 and 5.x before 5.0.6 allows remote servers to cause a denial of service (affecting availability to all clients) via an HTTP response. The issue trigger is a header that can be expected to exist in HTTP traffic without any malicious intent by the server.
nvd
CVE-2018-14767P3CRITICALCVSS 9.8v8.0v9.02018-07-31
CVE-2018-14767 [CRITICAL] CWE-20 CVE-2018-14767: In Kamailio before 5.0.7 and 5.1.x before 5.1.4, a crafted SIP message with a double "To" header and In Kamailio before 5.0.7 and 5.1.x before 5.1.4, a crafted SIP message with a double "To" header and an empty "To" tag causes a segmentation fault and crash. The reason is missing input validation in the "build_res_buf_from_sip_req" core function. This could result in denial of service and potentially the execution of arbitrary code.
nvd
CVE-2021-43113P2CRITICALCVSS 9.8v10.0v11.02021-12-15
CVE-2021-43113 [CRITICAL] CWE-77 CVE-2021-43113: iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injection via a CompareTool iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injection via a CompareTool filename that is mishandled on the gs (aka Ghostscript) command line in GhostscriptHelper.java.
nvd
CVE-2018-11780P2CRITICALCVSS 9.8v8.02018-09-17
CVE-2018-11780 [CRITICAL] CWE-94 CVE-2018-11780: A potential Remote Code Execution bug exists with the PDFInfo plugin in Apache SpamAssassin before 3 A potential Remote Code Execution bug exists with the PDFInfo plugin in Apache SpamAssassin before 3.4.2.
nvd
CVE-2019-19450P2CRITICALCVSS 9.8v10.02023-09-20
CVE-2019-19450 [CRITICAL] CVE-2019-19450: paraparser in ReportLab before 3.5.31 allows remote code execution because start_unichar in parapars paraparser in ReportLab before 3.5.31 allows remote code execution because start_unichar in paraparser.py evaluates untrusted user input in a unichar element in a crafted XML document with '<unichar code="' followed by arbitrary Python code, a similar issue to CVE-2019-17626.
nvd
CVE-2017-1000501P2CRITICALCVSS 9.8v7.0v8.0+1 more2018-01-03
CVE-2017-1000501 [CRITICAL] CWE-22 CVE-2017-1000501: Awstats version 7.6 and earlier is vulnerable to a path traversal flaw in the handling of the "confi Awstats version 7.6 and earlier is vulnerable to a path traversal flaw in the handling of the "config" and "migrate" parameters resulting in unauthenticated remote code execution.
nvd
CVE-2018-6307P3HIGHCVSS 8.1v8.0v9.02018-12-19
CVE-2018-6307 [HIGH] CWE-416 CVE-2018-6307: LibVNC before commit ca2a5ac02fbbadd0a21fabba779c1ea69173d10b contains heap use-after-free vulnerabi LibVNC before commit ca2a5ac02fbbadd0a21fabba779c1ea69173d10b contains heap use-after-free vulnerability in server code of file transfer extension that can result remote code execution.
nvd
CVE-2019-12086P3HIGHCVSS 7.5v8.0v9.02019-05-17
CVE-2019-12086 [HIGH] CWE-502 CVE-2019-12086: A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9. When Defau A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint, the service has the mysql-connector-java jar (8.0.14 or earlier) in the classpath, and an attacker can host a crafted MySQL server reachable by th
nvd
CVE-2017-2620P2CRITICALCVSS 9.9v7.02018-07-27
CVE-2017-2620 [CRITICAL] CWE-787 CVE-2017-2620: Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue. The issue could occur while copying VGA data in cirrus_bitblt_cputovideo. A privileged user inside guest could use this flaw to crash the QEMU process OR potentially execute arbitrary code on host with privileges of th
nvd
CVE-2018-8014P2CRITICALCVSS 9.8v8.02018-05-16
CVE-2018-8014 [CRITICAL] CWE-1188 CVE-2018-8014: The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5. The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.88 are insecure and enable 'supportsCredentials' for all origins. It is expected that users of the CORS filter will have configured it appropriately for their environment rather than using it in the default conf
nvd
CVE-2016-5008P2CRITICALCVSS 9.8v8.02016-07-13
CVE-2016-5008 [CRITICAL] CWE-284 CVE-2016-5008: libvirt before 2.0.0 improperly disables password checking when the password on a VNC server is set libvirt before 2.0.0 improperly disables password checking when the password on a VNC server is set to an empty string, which allows remote attackers to bypass authentication and establish a VNC session by connecting to the server.
nvd
CVE-2004-0835P3HIGHCVSS 7.5PoCv3.02004-11-03
CVE-2004-0835 [HIGH] CVE-2004-0835: MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CR MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CREATE/INSERT rights of the original table instead of the target table in an ALTER TABLE RENAME operation, which could allow attackers to conduct unauthorized activities.
nvd
CVE-2021-3657P2CRITICALCVSS 9.8v9.02022-02-18
CVE-2021-3657 [CRITICAL] CWE-119 CVE-2021-3657: A flaw was found in mbsync versions prior to 1.4.4. Due to inadequate handling of extremely large (> A flaw was found in mbsync versions prior to 1.4.4. Due to inadequate handling of extremely large (>=2GiB) IMAP literals, malicious or compromised IMAP servers, and hypothetically even external email senders, could cause several different buffer overflows, which could conceivably be exploited for remote code execution.
nvd
CVE-2022-48174P2CRITICALCVSS 9.8v11.02023-08-22
CVE-2022-48174 [CRITICAL] CWE-787 CVE-2022-48174: There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be executed from command to arbitrary code execution.
nvd
CVE-2017-15095P2CRITICALCVSS 9.8v8.0v9.02018-02-06
CVE-2017-15095 [CRITICAL] CWE-184 CVE-2017-15095: A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, w A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper. This issue extends the previous flaw CVE-2017-7525 by blacklisting more classes that could be us
nvd
Debian Linux vulnerabilities | cvebase