Debian Linux vulnerabilities
9,954 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358
Vulnerabilities
Page 333 of 498
CVE-2019-15165P4MEDIUMCVSS 5.3v8.0v9.02019-10-03
CVE-2019-15165 [MEDIUM] CWE-770 CVE-2019-15165: sf-pcapng.c in libpcap before 1.9.1 does not properly validate the PHB header length before allocati
sf-pcapng.c in libpcap before 1.9.1 does not properly validate the PHB header length before allocating memory.
nvd
CVE-2022-43594P4MEDIUMCVSS 5.9v11.02022-12-22
CVE-2022-43594 [MEDIUM] CWE-476 CVE-2022-43594: Multiple denial of service vulnerabilities exist in the image output closing functionality of OpenIm
Multiple denial of service vulnerabilities exist in the image output closing functionality of OpenImageIO Project OpenImageIO v2.4.4.2. Specially crafted ImageOutput Objects can lead to multiple null pointer dereferences. An attacker can provide malicious multiple inputs to trigger these vulnerabilities.This vulnerability applies to writing .bmp fil
nvd
CVE-2018-1000069P4MEDIUMCVSS 5.5v7.0v8.0+1 more2018-03-13
CVE-2018-1000069 [MEDIUM] CWE-611 CVE-2018-1000069: FreePlane version 1.5.9 and earlier contains a XML External Entity (XXE) vulnerability in XML Parser
FreePlane version 1.5.9 and earlier contains a XML External Entity (XXE) vulnerability in XML Parser in mindmap loader that can result in stealing data from victim's machine. This attack appears to require the victim to open a specially crafted mind map file. This vulnerability appears to have been fixed in 1.6+.
nvd
CVE-2022-43595P4MEDIUMCVSS 5.9v11.02022-12-22
CVE-2022-43595 [MEDIUM] CWE-476 CVE-2022-43595: Multiple denial of service vulnerabilities exist in the image output closing functionality of OpenIm
Multiple denial of service vulnerabilities exist in the image output closing functionality of OpenImageIO Project OpenImageIO v2.4.4.2. Specially crafted ImageOutput Objects can lead to multiple null pointer dereferences. An attacker can provide malicious multiple inputs to trigger these vulnerabilities.This vulnerability applies to writing .fits fi
nvd
CVE-2016-7074P4MEDIUMCVSS 5.9v8.02018-09-11
CVE-2016-7074 [MEDIUM] CWE-20 CVE-2016-7074: An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, all
An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, allowing an attacker in position of man-in-the-middle to alter the content of an AXFR because of insufficient validation of TSIG signatures. A missing check that the TSIG record is the last one, leading to the possibility of parsing records that are not cov
nvd
CVE-2016-2375P4MEDIUMCVSS 5.3v8.02017-01-06
CVE-2016-2375 [MEDIUM] CWE-125 CVE-2016-2375: An exploitable out-of-bounds read exists in the handling of the MXIT protocol in Pidgin. Specially c
An exploitable out-of-bounds read exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT contact information sent from the server can result in memory disclosure.
nvd
CVE-2022-48566P4MEDIUMCVSS 5.9v10.02023-08-22
CVE-2022-48566 [MEDIUM] CWE-362 CVE-2022-48566: An issue was discovered in compare_digest in Lib/hmac.py in Python through 3.9.1. Constant-time-defe
An issue was discovered in compare_digest in Lib/hmac.py in Python through 3.9.1. Constant-time-defeating optimisations were possible in the accumulator variable in hmac.compare_digest.
nvd
CVE-2017-17843P4MEDIUMCVSS 5.9v8.0v9.02017-12-27
CVE-2017-17843 [MEDIUM] CVE-2017-17843: An issue was discovered in Enigmail before 1.9.9 that allows remote attackers to trigger use of an i
An issue was discovered in Enigmail before 1.9.9 that allows remote attackers to trigger use of an intended public key for encryption, because incorrect regular expressions are used for extraction of an e-mail address from a comma-separated list, as demonstrated by a modified Full Name field and a homograph attack, aka TBE-01-002.
nvd
CVE-2004-1176P4HIGHCVSS 7.5v3.02005-04-14
CVE-2004-1176 [HIGH] CVE-2004-1176: Buffer underflow in extfs.c in Midnight Commander (mc) 4.5.55 and earlier allows remote attackers to
Buffer underflow in extfs.c in Midnight Commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code.
nvd
CVE-2024-2609P4MEDIUMCVSS 6.1v10.02024-03-19
CVE-2024-2609 [MEDIUM] CWE-356 CVE-2024-2609: The permission prompt input delay could expire while the window is not in focus. This makes it vulne
The permission prompt input delay could expire while the window is not in focus. This makes it vulnerable to clickjacking by malicious websites. This vulnerability affects Firefox < 124, Firefox ESR < 115.10, and Thunderbird < 115.10.
nvd
CVE-2020-10933P4MEDIUMCVSS 5.3v10.02020-05-04
CVE-2020-10933 [MEDIUM] CWE-908 CVE-2020-10933: An issue was discovered in Ruby 2.5.x through 2.5.7, 2.6.x through 2.6.5, and 2.7.0. If a victim cal
An issue was discovered in Ruby 2.5.x through 2.5.7, 2.6.x through 2.6.5, and 2.7.0. If a victim calls BasicSocket#read_nonblock(requested_size, buffer, exception: false), the method resizes the buffer to fit the requested size, but no data is copied. Thus, the buffer string provides the previous value of the heap. This may expose possibly sensitive
nvd
CVE-2021-22895P4MEDIUMCVSS 5.9v10.0v11.02021-06-11
CVE-2021-22895 [MEDIUM] CWE-295 CVE-2021-22895: Nextcloud Desktop Client before 3.3.1 is vulnerable to improper certificate validation due to lack o
Nextcloud Desktop Client before 3.3.1 is vulnerable to improper certificate validation due to lack of SSL certificate verification when using the "Register with a Provider" flow.
nvd
CVE-2021-3507P4MEDIUMCVSS 6.1v10.02021-05-06
CVE-2021-3507 [MEDIUM] CWE-119 CVE-2021-3507: A heap buffer overflow was found in the floppy disk emulator of QEMU up to 6.0.0 (including). It cou
A heap buffer overflow was found in the floppy disk emulator of QEMU up to 6.0.0 (including). It could occur in fdctrl_transfer_handler() in hw/block/fdc.c while processing DMA read data transfers from the floppy drive to the guest system. A privileged guest user could use this flaw to crash the QEMU process on the host resulting in DoS scenario, or p
nvd
CVE-2023-28756P4MEDIUMCVSS 5.3v10.02023-03-31
CVE-2023-28756 [MEDIUM] CWE-1333 CVE-2023-28756: A ReDoS issue was discovered in the Time component through 0.2.1 in Ruby through 3.2.1. The Time par
A ReDoS issue was discovered in the Time component through 0.2.1 in Ruby through 3.2.1. The Time parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to Time objects. The fixed versions are 0.1.1 and 0.2.2.
nvd
CVE-2020-2934P4MEDIUMCVSS 5.0v8.0v9.02020-04-15
CVE-2020-2934 [MEDIUM] CVE-2020-2934: Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported ve
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.19 and prior and 5.1.48 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks require human interaction from a
nvd
CVE-2018-16758P4MEDIUMCVSS 5.9v9.02018-10-10
CVE-2018-16758 [MEDIUM] CWE-306 CVE-2018-16758: Missing message authentication in the meta-protocol in Tinc VPN version 1.0.34 and earlier allows a
Missing message authentication in the meta-protocol in Tinc VPN version 1.0.34 and earlier allows a man-in-the-middle attack to disable the encryption of VPN packets.
nvd
CVE-2021-39365P4MEDIUMCVSS 5.9v9.0v10.0+1 more2021-08-22
CVE-2021-39365 [MEDIUM] CVE-2021-39365: In GNOME grilo though 0.3.13, grl-net-wc.c does not enable TLS certificate verification on the SoupS
In GNOME grilo though 0.3.13, grl-net-wc.c does not enable TLS certificate verification on the SoupSessionAsync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.
nvd
CVE-2017-1665P4MEDIUMCVSS 5.9v9.02018-01-04
CVE-2017-1665 [MEDIUM] CWE-326 CVE-2017-1665: IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 uses weaker than expected cryptographic algorithm
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 133559.
nvd
CVE-2022-3594P4MEDIUMCVSS 5.3v10.02022-10-18
CVE-2022-3594 [MEDIUM] CWE-404 CVE-2022-3594: A vulnerability was found in Linux Kernel. It has been declared as problematic. Affected by this vul
A vulnerability was found in Linux Kernel. It has been declared as problematic. Affected by this vulnerability is the function intr_callback of the file drivers/net/usb/r8152.c of the component BPF. The manipulation leads to logging of excessive data. The attack can be launched remotely. It is recommended to apply a patch to fix this issue. The associ
nvd
CVE-2019-14861P4MEDIUMCVSS 5.3v9.02019-12-10
CVE-2019-14861 [MEDIUM] CWE-276 CVE-2019-14861: All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue
All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the (poorly named) dnsserver RPC pipe provides administrative facilities to modify DNS records and zones. Samba, when acting as an AD DC, stores DNS records in LDAP. In AD, the default permissions on the DNS partition allow creation of new rec
nvd