Debian Linux vulnerabilities
9,954 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358
Vulnerabilities
Page 334 of 498
CVE-2017-13080P4MEDIUMCVSS 5.3v8.0v9.02017-10-17
CVE-2017-13080 [MEDIUM] CWE-323 CVE-2017-13080: Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during t
Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the group key handshake, allowing an attacker within radio range to replay frames from access points to clients.
nvd
CVE-2016-3170P4MEDIUMCVSS 5.3v7.0v8.02016-04-12
CVE-2016-3170 [MEDIUM] CWE-200 CVE-2016-3170: The "have you forgotten your password" links in the User module in Drupal 7.x before 7.43 and 8.x be
The "have you forgotten your password" links in the User module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allow remote attackers to obtain sensitive username information by leveraging a configuration that permits using an email address to login and a module that permits logging in.
nvd
CVE-2023-4049P4MEDIUMCVSS 5.9v11.0v12.02023-08-01
CVE-2023-4049 [MEDIUM] CWE-362 CVE-2023-4049: Race conditions in reference counting code were found through code inspection. These could have resu
Race conditions in reference counting code were found through code inspection. These could have resulted in potentially exploitable use-after-free vulnerabilities. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.
nvd
CVE-2017-6816P4MEDIUMCVSS 4.9v8.0v9.02017-03-12
CVE-2017-6816 [MEDIUM] CWE-863 CVE-2017-6816: In WordPress before 4.7.3 (wp-admin/plugins.php), unintended files can be deleted by administrators
In WordPress before 4.7.3 (wp-admin/plugins.php), unintended files can be deleted by administrators using the plugin deletion functionality.
nvd
CVE-2019-15132P4MEDIUMCVSS 5.3v9.02019-08-17
CVE-2019-15132 [MEDIUM] CWE-203 CVE-2019-15132: Zabbix through 4.4.0alpha1 allows User Enumeration. With login requests, it is possible to enumerate
Zabbix through 4.4.0alpha1 allows User Enumeration. With login requests, it is possible to enumerate application usernames based on the variability of server responses (e.g., the "Login name or password is incorrect" and "No permissions for system access" messages, or just blocking for a number of seconds). This affects both api_jsonrpc.php and inde
nvd
CVE-2017-13081P4MEDIUMCVSS 5.3v8.0v9.02017-10-17
CVE-2017-13081 [MEDIUM] CWE-323 CVE-2017-13081: Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the Integr
Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the Integrity Group Temporal Key (IGTK) during the group key handshake, allowing an attacker within radio range to spoof frames from access points to clients.
nvd
CVE-2008-4067P4MEDIUMCVSS 4.3v4.02008-09-24
CVE-2008-4067 [MEDIUM] CWE-22 CVE-2008-4067: Directory traversal vulnerability in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbi
Directory traversal vulnerability in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 on Linux allows remote attackers to read arbitrary files via a .. (dot dot) and URL-encoded / (slash) characters in a resource: URI.
nvd
CVE-2001-0458P4HIGHCVSS 7.5v2.22001-06-27
CVE-2001-0458 [HIGH] CVE-2001-0458: Multiple buffer overflows in ePerl before 2.2.14-0.7 allow local and remote attackers to execute arb
Multiple buffer overflows in ePerl before 2.2.14-0.7 allow local and remote attackers to execute arbitrary commands.
nvd
CVE-2019-3795P4MEDIUMCVSS 5.3v8.02019-04-09
CVE-2019-3795 [MEDIUM] CWE-330 CVE-2019-3795: Spring Security versions 4.2.x prior to 4.2.12, 5.0.x prior to 5.0.12, and 5.1.x prior to 5.1.5 cont
Spring Security versions 4.2.x prior to 4.2.12, 5.0.x prior to 5.0.12, and 5.1.x prior to 5.1.5 contain an insecure randomness vulnerability when using SecureRandomFactoryBean#setSeed to configure a SecureRandom instance. In order to be impacted, an honest application must provide a seed and make the resulting random material available to an attacker
nvd
CVE-2021-3474P4MEDIUMCVSS 5.3v9.0v10.02021-03-30
CVE-2021-3474 [MEDIUM] CWE-190 CVE-2021-3474: There's a flaw in OpenEXR in versions before 3.0.0-beta. A crafted input file that is processed by O
There's a flaw in OpenEXR in versions before 3.0.0-beta. A crafted input file that is processed by OpenEXR could cause a shift overflow in the FastHufDecoder, potentially leading to problems with application availability.
nvd
CVE-2021-3476P4MEDIUMCVSS 5.3v9.0v10.02021-03-30
CVE-2021-3476 [MEDIUM] CWE-190 CVE-2021-3476: A flaw was found in OpenEXR's B44 uncompression functionality in versions before 3.0.0-beta. An atta
A flaw was found in OpenEXR's B44 uncompression functionality in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to OpenEXR could trigger shift overflows, potentially affecting application availability.
nvd
CVE-2017-7791P4MEDIUMCVSS 5.3v8.0v9.02018-06-11
CVE-2017-7791 [MEDIUM] CWE-20 CVE-2017-7791: On pages containing an iframe, the "data:" protocol can be used to create a modal alert that will re
On pages containing an iframe, the "data:" protocol can be used to create a modal alert that will render over arbitrary domains following page navigation, spoofing of the origin of the modal alert from the iframe content. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
nvd
CVE-2020-35176P4MEDIUMCVSS 5.3v9.02020-12-12
CVE-2020-35176 [MEDIUM] CVE-2020-35176: In AWStats through 7.8, cgi-bin/awstats.pl?config= accepts a partial absolute pathname (omitting the
In AWStats through 7.8, cgi-bin/awstats.pl?config= accepts a partial absolute pathname (omitting the initial /etc), even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000501 and CVE-2020-29600.
nvd
CVE-2020-26298P4MEDIUMCVSS 5.4v9.0v10.02021-01-11
CVE-2020-26298 [MEDIUM] CWE-74 CVE-2020-26298: Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the `:escape_html` option was being used. This is fixed in version 3.5.1 by
nvd
CVE-2019-16910P4MEDIUMCVSS 5.3v10.02019-09-26
CVE-2019-16910 [MEDIUM] CVE-2019-16910: Arm Mbed TLS before 2.19.0 and Arm Mbed Crypto before 2.0.0, when deterministic ECDSA is enabled, us
Arm Mbed TLS before 2.19.0 and Arm Mbed Crypto before 2.0.0, when deterministic ECDSA is enabled, use an RNG with insufficient entropy for blinding, which might allow an attacker to recover a private key via side-channel attacks if a victim signs the same message many times. (For Mbed TLS, the fix is also available in versions 2.7.12 and 2.16.3.)
nvd
CVE-2021-20296P4MEDIUMCVSS 5.3v9.0v10.02021-04-01
CVE-2021-20296 [MEDIUM] CWE-476 CVE-2021-20296: A flaw was found in OpenEXR in versions before 3.0.0-beta. A crafted input file supplied by an attac
A flaw was found in OpenEXR in versions before 3.0.0-beta. A crafted input file supplied by an attacker, that is processed by the Dwa decompression functionality of OpenEXR's IlmImf library, could cause a NULL pointer dereference. The highest threat from this vulnerability is to system availability.
nvd
CVE-2021-30158P4MEDIUMCVSS 5.3v9.0v10.02021-04-06
CVE-2021-30158 [MEDIUM] CWE-287 CVE-2021-30158: An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Blocked
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Blocked users are unable to use Special:ResetTokens. This has security relevance because a blocked user might have accidentally shared a token, or might know that a token has been compromised, and yet is not able to block any potential future use of the toke
nvd
CVE-2012-1104P4MEDIUMCVSS 5.3v8.02019-12-05
CVE-2012-1104 [MEDIUM] CWE-269 CVE-2012-1104: A Security Bypass vulnerability exists in the phpCAS 1.2.2 library from the jasig project due to the
A Security Bypass vulnerability exists in the phpCAS 1.2.2 library from the jasig project due to the way proxying of services are managed.
nvd
CVE-2022-1328P4MEDIUMCVSS 5.3v9.02022-04-14
CVE-2022-1328 [MEDIUM] CWE-120 CVE-2022-1328: Buffer Overflow in uudecoder in Mutt affecting all versions starting from 0.94.13 before 2.2.3 allow
Buffer Overflow in uudecoder in Mutt affecting all versions starting from 0.94.13 before 2.2.3 allows read past end of input line
nvd
CVE-2009-1633P4HIGHCVSS 7.1v4.0v5.02009-05-28
CVE-2009-1633 [HIGH] CWE-119 CVE-2009-1633: Multiple buffer overflows in the cifs subsystem in the Linux kernel before 2.6.29.4 allow remote CIF
Multiple buffer overflows in the cifs subsystem in the Linux kernel before 2.6.29.4 allow remote CIFS servers to cause a denial of service (memory corruption) and possibly have unspecified other impact via (1) a malformed Unicode string, related to Unicode string area alignment in fs/cifs/sess.c; or (2) long Unicode characters, related to fs/cifs/cifssm
nvd