cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 335 of 498
CVE-2020-4051P4MEDIUMCVSS 5.4v10.02020-06-15
CVE-2020-4051 [MEDIUM] CWE-79 CVE-2020-4051: In Dijit before versions 1.11.11, and greater than or equal to 1.12.0 and less than 1.12.9, and grea In Dijit before versions 1.11.11, and greater than or equal to 1.12.0 and less than 1.12.9, and greater than or equal to 1.13.0 and less than 1.13.8, and greater than or equal to 1.14.0 and less than 1.14.7, and greater than or equal to 1.15.0 and less than 1.15.4, and greater than or equal to 1.16.0 and less than 1.16.3, there is a cross-site scriptin
nvd
CVE-2012-3177P4MEDIUMCVSS 6.8v6.02012-10-17
CVE-2012-3177 [MEDIUM] CVE-2012-3177: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.65 and earlier, and 5.5. Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.65 and earlier, and 5.5.27 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server.
nvd
CVE-2022-39348P4MEDIUMCVSS 5.4v10.02022-10-26
CVE-2022-39348 [MEDIUM] CWE-79 CVE-2022-39348: Twisted is an event-based framework for internet applications. Started with version 0.9.4, when the Twisted is an event-based framework for internet applications. Started with version 0.9.4, when the host header does not match a configured host `twisted.web.vhost.NameVirtualHost` will return a `NoResource` resource which renders the Host header unescaped into the 404 response allowing HTML and script injection. In practice this should be very diffic
nvd
CVE-2024-29025P4MEDIUMCVSS 5.3v10.02024-03-25
CVE-2024-29025 [MEDIUM] CWE-770 CVE-2024-29025: Netty is an asynchronous event-driven network application framework for rapid development of maintai Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. The `HttpPostRequestDecoder` can be tricked to accumulate data. While the decoder can store items on the disk if configured so, there are no limits to the number of fields the form can have, an attach
nvd
CVE-2017-3305P4MEDIUMCVSS 5.3v8.02017-04-24
CVE-2017-3305 [MEDIUM] CWE-319 CVE-2017-3305: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: C API). Supported Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: C API). Supported versions that are affected are 5.5.55 and earlier and 5.6.35 and earlier. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability
nvd
CVE-2021-46671P4MEDIUMCVSS 5.3v9.0v10.0+1 more2022-02-04
CVE-2021-46671 [MEDIUM] CWE-125 CVE-2021-46671: options.c in atftp before 0.7.5 reads past the end of an array, and consequently discloses server-si options.c in atftp before 0.7.5 reads past the end of an array, and consequently discloses server-side /etc/group data to a remote client.
nvd
CVE-2016-10165P4HIGHCVSS 7.1v8.02017-02-03
CVE-2016-10165 [HIGH] CWE-125 CVE-2016-10165: The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bounds heap read.
nvd
CVE-2020-8021P4MEDIUMCVSS 5.3v9.02020-05-19
CVE-2020-8021 [MEDIUM] CWE-269 CVE-2020-8021: a Improper Access Control vulnerability in of Open Build Service allows remote attackers to read fil a Improper Access Control vulnerability in of Open Build Service allows remote attackers to read files of an OBS package where the sourceaccess/access is disabled This issue affects: Open Build Service versions prior to 2.10.5.
nvd
CVE-2014-3710P4MEDIUMCVSS 5.0v7.0v8.02014-11-05
CVE-2014-3710 [MEDIUM] CWE-20 CVE-2014-3710: The donote function in readelf.c in file through 5.20, as used in the Fileinfo component in PHP 5.4. The donote function in readelf.c in file through 5.20, as used in the Fileinfo component in PHP 5.4.34, does not ensure that sufficient note headers are present, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file.
nvd
CVE-2015-8476P4MEDIUMCVSS 5.0v6.0v7.0+1 more2015-12-16
CVE-2015-8476 [MEDIUM] CVE-2015-8476: Multiple CRLF injection vulnerabilities in PHPMailer before 5.2.14 allow attackers to inject arbitra Multiple CRLF injection vulnerabilities in PHPMailer before 5.2.14 allow attackers to inject arbitrary SMTP commands via CRLF sequences in an (1) email address to the validateAddress function in class.phpmailer.php or (2) SMTP command to the sendCommand function in class.smtp.php, a different vulnerability than CVE-2012-0796.
nvd
CVE-2014-8104P4MEDIUMCVSS 6.8v7.0v8.02014-12-03
CVE-2014-8104 [MEDIUM] CWE-399 CVE-2014-8104: OpenVPN 2.x before 2.0.11, 2.1.x, 2.2.x before 2.2.3, and 2.3.x before 2.3.6 allows remote authentic OpenVPN 2.x before 2.0.11, 2.1.x, 2.2.x before 2.2.3, and 2.3.x before 2.3.6 allows remote authenticated users to cause a denial of service (server crash) via a small control channel packet.
nvd
CVE-2017-9527P4HIGHCVSS 7.8v9.02017-06-11
CVE-2017-9527 [HIGH] CWE-416 CVE-2017-9527: The mark_context_stack function in gc.c in mruby through 1.2.0 allows attackers to cause a denial of The mark_context_stack function in gc.c in mruby through 1.2.0 allows attackers to cause a denial of service (heap-based use-after-free and application crash) or possibly have unspecified other impact via a crafted .rb file.
nvd
CVE-2022-31088P4MEDIUMCVSS 5.3v11.02022-06-27
CVE-2022-31088 [MEDIUM] CWE-74 CVE-2022-31088: LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 the user name field at login could be used to enumerate LDAP data. This is only the case for LDAP search configuration. This issue has been fixed in version 8.0.
nvd
CVE-2023-51766P4MEDIUMCVSS 5.3v10.02023-12-24
CVE-2023-51766 [MEDIUM] CWE-345 CVE-2023-51766: Exim before 4.97.1 allows SMTP smuggling in certain PIPELINING/CHUNKING configurations. Remote attac Exim before 4.97.1 allows SMTP smuggling in certain PIPELINING/CHUNKING configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because Exim supports . but some other popular e-mail servers do not.
nvd
CVE-2022-24806P4MEDIUMCVSS 5.3v10.0v11.02024-04-16
CVE-2022-24806 [MEDIUM] CWE-20 CVE-2022-24806: net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can exploit an Improper Input Validation vulnerability when SETing malformed OIDs in master agent and subagent simultaneously. Version 5.9.2 contains a patch. Users should use strong SNMPv3 credentials and avo
nvd
CVE-2010-4180P4MEDIUMCVSS 4.3v5.02010-12-06
CVE-2010-4180 [MEDIUM] CVE-2010-4180: OpenSSL before 0.9.8q, and 1.0.x before 1.0.0c, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enab OpenSSL before 0.9.8q, and 1.0.x before 1.0.0c, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not properly prevent modification of the ciphersuite in the session cache, which allows remote attackers to force the downgrade to an unintended cipher via vectors involving sniffing network traffic to discover a session identifier.
nvd
CVE-2011-2924P4MEDIUMCVSS 5.5v8.0v9.0+1 more2019-11-19
CVE-2011-2924 [MEDIUM] CWE-59 CVE-2011-2924: foomatic-rip filter v4.0.12 and prior used insecurely creates temporary files for storage of PostScr foomatic-rip filter v4.0.12 and prior used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct symlink attacks by overwriting arbitrary files accessible with the privileges of the user running the foomatic-rip universal print f
nvd
CVE-2024-8508P4MEDIUMCVSS 5.3v11.02024-10-03
CVE-2024-8508 [MEDIUM] CWE-606 CVE-2024-8508: NLnet Labs Unbound up to and including version 1.21.0 contains a vulnerability when handling replies NLnet Labs Unbound up to and including version 1.21.0 contains a vulnerability when handling replies with very large RRsets that it needs to perform name compression for. Malicious upstreams responses with very large RRsets can cause Unbound to spend a considerable time applying name compression to downstream replies. This can lead to degraded perform
nvd
CVE-2024-53566P4MEDIUMCVSS 5.5v11.02024-12-02
CVE-2024-53566 [MEDIUM] CWE-22 CVE-2024-53566: An issue in the action_listcategories() function of Sangoma Asterisk v22/22.0.0/22.0.0-rc1/22.0.0-rc An issue in the action_listcategories() function of Sangoma Asterisk v22/22.0.0/22.0.0-rc1/22.0.0-rc2/22.0.0-pre1 allows attackers to execute a path traversal.
nvd
CVE-2016-3167P4HIGHCVSS 7.4v7.0v8.02016-04-12
CVE-2016-3167 [HIGH] CVE-2016-3167: Open redirect vulnerability in the drupal_goto function in Drupal 6.x before 6.38, when used with PH Open redirect vulnerability in the drupal_goto function in Drupal 6.x before 6.38, when used with PHP before 5.4.7, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a double-encoded URL in the "destination" parameter.
nvd
Debian Linux vulnerabilities | cvebase