Debian Linux vulnerabilities
9,954 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358
Vulnerabilities
Page 344 of 498
CVE-2015-4879P4MEDIUMCVSS 4.6v7.0v8.02015-10-21
CVE-2015-4879 [MEDIUM] CVE-2015-4879: Unspecified vulnerability in Oracle MySQL Server 5.5.44 and earlier, and 5.6.25 and earlier, allows
Unspecified vulnerability in Oracle MySQL Server 5.5.44 and earlier, and 5.6.25 and earlier, allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to DML.
nvd
CVE-2021-21290P4MEDIUMCVSS 5.5v9.0v10.02021-02-08
CVE-2021-21290 [MEDIUM] CWE-378 CVE-2021-21290: Netty is an open-source, asynchronous event-driven network application framework for rapid developme
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty before version 4.1.59.Final there is a vulnerability on Unix-like systems involving an insecure temp file. When netty's multipart decoders are used local information disclosure c
nvd
CVE-2022-31085P4MEDIUMCVSS 6.1v11.02022-06-27
CVE-2022-31085 [MEDIUM] CWE-311 CVE-2022-31085: LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings)
LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 the session files include the LDAP user name and password in clear text if the PHP OpenSSL extension is not installed or encryption is disabled by configuration. This issue has been fixed in versi
nvd
CVE-2021-3504P4MEDIUMCVSS 5.4v9.02021-05-11
CVE-2021-3504 [MEDIUM] CWE-125 CVE-2021-3504: A flaw was found in the hivex library in versions before 1.3.20. It is caused due to a lack of bound
A flaw was found in the hivex library in versions before 1.3.20. It is caused due to a lack of bounds check within the hivex_open function. An attacker could input a specially crafted Windows Registry (hive) file which would cause hivex to read memory beyond its normal bounds or cause the program to crash. The highest threat from this vulnerability is
nvd
CVE-2019-12497P4MEDIUMCVSS 5.3v8.02019-06-17
CVE-2019-12497 [MEDIUM] CWE-200 CVE-2019-12497: An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.8, Community Edition
An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.8, Community Edition 6.0.x through 6.0.19, and Community Edition 5.0.x through 5.0.36. In the customer or external frontend, personal information of agents (e.g., Name and mail address) can be disclosed in external notes.
nvd
CVE-2020-6394P4MEDIUMCVSS 5.4v9.0v10.02020-02-11
CVE-2020-6394 [MEDIUM] CVE-2020-6394: Insufficient policy enforcement in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote att
Insufficient policy enforcement in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass content security policy via a crafted HTML page.
nvd
CVE-2024-4769P4MEDIUMCVSS 5.9v10.02024-05-14
CVE-2024-4769 [MEDIUM] CWE-351 CVE-2024-4769: When importing resources using Web Workers, error messages would distinguish the difference between
When importing resources using Web Workers, error messages would distinguish the difference between `application/javascript` responses and non-script responses. This could have been abused to learn information cross-origin. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
nvd
CVE-2021-3475P4MEDIUMCVSS 5.3v9.0v10.02021-03-30
CVE-2021-3475 [MEDIUM] CWE-190 CVE-2021-3475: There is a flaw in OpenEXR in versions before 3.0.0-beta. An attacker who can submit a crafted file
There is a flaw in OpenEXR in versions before 3.0.0-beta. An attacker who can submit a crafted file to be processed by OpenEXR could cause an integer overflow, potentially leading to problems with application availability.
nvd
CVE-2017-7829P4MEDIUMCVSS 5.3v7.0v8.0+1 more2018-06-11
CVE-2017-7829 [MEDIUM] CWE-20 CVE-2017-7829: It is possible to spoof the sender's email address and display an arbitrary sender address to the em
It is possible to spoof the sender's email address and display an arbitrary sender address to the email recipient. The real sender's address is not displayed if preceded by a null character in the display string. This vulnerability affects Thunderbird < 52.5.2.
nvd
CVE-2020-11025P4MEDIUMCVSS 5.4v9.0v10.02020-04-30
CVE-2020-11025 [MEDIUM] CWE-79 CVE-2020-11025: In affected versions of WordPress, a cross-site scripting (XSS) vulnerability in the navigation sect
In affected versions of WordPress, a cross-site scripting (XSS) vulnerability in the navigation section of Customizer allows JavaScript code to be executed. Exploitation requires an authenticated user. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.1
nvd
CVE-2020-14556P4MEDIUMCVSS 4.8v9.0v10.02020-07-15
CVE-2020-14556 [MEDIUM] CVE-2020-14556: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Sup
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful
nvd
CVE-2021-39201P4MEDIUMCVSS 5.4v10.0v11.02021-09-09
CVE-2021-39201 [MEDIUM] CWE-79 CVE-2021-39201: WordPress is a free and open-source content management system written in PHP and paired with a MySQL
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. ### Impact The issue allows an authenticated but low-privileged user (like contributor/author) to execute XSS in the editor. This bypasses the restrictions imposed on users who do not have the permission to post `unfiltered_html`.
nvd
CVE-2018-10995P4MEDIUMCVSS 5.3v8.0v9.02018-05-30
CVE-2018-10995 [MEDIUM] CWE-20 CVE-2018-10995: SchedMD Slurm before 17.02.11 and 17.1x.x before 17.11.7 mishandles user names (aka user_name fields
SchedMD Slurm before 17.02.11 and 17.1x.x before 17.11.7 mishandles user names (aka user_name fields) and group ids (aka gid fields).
nvd
CVE-2010-0749P4MEDIUMCVSS 5.3v8.0v9.0+1 more2019-10-30
CVE-2010-0749 [MEDIUM] CWE-119 CVE-2010-0749: Transmission before 1.92 allows attackers to prevent download of a file by corrupted data during the
Transmission before 1.92 allows attackers to prevent download of a file by corrupted data during the endgame.
nvd
CVE-2020-2800P4MEDIUMCVSS 4.8v8.0v9.0+1 more2020-04-15
CVE-2020-2800 [MEDIUM] CVE-2020-2800: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Lightweight HTT
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Lightweight HTTP Server). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embed
nvd
CVE-2021-33515P4MEDIUMCVSS 4.8v10.02021-06-28
CVE-2021-33515 [MEDIUM] CWE-77 CVE-2021-33515: The submission service in Dovecot before 2.3.15 allows STARTTLS command injection in lib-smtp. Sensi
The submission service in Dovecot before 2.3.15 allows STARTTLS command injection in lib-smtp. Sensitive information can be redirected to an attacker-controlled address.
nvd
CVE-2020-36421P4MEDIUMCVSS 5.3v10.02021-07-19
CVE-2020-36421 [MEDIUM] CWE-203 CVE-2020-36421: An issue was discovered in Arm Mbed TLS before 2.23.0. Because of a side channel in modular exponent
An issue was discovered in Arm Mbed TLS before 2.23.0. Because of a side channel in modular exponentiation, an RSA private key used in a secure enclave could be disclosed.
nvd
CVE-2020-35480P4MEDIUMCVSS 5.3v9.0v10.02020-12-18
CVE-2020-35480 [MEDIUM] CWE-203 CVE-2020-35480: An issue was discovered in MediaWiki before 1.35.1. Missing users (accounts that don't exist) and hi
An issue was discovered in MediaWiki before 1.35.1. Missing users (accounts that don't exist) and hidden users (accounts that have been explicitly hidden due to being abusive, or similar) that the viewer cannot see are handled differently, exposing sensitive information about the hidden status to unprivileged viewers. This exists on various code pat
nvd
CVE-2020-1765P4MEDIUMCVSS 5.3v8.02020-01-10
CVE-2020-1765 [MEDIUM] CWE-472 CVE-2020-1765: An improper control of parameters allows the spoofing of the from fields of the following screens: A
An improper control of parameters allows the spoofing of the from fields of the following screens: AgentTicketCompose, AgentTicketForward, AgentTicketBounce and AgentTicketEmailOutbound. This issue affects: ((OTRS)) Community Edition 5.0.x version 5.0.39 and prior versions; 6.0.x version 6.0.24 and prior versions. OTRS 7.0.x version 7.0.13 and prior v
nvd
CVE-2016-0702P4MEDIUMCVSS 5.1v7.0v8.02016-03-03
CVE-2016-0702 [MEDIUM] CWE-200 CVE-2016-0702: The MOD_EXP_CTIME_COPY_FROM_PREBUF function in crypto/bn/bn_exp.c in OpenSSL 1.0.1 before 1.0.1s and
The MOD_EXP_CTIME_COPY_FROM_PREBUF function in crypto/bn/bn_exp.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g does not properly consider cache-bank access times during modular exponentiation, which makes it easier for local users to discover RSA keys by running a crafted application on the same Intel Sandy Bridge CPU core as a victim and le
nvd