Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 36 of 498
CVE-2022-32215P3MEDIUMCVSS 6.5v11.02022-07-14
CVE-2022-32215 [MEDIUM] CWE-444 CVE-2022-32215: The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding headers. This can lead to HTTP Request Smuggling (HRS).
nvd
CVE-2018-17082P3MEDIUMCVSS 6.1PoCv8.0v9.02018-09-16
CVE-2018-17082 [MEDIUM] CWE-79 CVE-2018-17082: The Apache2 component in PHP before 5.6.38, 7.0.x before 7.0.32, 7.1.x before 7.1.22, and 7.2.x befo
The Apache2 component in PHP before 5.6.38, 7.0.x before 7.0.32, 7.1.x before 7.1.22, and 7.2.x before 7.2.10 allows XSS via the body of a "Transfer-Encoding: chunked" request, because the bucket brigade is mishandled in the php_handler function in sapi/apache2handler/sapi_apache2.c.
nvd
CVE-2018-15126P3CRITICALCVSS 9.8v8.0v9.02018-12-19
CVE-2018-15126 [CRITICAL] CWE-416 CVE-2018-15126: LibVNC before commit 73cb96fec028a576a5a24417b57723b55854ad7b contains heap use-after-free vulnerabi
LibVNC before commit 73cb96fec028a576a5a24417b57723b55854ad7b contains heap use-after-free vulnerability in server code of file transfer extension that can result remote code execution
nvd
CVE-2013-1861P3MEDIUMCVSS 5.0PoCv7.02013-03-28
CVE-2013-1861 [MEDIUM] CWE-119 CVE-2013-1861: MariaDB 5.5.x before 5.5.30, 5.3.x before 5.3.13, 5.2.x before 5.2.15, and 5.1.x before 5.1.68, and
MariaDB 5.5.x before 5.5.30, 5.3.x before 5.3.13, 5.2.x before 5.2.15, and 5.1.x before 5.1.68, and Oracle MySQL 5.1.69 and earlier, 5.5.31 and earlier, and 5.6.11 and earlier allows remote attackers to cause a denial of service (crash) via a crafted geometry feature that specifies a large number of points, which is not properly handled when processing
nvd
CVE-2017-0916P3CRITICALCVSS 9.8v9.02018-03-21
CVE-2017-0916 [CRITICAL] CWE-77 CVE-2017-0916: Gitlab Community Edition version 10.3 is vulnerable to a lack of input validation in the system_hook
Gitlab Community Edition version 10.3 is vulnerable to a lack of input validation in the system_hook_push queue through web hook component resulting in remote code execution.
nvd
CVE-2019-10160P3CRITICALCVSS 9.8v8.0v9.02019-06-07
CVE-2019-10160 [CRITICAL] CWE-172 CVE-2019-10160: A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f2624
A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7, 3.5, 3.6, 3.7 and from v3.8.0a4 through v3.8.0b1, which still allows an attacker to exploit CVE-2019-9636 by abusing the user and password parts of a URL. When an application parses user-supplied URLs to sto
nvd
CVE-2014-5266P3MEDIUMCVSS 5.0PoCv7.02014-08-18
CVE-2014-5266 [MEDIUM] CVE-2014-5266: The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and
The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, does not limit the number of elements in an XML document, which allows remote attackers to cause a denial of service (CPU consumption) via a large document, a different vulnerability than CVE-2014-5265.
nvd
CVE-2023-23969P3HIGHCVSS 7.5v10.02023-02-01
CVE-2023-23969 [HIGH] CWE-770 CVE-2023-23969: In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, the parsed values of Accept-Lan
In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, the parsed values of Accept-Language headers are cached in order to avoid repetitive parsing. This leads to a potential denial-of-service vector via excessive memory usage if the raw value of Accept-Language headers is very large.
nvd
CVE-2023-3215P3HIGHCVSS 8.8v11.0v12.02023-06-13
CVE-2023-3215 [HIGH] CWE-416 CVE-2023-3215: Use after free in WebRTC in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to poten
Use after free in WebRTC in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2020-8159P3CRITICALCVSS 9.8v9.02020-05-12
CVE-2020-8159 [CRITICAL] CWE-22 CVE-2020-8159: There is a vulnerability in actionpack_page-caching gem < v1.2.1 that allows an attacker to write ar
There is a vulnerability in actionpack_page-caching gem < v1.2.1 that allows an attacker to write arbitrary files to a web server, potentially resulting in remote code execution if the attacker can write unescaped ERB to a view.
nvd
CVE-2018-14618P3CRITICALCVSS 9.8v9.02018-09-05
CVE-2018-14618 [CRITICAL] CVE-2018-14618: curl before version 7.61.1 is vulnerable to a buffer overrun in the NTLM authentication code. The in
curl before version 7.61.1 is vulnerable to a buffer overrun in the NTLM authentication code. The internal function Curl_ntlm_core_mk_nt_hash multiplies the length of the password by two (SUM) to figure out how large temporary storage area to allocate from the heap. The length value is then subsequently used to iterate over the password and generate outpu
nvd
CVE-2025-47273P2HIGHCVSS 8.8v11.02025-05-17
CVE-2025-47273 [HIGH] CWE-22 CVE-2025-47273: setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python
setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code
nvd
CVE-2023-3217P3HIGHCVSS 8.8v11.0v12.02023-06-13
CVE-2023-3217 [HIGH] CWE-416 CVE-2023-3217: Use after free in WebXR in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potent
Use after free in WebXR in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2016-9603P3CRITICALCVSS 9.9v7.02018-07-27
CVE-2016-9603 [CRITICAL] CWE-122 CVE-2016-9603: A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA emulator's VNC display driver s
A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA emulator's VNC display driver support before 2.9; the issue could occur when a VNC client attempted to update its display after a VGA operation is performed by a guest. A privileged user/process inside a guest could use this flaw to crash the QEMU process or, potentially, execute a
nvd
CVE-2020-17525P3HIGHCVSS 7.5v9.02021-03-17
CVE-2020-17525 [HIGH] CWE-476 CVE-2020-17525: Subversion's mod_authz_svn module will crash if the server is using in-repository authz rules with t
Subversion's mod_authz_svn module will crash if the server is using in-repository authz rules with the AuthzSVNReposRelativeAccessFile option and a client sends a request for a non-existing repository URL. This can lead to disruption for users of the service. This issue was fixed in mod_dav_svn+mod_authz_svn servers 1.14.1 and mod_dav_svn+mod_authz_sv
nvd
CVE-2017-9936P3MEDIUMCVSS 6.5PoCv8.0v9.0+1 more2017-06-26
CVE-2017-9936 [MEDIUM] CWE-772 CVE-2017-9936: In LibTIFF 4.0.8, there is a memory leak in tif_jbig.c. A crafted TIFF document can lead to a memory
In LibTIFF 4.0.8, there is a memory leak in tif_jbig.c. A crafted TIFF document can lead to a memory leak resulting in a remote denial of service attack.
nvd
CVE-2017-15120P3HIGHCVSS 7.5v8.0v9.02018-07-27
CVE-2017-15120 [HIGH] CWE-476 CVE-2017-15120: An issue has been found in the parsing of authoritative answers in PowerDNS Recursor before 4.0.8, l
An issue has been found in the parsing of authoritative answers in PowerDNS Recursor before 4.0.8, leading to a NULL pointer dereference when parsing a specially crafted answer containing a CNAME of a different class than IN. An unauthenticated remote attacker could cause a denial of service.
nvd
CVE-2017-8386P2HIGHCVSS 8.8v8.02017-06-01
CVE-2017-8386 [HIGH] CVE-2017-8386: git-shell in git before 2.4.12, 2.5.x before 2.5.6, 2.6.x before 2.6.7, 2.7.x before 2.7.5, 2.8.x be
git-shell in git before 2.4.12, 2.5.x before 2.5.6, 2.6.x before 2.6.7, 2.7.x before 2.7.5, 2.8.x before 2.8.5, 2.9.x before 2.9.4, 2.10.x before 2.10.3, 2.11.x before 2.11.2, and 2.12.x before 2.12.3 might allow remote authenticated users to gain privileges via a repository name that starts with a - (dash) character.
nvd
CVE-2021-44143P2CRITICALCVSS 9.8v9.0v10.0+1 more2021-11-22
CVE-2021-44143 [CRITICAL] CWE-787 CVE-2021-44143: A flaw was found in mbsync in isync 1.4.0 through 1.4.3. Due to an unchecked condition, a malicious
A flaw was found in mbsync in isync 1.4.0 through 1.4.3. Due to an unchecked condition, a malicious or compromised IMAP server could use a crafted mail message that lacks headers (i.e., one that starts with an empty line) to provoke a heap overflow, which could conceivably be exploited for remote code execution.
nvd
CVE-2018-1308P3HIGHCVSS 7.5v7.0v8.0+1 more2018-04-09
CVE-2018-1308 [HIGH] CWE-611 CVE-2018-1308: This vulnerability in Apache Solr 1.2 to 6.6.2 and 7.0.0 to 7.2.1 relates to an XML external entity
This vulnerability in Apache Solr 1.2 to 6.6.2 and 7.0.0 to 7.2.1 relates to an XML external entity expansion (XXE) in the `&dataConfig=` parameter of Solr's DataImportHandler. It can be used as XXE using file/ftp/http protocols in order to read arbitrary local files from the Solr server or the internal network.
nvd