Debian Linux vulnerabilities
9,955 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358
Vulnerabilities
Page 362 of 498
CVE-2022-46391P4MEDIUMCVSS 6.1v10.02022-12-04
CVE-2022-46391 [MEDIUM] CWE-79 CVE-2022-46391: AWStats 7.x through 7.8 allows XSS in the hostinfo plugin due to printing a response from Net::XWhoi
AWStats 7.x through 7.8 allows XSS in the hostinfo plugin due to printing a response from Net::XWhois without proper checks.
nvd
CVE-2023-47272P4MEDIUMCVSS 6.1v10.0v11.0+1 more2023-11-06
CVE-2023-47272 [MEDIUM] CWE-79 CVE-2023-47272: Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposi
Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposition header (used for attachment preview or download).
nvd
CVE-2017-5408P4MEDIUMCVSS 5.3v8.02018-06-11
CVE-2017-5408 [MEDIUM] CWE-200 CVE-2017-5408: Video files loaded video captions cross-origin without checking for the presence of CORS headers per
Video files loaded video captions cross-origin without checking for the presence of CORS headers permitting such cross-origin use, leading to potential information disclosure for video captions. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
nvd
CVE-2017-5405P4MEDIUMCVSS 5.3v8.02018-06-11
CVE-2017-5405 [MEDIUM] CWE-1187 CVE-2017-5405: Certain response codes in FTP connections can result in the use of uninitialized values for ports in
Certain response codes in FTP connections can result in the use of uninitialized values for ports in FTP operations. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
nvd
CVE-2022-0530P4MEDIUMCVSS 5.5v10.0v11.02022-02-09
CVE-2022-0530 [MEDIUM] CVE-2022-0530: A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a loca
A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.
nvd
CVE-2016-3992P4MEDIUMCVSS 6.2v7.0v8.02016-07-26
CVE-2016-3992 [MEDIUM] CWE-284 CVE-2016-3992: cronic before 3 allows local users to write to arbitrary files via a symlink attack on a (1) cronic.
cronic before 3 allows local users to write to arbitrary files via a symlink attack on a (1) cronic.out.$$, (2) cronic.err.$$, or (3) cronic.trace.$$ file in /tmp.
nvd
CVE-2017-5975P4MEDIUMCVSS 5.5v8.0v9.02017-03-01
CVE-2017-5975 [MEDIUM] CWE-787 CVE-2017-5975: Heap-based buffer overflow in the __zzip_get64 function in fetch.c in zziplib 0.13.62, 0.13.61, 0.13
Heap-based buffer overflow in the __zzip_get64 function in fetch.c in zziplib 0.13.62, 0.13.61, 0.13.60, 0.13.59, 0.13.58, 0.13.57, 0.13.56 allows remote attackers to cause a denial of service (crash) via a crafted ZIP file.
nvd
CVE-2022-1355P4MEDIUMCVSS 6.1v10.0v11.02022-08-31
CVE-2022-1355 [MEDIUM] CWE-121 CVE-2022-1355: A stack buffer overflow flaw was found in Libtiffs' tiffcp.c in main() function. This flaw allows an
A stack buffer overflow flaw was found in Libtiffs' tiffcp.c in main() function. This flaw allows an attacker to pass a crafted TIFF file to the tiffcp tool, triggering a stack buffer overflow issue, possibly corrupting the memory, and causing a crash that leads to a denial of service.
nvd
CVE-2024-50602P4MEDIUMCVSS 5.9v11.02024-10-27
CVE-2024-50602 [MEDIUM] CWE-754 CVE-2024-50602: An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser funct
An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser function because XML_StopParser can stop/suspend an unstarted parser.
nvd
CVE-2017-5976P4MEDIUMCVSS 5.5v8.0v9.02017-03-01
CVE-2017-5976 [MEDIUM] CWE-787 CVE-2017-5976: Heap-based buffer overflow in the zzip_mem_entry_extra_block function in memdisk.c in zziplib 0.13.6
Heap-based buffer overflow in the zzip_mem_entry_extra_block function in memdisk.c in zziplib 0.13.62, 0.13.61, 0.13.60, 0.13.59, 0.13.58, 0.13.57, 0.13.56 allows remote attackers to cause a denial of service (crash) via a crafted ZIP file.
nvd
CVE-2005-0206P4HIGHCVSS 7.5v3.02005-04-27
CVE-2005-0206 [HIGH] CVE-2005-0206: The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for
The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities.
nvd
CVE-2002-1372P4HIGHCVSS 7.5v2.2v3.02002-12-26
CVE-2002-1372 [HIGH] CWE-252 CVE-2002-1372: Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly check the return values o
Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly check the return values of various file and socket operations, which could allow a remote attacker to cause a denial of service (resource exhaustion) by causing file descriptors to be assigned and not released, as demonstrated by fanta.
nvd
CVE-2014-8594P4MEDIUMCVSS 5.4v7.02014-11-19
CVE-2014-8594 [MEDIUM] CWE-20 CVE-2014-8594: The do_mmu_update function in arch/x86/mm.c in Xen 4.x through 4.4.x does not properly restrict upda
The do_mmu_update function in arch/x86/mm.c in Xen 4.x through 4.4.x does not properly restrict updates to only PV page tables, which allows remote PV guests to cause a denial of service (NULL pointer dereference) by leveraging hardware emulation services for HVM guests using Hardware Assisted Paging (HAP).
nvd
CVE-2013-2255P4MEDIUMCVSS 5.9v8.0v9.0+1 more2019-11-01
CVE-2013-2255 [MEDIUM] CWE-295 CVE-2013-2255: HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack
HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to validate server-side SSL certificates.
nvd
CVE-2013-4449P4MEDIUMCVSS 4.3v7.0v8.02014-02-05
CVE-2013-4449 [MEDIUM] CWE-189 CVE-2013-4449: The rwm overlay in OpenLDAP 2.4.23, 2.4.36, and earlier does not properly count references, which al
The rwm overlay in OpenLDAP 2.4.23, 2.4.36, and earlier does not properly count references, which allows remote attackers to cause a denial of service (slapd crash) by unbinding immediately after a search request, which triggers rwm_conn_destroy to free the session context while it is being used by rwm_op_search.
nvd
CVE-2018-5117P4MEDIUMCVSS 5.3v7.0v8.0+1 more2018-06-11
CVE-2018-5117 [MEDIUM] CVE-2018-5117: If right-to-left text is used in the addressbar with left-to-right alignment, it is possible in some
If right-to-left text is used in the addressbar with left-to-right alignment, it is possible in some circumstances to scroll this text to spoof the displayed URL. This issue could result in the wrong URL being displayed as a location, which can mislead users to believe they are on a different site than the one loaded. This vulnerability affects Thunderbird <
nvd
CVE-2018-5168P4MEDIUMCVSS 5.3v7.0v8.0+1 more2018-06-11
CVE-2018-5168 [MEDIUM] CVE-2018-5168: Sites can bypass security checks on permissions to install lightweight themes by manipulating the "b
Sites can bypass security checks on permissions to install lightweight themes by manipulating the "baseURI" property of the theme element. This could allow a malicious site to install a theme without user interaction which could contain offensive or embarrassing images. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and F
nvd
CVE-2016-9189P4MEDIUMCVSS 5.5v8.02016-11-04
CVE-2016-9189 [MEDIUM] CWE-190 CVE-2016-9189: Pillow before 3.3.2 allows context-dependent attackers to obtain sensitive information by using the
Pillow before 3.3.2 allows context-dependent attackers to obtain sensitive information by using the "crafted image file" approach, related to an "Integer Overflow" issue affecting the Image.core.map_buffer in map.c component.
nvd
CVE-2017-5974P4MEDIUMCVSS 5.5v8.0v9.02017-03-01
CVE-2017-5974 [MEDIUM] CWE-119 CVE-2017-5974: Heap-based buffer overflow in the __zzip_get32 function in fetch.c in zziplib 0.13.62, 0.13.61, 0.13
Heap-based buffer overflow in the __zzip_get32 function in fetch.c in zziplib 0.13.62, 0.13.61, 0.13.60, 0.13.59, 0.13.58, 0.13.57, 0.13.56 allows remote attackers to cause a denial of service (crash) via a crafted ZIP file.
nvd
CVE-2025-63498P4MEDIUMCVSS 6.1v11.02025-11-24
CVE-2025-63498 [MEDIUM] CWE-79 CVE-2025-63498: alinto SOGo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the "userName" parameter.
alinto SOGo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the "userName" parameter.
nvd