cbcvebase.

Debian Linux vulnerabilities

9,955 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358

Vulnerabilities

Page 372 of 498
CVE-2021-46144P4MEDIUMCVSS 6.1v9.0v10.0+1 more2022-01-06
CVE-2021-46144 [MEDIUM] CWE-79 CVE-2021-46144: Roundcube before 1.4.13 and 1.5.x before 1.5.2 allows XSS via an HTML e-mail message with crafted Ca Roundcube before 1.4.13 and 1.5.x before 1.5.2 allows XSS via an HTML e-mail message with crafted Cascading Style Sheets (CSS) token sequences.
nvd
CVE-2020-13964P4MEDIUMCVSS 6.1v9.0v10.02020-06-09
CVE-2020-13964 [MEDIUM] CWE-79 CVE-2020-13964: An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. include/rcmail_ou An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. include/rcmail_output_html.php allows XSS via the username template object.
nvd
CVE-2018-14611P4MEDIUMCVSS 5.5v8.02018-07-27
CVE-2018-14611 [MEDIUM] CWE-416 CVE-2018-14611: An issue was discovered in the Linux kernel through 4.17.10. There is a use-after-free in try_merge_ An issue was discovered in the Linux kernel through 4.17.10. There is a use-after-free in try_merge_free_space() when mounting a crafted btrfs image, because of a lack of chunk type flag checks in btrfs_check_chunk_valid in fs/btrfs/volumes.c.
nvd
CVE-2013-1418P4MEDIUMCVSS 4.3v7.02013-11-18
CVE-2013-1418 [MEDIUM] CWE-476 CVE-2013-1418: The setup_server_realm function in main.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (ak The setup_server_realm function in main.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.10.7, when multiple realms are configured, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted request.
nvd
CVE-2022-23519P4MEDIUMCVSS 6.1v10.02022-12-14
CVE-2022-23519 [MEDIUM] CWE-79 CVE-2022-23519: rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Prior to ve rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Prior to version 1.4.4, a possible XSS vulnerability with certain configurations of Rails::Html::Sanitizer may allow an attacker to inject content if the application developer has overridden the sanitizer's allowed tags in either of the following ways: allow both
nvd
CVE-2018-3282P4MEDIUMCVSS 4.9v8.0v9.02018-10-17
CVE-2018-3282 [MEDIUM] CVE-2018-3282: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Storage Engines). Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Storage Engines). Supported versions that are affected are 5.5.61 and prior, 5.6.41 and prior, 5.7.23 and prior and 8.0.12 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successf
nvd
CVE-2017-16652P4MEDIUMCVSS 6.1v8.02018-06-13
CVE-2017-16652 [MEDIUM] CWE-601 CVE-2017-16652: An issue was discovered in Symfony 2.7.x before 2.7.38, 2.8.x before 2.8.31, 3.2.x before 3.2.14, an An issue was discovered in Symfony 2.7.x before 2.7.38, 2.8.x before 2.8.31, 3.2.x before 3.2.14, and 3.3.x before 3.3.13. DefaultAuthenticationSuccessHandler or DefaultAuthenticationFailureHandler takes the content of the _target_path parameter and generates a redirect response, but no check is performed on the path, which could be an absolute URL
nvd
CVE-2021-20303P4MEDIUMCVSS 6.1v10.02022-03-04
CVE-2021-20303 [MEDIUM] CWE-190 CVE-2021-20303: A flaw found in function dataWindowForTile() of IlmImf/ImfTiledMisc.cpp. An attacker who is able to A flaw found in function dataWindowForTile() of IlmImf/ImfTiledMisc.cpp. An attacker who is able to submit a crafted file to be processed by OpenEXR could trigger an integer overflow, leading to an out-of-bounds write on the heap. The greatest impact of this flaw is to application availability, with some potential impact to data integrity as well.
nvd
CVE-2022-23515P4MEDIUMCVSS 6.1v10.02022-12-14
CVE-2022-23515 [MEDIUM] CWE-79 CVE-2022-23515: Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, buil Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah >= 2.1.0, < 2.19.1 is vulnerable to cross-site scripting via the image/svg+xml media type in data URIs. This issue is patched in version 2.19.1.
nvd
CVE-2011-4968P4MEDIUMCVSS 4.8v8.02019-11-19
CVE-2011-4968 [MEDIUM] CWE-20 CVE-2011-4968: nginx http proxy module does not verify peer identity of https origin server which could facilitate nginx http proxy module does not verify peer identity of https origin server which could facilitate man-in-the-middle attack (MITM)
nvd
CVE-2020-36306P4MEDIUMCVSS 6.1v9.02021-04-06
CVE-2020-36306 [MEDIUM] CWE-79 CVE-2020-36306: Redmine before 4.0.7 and 4.1.x before 4.1.1 has XSS via the back_url field. Redmine before 4.0.7 and 4.1.x before 4.1.1 has XSS via the back_url field.
nvd
CVE-2020-36307P4MEDIUMCVSS 6.1v9.02021-04-06
CVE-2020-36307 [MEDIUM] CWE-79 CVE-2020-36307: Redmine before 4.0.7 and 4.1.x before 4.1.1 has stored XSS via textile inline links. Redmine before 4.0.7 and 4.1.x before 4.1.1 has stored XSS via textile inline links.
nvd
CVE-2018-2800P4MEDIUMCVSS 4.2v8.0v9.02018-04-19
CVE-2018-2800 [MEDIUM] CVE-2018-2800: Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: RMI). Supported ver Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 6u181, 7u171 and 8u162; JRockit: R28.3.17. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, JRockit. Successful attacks require human intera
nvd
CVE-2019-19813P4MEDIUMCVSS 5.5v9.02019-12-17
CVE-2019-19813 [MEDIUM] CWE-416 CVE-2019-19813: In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image, performing some operations, a In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in __mutex_lock in kernel/locking/mutex.c. This is related to mutex_can_spin_on_owner in kernel/locking/mutex.c, __btrfs_qgroup_free_meta in fs/btrfs/qgroup.c, and btrfs_insert_delayed_i
nvd
CVE-2014-3707P4MEDIUMCVSS 4.3v7.0v8.02014-11-15
CVE-2014-3707 [MEDIUM] CWE-200 CVE-2014-3707: The curl_easy_duphandle function in libcurl 7.17.1 through 7.38.0, when running with the CURLOPT_COP The curl_easy_duphandle function in libcurl 7.17.1 through 7.38.0, when running with the CURLOPT_COPYPOSTFIELDS option, does not properly copy HTTP POST data for an easy handle, which triggers an out-of-bounds read that allows remote web servers to read sensitive memory information.
nvd
CVE-2018-2818P4MEDIUMCVSS 4.9v7.0v8.02018-04-19
CVE-2018-2818 [MEDIUM] CVE-2018-2818: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server : Security : Privi Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server : Security : Privileges). Supported versions that are affected are 5.5.59 and prior, 5.6.39 and prior and 5.7.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks
nvd
CVE-2015-3439P4MEDIUMCVSS 4.3v7.0v8.02015-08-05
CVE-2015-3439 [MEDIUM] CWE-79 CVE-2015-3439: Cross-site scripting (XSS) vulnerability in the Ephox (formerly Moxiecode) plupload.flash.swf shim 2 Cross-site scripting (XSS) vulnerability in the Ephox (formerly Moxiecode) plupload.flash.swf shim 2.1.2 in Plupload, as used in WordPress 3.9.x, 4.0.x, and 4.1.x before 4.1.2 and other products, allows remote attackers to execute same-origin JavaScript functions via the target parameter, as demonstrated by executing a certain click function, related t
nvd
CVE-2015-2575P4MEDIUMCVSS 4.9v8.02015-04-16
CVE-2015-2575 [MEDIUM] CVE-2015-2575: Unspecified vulnerability in the MySQL Connectors component in Oracle MySQL 5.1.34 and earlier allow Unspecified vulnerability in the MySQL Connectors component in Oracle MySQL 5.1.34 and earlier allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Connector/J.
nvd
CVE-2018-16658P4MEDIUMCVSS 6.1v8.0v9.02018-09-07
CVE-2018-16658 [MEDIUM] CVE-2018-16658: An issue was discovered in the Linux kernel before 4.18.6. An information leak in cdrom_ioctl_drive_ An issue was discovered in the Linux kernel before 4.18.6. An information leak in cdrom_ioctl_drive_status in drivers/cdrom/cdrom.c could be used by local attackers to read kernel memory because a cast from unsigned long to int interferes with bounds checking. This is similar to CVE-2018-10940.
nvd
CVE-2019-6454P4MEDIUMCVSS 5.5v8.0v9.02019-03-21
CVE-2019-6454 [MEDIUM] CWE-787 CVE-2019-6454: An issue was discovered in sd-bus in systemd 239. bus_process_object() in libsystemd/sd-bus/bus-obje An issue was discovered in sd-bus in systemd 239. bus_process_object() in libsystemd/sd-bus/bus-objects.c allocates a variable-length stack buffer for temporarily storing the object path of incoming D-Bus messages. An unprivileged local user can exploit this by sending a specially crafted message to PID1, causing the stack pointer to jump over the sta
nvd
Debian Linux vulnerabilities | cvebase