Debian Linux vulnerabilities
9,955 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358
Vulnerabilities
Page 374 of 498
CVE-2004-1027P4MEDIUMCVSS 5.0v3.02005-03-01
CVE-2004-1027 [MEDIUM] CVE-2004-1027: Directory traversal vulnerability in the -x (extract) command line option in unarj allows remote att
Directory traversal vulnerability in the -x (extract) command line option in unarj allows remote attackers to overwrite arbitrary files via an arj archive with filenames that contain .. (dot dot) sequences.
nvd
CVE-2015-8537P4MEDIUMCVSS 5.3v8.02016-04-12
CVE-2015-8537 [MEDIUM] CWE-200 CVE-2015-8537: app/views/journals/index.builder in Redmine before 2.6.9, 3.0.x before 3.0.7, and 3.1.x before 3.1.3
app/views/journals/index.builder in Redmine before 2.6.9, 3.0.x before 3.0.7, and 3.1.x before 3.1.3 allows remote attackers to obtain sensitive information by viewing an Atom feed.
nvd
CVE-2015-8346P4MEDIUMCVSS 5.3v8.02016-04-12
CVE-2015-8346 [MEDIUM] CWE-199 CVE-2015-8346: app/views/timelog/_form.html.erb in Redmine before 2.6.8, 3.0.x before 3.0.6, and 3.1.x before 3.1.2
app/views/timelog/_form.html.erb in Redmine before 2.6.8, 3.0.x before 3.0.6, and 3.1.x before 3.1.2 allows remote attackers to obtain sensitive information about subjects of issues by viewing the time logging form.
nvd
CVE-2024-46544P4MEDIUMCVSS 5.9v11.02024-09-23
CVE-2024-46544 [MEDIUM] CWE-276 CVE-2024-46544: Incorrect Default Permissions vulnerability in Apache Tomcat Connectors allows local users to view a
Incorrect Default Permissions vulnerability in Apache Tomcat Connectors allows local users to view and modify shared memory containing mod_jk configuration which may lead to information disclosure and/or denial of service.
This issue affects Apache Tomcat Connectors: from 1.2.9-beta through 1.2.49. Only mod_jk on Unix like systems is affected. Neit
nvd
CVE-2021-0129P4MEDIUMCVSS 5.7v9.02021-06-09
CVE-2021-0129 [MEDIUM] CVE-2021-0129: Improper access control in BlueZ may allow an authenticated user to potentially enable information d
Improper access control in BlueZ may allow an authenticated user to potentially enable information disclosure via adjacent access.
nvd
CVE-2021-32435P4MEDIUMCVSS 5.5v9.02022-03-10
CVE-2021-32435 [MEDIUM] CWE-787 CVE-2021-32435: Stack-based buffer overflow in the function get_key in parse.c of abcm2ps v8.14.11 allows remote att
Stack-based buffer overflow in the function get_key in parse.c of abcm2ps v8.14.11 allows remote attackers to cause a Denial of Service (DoS) via unspecified vectors.
nvd
CVE-2019-15587P4MEDIUMCVSS 5.4v9.0v10.02019-10-22
CVE-2019-15587 [MEDIUM] CWE-79 CVE-2019-15587: In the Loofah gem for Ruby through v2.3.0 unsanitized JavaScript may occur in sanitized output when
In the Loofah gem for Ruby through v2.3.0 unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.
nvd
CVE-2022-39253P4MEDIUMCVSS 5.5v10.02022-10-19
CVE-2022-39253 [MEDIUM] CWE-200 CVE-2022-39253: Git is an open source, scalable, distributed revision control system. Versions prior to 2.30.6, 2.31
Git is an open source, scalable, distributed revision control system. Versions prior to 2.30.6, 2.31.5, 2.32.4, 2.33.5, 2.34.5, 2.35.5, 2.36.3, and 2.37.4 are subject to exposure of sensitive information to a malicious actor. When performing a local clone (where the source and target of the clone are on the same volume), Git copies the contents of t
nvd
CVE-2018-3837P4MEDIUMCVSS 5.5v8.0v9.02018-04-10
CVE-2018-3837 [MEDIUM] CWE-125 CVE-2018-3837: An exploitable information disclosure vulnerability exists in the PCX image rendering functionality
An exploitable information disclosure vulnerability exists in the PCX image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A specially crafted PCX image can cause an out-of-bounds read on the heap, resulting in information disclosure . An attacker can display a specially crafted image to trigger this vulnerability.
nvd
CVE-2019-14275P4MEDIUMCVSS 5.5v8.02019-07-26
CVE-2019-14275 [MEDIUM] CWE-787 CVE-2019-14275: Xfig fig2dev 3.2.7a has a stack-based buffer overflow in the calc_arrow function in bound.c.
Xfig fig2dev 3.2.7a has a stack-based buffer overflow in the calc_arrow function in bound.c.
nvd
CVE-2020-11088P4MEDIUMCVSS 5.4v10.02020-05-29
CVE-2020-11088 [MEDIUM] CWE-125 CVE-2020-11088: In FreeRDP less than or equal to 2.0.0, there is an out-of-bound read in ntlm_read_NegotiateMessage.
In FreeRDP less than or equal to 2.0.0, there is an out-of-bound read in ntlm_read_NegotiateMessage. This has been fixed in 2.1.0.
nvd
CVE-2018-3081P4MEDIUMCVSS 5.0v8.0v9.02018-07-18
CVE-2018-3081 [MEDIUM] CVE-2018-3081: Vulnerability in the MySQL Client component of Oracle MySQL (subcomponent: Client programs). Support
Vulnerability in the MySQL Client component of Oracle MySQL (subcomponent: Client programs). Supported versions that are affected are 5.5.60 and prior, 5.6.40 and prior, 5.7.22 and prior and 8.0.11 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Client. Successful att
nvd
CVE-2020-11087P4MEDIUMCVSS 5.4v10.02020-05-29
CVE-2020-11087 [MEDIUM] CWE-125 CVE-2020-11087: In FreeRDP less than or equal to 2.0.0, there is an out-of-bound read in ntlm_read_AuthenticateMessa
In FreeRDP less than or equal to 2.0.0, there is an out-of-bound read in ntlm_read_AuthenticateMessage. This has been fixed in 2.1.0.
nvd
CVE-2016-2178P4MEDIUMCVSS 5.5v8.02016-06-20
CVE-2016-2178 [MEDIUM] CWE-203 CVE-2016-2178: The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ens
The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of constant-time operations, which makes it easier for local users to discover a DSA private key via a timing side-channel attack.
nvd
CVE-2020-11089P4MEDIUMCVSS 5.5v10.02020-05-29
CVE-2020-11089 [MEDIUM] CWE-125 CVE-2020-11089: In FreeRDP before 2.1.0, there is an out-of-bound read in irp functions (parallel_process_irp_create
In FreeRDP before 2.1.0, there is an out-of-bound read in irp functions (parallel_process_irp_create, serial_process_irp_create, drive_process_irp_write, printer_process_irp_write, rdpei_recv_pdu, serial_process_irp_write). This has been fixed in 2.1.0.
nvd
CVE-2022-25375P4MEDIUMCVSS 5.5v9.0v10.0+1 more2022-02-20
CVE-2022-25375 [MEDIUM] CWE-1284 CVE-2022-25375: An issue was discovered in drivers/usb/gadget/function/rndis.c in the Linux kernel before 5.16.10. T
An issue was discovered in drivers/usb/gadget/function/rndis.c in the Linux kernel before 5.16.10. The RNDIS USB gadget lacks validation of the size of the RNDIS_MSG_SET command. Attackers can obtain sensitive information from kernel memory.
nvd
CVE-2017-0368P4MEDIUMCVSS 5.3v7.02018-04-13
CVE-2017-0368 [MEDIUM] CWE-20 CVE-2017-0368: Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw making rawHTML mode apply to system messa
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw making rawHTML mode apply to system messages.
nvd
CVE-2020-9359P4MEDIUMCVSS 5.3v8.02020-03-24
CVE-2020-9359 [MEDIUM] CVE-2020-9359: KDE Okular before 1.10.0 allows code execution via an action link in a PDF document.
KDE Okular before 1.10.0 allows code execution via an action link in a PDF document.
nvd
CVE-2014-1935P4MEDIUMCVSS 5.3v8.0v9.0+1 more2019-11-21
CVE-2014-1935 [MEDIUM] CWE-20 CVE-2014-1935: 9base 1:6-6 and 1:6-7 insecurely creates temporary files which results in predictable filenames.
9base 1:6-6 and 1:6-7 insecurely creates temporary files which results in predictable filenames.
nvd
CVE-2019-11579P4MEDIUMCVSS 5.3v8.02019-04-28
CVE-2019-11579 [MEDIUM] CWE-125 CVE-2019-11579: dhcp.c in dhcpcd before 7.2.1 contains a 1-byte read overflow with DHO_OPTSOVERLOADED.
dhcp.c in dhcpcd before 7.2.1 contains a 1-byte read overflow with DHO_OPTSOVERLOADED.
nvd