cbcvebase.

Debian Linux vulnerabilities

9,955 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358

Vulnerabilities

Page 375 of 498
CVE-2017-3142P4LOWCVSS 3.7v8.0v9.02019-01-16
CVE-2017-3142 [LOW] CWE-20 CVE-2017-3142: An attacker who is able to send and receive messages to an authoritative DNS server and who has know An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name may be able to circumvent TSIG authentication of AXFR requests via a carefully constructed request packet. A server that relies solely on TSIG keys for protection with no other ACL protection could be manipulated into: providi
nvd
CVE-2015-7762P4MEDIUMCVSS 5.0v7.0v8.02015-11-06
CVE-2015-7762 [MEDIUM] CWE-200 CVE-2015-7762: rx/rx.c in OpenAFS before 1.6.15 and 1.7.x before 1.7.33 does not properly initialize the padding of rx/rx.c in OpenAFS before 1.6.15 and 1.7.x before 1.7.33 does not properly initialize the padding of a data structure when constructing an Rx acknowledgement (ACK) packet, which allows remote attackers to obtain sensitive information by (1) conducting a replay attack or (2) sniffing the network.
nvd
CVE-2018-3665P4MEDIUMCVSS 5.6v8.0v9.02018-06-21
CVE-2018-3665 [MEDIUM] CWE-200 CVE-2018-3665: System software utilizing Lazy FP state restore technique on systems using Intel Core-based micropro System software utilizing Lazy FP state restore technique on systems using Intel Core-based microprocessors may potentially allow a local process to infer data from another process through a speculative execution side channel.
nvd
CVE-2021-32862P4MEDIUMCVSS 5.4v10.02022-08-18
CVE-2021-32862 [MEDIUM] CWE-79 CVE-2021-32862: The GitHub Security Lab discovered sixteen ways to exploit a cross-site scripting vulnerability in n The GitHub Security Lab discovered sixteen ways to exploit a cross-site scripting vulnerability in nbconvert. When using nbconvert to generate an HTML version of a user-controllable notebook, it is possible to inject arbitrary HTML which may lead to cross-site scripting (XSS) vulnerabilities if these HTML notebooks are served by a web server (eg: nbv
nvd
CVE-2022-26874P4MEDIUMCVSS 5.4v9.0v10.02022-03-11
CVE-2022-26874 [MEDIUM] CWE-79 CVE-2022-26874: lib/Horde/Mime/Viewer/Ooo.php in Horde Mime_Viewer before 2.2.4 allows XSS via an OpenOffice documen lib/Horde/Mime/Viewer/Ooo.php in Horde Mime_Viewer before 2.2.4 allows XSS via an OpenOffice document, leading to account takeover in Horde Groupware Webmail Edition. This occurs after XSLT rendering.
nvd
CVE-2018-10060P4MEDIUMCVSS 5.4v9.02018-04-12
CVE-2018-10060 [MEDIUM] CWE-79 CVE-2018-10060: Cacti before 1.1.37 has XSS because it does not properly reject unintended characters, related to us Cacti before 1.1.37 has XSS because it does not properly reject unintended characters, related to use of the sanitize_uri function in lib/functions.php.
nvd
CVE-2011-2207P4MEDIUMCVSS 5.3v8.02019-11-27
CVE-2011-2207 [MEDIUM] CWE-295 CVE-2011-2207: dirmngr before 2.1.0 improperly handles certain system calls, which allows remote attackers to cause dirmngr before 2.1.0 improperly handles certain system calls, which allows remote attackers to cause a denial of service (DOS) via a specially-crafted certificate.
nvd
CVE-2016-9646P4MEDIUMCVSS 5.3v7.0v8.0+1 more2018-04-13
CVE-2016-9646 [MEDIUM] CWE-287 CVE-2016-9646: ikiwiki before 3.20161229 incorrectly called the CGI::FormBuilder->field method (similar to the CGI- ikiwiki before 3.20161229 incorrectly called the CGI::FormBuilder->field method (similar to the CGI->param API that led to Bugzilla's CVE-2014-1572), which can be abused to lead to commit metadata forgery.
nvd
CVE-2018-10846P4MEDIUMCVSS 5.6v8.02018-08-22
CVE-2018-10846 [MEDIUM] CWE-385 CVE-2018-10846: A cache-based side channel in GnuTLS implementation that leads to plain text recovery in cross-VM at A cache-based side channel in GnuTLS implementation that leads to plain text recovery in cross-VM attack setting was found. An attacker could use a combination of "Just in Time" Prime+probe attack in combination with Lucky-13 attack to recover plain text using crafted packets.
nvd
CVE-2021-31865P4MEDIUMCVSS 5.3v9.02021-04-28
CVE-2021-31865 [MEDIUM] CVE-2021-31865: Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows users to circumvent the allo Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows users to circumvent the allowed filename extensions of uploaded attachments.
nvd
CVE-2016-1692P4MEDIUMCVSS 5.3v8.02016-06-05
CVE-2016-1692 [MEDIUM] CWE-284 CVE-2016-1692: WebKit/Source/core/css/StyleSheetContents.cpp in Blink, as used in Google Chrome before 51.0.2704.63 WebKit/Source/core/css/StyleSheetContents.cpp in Blink, as used in Google Chrome before 51.0.2704.63, permits cross-origin loading of CSS stylesheets by a ServiceWorker even when the stylesheet download has an incorrect MIME type, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.
nvd
CVE-2018-25047P4MEDIUMCVSS 5.4v10.02022-09-15
CVE-2018-25047 [MEDIUM] CWE-79 CVE-2018-25047: In Smarty before 3.1.47 and 4.x before 4.2.1, libs/plugins/function.mailto.php allows XSS. A web pag In Smarty before 3.1.47 and 4.x before 4.2.1, libs/plugins/function.mailto.php allows XSS. A web page that uses smarty_function_mailto, and that could be parameterized using GET or POST input parameters, could allow injection of JavaScript code by a user.
nvd
CVE-2016-7056P4MEDIUMCVSS 5.5v8.0v9.02018-09-10
CVE-2016-7056 [MEDIUM] CWE-385 CVE-2016-7056: A timing attack flaw was found in OpenSSL 1.0.1u and before that could allow a malicious user with l A timing attack flaw was found in OpenSSL 1.0.1u and before that could allow a malicious user with local access to recover ECDSA P-256 private keys.
nvd
CVE-2022-31628P4MEDIUMCVSS 5.5v10.0v11.02022-09-28
CVE-2022-31628 [MEDIUM] CWE-674 CVE-2022-31628: In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code would recursively uncom In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code would recursively uncompress "quines" gzip files, resulting in an infinite loop.
nvd
CVE-2023-27539P4MEDIUMCVSS 5.3v10.0v11.02025-01-09
CVE-2023-27539 [MEDIUM] CVE-2023-27539: There is a denial of service vulnerability in the header parsing component of Rack. There is a denial of service vulnerability in the header parsing component of Rack.
nvd
CVE-2018-16862P4MEDIUMCVSS 5.5v8.02018-11-26
CVE-2018-16862 [MEDIUM] CWE-200 CVE-2018-16862: A security flaw was found in the Linux kernel in a way that the cleancache subsystem clears an inode A security flaw was found in the Linux kernel in a way that the cleancache subsystem clears an inode after the final file truncation (removal). The new file created with the same inode may contain leftover pages from cleancache and the old file data instead of the new one.
nvd
CVE-2016-1694P4MEDIUMCVSS 5.3v8.02016-06-05
CVE-2016-1694 [MEDIUM] CWE-284 CVE-2016-1694: browser/browsing_data/browsing_data_remover.cc in Google Chrome before 51.0.2704.63 deletes HPKP pin browser/browsing_data/browsing_data_remover.cc in Google Chrome before 51.0.2704.63 deletes HPKP pins during cache clearing, which makes it easier for remote attackers to spoof web sites via a valid certificate from an arbitrary recognized Certification Authority.
nvd
CVE-2022-41946P4MEDIUMCVSS 5.5v10.02022-11-23
CVE-2022-41946 [MEDIUM] CWE-200 CVE-2022-41946: pgjdbc is an open source postgresql JDBC Driver. In affected versions a prepared statement using eit pgjdbc is an open source postgresql JDBC Driver. In affected versions a prepared statement using either `PreparedStatement.setText(int, InputStream)` or `PreparedStatemet.setBytea(int, InputStream)` will create a temporary file if the InputStream is larger than 2k. This will create a temporary file which is readable by other users on Unix like syste
nvd
CVE-2020-36308P4MEDIUMCVSS 5.3v9.02021-04-06
CVE-2020-36308 [MEDIUM] CWE-74 CVE-2020-36308: Redmine before 4.0.7 and 4.1.x before 4.1.1 allows attackers to discover the subject of a non-visibl Redmine before 4.0.7 and 4.1.x before 4.1.1 allows attackers to discover the subject of a non-visible issue by performing a CSV export and reading time entries.
nvd
CVE-2020-5202P4MEDIUMCVSS 5.5v8.0v9.0+1 more2020-01-21
CVE-2020-5202 [MEDIUM] CVE-2020-5202: apt-cacher-ng through 3.3 allows local users to obtain sensitive information by hijacking the hardco apt-cacher-ng through 3.3 allows local users to obtain sensitive information by hijacking the hardcoded TCP port. The /usr/lib/apt-cacher-ng/acngtool program attempts to connect to apt-cacher-ng via TCP on localhost port 3142, even if the explicit SocketPath=/var/run/apt-cacher-ng/socket command-line option is passed. The cron job /etc/cron.daily/apt-cacher-n
nvd
Debian Linux vulnerabilities | cvebase