cbcvebase.

Debian Linux vulnerabilities

9,955 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358

Vulnerabilities

Page 377 of 498
CVE-2017-8362P4MEDIUMCVSS 6.5v8.02017-04-30
CVE-2017-8362 [MEDIUM] CWE-125 CVE-2017-8362: The flac_buffer_copy function in flac.c in libsndfile 1.0.28 allows remote attackers to cause a deni The flac_buffer_copy function in flac.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted audio file.
nvd
CVE-2023-45364P4MEDIUMCVSS 5.3v11.0v12.02023-10-09
CVE-2023-45364 [MEDIUM] CWE-732 CVE-2023-45364: An issue was discovered in includes/page/Article.php in MediaWiki 1.36.x through 1.39.x before 1.39. An issue was discovered in includes/page/Article.php in MediaWiki 1.36.x through 1.39.x before 1.39.5 and 1.40.x before 1.40.1. Deleted revision existence is leaked due to incorrect permissions being checked. This reveals that a given revision ID belonged to the given page title, and its timestamp, both of which are not supposed to be public informa
nvd
CVE-2022-0718P4MEDIUMCVSS 4.9v10.0v11.02022-08-29
CVE-2022-0718 [MEDIUM] CWE-522 CVE-2022-0718: A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorrect masking in debug logs, causing any part of the password after the double quote to be plaintext.
nvd
CVE-2021-24119P4MEDIUMCVSS 4.9v9.0v10.02021-07-14
CVE-2021-24119 [MEDIUM] CWE-203 CVE-2021-24119: In Trusted Firmware Mbed TLS 2.24.0, a side-channel vulnerability in base64 PEM file decoding allows In Trusted Firmware Mbed TLS 2.24.0, a side-channel vulnerability in base64 PEM file decoding allows system-level (administrator) attackers to obtain information about secret RSA keys via a controlled-channel and side-channel attack on software running in isolated environments that can be single stepped, especially Intel SGX.
nvd
CVE-2021-28544P4MEDIUMCVSS 4.3v10.0v11.02022-04-12
CVE-2021-28544 [MEDIUM] CWE-200 CVE-2021-28544: Apache Subversion SVN authz protected copyfrom paths regression Subversion servers reveal 'copyfrom' Apache Subversion SVN authz protected copyfrom paths regression Subversion servers reveal 'copyfrom' paths that should be hidden according to configured path-based authorization (authz) rules. When a node has been copied from a protected location, users with access to the copy can see the 'copyfrom' path of the original. This also reveals the fact t
nvd
CVE-2019-20043P4MEDIUMCVSS 4.3v9.0v10.02019-12-27
CVE-2019-20043 [MEDIUM] CWE-269 CVE-2019-20043: In in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in WordPress 3.7 to 5.3.0, a In in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in WordPress 3.7 to 5.3.0, authenticated users who do not have the rights to publish a post are able to mark posts as sticky or unsticky via the REST API. For example, the contributor role does not have such rights, but this allowed them to bypass that. This has been patched in
nvd
CVE-2010-2249P4MEDIUMCVSS 6.5v5.02010-06-30
CVE-2010-2249 [MEDIUM] CWE-401 CVE-2010-2249: Memory leak in pngrutil.c in libpng before 1.2.44, and 1.4.x before 1.4.3, allows remote attackers t Memory leak in pngrutil.c in libpng before 1.2.44, and 1.4.x before 1.4.3, allows remote attackers to cause a denial of service (memory consumption and application crash) via a PNG image containing malformed Physical Scale (aka sCAL) chunks.
nvd
CVE-2021-29450P4MEDIUMCVSS 4.3v9.0v10.02021-04-15
CVE-2021-29450 [MEDIUM] CWE-200 CVE-2021-29450: Wordpress is an open source CMS. One of the blocks in the WordPress editor can be exploited in a way Wordpress is an open source CMS. One of the blocks in the WordPress editor can be exploited in a way that exposes password-protected posts and pages. This requires at least contributor privileges. This has been patched in WordPress 5.7.1, along with the older affected versions via minor releases. It's strongly recommended that you keep auto-updates
nvd
CVE-2008-3281P4MEDIUMCVSS 6.5v4.02008-08-27
CVE-2008-3281 [MEDIUM] CWE-776 CVE-2008-3281: libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribut libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document.
nvd
CVE-2009-0590P4MEDIUMCVSS 5.0v4.0v5.02009-03-27
CVE-2009-0590 [MEDIUM] CWE-119 CVE-2009-0590: The ASN1_STRING_print_ex function in OpenSSL before 0.9.8k allows remote attackers to cause a denial The ASN1_STRING_print_ex function in OpenSSL before 0.9.8k allows remote attackers to cause a denial of service (invalid memory access and application crash) via vectors that trigger printing of a (1) BMPString or (2) UniversalString with an invalid encoded length.
nvd
CVE-2015-3234P4MEDIUMCVSS 4.3v7.0v8.02015-06-22
CVE-2015-3234 [MEDIUM] CWE-20 CVE-2015-3234: The OpenID module in Drupal 6.x before 6.36 and 7.x before 7.38 allows remote attackers to log into The OpenID module in Drupal 6.x before 6.36 and 7.x before 7.38 allows remote attackers to log into other users' accounts by leveraging an OpenID identity from certain providers, as demonstrated by the Verisign, LiveJournal, and StackExchange providers.
nvd
CVE-2012-0259P4MEDIUMCVSS 6.5v6.02012-06-05
CVE-2012-0259 [MEDIUM] CWE-125 CVE-2012-0259: The GetEXIFProperty function in magick/property.c in ImageMagick before 6.7.6-3 allows remote attack The GetEXIFProperty function in magick/property.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (crash) via a zero value in the component count of an EXIF XResolution tag in a JPEG file, which triggers an out-of-bounds read.
nvd
CVE-2021-32672P4MEDIUMCVSS 4.3v10.0v11.02021-10-04
CVE-2021-32672 [MEDIUM] CWE-125 CVE-2021-32672: Redis is an open source, in-memory database that persists on disk. When using the Redis Lua Debugger Redis is an open source, in-memory database that persists on disk. When using the Redis Lua Debugger, users can send malformed requests that cause the debugger’s protocol parser to read data beyond the actual buffer. This issue affects all versions of Redis with Lua debugging support (3.2 or newer). The problem is fixed in versions 6.2.6, 6.0.16 and
nvd
CVE-2016-1523P4MEDIUMCVSS 6.5v7.0v8.02016-02-13
CVE-2016-1523 [MEDIUM] CVE-2016-1523: The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozi The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, mishandles a return value, which allows remote attackers to cause a denial of service (missing initialization, NULL pointer dereference, and application crash) via a crafted Graphite smart font.
nvd
CVE-2018-20662P4MEDIUMCVSS 6.5v8.0v9.02019-01-03
CVE-2018-20662 [MEDIUM] CWE-20 CVE-2018-20662: In Poppler 0.72.0, PDFDoc::setup in PDFDoc.cc allows attackers to cause a denial-of-service (applica In Poppler 0.72.0, PDFDoc::setup in PDFDoc.cc allows attackers to cause a denial-of-service (application crash caused by Object.h SIGABRT, because of a wrong return value from PDFDoc::setup) by crafting a PDF file in which an xref data structure is mishandled during extractPDFSubtype processing.
nvd
CVE-2016-2270P4MEDIUMCVSS 6.8v7.0v8.02016-02-19
CVE-2016-2270 [MEDIUM] CWE-20 CVE-2016-2270: Xen 4.6.x and earlier allows local guest administrators to cause a denial of service (host reboot) v Xen 4.6.x and earlier allows local guest administrators to cause a denial of service (host reboot) via vectors related to multiple mappings of MMIO pages with different cachability settings.
nvd
CVE-2024-50349P4MEDIUMCVSS 4.7v11.02025-01-14
CVE-2024-50349 [MEDIUM] CWE-116 CVE-2024-50349: Git is a fast, scalable, distributed revision control system with an unusually rich command set that Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When Git asks for credentials via a terminal prompt (i.e. without using any credential helper), it prints out the host name for which the user is expected to provide a username and/or
nvd
CVE-2009-3939P4HIGHCVSS 7.1v5.02009-11-16
CVE-2009-3939 [HIGH] CWE-732 CVE-2009-3939: The poll_mode_io file for the megaraid_sas driver in the Linux kernel 2.6.31.6 and earlier has world The poll_mode_io file for the megaraid_sas driver in the Linux kernel 2.6.31.6 and earlier has world-writable permissions, which allows local users to change the I/O mode of the driver by modifying this file.
nvd
CVE-2017-16355P4MEDIUMCVSS 4.7v9.02017-12-14
CVE-2017-16355 [MEDIUM] CWE-200 CVE-2017-16355: In agent/Core/SpawningKit/Spawner.h in Phusion Passenger 5.1.10 (fixed in Passenger Open Source 5.1. In agent/Core/SpawningKit/Spawner.h in Phusion Passenger 5.1.10 (fixed in Passenger Open Source 5.1.11 and Passenger Enterprise 5.1.10), if Passenger is running as root, it is possible to list the contents of arbitrary files on a system by symlinking a file named REVISION from the application root folder to a file of choice and querying passenger-st
nvd
CVE-2015-1572P4MEDIUMCVSS 4.6v7.02015-02-24
CVE-2015-1572 [MEDIUM] CVE-2015-1572: Heap-based buffer overflow in closefs.c in the libext2fs library in e2fsprogs before 1.42.12 allows Heap-based buffer overflow in closefs.c in the libext2fs library in e2fsprogs before 1.42.12 allows local users to execute arbitrary code by causing a crafted block group descriptor to be marked as dirty. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-0247.
nvd
Debian Linux vulnerabilities | cvebase