cbcvebase.

Debian Linux vulnerabilities

9,955 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358

Vulnerabilities

Page 387 of 498
CVE-2009-1895P4HIGHCVSS 7.2v4.0v5.02009-07-16
CVE-2009-1895 [HIGH] CWE-16 CVE-2009-1895: The personality subsystem in the Linux kernel before 2.6.31-rc3 has a PER_CLEAR_ON_SETID setting tha The personality subsystem in the Linux kernel before 2.6.31-rc3 has a PER_CLEAR_ON_SETID setting that does not clear the ADDR_COMPAT_LAYOUT and MMAP_PAGE_ZERO flags when executing a setuid or setgid program, which makes it easier for local users to leverage the details of memory usage to (1) conduct NULL pointer dereference attacks, (2) bypass the mmap_m
nvd
CVE-2004-0579P4HIGHCVSS 7.2v3.02004-08-06
CVE-2004-0579 [HIGH] CVE-2004-0579: Format string vulnerability in super before 3.23 allows local users to execute arbitrary code as roo Format string vulnerability in super before 3.23 allows local users to execute arbitrary code as root.
nvd
CVE-2000-0867P4HIGHCVSS 7.2v2.1v2.22000-11-14
CVE-2000-0867 [HIGH] CVE-2000-0867: Kernel logging daemon (klogd) in Linux does not properly cleanse user-injected format strings, which Kernel logging daemon (klogd) in Linux does not properly cleanse user-injected format strings, which allows local users to gain root privileges by triggering malformed kernel messages.
nvd
CVE-2021-38509P4MEDIUMCVSS 4.3v9.0v10.0+1 more2021-12-08
CVE-2021-38509 [MEDIUM] CWE-1021 CVE-2021-38509: Due to an unusual sequence of attacker-controlled events, a Javascript alert() dialog with arbitrary Due to an unusual sequence of attacker-controlled events, a Javascript alert() dialog with arbitrary (although unstyled) contents could be displayed over top an uncontrolled webpage of the attacker's choosing. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
nvd
CVE-2018-11563P4MEDIUMCVSS 4.6v8.02019-07-08
CVE-2018-11563 [MEDIUM] CVE-2018-11563: An issue was discovered in Open Ticket Request System (OTRS) 6.0.x through 6.0.7. A carefully constr An issue was discovered in Open Ticket Request System (OTRS) 6.0.x through 6.0.7. A carefully constructed email could be used to inject and execute arbitrary stylesheet or JavaScript code in a logged in customer's browser in the context of the OTRS customer panel application.
nvd
CVE-2017-9143P4MEDIUMCVSS 6.5v8.0v9.02017-05-22
CVE-2017-9143 [MEDIUM] CWE-772 CVE-2017-9143: In ImageMagick 7.0.5-5, the ReadARTImage function in coders/art.c allows attackers to cause a denial In ImageMagick 7.0.5-5, the ReadARTImage function in coders/art.c allows attackers to cause a denial of service (memory leak) via a crafted .art file.
nvd
CVE-2017-8345P4MEDIUMCVSS 6.5v8.0v9.02017-04-30
CVE-2017-8345 [MEDIUM] CWE-772 CVE-2017-8345: In ImageMagick 7.0.5-5, the ReadMNGImage function in png.c allows attackers to cause a denial of ser In ImageMagick 7.0.5-5, the ReadMNGImage function in png.c allows attackers to cause a denial of service (memory leak) via a crafted file.
nvd
CVE-2017-8357P4MEDIUMCVSS 6.5v8.0v9.02017-04-30
CVE-2017-8357 [MEDIUM] CWE-772 CVE-2017-8357: In ImageMagick 7.0.5-5, the ReadEPTImage function in ept.c allows attackers to cause a denial of ser In ImageMagick 7.0.5-5, the ReadEPTImage function in ept.c allows attackers to cause a denial of service (memory leak) via a crafted file.
nvd
CVE-2020-24588P4LOWCVSS 3.5v9.02021-05-11
CVE-2020-24588 [LOW] CWE-327 CVE-2020-24588: The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that the A-MSDU flag in the plaintext QoS header field is authenticated. Against devices that support receiving non-SSP A-MSDU frames (which is mandatory as part of 802.11n), an adversary can abuse this to inject arbitrary
nvd
CVE-2022-24349P4MEDIUMCVSS 4.4v9.02022-03-09
CVE-2022-24349 [MEDIUM] CWE-79 CVE-2022-24349: An authenticated user can create a link with reflected XSS payload for actions’ pages, and send it t An authenticated user can create a link with reflected XSS payload for actions’ pages, and send it to other users. Malicious code has access to all the same objects as the rest of the web page and can make arbitrary modifications to the contents of the page being displayed to a victim. This attack can be implemented with the help of social engineerin
nvd
CVE-2022-24919P4MEDIUMCVSS 4.4v9.02022-03-09
CVE-2022-24919 [MEDIUM] CWE-79 CVE-2022-24919: An authenticated user can create a link with reflected Javascript code inside it for graphs’ page an An authenticated user can create a link with reflected Javascript code inside it for graphs’ page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict. Malicious code has access to all the same objects as the rest of the web page and can mak
nvd
CVE-2017-8348P4MEDIUMCVSS 6.5v8.0v9.02017-04-30
CVE-2017-8348 [MEDIUM] CWE-772 CVE-2017-8348: In ImageMagick 7.0.5-5, the ReadMATImage function in mat.c allows attackers to cause a denial of ser In ImageMagick 7.0.5-5, the ReadMATImage function in mat.c allows attackers to cause a denial of service (memory leak) via a crafted file.
nvd
CVE-2017-8354P4MEDIUMCVSS 6.5v8.0v9.02017-04-30
CVE-2017-8354 [MEDIUM] CWE-772 CVE-2017-8354: In ImageMagick 7.0.5-5, the ReadBMPImage function in bmp.c allows attackers to cause a denial of ser In ImageMagick 7.0.5-5, the ReadBMPImage function in bmp.c allows attackers to cause a denial of service (memory leak) via a crafted file.
nvd
CVE-2017-8349P4MEDIUMCVSS 6.5v8.0v9.02017-04-30
CVE-2017-8349 [MEDIUM] CWE-772 CVE-2017-8349: In ImageMagick 7.0.5-5, the ReadSFWImage function in sfw.c allows attackers to cause a denial of ser In ImageMagick 7.0.5-5, the ReadSFWImage function in sfw.c allows attackers to cause a denial of service (memory leak) via a crafted file.
nvd
CVE-2017-8346P4MEDIUMCVSS 6.5v8.0v9.02017-04-30
CVE-2017-8346 [MEDIUM] CWE-772 CVE-2017-8346: In ImageMagick 7.0.5-5, the ReadDCMImage function in dcm.c allows attackers to cause a denial of ser In ImageMagick 7.0.5-5, the ReadDCMImage function in dcm.c allows attackers to cause a denial of service (memory leak) via a crafted file.
nvd
CVE-2017-8343P4MEDIUMCVSS 6.5v8.0v9.02017-04-30
CVE-2017-8343 [MEDIUM] CWE-772 CVE-2017-8343: In ImageMagick 7.0.5-5, the ReadAAIImage function in aai.c allows attackers to cause a denial of ser In ImageMagick 7.0.5-5, the ReadAAIImage function in aai.c allows attackers to cause a denial of service (memory leak) via a crafted file.
nvd
CVE-2017-8347P4MEDIUMCVSS 6.5v8.0v9.02017-04-30
CVE-2017-8347 [MEDIUM] CWE-772 CVE-2017-8347: In ImageMagick 7.0.5-5, the ReadEXRImage function in exr.c allows attackers to cause a denial of ser In ImageMagick 7.0.5-5, the ReadEXRImage function in exr.c allows attackers to cause a denial of service (memory leak) via a crafted file.
nvd
CVE-2017-8355P4MEDIUMCVSS 6.5v8.0v9.02017-04-30
CVE-2017-8355 [MEDIUM] CWE-772 CVE-2017-8355: In ImageMagick 7.0.5-5, the ReadMTVImage function in mtv.c allows attackers to cause a denial of ser In ImageMagick 7.0.5-5, the ReadMTVImage function in mtv.c allows attackers to cause a denial of service (memory leak) via a crafted file.
nvd
CVE-2017-8356P4MEDIUMCVSS 6.5v8.0v9.02017-04-30
CVE-2017-8356 [MEDIUM] CWE-772 CVE-2017-8356: In ImageMagick 7.0.5-5, the ReadSUNImage function in sun.c allows attackers to cause a denial of ser In ImageMagick 7.0.5-5, the ReadSUNImage function in sun.c allows attackers to cause a denial of service (memory leak) via a crafted file.
nvd
CVE-2017-8352P4MEDIUMCVSS 6.5v8.0v9.02017-04-30
CVE-2017-8352 [MEDIUM] CWE-772 CVE-2017-8352: In ImageMagick 7.0.5-5, the ReadXWDImage function in xwd.c allows attackers to cause a denial of ser In ImageMagick 7.0.5-5, the ReadXWDImage function in xwd.c allows attackers to cause a denial of service (memory leak) via a crafted file.
nvd
Debian Linux vulnerabilities | cvebase