cbcvebase.

Debian Linux vulnerabilities

9,955 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358

Vulnerabilities

Page 398 of 498
CVE-2013-4135P4MEDIUMCVSS 4.3v7.02013-11-05
CVE-2013-4135 [MEDIUM] CWE-310 CVE-2013-4135: The vos command in OpenAFS 1.6.x before 1.6.5, when using the -encrypt option, only enables integrit The vos command in OpenAFS 1.6.x before 1.6.5, when using the -encrypt option, only enables integrity protection and sends data in cleartext, which allows remote attackers to obtain sensitive information by sniffing the network.
nvd
CVE-2019-12248P4MEDIUMCVSS 4.3v8.02019-06-17
CVE-2019-12248 [MEDIUM] CVE-2019-12248: An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.7, Community Edition An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.7, Community Edition 6.0.x through 6.0.19, and Community Edition 5.0.x through 5.0.36. An attacker could send a malicious email to an OTRS system. If a logged-in agent user quotes it, the email could cause the browser to load external image resources.
nvd
CVE-1999-0457P4HIGHCVSS 7.2v1.3v1.3.1+1 more1999-01-17
CVE-1999-0457 [HIGH] CVE-1999-0457: Linux ftpwatch program allows local users to gain root privileges. Linux ftpwatch program allows local users to gain root privileges.
nvd
CVE-1999-1276P4HIGHCVSS 7.2v2.11998-12-07
CVE-1999-1276 [HIGH] CVE-1999-1276: fte-console in the fte package before 0.46b-4.1 does not drop root privileges, which allows local us fte-console in the fte package before 0.46b-4.1 does not drop root privileges, which allows local users to gain root access via the virtual console device.
nvd
CVE-2021-30159P4MEDIUMCVSS 4.3v9.0v10.02021-04-09
CVE-2021-30159 [MEDIUM] CVE-2021-30159: An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Users c An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Users can bypass intended restrictions on deleting pages in certain "fast double move" situations. MovePage::isValidMoveTarget() uses FOR UPDATE, but it's only called if Title::getArticleID() returns non-zero with no special flags. Next, MovePage::moveToInternal() w
nvd
CVE-2015-1248P4MEDIUMCVSS 4.3v7.02015-04-19
CVE-2015-1248 [MEDIUM] CWE-264 CVE-2015-1248: The FileSystem API in Google Chrome before 40.0.2214.91 allows remote attackers to bypass the SafeBr The FileSystem API in Google Chrome before 40.0.2214.91 allows remote attackers to bypass the SafeBrowsing for Executable Files protection mechanism by creating a .exe file in a temporary filesystem and then referencing this file with a filesystem:http: URL.
nvd
CVE-2022-24917P4MEDIUMCVSS 4.4v9.02022-03-09
CVE-2022-24917 [MEDIUM] CWE-79 CVE-2022-24917: An authenticated user can create a link with reflected Javascript code inside it for services’ page An authenticated user can create a link with reflected Javascript code inside it for services’ page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict. Malicious code has access to all the same objects as the rest of the web page and can ma
nvd
CVE-2011-1136P4MEDIUMCVSS 4.7v8.0v9.0+1 more2019-11-14
CVE-2011-1136 [MEDIUM] CWE-59 CVE-2011-1136: In tesseract 2.03 and 2.04, an attacker can rewrite an arbitrary user file by guessing the PID and c In tesseract 2.03 and 2.04, an attacker can rewrite an arbitrary user file by guessing the PID and creating a link to the user's file.
nvd
CVE-2021-21366P4MEDIUMCVSS 4.3v10.02021-03-12
CVE-2021-21366 [MEDIUM] CWE-115 CVE-2021-21366: xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer mo xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. xmldom versions 0.4.0 and older do not correctly preserve system identifiers, FPIs or namespaces when repeatedly parsing and serializing maliciously crafted documents. This may lead to unexpected syntactic changes during XML processing in some d
nvd
CVE-2019-18179P4MEDIUMCVSS 4.3v8.02020-01-06
CVE-2019-18179 [MEDIUM] CVE-2019-18179: An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.12, and Community Edi An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.12, and Community Edition 5.0.x through 5.0.38 and 6.0.x through 6.0.23. An attacker who is logged into OTRS as an agent is able to list tickets assigned to other agents, even tickets in a queue where the attacker doesn't have permissions.
nvd
CVE-2009-2416P4MEDIUMCVSS 6.5v4.02009-08-11
CVE-2009-2416 [MEDIUM] CWE-416 CVE-2009-2416: Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and l Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in an XML file, as demonstrated by the Codenomicon XML fuzzing framework.
nvd
CVE-2020-10932P4MEDIUMCVSS 4.7v10.02020-04-15
CVE-2020-10932 [MEDIUM] CWE-203 CVE-2020-10932: An issue was discovered in Arm Mbed TLS before 2.16.6 and 2.7.x before 2.7.15. An attacker that can An issue was discovered in Arm Mbed TLS before 2.16.6 and 2.7.x before 2.7.15. An attacker that can get precise enough side-channel measurements can recover the long-term ECDSA private key by (1) reconstructing the projective coordinate of the result of scalar multiplication by exploiting side channels in the conversion to affine coordinates; (2) usi
nvd
CVE-2020-26247P4MEDIUMCVSS 4.3v9.0v10.02020-12-30
CVE-2020-26247 [MEDIUM] CWE-611 CVE-2020-26247: Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector suppo Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri before version 1.11.0.rc4 there is an XXE vulnerability. XML Schemas parsed by Nokogiri::XML::Schema are trusted by default, allowing external resources to be accessed over the network, potentially enabling XXE or SSRF attacks. This be
nvd
CVE-2017-9404P4MEDIUMCVSS 6.5v8.0v9.0+1 more2017-06-02
CVE-2017-9404 [MEDIUM] CWE-772 CVE-2017-9404: In LibTIFF 4.0.7, a memory leak vulnerability was found in the function OJPEGReadHeaderInfoSecTables In LibTIFF 4.0.7, a memory leak vulnerability was found in the function OJPEGReadHeaderInfoSecTablesQTable in tif_ojpeg.c, which allows attackers to cause a denial of service via a crafted file.
nvd
CVE-2017-9406P4MEDIUMCVSS 6.5v8.0v9.02017-06-02
CVE-2017-9406 [MEDIUM] CWE-772 CVE-2017-9406: In Poppler 0.54.0, a memory leak vulnerability was found in the function gmalloc in gmem.cc, which a In Poppler 0.54.0, a memory leak vulnerability was found in the function gmalloc in gmem.cc, which allows attackers to cause a denial of service via a crafted file.
nvd
CVE-2017-9403P4MEDIUMCVSS 6.5v8.0v9.0+1 more2017-06-02
CVE-2017-9403 [MEDIUM] CWE-772 CVE-2017-9403: In LibTIFF 4.0.7, a memory leak vulnerability was found in the function TIFFReadDirEntryLong8Array i In LibTIFF 4.0.7, a memory leak vulnerability was found in the function TIFFReadDirEntryLong8Array in tif_dirread.c, which allows attackers to cause a denial of service via a crafted file.
nvd
CVE-2019-14443P4MEDIUMCVSS 6.5v8.02019-07-30
CVE-2019-14443 [MEDIUM] CWE-369 CVE-2019-14443: An issue was discovered in Libav 12.3. Division by zero in range_decode_culshift in libavcodec/apede An issue was discovered in Libav 12.3. Division by zero in range_decode_culshift in libavcodec/apedec.c allows remote attackers to cause a denial of service (application crash), as demonstrated by avconv.
nvd
CVE-2024-10978P4MEDIUMCVSS 4.2v11.02024-11-14
CVE-2024-10978 [MEDIUM] CWE-266 CVE-2024-10978: Incorrect privilege assignment in PostgreSQL allows a less-privileged application user to view or ch Incorrect privilege assignment in PostgreSQL allows a less-privileged application user to view or change different rows from those intended. An attack requires the application to use SET ROLE, SET SESSION AUTHORIZATION, or an equivalent feature. The problem arises when an application query uses parameters from the attacker or conveys query results t
nvd
CVE-2021-36368P4LOWCVSS 3.7v9.0v10.0+1 more2022-03-13
CVE-2021-36368 [LOW] CWE-287 CVE-2021-36368: An issue was discovered in OpenSSH before 8.9. If a client is using public-key authentication with a An issue was discovered in OpenSSH before 8.9. If a client is using public-key authentication with agent forwarding but without -oLogLevel=verbose, and an attacker has silently modified the server to support the None authentication option, then the user cannot determine whether FIDO authentication is going to confirm that the user wishes to connect to
nvd
CVE-2017-16532P4MEDIUMCVSS 6.6v7.02017-11-04
CVE-2017-16532 [MEDIUM] CWE-476 CVE-2017-16532: The get_endpoints function in drivers/usb/misc/usbtest.c in the Linux kernel through 4.13.11 allows The get_endpoints function in drivers/usb/misc/usbtest.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a crafted USB device.
nvd
Debian Linux vulnerabilities | cvebase