cbcvebase.

Debian Linux vulnerabilities

9,953 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358

Vulnerabilities

Page 40 of 498
CVE-2017-2640P3CRITICALCVSS 9.8v8.02018-07-27
CVE-2017-2640 [CRITICAL] CWE-787 CVE-2017-2640: An out-of-bounds write flaw was found in the way Pidgin before 2.12.0 processed XML content. A malic An out-of-bounds write flaw was found in the way Pidgin before 2.12.0 processed XML content. A malicious remote server could potentially use this flaw to crash Pidgin or execute arbitrary code in the context of the pidgin process.
nvd
CVE-2014-4172P3CRITICALCVSS 9.8v7.02020-01-24
CVE-2014-4172 [CRITICAL] CWE-74 CVE-2014-4172: A URL parameter injection vulnerability was found in the back-channel ticket validation step of the A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.2, .NET CAS Client before 1.0.2, and phpCAS before 1.3.3 that allow remote attackers to inject arbitrary web script or HTML via the (1) service parameter to validation/AbstractUrlBasedTicketValidator.java
nvd
CVE-2022-46340P3HIGHCVSS 8.8v11.02022-12-14
CVE-2022-46340 [HIGH] CWE-787 CVE-2022-46340: A vulnerability was found in X.Org. This security flaw occurs becuase the swap handler for the XTest A vulnerability was found in X.Org. This security flaw occurs becuase the swap handler for the XTestFakeInput request of the XTest extension may corrupt the stack if GenericEvents with lengths larger than 32 bytes are sent through a the XTestFakeInput request. This issue can lead to local privileges elevation on systems where the X server is running p
nvd
CVE-2022-26499P3CRITICALCVSS 9.1v10.0v11.02022-04-15
CVE-2022-26499 [CRITICAL] CWE-918 CVE-2022-26499: An SSRF issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it's possible to send An SSRF issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it's possible to send arbitrary requests (such as GET) to interfaces such as localhost by using the Identity header. This is fixed in 16.25.2, 18.11.2, and 19.3.2.
nvd
CVE-2019-0217P3HIGHCVSS 7.5v8.0v9.02019-04-08
CVE-2019-0217 [HIGH] CWE-362 CVE-2019-0217: In Apache HTTP Server 2.4 release 2.4.38 and prior, a race condition in mod_auth_digest when running In Apache HTTP Server 2.4 release 2.4.38 and prior, a race condition in mod_auth_digest when running in a threaded server could allow a user with valid credentials to authenticate using another username, bypassing configured access control restrictions.
nvd
CVE-2019-5477P3CRITICALCVSS 9.8v8.0v10.02019-08-16
CVE-2019-5477 [CRITICAL] CWE-78 CVE-2019-5477: A command injection vulnerability in Nokogiri v1.10.3 and earlier allows commands to be executed in A command injection vulnerability in Nokogiri v1.10.3 and earlier allows commands to be executed in a subprocess via Ruby's `Kernel.open` method. Processes are vulnerable only if the undocumented method `Nokogiri::CSS::Tokenizer#load_file` is being called with unsafe user input as the filename. This vulnerability appears in code generated by the Rexic
nvd
CVE-2022-46343P3HIGHCVSS 8.8v11.02022-12-14
CVE-2022-46343 [HIGH] CWE-416 CVE-2022-46343: A vulnerability was found in X.Org. This security flaw occurs because the handler for the ScreenSave A vulnerability was found in X.Org. This security flaw occurs because the handler for the ScreenSaverSetAttributes request may write to memory after it has been freed. This issue can lead to local privileges elevation on systems where the X server is running privileged and remote code execution for ssh X forwarding sessions.
nvd
CVE-2021-31439P3HIGHCVSS 8.8v10.0v11.02021-05-21
CVE-2021-31439 [HIGH] CWE-122 CVE-2021-31439: This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installat This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Synology DiskStation Manager. Authentication is not required to exploit this vulnerablity. The specific flaw exists within the processing of DSI structures in Netatalk. The issue results from the lack of proper validation of the length of user-s
nvd
CVE-2024-25126P3HIGHCVSS 7.5v10.02024-02-29
CVE-2024-25126 [HIGH] CWE-1333 CVE-2024-25126: Rack is a modular Ruby web server interface. Carefully crafted content type headers can cause Rack’s Rack is a modular Ruby web server interface. Carefully crafted content type headers can cause Rack’s media type parser to take much longer than expected, leading to a possible denial of service vulnerability (ReDos 2nd degree polynomial). This vulnerability is patched in 3.0.9.1 and 2.2.8.1.
nvd
CVE-2015-3214P3MEDIUMCVSS 6.9PoCv7.0v8.02015-08-31
CVE-2015-3214 [MEDIUM] CWE-119 CVE-2015-3214: The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not dist The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, which might allow guest OS users to execute arbitrary code on the host OS by triggering use of an invalid index.
nvd
CVE-2021-32743P3HIGHCVSS 8.8v9.02021-07-15
CVE-2021-32743 [HIGH] CWE-202 CVE-2021-32743: Icinga is a monitoring system which checks the availability of network resources, notifies users of Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. In versions prior to 2.11.10 and from version 2.12.0 through version 2.12.4, some of the Icinga 2 features that require credentials for external services expose those credentials through the API to a
nvd
CVE-2019-3842P3HIGHCVSS 7.0PoCv8.02019-04-09
CVE-2019-3842 [HIGH] CWE-285 CVE-2019-3842: In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the enviro In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variable. It is possible for an attacker, in some particular configurations, to set a XDG_SEAT environment variable which allows for commands to be checked against polkit policies using the "allow_active" element rather tha
nvd
CVE-2019-10193P3HIGHCVSS 7.2v9.0v10.02019-07-11
CVE-2019-10193 [HIGH] CWE-121 CVE-2019-10193: A stack-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x A stack-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before 5.0.4. By corrupting a hyperloglog using the SETRANGE command, an attacker could cause Redis to perform controlled increments of up to 12 bytes past the end of a stack-allocated buffer.
nvd
CVE-2021-3449P3MEDIUMCVSS 5.9v9.0v10.02021-03-25
CVE-2021-3449 [MEDIUM] CWE-476 CVE-2021-3449: An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a cr
nvd
CVE-2021-32675P3HIGHCVSS 7.5v10.0v11.02021-10-04
CVE-2021-32675 [HIGH] CWE-770 CVE-2021-32675: Redis is an open source, in-memory database that persists on disk. When parsing an incoming Redis St Redis is an open source, in-memory database that persists on disk. When parsing an incoming Redis Standard Protocol (RESP) request, Redis allocates memory according to user-specified values which determine the number of elements (in the multi-bulk header) and size of each element (in the bulk header). An attacker delivering specially crafted requests
nvd
CVE-2019-1010174P3CRITICALCVSS 9.8v8.0v9.02019-07-25
CVE-2019-1010174 [CRITICAL] CWE-77 CVE-2019-1010174: CImg The CImg Library v.2.3.3 and earlier is affected by: command injection. The impact is: RCE. The CImg The CImg Library v.2.3.3 and earlier is affected by: command injection. The impact is: RCE. The component is: load_network() function. The attack vector is: Loading an image from a user-controllable url can lead to command injection, because no string sanitization is done on the url. The fixed version is: v.2.3.4.
nvd
CVE-2018-6913P3CRITICALCVSS 9.8v7.0v8.0+1 more2018-04-17
CVE-2018-6913 [CRITICAL] CWE-787 CVE-2018-6913: Heap-based buffer overflow in the pack function in Perl before 5.26.2 allows context-dependent attac Heap-based buffer overflow in the pack function in Perl before 5.26.2 allows context-dependent attackers to execute arbitrary code via a large item count.
nvd
CVE-2013-6275P3MEDIUMCVSS 6.5PoCv8.0v9.0+1 more2019-11-05
CVE-2013-6275 [MEDIUM] CWE-352 CVE-2013-6275: Multiple CSRF issues in Horde Groupware Webmail Edition 5.1.2 and earlier in basic.php. Multiple CSRF issues in Horde Groupware Webmail Edition 5.1.2 and earlier in basic.php.
nvd
CVE-2022-25315P3CRITICALCVSS 9.8v10.0v11.02022-02-18
CVE-2022-25315 [CRITICAL] CWE-190 CVE-2022-25315: In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames. In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.
nvd
CVE-2017-12186P3CRITICALCVSS 9.8v8.0v9.02018-01-24
CVE-2017-12186 [CRITICAL] CWE-391 CVE-2017-12186: xorg-x11-server before 1.19.5 was missing length validation in X-Resource extension allowing malicio xorg-x11-server before 1.19.5 was missing length validation in X-Resource extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
nvd
Debian Linux vulnerabilities | cvebase