cbcvebase.

Debian Linux vulnerabilities

9,953 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358

Vulnerabilities

Page 41 of 498
CVE-2025-3887P2HIGHCVSS 8.8v11.02025-05-22
CVE-2025-3887 [HIGH] CWE-121 CVE-2025-3887: GStreamer H265 Codec Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This v GStreamer H265 Codec Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw
nvd
CVE-2017-3145P3HIGHCVSS 7.5v7.0v8.0+1 more2019-01-16
CVE-2017-3145 [HIGH] CWE-416 CVE-2017-3145: BIND was improperly sequencing cleanup operations on upstream recursion fetch contexts, leading in s BIND was improperly sequencing cleanup operations on upstream recursion fetch contexts, leading in some cases to a use-after-free error that can trigger an assertion failure and crash in named. Affects BIND 9.0.0 to 9.8.x, 9.9.0 to 9.9.11, 9.10.0 to 9.10.6, 9.11.0 to 9.11.2, 9.9.3-S1 to 9.9.11-S1, 9.10.5-S1 to 9.10.6-S1, 9.12.0a1 to 9.12.0rc1.
nvd
CVE-2017-12185P3CRITICALCVSS 9.8v8.0v9.02018-01-24
CVE-2017-12185 [CRITICAL] CWE-391 CVE-2017-12185: xorg-x11-server before 1.19.5 was missing length validation in MIT-SCREEN-SAVER extension allowing m xorg-x11-server before 1.19.5 was missing length validation in MIT-SCREEN-SAVER extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
nvd
CVE-2021-28662P3MEDIUMCVSS 6.5v10.02021-05-27
CVE-2021-28662 [MEDIUM] CWE-116 CVE-2021-28662: An issue was discovered in Squid 4.x before 4.15 and 5.x before 5.0.6. If a remote server sends a ce An issue was discovered in Squid 4.x before 4.15 and 5.x before 5.0.6. If a remote server sends a certain response header over HTTP or HTTPS, there is a denial of service. This header can plausibly occur in benign network traffic.
nvd
CVE-2019-9850P3CRITICALCVSS 9.8v8.0v9.0+1 more2019-08-15
CVE-2019-9850 [CRITICAL] CVE-2019-9850: LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launched from. LibreOffice also has a feature where documents can specify that pre-installed scripts can be executed on various document script events such as mouse-over, etc. Protection
nvd
CVE-2018-14600P3CRITICALCVSS 9.8v8.02018-08-24
CVE-2018-14600 [CRITICAL] CWE-787 CVE-2018-14600: An issue was discovered in libX11 through 1.6.5. The function XListExtensions in ListExt.c interpret An issue was discovered in libX11 through 1.6.5. The function XListExtensions in ListExt.c interprets a variable as signed instead of unsigned, resulting in an out-of-bounds write (of up to 128 bytes), leading to DoS or remote code execution.
nvd
CVE-2015-7695P3CRITICALCVSS 9.8v7.0v8.02016-06-07
CVE-2015-7695 [CRITICAL] CWE-89 CVE-2015-7695: The PDO adapters in Zend Framework before 1.12.16 do not filer null bytes in SQL statements, which a The PDO adapters in Zend Framework before 1.12.16 do not filer null bytes in SQL statements, which allows remote attackers to execute arbitrary SQL commands via a crafted query.
nvd
CVE-2022-21831P3CRITICALCVSS 9.8v10.02022-05-26
CVE-2022-21831 [CRITICAL] CWE-94 CVE-2022-21831: A code injection vulnerability exists in the Active Storage >= v5.2.0 that could allow an attacker t A code injection vulnerability exists in the Active Storage >= v5.2.0 that could allow an attacker to execute code via image_processing arguments.
nvd
CVE-2022-21723P3CRITICALCVSS 9.1v9.0v10.02022-01-27
CVE-2022-21723 [CRITICAL] CWE-125 CVE-2022-21723: PJSIP is a free and open source multimedia communication library written in C language implementing PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions 2.11.1 and prior, parsing an incoming SIP message that contains a malformed multipart can potentially cause out-of-bound read access. This issue affects all PJSIP users
nvd
CVE-2005-3302P3HIGHCVSS 7.3PoCv3.12005-10-24
CVE-2005-3302 [HIGH] CWE-94 CVE-2005-3302: Eval injection vulnerability in bvh_import.py in Blender 2.36 allows attackers to execute arbitrary Eval injection vulnerability in bvh_import.py in Blender 2.36 allows attackers to execute arbitrary Python code via a hierarchy element in a .bvh file, which is supplied to an eval function call.
nvd
CVE-2016-5180P3CRITICALCVSS 9.8v8.02016-10-03
CVE-2016-5180 [CRITICAL] CWE-787 CVE-2016-5180: Heap-based buffer overflow in the ares_create_query function in c-ares 1.x before 1.12.0 allows remo Heap-based buffer overflow in the ares_create_query function in c-ares 1.x before 1.12.0 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly execute arbitrary code via a hostname with an escaped trailing dot.
nvd
CVE-2021-33833P3CRITICALCVSS 9.8v9.02021-06-09
CVE-2021-33833 [CRITICAL] CWE-787 CVE-2021-33833: ConnMan (aka Connection Manager) 1.30 through 1.39 has a stack-based buffer overflow in uncompress i ConnMan (aka Connection Manager) 1.30 through 1.39 has a stack-based buffer overflow in uncompress in dnsproxy.c via NAME, RDATA, or RDLENGTH (for A or AAAA).
nvd
CVE-2019-12523P3CRITICALCVSS 9.1v9.0v10.02019-11-26
CVE-2019-12523 [CRITICAL] CVE-2019-12523: An issue was discovered in Squid before 4.9. When handling a URN request, a corresponding HTTP reque An issue was discovered in Squid before 4.9. When handling a URN request, a corresponding HTTP request is made. This HTTP request doesn't go through the access checks that incoming HTTP requests go through. This causes all access checks to be bypassed and allows access to restricted HTTP servers, e.g., an attacker can connect to HTTP servers that only lis
nvd
CVE-2022-30123P3CRITICALCVSS 10.0v11.02022-12-05
CVE-2022-30123 [CRITICAL] CWE-150 CVE-2022-30123: A sequence injection vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 which could allow A sequence injection vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 which could allow is a possible shell escape in the Lint and CommonLogger components of Rack.
nvd
CVE-2018-20181P3CRITICALCVSS 9.8v8.0v9.02019-03-15
CVE-2018-20181 [CRITICAL] CWE-191 CVE-2018-20181: rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function seamless_process() and results in memory corruption and probably even a remote code execution.
nvd
CVE-2018-20180P3CRITICALCVSS 9.8v8.0v9.02019-03-15
CVE-2018-20180 [CRITICAL] CWE-191 CVE-2018-20180: rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function rdpsnddbg_process() and results in memory corruption and probably even a remote code execution.
nvd
CVE-2017-10672P3CRITICALCVSS 9.8v8.0v9.02017-06-29
CVE-2017-10672 [CRITICAL] CWE-416 CVE-2017-10672: Use-after-free in the XML-LibXML module through 2.0129 for Perl allows remote attackers to execute a Use-after-free in the XML-LibXML module through 2.0129 for Perl allows remote attackers to execute arbitrary code by controlling the arguments to a replaceChild call.
nvd
CVE-2016-2342P3HIGHCVSS 8.1v7.0v8.02016-03-17
CVE-2016-2342 [HIGH] CWE-119 CVE-2016-2342: The bgp_nlri_parse_vpnv4 function in bgp_mplsvpn.c in the VPNv4 NLRI parser in bgpd in Quagga before The bgp_nlri_parse_vpnv4 function in bgp_mplsvpn.c in the VPNv4 NLRI parser in bgpd in Quagga before 1.0.20160309, when a certain VPNv4 configuration is used, relies on a Labeled-VPN SAFI routes-data length field during a data copy, which allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow) via a c
nvd
CVE-2019-11187P3CRITICALCVSS 9.8v8.02019-08-15
CVE-2019-11187 [CRITICAL] CWE-287 CVE-2019-11187: Incorrect Access Control in the LDAP class of GONICUS GOsa through 2019-04-11 allows an attacker to Incorrect Access Control in the LDAP class of GONICUS GOsa through 2019-04-11 allows an attacker to log into any account with a username containing the case-insensitive substring "success" when an arbitrary password is provided.
nvd
CVE-2021-33477P3HIGHCVSS 8.8v9.02021-05-20
CVE-2021-33477 [HIGH] CWE-755 CVE-2021-33477: rxvt-unicode 9.22, rxvt 2.7.10, mrxvt 0.5.4, and Eterm 0.9.7 allow (potentially remote) code executi rxvt-unicode 9.22, rxvt 2.7.10, mrxvt 0.5.4, and Eterm 0.9.7 allow (potentially remote) code execution because of improper handling of certain escape sequences (ESC G Q). A response is terminated by a newline.
nvd
Debian Linux vulnerabilities | cvebase