cbcvebase.

Debian Linux vulnerabilities

9,955 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358

Vulnerabilities

Page 412 of 498
CVE-2019-5779P4MEDIUMCVSS 4.3v9.02019-02-19
CVE-2019-5779 [MEDIUM] CWE-862 CVE-2019-5779: Insufficient policy validation in ServiceWorker in Google Chrome prior to 72.0.3626.81 allowed a rem Insufficient policy validation in ServiceWorker in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2020-25684P4LOWCVSS 3.7v9.0v10.02021-01-20
CVE-2020-25684 [LOW] CWE-358 CVE-2020-25684: A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmas A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmasq checks in the forward.c:reply_query() if the reply destination address/port is used by the pending forwarded queries. However, it does not use the address/port to retrieve the exact forwarded query, substantially reducing the number of attempts an atta
nvd
CVE-2012-3867P4MEDIUMCVSS 4.3v6.02012-08-06
CVE-2012-3867 [MEDIUM] CWE-264 CVE-2012-3867: lib/puppet/ssl/certificate_authority.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet lib/puppet/ssl/certificate_authority.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, does not properly restrict the characters in the Common Name field of a Certificate Signing Request (CSR), which makes it easier for user-assisted remote attackers to trick administrators into signing a crafted agent certificate
nvd
CVE-2018-6082P4MEDIUMCVSS 4.7v9.02018-11-14
CVE-2018-6082 [MEDIUM] CWE-200 CVE-2018-6082: Including port 22 in the list of allowed FTP ports in Networking in Google Chrome prior to 65.0.3325 Including port 22 in the list of allowed FTP ports in Networking in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially enumerate internal host services via a crafted HTML page.
nvd
CVE-2020-8284P4LOWCVSS 3.7v9.0v10.02020-12-14
CVE-2020-8284 [LOW] CWE-200 CVE-2020-8284: A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting ba A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, for example doing port scanning and service banner extractions.
nvd
CVE-2022-24851P4MEDIUMCVSS 4.8v11.02022-04-15
CVE-2022-24851 [MEDIUM] CWE-22 CVE-2022-24851: LDAP Account Manager (LAM) is an open source web frontend for managing entries stored in an LDAP dir LDAP Account Manager (LAM) is an open source web frontend for managing entries stored in an LDAP directory. The profile editor tool has an edit profile functionality, the parameters on this page are not properly sanitized and hence leads to stored XSS attacks. An authenticated user can store XSS payloads in the profiles, which gets triggered when any
nvd
CVE-2012-0867P4MEDIUMCVSS 4.3v6.02012-07-18
CVE-2012-0867 [MEDIUM] CWE-20 CVE-2012-0867: PostgreSQL 8.4.x before 8.4.11, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 truncates the common name PostgreSQL 8.4.x before 8.4.11, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 truncates the common name to only 32 characters when verifying SSL certificates, which allows remote attackers to spoof connections when the host name is exactly 32 characters.
nvd
CVE-2015-4830P4MEDIUMCVSS 4.0v7.0v8.02015-10-21
CVE-2015-4830 [MEDIUM] CVE-2015-4830: Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows re Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows remote authenticated users to affect integrity via unknown vectors related to Server : Security : Privileges.
nvd
CVE-2017-10081P4MEDIUMCVSS 4.3v8.0v9.02017-08-08
CVE-2017-10081 [MEDIUM] CVE-2017-10081: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful a
nvd
CVE-2021-3731P4MEDIUMCVSS 4.7v10.0v11.02021-08-23
CVE-2021-3731 [MEDIUM] CWE-1021 CVE-2021-3731: LedgerSMB does not sufficiently guard against being wrapped by other sites, making it vulnerable to LedgerSMB does not sufficiently guard against being wrapped by other sites, making it vulnerable to 'clickjacking'. This allows an attacker to trick a targetted user to execute unintended actions.
nvd
CVE-2020-0093P4MEDIUMCVSS 5.0v8.02020-05-14
CVE-2020-0093 [MEDIUM] CWE-125 CVE-2020-0093: In exif_data_save_data_entry of exif-data.c, there is a possible out of bounds read due to a missing In exif_data_save_data_entry of exif-data.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-148705132
nvd
CVE-2004-1076P4HIGHCVSS 7.2v3.02005-01-10
CVE-2004-1076 [HIGH] CVE-2004-1076: Multiple buffer overflows in the RtConfigLoad function in rt-config.c for Atari800 before 1.3.4 allo Multiple buffer overflows in the RtConfigLoad function in rt-config.c for Atari800 before 1.3.4 allow local users to execute arbitrary code via large values in the configuration file.
nvd
CVE-2001-0834P4MEDIUMCVSS 6.4v2.22001-12-06
CVE-2001-0834 [MEDIUM] CVE-2001-0834: htsearch CGI program in htdig (ht://Dig) 3.1.5 and earlier allows remote attackers to use the -c opt htsearch CGI program in htdig (ht://Dig) 3.1.5 and earlier allows remote attackers to use the -c option to specify an alternate configuration file, which could be used to (1) cause a denial of service (CPU consumption) by specifying a large file such as /dev/zero, or (2) read arbitrary files by uploading an alternate configuration file that specifies the targ
nvd
CVE-2020-4032P4MEDIUMCVSS 4.3v10.02020-06-22
CVE-2020-4032 [MEDIUM] CWE-681 CVE-2020-4032: In FreeRDP before version 2.1.2, there is an integer casting vulnerability in update_recv_secondary_ In FreeRDP before version 2.1.2, there is an integer casting vulnerability in update_recv_secondary_order. All clients with +glyph-cache /relax-order-checks are affected. This is fixed in version 2.1.2.
nvd
CVE-2018-10545P4MEDIUMCVSS 4.7v7.0v8.0+1 more2018-04-29
CVE-2018-10545 [MEDIUM] CWE-200 CVE-2018-10545: An issue was discovered in PHP before 5.6.35, 7.0.x before 7.0.29, 7.1.x before 7.1.16, and 7.2.x be An issue was discovered in PHP before 5.6.35, 7.0.x before 7.0.29, 7.1.x before 7.1.16, and 7.2.x before 7.2.4. Dumpable FPM child processes allow bypassing opcache access controls because fpm_unix.c makes a PR_SET_DUMPABLE prctl call, allowing one user (in a multiuser environment) to obtain sensitive information from the process memory of a second
nvd
CVE-2020-29130P4MEDIUMCVSS 4.3v9.02020-11-26
CVE-2020-29130 [MEDIUM] CWE-125 CVE-2020-29130: slirp.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount o slirp.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length.
nvd
CVE-2018-5170P4MEDIUMCVSS 4.3v7.0v8.0+1 more2018-06-11
CVE-2018-5170 [MEDIUM] CWE-20 CVE-2018-5170: It is possible to spoof the filename of an attachment and display an arbitrary attachment name. This It is possible to spoof the filename of an attachment and display an arbitrary attachment name. This could lead to a user opening a remote attachment which is a different file type than expected. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
nvd
CVE-2002-0062P4HIGHCVSS 7.2v2.22002-03-08
CVE-2002-0062 [HIGH] CWE-120 CVE-2002-0062: Buffer overflow in ncurses 5.0, and the ncurses4 compatibility package as used in Red Hat Linux, all Buffer overflow in ncurses 5.0, and the ncurses4 compatibility package as used in Red Hat Linux, allows local users to gain privileges, related to "routines for moving the physical cursor and scrolling."
nvd
CVE-2020-6441P4MEDIUMCVSS 4.3v9.0v10.02020-04-13
CVE-2020-6441 [MEDIUM] CWE-276 CVE-2020-6441: Insufficient policy enforcement in omnibox in Google Chrome prior to 81.0.4044.92 allowed a remote a Insufficient policy enforcement in omnibox in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass security UI via a crafted HTML page.
nvd
CVE-2020-6437P4MEDIUMCVSS 4.3v9.0v10.02020-04-13
CVE-2020-6437 [MEDIUM] CVE-2020-6437: Inappropriate implementation in WebView in Google Chrome prior to 81.0.4044.92 allowed a remote atta Inappropriate implementation in WebView in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to spoof security UI via a crafted application.
nvd
Debian Linux vulnerabilities | cvebase