Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 43 of 498
CVE-2018-18505P3CRITICALCVSS 10.0v8.0v9.02019-02-05
CVE-2018-18505 [CRITICAL] CVE-2018-18505: An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authenti
An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authentication to communication between IPC endpoints and server parents during IPC process creation. This authentication is insufficient for channels created after the IPC process is started, leading to the authentication not being correctly applied to later chann
nvd
CVE-2017-5522P3CRITICALCVSS 9.8v8.02017-03-15
CVE-2017-5522 [CRITICAL] CWE-119 CVE-2017-5522: Stack-based buffer overflow in MapServer before 6.0.6, 6.2.x before 6.2.4, 6.4.x before 6.4.5, and 7
Stack-based buffer overflow in MapServer before 6.0.6, 6.2.x before 6.2.4, 6.4.x before 6.4.5, and 7.0.x before 7.0.4 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via vectors involving WFS get feature requests.
nvd
CVE-2022-23218P3CRITICALCVSS 9.8v10.02022-01-14
CVE-2022-23218 [CRITICAL] CWE-120 CVE-2022-23218: The deprecated compatibility function svcunix_create in the sunrpc module of the GNU C Library (aka
The deprecated compatibility function svcunix_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its path argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a stack protector enabled) arbitrary
nvd
CVE-2017-9993P3HIGHCVSS 7.5v8.0v9.02017-06-28
CVE-2017-9993 [HIGH] CWE-200 CVE-2017-9993: FFmpeg before 2.8.12, 3.0.x and 3.1.x before 3.1.9, 3.2.x before 3.2.6, and 3.3.x before 3.3.2 does
FFmpeg before 2.8.12, 3.0.x and 3.1.x before 3.1.9, 3.2.x before 3.2.6, and 3.3.x before 3.3.2 does not properly restrict HTTP Live Streaming filename extensions and demuxer names, which allows attackers to read arbitrary files via crafted playlist data.
nvd
CVE-2020-36179P3HIGHCVSS 8.1v9.02021-01-07
CVE-2020-36179 [HIGH] CWE-502 CVE-2020-36179: FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadg
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapterCPDS.
nvd
CVE-2023-6185P3HIGHCVSS 8.8v11.0v12.02023-12-11
CVE-2023-6185 [HIGH] CVE-2023-6185: Improper Input Validation vulnerability in GStreamer integration of The Document Foundation LibreOff
Improper Input Validation vulnerability in GStreamer integration of The Document Foundation LibreOffice allows an attacker to execute arbitrary GStreamer plugins.
In affected versions the filename of the embedded video is not sufficiently escaped when passed to GStreamer enabling an attacker to run arbitrary gstreamer plugins depending on what plugins are inst
nvd
CVE-2018-1000544P3CRITICALCVSS 9.8v8.0v9.02018-06-26
CVE-2018-1000544 [CRITICAL] CWE-59 CVE-2018-1000544: rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::F
rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary files to the filesystem. This attack appear to be exploitable via If a site allows uploading of .zip files , an attacker can upload a malicious file that contains symlinks or files with absolute pa
nvd
CVE-2015-0244P3CRITICALCVSS 9.8v7.0v8.02020-01-27
CVE-2015-0244 [CRITICAL] CWE-89 CVE-2015-0244: PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x be
PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 does not properly handle errors while reading a protocol message, which allows remote attackers to conduct SQL injection attacks via crafted binary data in a parameter and causing an error, which triggers the loss of synchronization and part
nvd
CVE-2022-32221P3CRITICALCVSS 9.8v10.0v11.02022-12-05
CVE-2022-32221 [CRITICAL] CWE-200 CVE-2022-32221: When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION
When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously was used to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either
nvd
CVE-2019-3462P3HIGHCVSS 8.1v8.0v9.02019-01-28
CVE-2019-3462 [HIGH] CWE-350 CVE-2019-3462: Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1.4.8 and ea
Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1.4.8 and earlier can lead to content injection by a MITM attacker, potentially leading to remote code execution on the target machine.
nvd
CVE-2020-28035P3CRITICALCVSS 9.8v10.02020-11-02
CVE-2020-28035 [CRITICAL] CVE-2020-28035: WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC.
WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC.
nvd
CVE-2017-12180P3CRITICALCVSS 9.8v8.0v9.02018-01-24
CVE-2017-12180 [CRITICAL] CWE-391 CVE-2017-12180: xorg-x11-server before 1.19.5 was missing length validation in XFree86 VidModeExtension allowing mal
xorg-x11-server before 1.19.5 was missing length validation in XFree86 VidModeExtension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
nvd
CVE-2017-12182P3CRITICALCVSS 9.8v8.0v9.02018-01-24
CVE-2017-12182 [CRITICAL] CWE-391 CVE-2017-12182: xorg-x11-server before 1.19.5 was missing length validation in XFree86 DRI extension allowing malici
xorg-x11-server before 1.19.5 was missing length validation in XFree86 DRI extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
nvd
CVE-2017-12181P3CRITICALCVSS 9.8v8.0v9.02018-01-24
CVE-2017-12181 [CRITICAL] CWE-391 CVE-2017-12181: xorg-x11-server before 1.19.5 was missing length validation in XFree86 DGA extension allowing malici
xorg-x11-server before 1.19.5 was missing length validation in XFree86 DGA extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
nvd
CVE-2017-12183P3CRITICALCVSS 9.8v8.0v9.02018-01-24
CVE-2017-12183 [CRITICAL] CWE-391 CVE-2017-12183: xorg-x11-server before 1.19.5 was missing length validation in XFIXES extension allowing malicious X
xorg-x11-server before 1.19.5 was missing length validation in XFIXES extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
nvd
CVE-2017-12184P3CRITICALCVSS 9.8v8.0v9.02018-01-24
CVE-2017-12184 [CRITICAL] CWE-391 CVE-2017-12184: xorg-x11-server before 1.19.5 was missing length validation in XINERAMA extension allowing malicious
xorg-x11-server before 1.19.5 was missing length validation in XINERAMA extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
nvd
CVE-2017-12176P3CRITICALCVSS 9.8v8.0v9.02018-01-24
CVE-2017-12176 [CRITICAL] CWE-391 CVE-2017-12176: xorg-x11-server before 1.19.5 was missing extra length validation in ProcEstablishConnection functio
xorg-x11-server before 1.19.5 was missing extra length validation in ProcEstablishConnection function allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
nvd
CVE-2016-2774P3MEDIUMCVSS 5.9v8.02016-03-09
CVE-2016-2774 [MEDIUM] CWE-20 CVE-2016-2774: ISC DHCP 4.1.x before 4.1-ESV-R13 and 4.2.x and 4.3.x before 4.3.4 does not restrict the number of c
ISC DHCP 4.1.x before 4.1-ESV-R13 and 4.2.x and 4.3.x before 4.3.4 does not restrict the number of concurrent TCP sessions, which allows remote attackers to cause a denial of service (INSIST assertion failure or request-processing outage) by establishing many sessions.
nvd
CVE-2023-25725P3CRITICALCVSS 9.1v10.0v11.02023-02-14
CVE-2023-25725 [CRITICAL] CWE-444 CVE-2023-25725: HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently l
HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently lost in some situations, aka "request smuggling." The HTTP header parsers in HAProxy may accept empty header field names, which could be used to truncate the list of HTTP headers and thus make some headers disappear after being parsed and processed f
nvd
CVE-2017-11509P3HIGHCVSS 8.8v7.0v8.0+1 more2018-03-28
CVE-2017-11509 [HIGH] CWE-89 CVE-2017-11509: An authenticated remote attacker can execute arbitrary code in Firebird SQL Server versions 2.5.7 an
An authenticated remote attacker can execute arbitrary code in Firebird SQL Server versions 2.5.7 and 3.0.2 by executing a malformed SQL statement.
nvd