cbcvebase.

Debian Linux vulnerabilities

9,953 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358

Vulnerabilities

Page 44 of 498
CVE-2011-0419P3MEDIUMCVSS 4.3PoCv5.0v6.0+1 more2011-05-16
CVE-2011-0419 [MEDIUM] CWE-770 CVE-2011-0419: Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portabl Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apache HTTP Server before 2.2.18, and in fnmatch.c in libc in NetBSD 5.1, OpenBSD 4.8, FreeBSD, Apple Mac OS X 10.6, Oracle Solaris 10, and Android, allows context-dependent attackers to cause a denial of ser
nvd
CVE-2018-8034P3HIGHCVSS 7.5v8.0v9.02018-08-01
CVE-2018-8034 [HIGH] CWE-295 CVE-2018-8034: The host name verification when using TLS with the WebSocket client was missing. It is now enabled b The host name verification when using TLS with the WebSocket client was missing. It is now enabled by default. Versions Affected: Apache Tomcat 9.0.0.M1 to 9.0.9, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, and 7.0.35 to 7.0.88.
nvd
CVE-2022-26496P3CRITICALCVSS 9.8v10.0v11.02022-03-06
CVE-2022-26496 [CRITICAL] CWE-787 CVE-2022-26496: In nbd-server in nbd before 3.24, there is a stack-based buffer overflow. An attacker can cause a bu In nbd-server in nbd before 3.24, there is a stack-based buffer overflow. An attacker can cause a buffer overflow in the parsing of the name field by sending a crafted NBD_OPT_INFO or NBD_OPT_GO message with an large value as the length of the name.
nvd
CVE-2022-0730P3CRITICALCVSS 9.8v9.0v10.0+1 more2022-03-03
CVE-2022-0730 [CRITICAL] CWE-287 CVE-2022-0730: Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types. Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types.
nvd
CVE-2019-12468P3CRITICALCVSS 9.8v9.02019-07-10
CVE-2019-12468 [CRITICAL] CWE-306 CVE-2019-12468: An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.27.0 through 1.32.1. Di An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.27.0 through 1.32.1. Directly POSTing to Special:ChangeEmail would allow for bypassing re-authentication, allowing for potential account takeover.
nvd
CVE-2016-8864P3HIGHCVSS 7.5v8.02016-11-02
CVE-2016-8864 [HIGH] CWE-617 CVE-2016-8864: named in ISC BIND 9.x before 9.9.9-P4, 9.10.x before 9.10.4-P4, and 9.11.x before 9.11.0-P1 allows r named in ISC BIND 9.x before 9.9.9-P4, 9.10.x before 9.10.4-P4, and 9.11.x before 9.11.0-P1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a DNAME record in the answer section of a response to a recursive query, related to db.c and resolver.c.
nvd
CVE-2018-12892P3CRITICALCVSS 9.9v9.02018-07-02
CVE-2018-12892 [CRITICAL] CWE-200 CVE-2018-12892: An issue was discovered in Xen 4.7 through 4.10.x. libxl fails to pass the readonly flag to qemu whe An issue was discovered in Xen 4.7 through 4.10.x. libxl fails to pass the readonly flag to qemu when setting up a SCSI disk, due to what was probably an erroneous merge conflict resolution. Malicious guest administrators or (in some situations) users may be able to write to supposedly read-only disk images. Only emulated SCSI disks (specified as
nvd
CVE-2021-35474P3CRITICALCVSS 9.8v10.02021-06-30
CVE-2021-35474 [CRITICAL] CWE-121 CVE-2021-35474: Stack-based Buffer Overflow vulnerability in cachekey plugin of Apache Traffic Server. This issue af Stack-based Buffer Overflow vulnerability in cachekey plugin of Apache Traffic Server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.
nvd
CVE-2022-32292P3CRITICALCVSS 9.8v11.02022-08-03
CVE-2022-32292 [CRITICAL] CWE-787 CVE-2022-32292: In ConnMan through 1.41, remote attackers able to send HTTP requests to the gweb component are able In ConnMan through 1.41, remote attackers able to send HTTP requests to the gweb component are able to exploit a heap-based buffer overflow in received_data to execute code.
nvd
CVE-2018-8787P3CRITICALCVSS 9.8v8.02018-11-29
CVE-2018-8787 [CRITICAL] CWE-680 CVE-2018-8787: FreeRDP prior to version 2.0.0-rc4 contains an Integer Overflow that leads to a Heap-Based Buffer Ov FreeRDP prior to version 2.0.0-rc4 contains an Integer Overflow that leads to a Heap-Based Buffer Overflow in function gdi_Bitmap_Decompress() and results in a memory corruption and probably even a remote code execution.
nvd
CVE-2016-0705P3CRITICALCVSS 9.8v7.0v8.02016-03-03
CVE-2016-0705 [CRITICAL] CVE-2016-0705: Double free vulnerability in the dsa_priv_decode function in crypto/dsa/dsa_ameth.c in OpenSSL 1.0.1 Double free vulnerability in the dsa_priv_decode function in crypto/dsa/dsa_ameth.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a malformed DSA private key.
nvd
CVE-2019-15941P3CRITICALCVSS 9.8v10.02019-09-25
CVE-2019-15941 [CRITICAL] CWE-863 CVE-2019-15941: OpenID Connect Issuer in LemonLDAP::NG 2.x through 2.0.5 may allow an attacker to bypass access cont OpenID Connect Issuer in LemonLDAP::NG 2.x through 2.0.5 may allow an attacker to bypass access control rules via a crafted OpenID Connect authorization request. To be vulnerable, there must exist an OIDC Relaying party within the LemonLDAP configuration with weaker access control rules than the target RP, and no filtering on redirection URIs.
nvd
CVE-2018-8786P3CRITICALCVSS 9.8v8.02018-11-29
CVE-2018-8786 [CRITICAL] CWE-680 CVE-2018-8786: FreeRDP prior to version 2.0.0-rc4 contains an Integer Truncation that leads to a Heap-Based Buffer FreeRDP prior to version 2.0.0-rc4 contains an Integer Truncation that leads to a Heap-Based Buffer Overflow in function update_read_bitmap_update() and results in a memory corruption and probably even a remote code execution.
nvd
CVE-2022-24754P3CRITICALCVSS 9.8v9.02022-03-11
CVE-2022-24754 [CRITICAL] CWE-120 CVE-2022-24754: PJSIP is a free and open source multimedia communication library written in C language. In versions PJSIP is a free and open source multimedia communication library written in C language. In versions prior to and including 2.12 PJSIP there is a stack-buffer overflow vulnerability which only impacts PJSIP users who accept hashed digest credentials (credentials with data_type `PJSIP_CRED_DATA_DIGEST`). This issue has been patched in the master bran
nvd
CVE-2023-46850P3CRITICALCVSS 9.8v12.02023-11-11
CVE-2023-46850 [CRITICAL] CWE-416 CVE-2023-46850: Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buff Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending network buffers to a remote peer.
nvd
CVE-2018-20177P3CRITICALCVSS 9.8v8.0v9.02019-03-15
CVE-2018-20177 [CRITICAL] CWE-190 CVE-2018-20177: rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to a Heap-Based rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to a Heap-Based Buffer Overflow in the function rdp_in_unistr() and results in memory corruption and possibly even a remote code execution.
nvd
CVE-2021-43008P3HIGHCVSS 7.5v9.02022-04-05
CVE-2021-43008 [HIGH] CVE-2021-43008: Improper Access Control in Adminer versions 1.12.0 to 4.6.2 (fixed in version 4.6.3) allows an attac Improper Access Control in Adminer versions 1.12.0 to 4.6.2 (fixed in version 4.6.3) allows an attacker to achieve Arbitrary File Read on the remote server by requesting the Adminer to connect to a remote MySQL database.
nvd
CVE-2018-1057P3HIGHCVSS 8.8v8.02018-03-13
CVE-2018-1057 [HIGH] CWE-863 CVE-2018-1057: On a Samba 4 AD DC the LDAP server in all versions of Samba from 4.0.0 onwards incorrectly validates On a Samba 4 AD DC the LDAP server in all versions of Samba from 4.0.0 onwards incorrectly validates permissions to modify passwords over LDAP allowing authenticated users to change any other users' passwords, including administrative users and privileged service accounts (eg Domain Controllers).
nvd
CVE-2022-21664P3HIGHCVSS 8.8v9.0v10.0+1 more2022-01-06
CVE-2022-21664 [HIGH] CWE-89 CVE-2022-21664: WordPress is a free and open-source content management system written in PHP and paired with a Maria WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to lack of proper sanitization in one of the classes, there's potential for unintended SQL queries to be executed. This has been patched in WordPress version 5.8.3. Older affected versions are also fixed via security release, that go bac
nvd
CVE-2018-8795P3CRITICALCVSS 9.8v8.0v9.02019-02-05
CVE-2018-8795 [CRITICAL] CWE-680 CVE-2018-8795: rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to a Heap-Based rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to a Heap-Based Buffer Overflow in function process_bitmap_updates() and results in a memory corruption and probably even a remote code execution.
nvd
Debian Linux vulnerabilities | cvebase