cbcvebase.

Debian Linux vulnerabilities

9,953 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358

Vulnerabilities

Page 45 of 498
CVE-2015-0408P3CRITICALCVSS 10.0v7.0v8.02015-01-21
CVE-2015-0408 [CRITICAL] CVE-2015-0408: Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to RMI.
nvd
CVE-2015-0258P3HIGHCVSS 8.8v8.02020-02-17
CVE-2015-0258 [HIGH] CWE-434 CVE-2015-0258: Multiple incomplete blacklist vulnerabilities in the avatar upload functionality in manageuser.php i Multiple incomplete blacklist vulnerabilities in the avatar upload functionality in manageuser.php in Collabtive before 2.1 allow remote authenticated users to execute arbitrary code by uploading a file with a (1) .php3, (2) .php4, (3) .php5, or (4) .phtml extension.
nvd
CVE-2018-8793P3CRITICALCVSS 9.8v8.0v9.02019-02-05
CVE-2018-8793 [CRITICAL] CWE-122 CVE-2018-8793: rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function cssp_r rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function cssp_read_tsrequest() that results in a memory corruption and probably even a remote code execution.
nvd
CVE-2018-8800P3CRITICALCVSS 9.8v8.0v9.02019-02-05
CVE-2018-8800 [CRITICAL] CWE-122 CVE-2018-8800: rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function ui_cli rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function ui_clip_handle_data() that results in a memory corruption and probably even a remote code execution.
nvd
CVE-2021-40874P3CRITICALCVSS 9.8v10.02022-07-18
CVE-2021-40874 [CRITICAL] CWE-287 CVE-2021-40874: An issue was discovered in LemonLDAP::NG (aka lemonldap-ng) 2.0.13. When using the RESTServer plug-i An issue was discovered in LemonLDAP::NG (aka lemonldap-ng) 2.0.13. When using the RESTServer plug-in to operate a REST password validation service (for another LemonLDAP::NG instance, for example) and using the Kerberos authentication method combined with another method with the Combination authentication plug-in, any password will be recognized
nvd
CVE-2020-17527P3HIGHCVSS 7.5v9.0v10.02020-12-03
CVE-2020-17527 [HIGH] CWE-200 CVE-2020-17527: While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream received on an HTTP/2 connection for the request associated with the subsequent stream. While this would most likely lead to an error and the closure of the
nvd
CVE-2018-10929P3HIGHCVSS 8.8v8.0v9.02018-09-04
CVE-2018-10929 [HIGH] CWE-20 CVE-2018-10929: A flaw was found in RPC request using gfs2_create_req in glusterfs server. An authenticated attacker A flaw was found in RPC request using gfs2_create_req in glusterfs server. An authenticated attacker could use this flaw to create arbitrary files and execute arbitrary code on glusterfs server nodes.
nvd
CVE-2016-2195P3CRITICALCVSS 9.8v8.02016-05-13
CVE-2016-2195 [CRITICAL] CWE-119 CVE-2016-2195: Integer overflow in the PointGFp constructor in Botan before 1.10.11 and 1.11.x before 1.11.27 allow Integer overflow in the PointGFp constructor in Botan before 1.10.11 and 1.11.x before 1.11.27 allows remote attackers to overwrite memory and possibly execute arbitrary code via a crafted ECC point, which triggers a heap-based buffer overflow.
nvd
CVE-2017-1000487P3CRITICALCVSS 9.8v7.0v8.0+1 more2018-01-03
CVE-2017-1000487 [CRITICAL] CWE-78 CVE-2017-1000487: Plexus-utils before 3.0.16 is vulnerable to command injection because it does not correctly process Plexus-utils before 3.0.16 is vulnerable to command injection because it does not correctly process the contents of double quoted strings.
nvd
CVE-2021-31215P3HIGHCVSS 8.8v9.02021-05-13
CVE-2021-31215 [HIGH] CVE-2021-31215: SchedMD Slurm before 20.02.7 and 20.03.x through 20.11.x before 20.11.7 allows remote code execution SchedMD Slurm before 20.02.7 and 20.03.x through 20.11.x before 20.11.7 allows remote code execution as SlurmUser because use of a PrologSlurmctld or EpilogSlurmctld script leads to environment mishandling.
nvd
CVE-2018-5950P3MEDIUMCVSS 6.1PoCv7.0v8.0+1 more2018-01-23
CVE-2018-5950 [MEDIUM] CWE-79 CVE-2018-5950: Cross-site scripting (XSS) vulnerability in the web UI in Mailman before 2.1.26 allows remote attack Cross-site scripting (XSS) vulnerability in the web UI in Mailman before 2.1.26 allows remote attackers to inject arbitrary web script or HTML via a user-options URL.
nvd
CVE-2023-4430P3HIGHCVSS 8.8v11.0v12.02023-08-23
CVE-2023-4430 [HIGH] CWE-416 CVE-2023-4430: Use after free in Vulkan in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to poten Use after free in Vulkan in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2022-29501P3HIGHCVSS 8.8v11.02022-05-05
CVE-2022-29501 [HIGH] CVE-2022-29501: SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Escalation of Privi SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Escalation of Privileges and code execution.
nvd
CVE-2019-1010238P3CRITICALCVSS 9.8v10.02019-07-19
CVE-2019-1010238 [CRITICAL] CWE-787 CVE-2019-1010238: Gnome Pango 1.42 and later is affected by: Buffer Overflow. The impact is: The heap based buffer ove Gnome Pango 1.42 and later is affected by: Buffer Overflow. The impact is: The heap based buffer overflow can be used to get code execution. The component is: function name: pango_log2vis_get_embedding_levels, assignment of nchars and the loop condition. The attack vector is: Bug can be used when application pass invalid utf-8 strings to funct
nvd
CVE-2022-46344P3HIGHCVSS 8.8v11.02022-12-14
CVE-2022-46344 [HIGH] CWE-125 CVE-2022-46344: A vulnerability was found in X.Org. This security flaw occurs because the handler for the XIChangePr A vulnerability was found in X.Org. This security flaw occurs because the handler for the XIChangeProperty request has a length-validation issues, resulting in out-of-bounds memory reads and potential information disclosure. This issue can lead to local privileges elevation on systems where the X server is running privileged and remote code execution
nvd
CVE-2018-10926P3HIGHCVSS 8.8v8.0v9.02018-09-04
CVE-2018-10926 [HIGH] CWE-20 CVE-2018-10926: A flaw was found in RPC request using gfs3_mknod_req supported by glusterfs server. An authenticated A flaw was found in RPC request using gfs3_mknod_req supported by glusterfs server. An authenticated attacker could use this flaw to write files to an arbitrary location via path traversal and execute arbitrary code on a glusterfs server node.
nvd
CVE-2018-1000120P3CRITICALCVSS 9.8v7.0v8.0+1 more2018-03-14
CVE-2018-1000120 [CRITICAL] CWE-787 CVE-2018-1000120: A buffer overflow exists in curl 7.12.3 to and including curl 7.58.0 in the FTP URL handling that al A buffer overflow exists in curl 7.12.3 to and including curl 7.58.0 in the FTP URL handling that allows an attacker to cause a denial of service or worse.
nvd
CVE-2015-7512P3CRITICALCVSS 9.0v7.0v8.02016-01-08
CVE-2015-7512 [CRITICAL] CWE-120 CVE-2015-7512: Buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU, when a guest NIC has a larg Buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU, when a guest NIC has a larger MTU, allows remote attackers to cause a denial of service (guest OS crash) or execute arbitrary code via a large packet.
nvd
CVE-2018-20346P3HIGHCVSS 8.1v8.02018-12-21
CVE-2018-20346 [HIGH] CWE-190 CVE-2018-20346: SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and result SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries that occur after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases), aka Magell
nvd
CVE-2015-0857P3CRITICALCVSS 9.8v8.02016-05-06
CVE-2015-0857 [CRITICAL] CWE-77 CVE-2015-0857: Cool Projects TarDiff allows remote attackers to execute arbitrary commands via shell metacharacters Cool Projects TarDiff allows remote attackers to execute arbitrary commands via shell metacharacters in the name of a (1) tar file or (2) file within a tar file.
nvd
Debian Linux vulnerabilities | cvebase