Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 46 of 498
CVE-2022-22822P3CRITICALCVSS 9.8v10.0v11.02022-01-10
CVE-2022-22822 [CRITICAL] CWE-190 CVE-2022-22822: addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
nvd
CVE-2016-9131P3HIGHCVSS 7.5v8.02017-01-12
CVE-2016-9131 [HIGH] CWE-20 CVE-2016-9131: named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x before 9.11.0-P2 allows r
named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x before 9.11.0-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed response to an RTYPE ANY query.
nvd
CVE-2022-24805P3HIGHCVSS 8.8v10.0v11.02024-04-16
CVE-2022-24805 [HIGH] CWE-120 CVE-2022-24805: net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a buffer overflow in the handling of the `INDEX` of `NET-SNMP-VACM-MIB` can cause an out-of-bounds memory access. A user with read-only credentials can exploit the issue. Version 5.9.2 contains a patch. Users should use strong SNMPv3 credentials
nvd
CVE-2017-12936P3HIGHCVSS 8.8v8.0v9.02017-08-18
CVE-2017-12936 [HIGH] CWE-416 CVE-2017-12936: The ReadWMFImage function in coders/wmf.c in GraphicsMagick 1.3.26 has a use-after-free issue for da
The ReadWMFImage function in coders/wmf.c in GraphicsMagick 1.3.26 has a use-after-free issue for data associated with exception reporting.
nvd
CVE-2020-14001P3CRITICALCVSS 9.8v9.0v10.02020-07-17
CVE-2020-14001 [CRITICAL] CWE-862 CVE-2020-14001: The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by de
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Th
nvd
CVE-2015-8327P3HIGHCVSS 7.5v8.02015-12-17
CVE-2015-8327 [HIGH] CVE-2015-8327: Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.2.0 and
Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.2.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via ` (backtick) characters in a print job.
nvd
CVE-2021-38503P3CRITICALCVSS 10.0v9.0v10.0+1 more2021-12-08
CVE-2021-38503 [CRITICAL] CWE-863 CVE-2021-38503: The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypas
The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypass restrictions such as executing scripts or navigating the top-level frame. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
nvd
CVE-2023-5482P3HIGHCVSS 8.8v11.0v12.02023-11-01
CVE-2023-5482 [HIGH] CWE-345 CVE-2023-5482: Insufficient data validation in USB in Google Chrome prior to 119.0.6045.105 allowed a remote attack
Insufficient data validation in USB in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2022-23219P3CRITICALCVSS 9.8v10.02022-01-14
CVE-2022-23219 [CRITICAL] CWE-120 CVE-2022-23219: The deprecated compatibility function clnt_create in the sunrpc module of the GNU C Library (aka gli
The deprecated compatibility function clnt_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its hostname argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a stack protector enabled) arbitrar
nvd
CVE-2017-15398P3CRITICALCVSS 9.8v8.0v9.0+1 more2018-08-28
CVE-2017-15398 [CRITICAL] CWE-119 CVE-2017-15398: A stack buffer overflow in the QUIC networking stack in Google Chrome prior to 62.0.3202.89 allowed
A stack buffer overflow in the QUIC networking stack in Google Chrome prior to 62.0.3202.89 allowed a remote attacker to gain code execution via a malicious server.
nvd
CVE-2011-2748P3HIGHCVSS 7.8v5.0v6.0+1 more2011-08-15
CVE-2011-2748 [HIGH] CWE-20 CVE-2011-2748: The server in ISC DHCP 3.x and 4.x before 4.2.2, 3.1-ESV before 3.1-ESV-R3, and 4.1-ESV before 4.1-E
The server in ISC DHCP 3.x and 4.x before 4.2.2, 3.1-ESV before 3.1-ESV-R3, and 4.1-ESV before 4.1-ESV-R3 allows remote attackers to cause a denial of service (daemon exit) via a crafted DHCP packet.
nvd
CVE-2011-2749P3HIGHCVSS 7.8v5.0v6.0+1 more2011-08-15
CVE-2011-2749 [HIGH] CWE-20 CVE-2011-2749: The server in ISC DHCP 3.x and 4.x before 4.2.2, 3.1-ESV before 3.1-ESV-R3, and 4.1-ESV before 4.1-E
The server in ISC DHCP 3.x and 4.x before 4.2.2, 3.1-ESV before 3.1-ESV-R3, and 4.1-ESV before 4.1-ESV-R3 allows remote attackers to cause a denial of service (daemon exit) via a crafted BOOTP packet.
nvd
CVE-2018-7440P3CRITICALCVSS 9.8v7.02018-02-23
CVE-2018-7440 [CRITICAL] CVE-2018-7440: An issue was discovered in Leptonica through 1.75.3. The gplotMakeOutput function allows command inj
An issue was discovered in Leptonica through 1.75.3. The gplotMakeOutput function allows command injection via a $(command) approach in the gplot rootname argument. This issue exists because of an incomplete fix for CVE-2018-3836.
nvd
CVE-2014-8650P3CRITICALCVSS 9.8v8.0v9.0+1 more2019-12-15
CVE-2014-8650 [CRITICAL] CWE-287 CVE-2014-8650: python-requests-Kerberos through 0.5 does not handle mutual authentication
python-requests-Kerberos through 0.5 does not handle mutual authentication
nvd
CVE-2016-1285P3MEDIUMCVSS 6.8v7.0v8.0+1 more2016-03-09
CVE-2016-1285 [MEDIUM] CVE-2016-1285: named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME rec
named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed packet to the rndc (aka control channel) interface, related to alist.c and sexpr.c.
nvd
CVE-2020-35605P3CRITICALCVSS 9.8v10.02020-12-21
CVE-2020-35605 [CRITICAL] CVE-2020-35605: The Graphics Protocol feature in graphics.c in kitty before 0.19.3 allows remote attackers to execut
The Graphics Protocol feature in graphics.c in kitty before 0.19.3 allows remote attackers to execute arbitrary code because a filename containing special characters can be included in an error message.
nvd
CVE-2020-24379P3CRITICALCVSS 9.8v9.0v10.02020-09-09
CVE-2020-24379 [CRITICAL] CWE-611 CVE-2020-24379: WebDAV implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to XXE injection.
WebDAV implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to XXE injection.
nvd
CVE-2017-12187P3CRITICALCVSS 9.8v8.0v9.02018-01-24
CVE-2017-12187 [CRITICAL] CWE-391 CVE-2017-12187: xorg-x11-server before 1.19.5 was missing length validation in RENDER extension allowing malicious X
xorg-x11-server before 1.19.5 was missing length validation in RENDER extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
nvd
CVE-2012-4384P3MEDIUMCVSS 6.1PoCv8.02019-11-13
CVE-2012-4384 [MEDIUM] CWE-79 CVE-2012-4384: letodms has multiple XSS issues: Reflected XSS in Login Page, Stored XSS in Document Owner/User name
letodms has multiple XSS issues: Reflected XSS in Login Page, Stored XSS in Document Owner/User name, Stored XSS in Calendar
nvd
CVE-2022-1664P3CRITICALCVSS 9.8v9.0v10.0+1 more2022-05-26
CVE-2022-1664 [CRITICAL] CWE-22 CVE-2022-1664: Dpkg::Source::Archive in dpkg, the Debian package management system, before version 1.21.8, 1.20.10,
Dpkg::Source::Archive in dpkg, the Debian package management system, before version 1.21.8, 1.20.10, 1.19.8, 1.18.26 is prone to a directory traversal vulnerability. When extracting untrusted source packages in v2 and v3 source package formats that include a debian.tar, the in-place extraction can lead to directory traversal situations on specially c
nvd