cbcvebase.

Debian Linux vulnerabilities

9,953 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358

Vulnerabilities

Page 47 of 498
CVE-2022-26520P3CRITICALCVSS 9.8v10.0v11.02022-03-10
CVE-2022-26520 [CRITICAL] CVE-2022-26520: In pgjdbc before 42.3.3, an attacker (who controls the jdbc URL or properties) can call java.util.lo In pgjdbc before 42.3.3, an attacker (who controls the jdbc URL or properties) can call java.util.logging.FileHandler to write to arbitrary files through the loggerFile and loggerLevel connection properties. An example situation is that an attacker could create an executable JSP file under a Tomcat web root. NOTE: the vendor's position is that there is no
nvd
CVE-2022-28347P3CRITICALCVSS 9.8v11.02022-04-12
CVE-2022-28347 [CRITICAL] CWE-89 CVE-2022-28347: A SQL injection issue was discovered in QuerySet.explain() in Django 2.2 before 2.2.28, 3.2 before 3 A SQL injection issue was discovered in QuerySet.explain() in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. This occurs by passing a crafted dictionary (with dictionary expansion) as the **options argument, and placing the injection payload in an option name.
nvd
CVE-2019-12838P3CRITICALCVSS 9.8v8.0v9.0+1 more2019-07-11
CVE-2019-12838 [CRITICAL] CWE-89 CVE-2019-12838: SchedMD Slurm 17.11.x, 18.08.0 through 18.08.7, and 19.05.0 allows SQL Injection. SchedMD Slurm 17.11.x, 18.08.0 through 18.08.7, and 19.05.0 allows SQL Injection.
nvd
CVE-2019-14896P3CRITICALCVSS 9.8v8.02019-11-27
CVE-2019-14896 [CRITICAL] CWE-122 CVE-2019-14896: A heap-based buffer overflow vulnerability was found in the Linux kernel, version kernel-2.6.32, in A heap-based buffer overflow vulnerability was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip driver. A remote attacker could cause a denial of service (system crash) or, possibly execute arbitrary code, when the lbs_ibss_join_existing function is called after a STA connects to an AP.
nvd
CVE-2021-35368P3CRITICALCVSS 9.8v10.02021-11-05
CVE-2021-35368 [CRITICAL] CVE-2021-35368: OWASP ModSecurity Core Rule Set 3.1.x before 3.1.2, 3.2.x before 3.2.1, and 3.3.x before 3.3.2 is af OWASP ModSecurity Core Rule Set 3.1.x before 3.1.2, 3.2.x before 3.2.1, and 3.3.x before 3.3.2 is affected by a Request Body Bypass via a trailing pathname.
nvd
CVE-2020-24660P3CRITICALCVSS 9.8v10.02020-09-14
CVE-2020-24660 [CRITICAL] CWE-425 CVE-2020-24660: An issue was discovered in LemonLDAP::NG through 2.0.8, when NGINX is used. An attacker may bypass U An issue was discovered in LemonLDAP::NG through 2.0.8, when NGINX is used. An attacker may bypass URL-based access control to protected Virtual Hosts by submitting a non-normalized URI. This also affects versions before 0.5.2 of the "Lemonldap::NG handler for Node.js" package.
nvd
CVE-2020-35728P3HIGHCVSS 8.1v9.02020-12-27
CVE-2020-35728 [HIGH] CWE-502 CVE-2020-35728: FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadg FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool (aka embedded Xalan in org.glassfish.web/javax.servlet.jsp.jstl).
nvd
CVE-2018-20182P3CRITICALCVSS 9.8v8.0v9.02019-03-15
CVE-2018-20182 [CRITICAL] CWE-119 CVE-2018-20182: rdesktop versions up to and including v1.8.3 contain a Buffer Overflow over the global variables in rdesktop versions up to and including v1.8.3 contain a Buffer Overflow over the global variables in the function seamless_process_line() that results in memory corruption and probably even a remote code execution.
nvd
CVE-2017-0918P3HIGHCVSS 8.8v9.02018-03-21
CVE-2017-0918 [HIGH] CWE-23 CVE-2017-0918: Gitlab Community Edition version 10.3 is vulnerable to a path traversal issue in the GitLab CI runne Gitlab Community Edition version 10.3 is vulnerable to a path traversal issue in the GitLab CI runner component resulting in remote code execution.
nvd
CVE-2018-1000007P3CRITICALCVSS 9.8v7.0v8.0+1 more2018-01-24
CVE-2018-1000007 [CRITICAL] CWE-601 CVE-2018-1000007: libcurl 7.1 through 7.57.0 might accidentally leak authentication data to third parties. When asked libcurl 7.1 through 7.57.0 might accidentally leak authentication data to third parties. When asked to send custom headers in its HTTP requests, libcurl will send that set of headers first to the host in the initial URL but also, if asked to follow redirects and a 30X HTTP response code is returned, to the host mentioned in URL in the `Location
nvd
CVE-2013-2745P3CRITICALCVSS 9.8v8.0v9.0+1 more2019-12-04
CVE-2013-2745 [CRITICAL] CWE-89 CVE-2013-2745: An SQL Injection vulnerability exists in MiniDLNA prior to 1.1.0 An SQL Injection vulnerability exists in MiniDLNA prior to 1.1.0
nvd
CVE-2018-5333P3MEDIUMCVSS 5.5PoCv7.0v8.02018-01-11
CVE-2018-5333 [MEDIUM] CWE-476 CVE-2018-5333: In the Linux kernel through 4.14.13, the rds_cmsg_atomic function in net/rds/rdma.c mishandles cases In the Linux kernel through 4.14.13, the rds_cmsg_atomic function in net/rds/rdma.c mishandles cases where page pinning fails or an invalid address is supplied, leading to an rds_atomic_free_op NULL pointer dereference.
nvd
CVE-2017-2615P3CRITICALCVSS 9.1v7.02018-07-03
CVE-2017-2615 [CRITICAL] CWE-787 CVE-2017-2615: Quick emulator (QEMU) built with the Cirrus CLGD 54xx VGA emulator support is vulnerable to an out-o Quick emulator (QEMU) built with the Cirrus CLGD 54xx VGA emulator support is vulnerable to an out-of-bounds access issue. It could occur while copying VGA data via bitblt copy in backward mode. A privileged user inside a guest could use this flaw to crash the QEMU process resulting in DoS or potentially execute arbitrary code on the host with privi
nvd
CVE-2014-0457P3CRITICALCVSS 10.0v6.0v7.0+1 more2014-04-16
CVE-2014-0457 [CRITICAL] CVE-2014-0457: Unspecified vulnerability in Oracle Java SE 5.0u61, SE 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3. Unspecified vulnerability in Oracle Java SE 5.0u61, SE 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.
nvd
CVE-2023-34967P3MEDIUMCVSS 5.3v11.0v12.02023-07-20
CVE-2023-34967 [MEDIUM] CWE-843 CVE-2023-34967: A Type Confusion vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing S A Type Confusion vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC packets, one encoded data structure is a key-value style dictionary where the keys are character strings, and the values can be any of the supported types in the mdssvc protocol. Due to a lack of type checking in callers of the dal
nvd
CVE-2018-14720P3CRITICALCVSS 9.8v8.0v9.02019-01-02
CVE-2018-14720 [CRITICAL] CWE-502 CVE-2018-14720: FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XX FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization.
nvd
CVE-2024-47606P3CRITICALCVSS 9.8v11.02024-12-12
CVE-2024-47606 [CRITICAL] CWE-190 CVE-2024-47606: GStreamer is a library for constructing graphs of media-handling components. An integer underflow ha GStreamer is a library for constructing graphs of media-handling components. An integer underflow has been detected in the function qtdemux_parse_theora_extension within qtdemux.c. The vulnerability occurs due to an underflow of the gint size variable, which causes size to hold a large unintended value when cast to an unsigned integer. This 32-bit
nvd
CVE-2015-5400P3MEDIUMCVSS 6.8v7.0v8.02015-09-28
CVE-2015-5400 [MEDIUM] CWE-264 CVE-2015-5400: Squid before 3.5.6 does not properly handle CONNECT method peer responses when configured with cache Squid before 3.5.6 does not properly handle CONNECT method peer responses when configured with cache_peer, which allows remote attackers to bypass intended restrictions and gain access to a backend proxy via a CONNECT request.
nvd
CVE-2021-22191P3HIGHCVSS 8.8v9.02021-03-15
CVE-2021-22191 [HIGH] CWE-74 CVE-2021-22191: Improper URL handling in Wireshark 3.4.0 to 3.4.3 and 3.2.0 to 3.2.11 could allow remote code execut Improper URL handling in Wireshark 3.4.0 to 3.4.3 and 3.2.0 to 3.2.11 could allow remote code execution via via packet injection or crafted capture file.
nvd
CVE-2019-20444P3CRITICALCVSS 9.1v8.0v9.0+1 more2020-01-29
CVE-2019-20444 [CRITICAL] CWE-444 CVE-2019-20444: HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header with an incorrect syntax, or might be interpreted as an "invalid fold."
nvd
Debian Linux vulnerabilities | cvebase