Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 48 of 498
CVE-2019-20444P3CRITICALCVSS 9.1v8.0v9.0+1 more2020-01-29
CVE-2019-20444 [CRITICAL] CWE-444 CVE-2019-20444: HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might
HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header with an incorrect syntax, or might be interpreted as an "invalid fold."
nvd
CVE-2022-39955P3CRITICALCVSS 9.8v10.02022-09-20
CVE-2022-39955 [CRITICAL] CWE-863 CVE-2022-39955: The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass by submitting a s
The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass by submitting a specially crafted HTTP Content-Type header field that indicates multiple character encoding schemes. A vulnerable back-end can potentially be exploited by declaring multiple Content-Type "charset" names and therefore bypassing the configurable CRS Co
nvd
CVE-2018-8797P3CRITICALCVSS 9.8v8.0v9.02019-02-05
CVE-2018-8797 [CRITICAL] CWE-122 CVE-2018-8797: rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function proces
rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function process_plane() that results in a memory corruption and probably even a remote code execution.
nvd
CVE-2017-10102P3CRITICALCVSS 9.0v8.0v9.02017-08-08
CVE-2017-10102 [CRITICAL] CVE-2017-10102: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supp
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. While the v
nvd
CVE-2016-4303P3CRITICALCVSS 9.8v8.02016-09-26
CVE-2016-4303 [CRITICAL] CWE-120 CVE-2016-4303: The parse_string function in cjson.c in the cJSON library mishandles UTF8/16 strings, which allows r
The parse_string function in cjson.c in the cJSON library mishandles UTF8/16 strings, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a non-hex character in a JSON string, which triggers a heap-based buffer overflow.
nvd
CVE-2018-3183P3CRITICALCVSS 9.0v9.02018-10-17
CVE-2018-3183 [CRITICAL] CVE-2018-3183: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: S
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Scripting). Supported versions that are affected are Java SE: 8u182 and 11; Java SE Embedded: 8u181; JRockit: R28.3.19. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE
nvd
CVE-2019-12519P3CRITICALCVSS 9.8v9.0v10.02020-04-15
CVE-2019-12519 [CRITICAL] CWE-787 CVE-2019-12519: An issue was discovered in Squid through 4.7. When handling the tag esi:when when ESI is enabled, Sq
An issue was discovered in Squid through 4.7. When handling the tag esi:when when ESI is enabled, Squid calls ESIExpression::Evaluate. This function uses a fixed stack buffer to hold the expression while it's being evaluated. When processing the expression, it could either evaluate the top of the stack, or add a new member to the stack. When addin
nvd
CVE-2022-21722P3CRITICALCVSS 9.1v9.0v10.02022-01-27
CVE-2022-21722 [CRITICAL] CWE-125 CVE-2022-21722: PJSIP is a free and open source multimedia communication library written in C language implementing
PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In version 2.11.1 and prior, there are various cases where it is possible that certain incoming RTP/RTCP packets can potentially cause out-of-bound read access. This issue affects a
nvd
CVE-2019-3465P3HIGHCVSS 8.8v8.0v9.0+1 more2019-11-07
CVE-2019-3465 [HIGH] CWE-347 CVE-2019-3465: Rob Richards XmlSecLibs, all versions prior to v3.0.3, as used for example by SimpleSAMLphp, perform
Rob Richards XmlSecLibs, all versions prior to v3.0.3, as used for example by SimpleSAMLphp, performed incorrect validation of cryptographic signatures in XML messages, allowing an authenticated attacker to impersonate others or elevate privileges by creating a crafted XML message.
nvd
CVE-2018-10904P3HIGHCVSS 8.8v8.0v9.02018-09-04
CVE-2018-10904 [HIGH] CWE-426 CVE-2018-10904: It was found that glusterfs server does not properly sanitize file paths in the "trusted.io-stats-du
It was found that glusterfs server does not properly sanitize file paths in the "trusted.io-stats-dump" extended attribute which is used by the "debug/io-stats" translator. Attacker can use this flaw to create files and execute arbitrary code. To exploit this attacker would require sufficient access to modify the extended attributes of files on a glus
nvd
CVE-2018-10928P3HIGHCVSS 8.8v8.0v9.02018-09-04
CVE-2018-10928 [HIGH] CWE-59 CVE-2018-10928: A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink dest
A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink destinations to point to file paths outside of the gluster volume. An authenticated attacker could use this flaw to create arbitrary symlinks pointing anywhere on the server and execute arbitrary code on glusterfs server nodes.
nvd
CVE-2021-39150P3HIGHCVSS 8.5v9.0v10.0+1 more2021-08-23
CVE-2021-39150 [HIGH] CWE-502 CVE-2021-39150: XStream is a simple library to serialize objects to XML and back again. In affected versions this vu
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream with a Java runtime version 14 to 8. No user is affected, who followed the recommendation to
nvd
CVE-2016-7161P3CRITICALCVSS 9.8v8.02016-10-05
CVE-2016-7161 [CRITICAL] CWE-787 CVE-2016-7161: Heap-based buffer overflow in the .receive callback of xlnx.xps-ethernetlite in QEMU (aka Quick Emul
Heap-based buffer overflow in the .receive callback of xlnx.xps-ethernetlite in QEMU (aka Quick Emulator) allows attackers to execute arbitrary code on the QEMU host via a large ethlite packet.
nvd
CVE-2017-16664P3HIGHCVSS 8.8v7.0v8.0+1 more2017-11-21
CVE-2017-16664 [HIGH] CWE-94 CVE-2017-16664: Code injection exists in Kernel/System/Spelling.pm in Open Ticket Request System (OTRS) 5 before 5.0
Code injection exists in Kernel/System/Spelling.pm in Open Ticket Request System (OTRS) 5 before 5.0.24, 4 before 4.0.26, and 3.3 before 3.3.20. In the agent interface, an authenticated remote attacker can execute shell commands as the webserver user via URL manipulation.
nvd
CVE-2021-30151P3MEDIUMCVSS 6.1PoCv9.02021-04-06
CVE-2021-30151 [MEDIUM] CWE-79 CVE-2021-30151: Sidekiq through 5.1.3 and 6.x through 6.2.0 allows XSS via the queue name of the live-poll feature w
Sidekiq through 5.1.3 and 6.x through 6.2.0 allows XSS via the queue name of the live-poll feature when Internet Explorer is used.
nvd
CVE-2014-4943P3MEDIUMCVSS 6.9PoCv7.02014-07-19
CVE-2014-4943 [MEDIUM] CWE-269 CVE-2014-4943: The PPPoL2TP feature in net/l2tp/l2tp_ppp.c in the Linux kernel through 3.15.6 allows local users to
The PPPoL2TP feature in net/l2tp/l2tp_ppp.c in the Linux kernel through 3.15.6 allows local users to gain privileges by leveraging data-structure differences between an l2tp socket and an inet socket.
nvd
CVE-2017-14632P3CRITICALCVSS 9.8v7.0v9.02017-09-21
CVE-2017-14632 [CRITICAL] CWE-119 CVE-2017-14632: Xiph.Org libvorbis 1.3.5 allows Remote Code Execution upon freeing uninitialized memory in the funct
Xiph.Org libvorbis 1.3.5 allows Remote Code Execution upon freeing uninitialized memory in the function vorbis_analysis_headerout() in info.c when vi->channels<=0, a similar issue to Mozilla bug 550184.
nvd
CVE-2018-18311P3CRITICALCVSS 9.8v8.0v9.02018-12-07
CVE-2018-18311 [CRITICAL] CWE-190 CVE-2018-18311: Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression t
Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.
nvd
CVE-2019-12384P3MEDIUMCVSS 5.9v8.02019-06-24
CVE-2019-12384 [MEDIUM] CWE-502 CVE-2019-12384: FasterXML jackson-databind 2.x before 2.9.9.1 might allow attackers to have a variety of impacts by
FasterXML jackson-databind 2.x before 2.9.9.1 might allow attackers to have a variety of impacts by leveraging failure to block the logback-core class from polymorphic deserialization. Depending on the classpath content, remote code execution may be possible.
nvd
CVE-2018-1122P3HIGHCVSS 7.0PoCv7.0v8.0+1 more2018-05-23
CVE-2018-1122 [HIGH] CWE-829 CVE-2018-1122: procps-ng before version 3.3.15 is vulnerable to a local privilege escalation in top. If a user runs
procps-ng before version 3.3.15 is vulnerable to a local privilege escalation in top. If a user runs top with HOME unset in an attacker-controlled directory, the attacker could achieve privilege escalation by exploiting one of several vulnerabilities in the config_file() function.
nvd