Debian Linux vulnerabilities
9,956 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,956
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4169MEDIUM4296LOW358
Vulnerabilities
Page 487 of 498
CVE-2019-2422P4LOWCVSS 3.1v8.0v9.02019-01-16
CVE-2019-2422 [LOW] CVE-2019-2422: Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Libraries). Supported versio
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 7u201, 8u192 and 11.0.1; Java SE Embedded: 8u191. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction fr
nvd
CVE-2014-0420P4LOWCVSS 2.8v7.02014-01-15
CVE-2014-0420 [LOW] CVE-2014-0420: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.34 and earlier, and 5.6.
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.34 and earlier, and 5.6.14 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Replication.
nvd
CVE-2024-21085P4LOWCVSS 3.7v10.02024-04-16
CVE-2024-21085 [LOW] CVE-2024-21085: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (co
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Concurrency). Supported versions that are affected are Oracle Java SE: 8u401, 8u401-perf, 11.0.22; Oracle GraalVM Enterprise Edition: 20.3.13 and 21.3.9. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple
nvd
CVE-2011-3374P4LOWCVSS 3.7v8.0v9.0+1 more2019-11-26
CVE-2011-3374 [LOW] CWE-347 CVE-2011-3374: It was found that apt-key in apt, all versions, do not correctly validate gpg keys with the master k
It was found that apt-key in apt, all versions, do not correctly validate gpg keys with the master keyring, leading to a potential man-in-the-middle attack.
nvd
CVE-2015-3011P4LOWCVSS 3.5v7.02015-05-08
CVE-2015-3011 [LOW] CWE-79 CVE-2015-3011: Multiple cross-site scripting (XSS) vulnerabilities in the contacts application in ownCloud Server C
Multiple cross-site scripting (XSS) vulnerabilities in the contacts application in ownCloud Server Community Edition before 5.0.19, 6.x before 6.0.7, and 7.x before 7.0.5 allow remote authenticated users to inject arbitrary web script or HTML via a crafted contact.
nvd
CVE-2017-8822P4LOWCVSS 3.7v8.0v9.02017-12-03
CVE-2017-8822 [LOW] CWE-417 CVE-2017-8822: In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3
In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, relays (that have incompletely downloaded descriptors) can pick themselves in a circuit path, leading to a degradation of anonymity, aka TROVE-2017-012.
nvd
CVE-2016-0643P4LOWCVSS 3.3v8.02016-04-21
CVE-2016-0643 [LOW] CVE-2016-0643: Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and ear
Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows local users to affect confidentiality via vectors related to DML.
nvd
CVE-2020-27746P4LOWCVSS 3.7v10.02020-11-27
CVE-2020-27746 [LOW] CWE-362 CVE-2020-27746: Slurm before 19.05.8 and 20.x before 20.02.6 exposes Sensitive Information to an Unauthorized Actor
Slurm before 19.05.8 and 20.x before 20.02.6 exposes Sensitive Information to an Unauthorized Actor because xauth for X11 magic cookies is affected by a race condition in a read operation on the /proc filesystem.
nvd
CVE-2020-11045P4LOWCVSS 3.3v9.0v10.02020-05-07
CVE-2020-11045 [LOW] CWE-125 CVE-2020-11045: In FreeRDP after 1.0 and before 2.0.0, there is an out-of-bound read in in update_read_bitmap_data t
In FreeRDP after 1.0 and before 2.0.0, there is an out-of-bound read in in update_read_bitmap_data that allows client memory to be read to an image buffer. The result displayed on screen as colour.
nvd
CVE-2020-12829P4LOWCVSS 3.8v10.02020-08-31
CVE-2020-12829 [LOW] CWE-190 CVE-2020-12829: In QEMU through 5.0.0, an integer overflow was found in the SM501 display driver implementation. Thi
In QEMU through 5.0.0, an integer overflow was found in the SM501 display driver implementation. This flaw occurs in the COPY_AREA macro while handling MMIO write operations through the sm501_2d_engine_write() callback. A local attacker could abuse this flaw to crash the QEMU process in sm501_2d_operation() in hw/display/sm501.c on the host, resulting
nvd
CVE-2022-33747P4LOWCVSS 3.8v11.02022-10-11
CVE-2022-33747 [LOW] CWE-404 CVE-2022-33747: Arm: unbounded memory consumption for 2nd-level page tables Certain actions require e.g. removing pa
Arm: unbounded memory consumption for 2nd-level page tables Certain actions require e.g. removing pages from a guest's P2M (Physical-to-Machine) mapping. When large pages are in use to map guest pages in the 2nd-stage page tables, such a removal operation may incur a memory allocation (to replace a large mapping with individual smaller ones). These mem
nvd
CVE-2016-10538P4LOWCVSS 3.5v8.02018-05-31
CVE-2016-10538 [LOW] CWE-22 CVE-2016-10538: The package `node-cli` before 1.0.0 insecurely uses the lock_file and log_file. Both of these are te
The package `node-cli` before 1.0.0 insecurely uses the lock_file and log_file. Both of these are temporary, but it allows the starting user to overwrite any file they have access to.
nvd
CVE-2017-3653P4LOWCVSS 3.1v8.0v9.02017-08-08
CVE-2017-3653 [LOW] CVE-2017-3653: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported v
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.5.56 and earlier, 5.6.36 and earlier and 5.7.18 and earlier. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnera
nvd
CVE-2019-17052P4LOWCVSS 3.3v8.02019-10-01
CVE-2019-17052 [LOW] CWE-276 CVE-2019-17052: ax25_create in net/ax25/af_ax25.c in the AF_AX25 network module in the Linux kernel 3.16 through 5.3
ax25_create in net/ax25/af_ax25.c in the AF_AX25 network module in the Linux kernel 3.16 through 5.3.2 does not enforce CAP_NET_RAW, which means that unprivileged users can create a raw socket, aka CID-0614e2b73768.
nvd
CVE-2012-2947P4LOWCVSS 2.6v6.02012-06-02
CVE-2012-2947 [LOW] CWE-284 CVE-2012-2947: chan_iax2.c in the IAX2 channel driver in Certified Asterisk 1.8.11-cert before 1.8.11-cert2 and Ast
chan_iax2.c in the IAX2 channel driver in Certified Asterisk 1.8.11-cert before 1.8.11-cert2 and Asterisk Open Source 1.8.x before 1.8.12.1 and 10.x before 10.4.1, when a certain mohinterpret setting is enabled, allows remote attackers to cause a denial of service (daemon crash) by placing a call on hold.
nvd
CVE-2004-1180P4MEDIUMCVSS 5.0v3.02004-02-16
CVE-2004-1180 [MEDIUM] CVE-2004-1180: Unknown vulnerability in the rwho daemon (rwhod) before 0.17, on little endian architectures, allows
Unknown vulnerability in the rwho daemon (rwhod) before 0.17, on little endian architectures, allows remote attackers to cause a denial of service (application crash).
nvd
CVE-2005-3847P4MEDIUMCVSS 5.5v3.12005-11-27
CVE-2005-3847 [MEDIUM] CWE-667 CVE-2005-3847: The handle_stop_signal function in signal.c in Linux kernel 2.6.11 up to other versions before 2.6.1
The handle_stop_signal function in signal.c in Linux kernel 2.6.11 up to other versions before 2.6.13 and 2.6.12.6 allows local users to cause a denial of service (deadlock) by sending a SIGKILL to a real-time threaded process while it is performing a core dump.
nvd
CVE-2004-1174P4MEDIUMCVSS 5.0v3.02005-04-14
CVE-2004-1174 [MEDIUM] CVE-2004-1174: direntry.c in Midnight Commander (mc) 4.5.55 and earlier allows attackers to cause a denial of servi
direntry.c in Midnight Commander (mc) 4.5.55 and earlier allows attackers to cause a denial of service by "manipulating non-existing file handles."
nvd
CVE-1999-0831P4MEDIUMCVSS 5.0v2.21999-11-19
CVE-1999-0831 [MEDIUM] CVE-1999-0831: Denial of service in Linux syslogd via a large number of connections.
Denial of service in Linux syslogd via a large number of connections.
nvd
CVE-2003-0362P4MEDIUMCVSS 5.0v0.9.1v0.9.2+2 more2003-06-09
CVE-2003-0362 [MEDIUM] CVE-2003-0362: Buffer overflow in gPS before 0.10.2 may allow local users to cause a denial of service (SIGSEGV) in
Buffer overflow in gPS before 0.10.2 may allow local users to cause a denial of service (SIGSEGV) in rgpsp via long command lines.
nvd