Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 49 of 498
CVE-2021-3517P3HIGHCVSS 8.6v9.02021-05-19
CVE-2021-3517 [HIGH] CWE-787 CVE-2021-3517: There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An at
There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application linked with the affected functionality of libxml2 could trigger an out-of-bounds read. The most likely impact of this flaw is to application availability, with some potential im
nvd
CVE-2023-42852P3HIGHCVSS 8.8v11.0v12.02023-10-25
CVE-2023-42852 [HIGH] CVE-2023-42852: A logic issue was addressed with improved checks. This issue is fixed in iOS 17.1 and iPadOS 17.1, w
A logic issue was addressed with improved checks. This issue is fixed in iOS 17.1 and iPadOS 17.1, watchOS 10.1, iOS 16.7.2 and iPadOS 16.7.2, macOS Sonoma 14.1, Safari 17.1, tvOS 17.1. Processing web content may lead to arbitrary code execution.
nvd
CVE-2020-6061P3CRITICALCVSS 9.8v9.0v10.02020-02-19
CVE-2020-6061 [CRITICAL] CWE-125 CVE-2020-6061: An exploitable heap out-of-bounds read vulnerability exists in the way CoTURN 4.5.1.1 web server par
An exploitable heap out-of-bounds read vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to information leaks and other misbehavior. An attacker needs to send an HTTPS request to trigger this vulnerability.
nvd
CVE-2022-31629P3MEDIUMCVSS 6.5v10.0v11.02022-09-28
CVE-2022-31629 [MEDIUM] CWE-20 CVE-2022-31629: In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the vulnerability enables network and same-site at
In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the vulnerability enables network and same-site attackers to set a standard insecure cookie in the victim's browser which is treated as a `__Host-` or `__Secure-` cookie by PHP applications.
nvd
CVE-2021-22945P3CRITICALCVSS 9.1v11.02021-09-23
CVE-2021-22945 [CRITICAL] CWE-415 CVE-2021-22945: When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances errone
When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory area and both use that again in a subsequent call to send data and also free it *again*.
nvd
CVE-2014-2490P3CRITICALCVSS 9.3v7.02014-07-17
CVE-2014-2490 [CRITICAL] CVE-2014-2490: Unspecified vulnerability in the Java SE component in Oracle Java SE 7u60 and SE 8u5 allows remote a
Unspecified vulnerability in the Java SE component in Oracle Java SE 7u60 and SE 8u5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.
nvd
CVE-2022-26307P3HIGHCVSS 8.8v10.02022-07-25
CVE-2022-26307 [HIGH] CWE-326 CVE-2022-26307: LibreOffice supports the storage of passwords for web connections in the user’s configuration databa
LibreOffice supports the storage of passwords for web connections in the user’s configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in LibreOffice existed where master key was poorly encoded resulting in weakening its entropy from 128 to 43 bits making the stored passwords vulerable to a bru
nvd
CVE-2017-0899P3CRITICALCVSS 9.8v8.0v9.02017-08-31
CVE-2017-0899 [CRITICAL] CWE-150 CVE-2017-0899: RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that inc
RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters. Printing the gem specification would execute terminal escape sequences.
nvd
CVE-2014-0461P3CRITICALCVSS 9.3v6.0v7.0+1 more2014-04-16
CVE-2014-0461 [CRITICAL] CVE-2014-0461: Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows rem
Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.
nvd
CVE-2006-5051P3HIGHCVSS 8.1v3.12006-09-27
CVE-2006-5051 [HIGH] CWE-415 CVE-2006-5051: Signal handler race condition in OpenSSH before 4.4 allows remote attackers to cause a denial of ser
Signal handler race condition in OpenSSH before 4.4 allows remote attackers to cause a denial of service (crash), and possibly execute arbitrary code if GSSAPI authentication is enabled, via unspecified vectors that lead to a double-free.
nvd
CVE-2018-5712P3MEDIUMCVSS 6.1v7.02018-01-16
CVE-2018-5712 [MEDIUM] CWE-79 CVE-2018-5712: An issue was discovered in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x be
An issue was discovered in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1. There is Reflected XSS on the PHAR 404 error page via the URI of a request for a .phar file.
nvd
CVE-2021-23926P3CRITICALCVSS 9.1v9.02021-01-14
CVE-2021-23926 [CRITICAL] CWE-776 CVE-2021-23926: The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect th
The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion attacks. Affects XMLBeans up to and including v2.6.0.
nvd
CVE-2022-29599P3CRITICALCVSS 9.8v10.0v11.02022-05-23
CVE-2022-29599 [CRITICAL] CWE-116 CVE-2022-29599: In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quo
In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing shell injection attacks.
nvd
CVE-2020-5260P3HIGHCVSS 7.5v8.0v9.0+1 more2020-04-14
CVE-2020-5260 [HIGH] CWE-20 CVE-2020-5260: Affected versions of Git have a vulnerability whereby Git can be tricked into sending private creden
Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker. Git uses external "credential helper" programs to store and retrieve passwords or other credentials from secure storage provided by the operating system. Specially-crafted URLs that contain an encoded newline can
nvd
CVE-2017-5116P3HIGHCVSS 8.8v9.0v10.02017-10-27
CVE-2017-5116 [HIGH] CWE-843 CVE-2017-5116: Type confusion in V8 in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.31
Type confusion in V8 in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.3163.81 for Android, allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
nvd
CVE-2021-45341P3HIGHCVSS 8.8v10.0v11.02022-01-25
CVE-2021-45341 [HIGH] CWE-120 CVE-2021-45341: A buffer overflow vulnerability in CDataMoji of the jwwlib component of LibreCAD 2.2.0-rc3 and older
A buffer overflow vulnerability in CDataMoji of the jwwlib component of LibreCAD 2.2.0-rc3 and older allows an attacker to achieve Remote Code Execution using a crafted JWW document.
nvd
CVE-2022-23608P3CRITICALCVSS 9.8v9.0v10.02022-02-22
CVE-2022-23608 [CRITICAL] CWE-416 CVE-2022-23608: PJSIP is a free and open source multimedia communication library written in C language implementing
PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions up to and including 2.11.1 when in a dialog set (or forking) scenario, a hash key shared by multiple UAC dialogs can potentially be prematurely freed when one of the dia
nvd
CVE-2017-12904P3HIGHCVSS 8.8v7.0v8.0+1 more2017-08-23
CVE-2017-12904 [HIGH] CWE-943 CVE-2017-12904: Improper Neutralization of Special Elements used in an OS Command in bookmarking function of Newsbeu
Improper Neutralization of Special Elements used in an OS Command in bookmarking function of Newsbeuter versions 0.7 through 2.9 allows remote attackers to perform user-assisted code execution by crafting an RSS item that includes shell code in its title and/or URL.
nvd
CVE-2016-2105P3HIGHCVSS 7.5v8.02016-05-05
CVE-2016-2105 [HIGH] CWE-190 CVE-2016-2105: Integer overflow in the EVP_EncodeUpdate function in crypto/evp/encode.c in OpenSSL before 1.0.1t an
Integer overflow in the EVP_EncodeUpdate function in crypto/evp/encode.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (heap memory corruption) via a large amount of binary data.
nvd
CVE-2017-11107P3MEDIUMCVSS 6.1PoCv8.02017-07-08
CVE-2017-11107 [MEDIUM] CWE-79 CVE-2017-11107: phpLDAPadmin through 1.2.3 has XSS in htdocs/entry_chooser.php via the form, element, rdn, or contai
phpLDAPadmin through 1.2.3 has XSS in htdocs/entry_chooser.php via the form, element, rdn, or container parameter.
nvd