Debian Linux vulnerabilities
9,956 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,956
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4169MEDIUM4296LOW358
Vulnerabilities
Page 490 of 498
CVE-2003-0440P4MEDIUMCVSS 4.6v3.02003-08-18
CVE-2003-0440 [MEDIUM] CVE-2003-0440: The (1) semi MIME library 1.14.5 and earlier, and (2) wemi 1.14.0 and possibly other versions, allow
The (1) semi MIME library 1.14.5 and earlier, and (2) wemi 1.14.0 and possibly other versions, allows local users to overwrite arbitrary files via a symlink attack on temporary files.
nvd
CVE-2018-2773P4MEDIUMCVSS 4.1v7.0v8.02018-04-19
CVE-2018-2773 [MEDIUM] CVE-2018-2773: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs). Support
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs). Supported versions that are affected are 5.5.59 and prior, 5.6.39 and prior and 5.7.21 and prior. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful att
nvd
CVE-2001-0131P4LOWCVSS 3.3v2.22001-03-12
CVE-2001-0131 [LOW] CWE-59 CVE-2001-0131: htpasswd and htdigest in Apache 2.0a9, 1.3.14, and others allows local users to overwrite arbitrary
htpasswd and htdigest in Apache 2.0a9, 1.3.14, and others allows local users to overwrite arbitrary files via a symlink attack.
nvd
CVE-2020-14796P4LOWCVSS 3.1v9.0v10.02020-10-21
CVE-2020-14796 [LOW] CVE-2020-14796: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Sup
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful
nvd
CVE-2018-3066P4LOWCVSS 3.3v8.0v9.02018-07-18
CVE-2018-3066 [LOW] CVE-2018-3066: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Options). Support
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Options). Supported versions that are affected are 5.5.60 and prior, 5.6.40 and prior and 5.7.22 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerab
nvd
CVE-2019-2933P4LOWCVSS 3.1v8.02019-10-16
CVE-2019-2933 [LOW] CVE-2019-2933: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Sup
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful a
nvd
CVE-2017-10193P4LOWCVSS 3.1v8.0v9.02017-08-08
CVE-2017-10193 [LOW] CVE-2017-10193: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security).
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful
nvd
CVE-2020-27768P4LOWCVSS 3.3v9.02021-02-23
CVE-2020-27768 [LOW] CWE-190 CVE-2020-27768: In ImageMagick, there is an outside the range of representable values of type 'unsigned int' at Magi
In ImageMagick, there is an outside the range of representable values of type 'unsigned int' at MagickCore/quantum-private.h. This flaw affects ImageMagick versions prior to 7.0.9-0.
nvd
CVE-2009-0834P4LOWCVSS 3.6v4.0v5.02009-03-06
CVE-2009-0834 [LOW] CVE-2009-0834: The audit_syscall_entry function in the Linux kernel 2.6.28.7 and earlier on the x86_64 platform doe
The audit_syscall_entry function in the Linux kernel 2.6.28.7 and earlier on the x86_64 platform does not properly handle (1) a 32-bit process making a 64-bit syscall or (2) a 64-bit process making a 32-bit syscall, which allows local users to bypass certain syscall audit configurations via crafted syscalls, a related issue to CVE-2009-0342 and CVE-2009-0343.
nvd
CVE-2020-27764P4LOWCVSS 3.3v9.02020-12-03
CVE-2020-27764 [LOW] CWE-190 CVE-2020-27764: In /MagickCore/statistic.c, there are several areas in ApplyEvaluateOperator() where a size_t cast s
In /MagickCore/statistic.c, there are several areas in ApplyEvaluateOperator() where a size_t cast should have been a ssize_t cast, which causes out-of-range values under some circumstances when a crafted input file is processed by ImageMagick. Red Hat Product Security marked this as Low severity because although it could potentially lead to an impact
nvd
CVE-2020-27758P4LOWCVSS 3.3v9.02020-12-08
CVE-2020-27758 [LOW] CWE-190 CVE-2020-27758: A flaw was found in ImageMagick in coders/txt.c. An attacker who submits a crafted file that is proc
A flaw was found in ImageMagick in coders/txt.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type `unsigned long long`. This would most likely lead to an impact to application availability, but could potentially cause other problems related to undefi
nvd
CVE-2020-27775P4LOWCVSS 3.3v9.02020-12-04
CVE-2020-27775 [LOW] CWE-190 CVE-2020-27775: A flaw was found in ImageMagick in MagickCore/quantum.h. An attacker who submits a crafted file that
A flaw was found in ImageMagick in MagickCore/quantum.h. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type unsigned char. This would most likely lead to an impact to application availability, but could potentially cause other problems related to undef
nvd
CVE-2020-27774P4LOWCVSS 3.3v9.02020-12-04
CVE-2020-27774 [LOW] CWE-190 CVE-2020-27774: A flaw was found in ImageMagick in MagickCore/statistic.c. An attacker who submits a crafted file th
A flaw was found in ImageMagick in MagickCore/statistic.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of a too large shift for 64-bit type `ssize_t`. This would most likely lead to an impact to application availability, but could potentially cause other problems related to undefi
nvd
CVE-2020-27772P4LOWCVSS 3.3v9.02020-12-04
CVE-2020-27772 [LOW] CWE-190 CVE-2020-27772: A flaw was found in ImageMagick in coders/bmp.c. An attacker who submits a crafted file that is proc
A flaw was found in ImageMagick in coders/bmp.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type `unsigned int`. This would most likely lead to an impact to application availability, but could potentially cause other problems related to undefined be
nvd
CVE-2020-27751P4LOWCVSS 3.3v9.02020-12-08
CVE-2020-27751 [LOW] CWE-190 CVE-2020-27751: A flaw was found in ImageMagick in MagickCore/quantum-export.c. An attacker who submits a crafted fi
A flaw was found in ImageMagick in MagickCore/quantum-export.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type `unsigned long long` as well as a shift exponent that is too large for 64-bit type. This would most likely lead to an impact to applicati
nvd
CVE-2020-27761P4LOWCVSS 3.3v9.02020-12-03
CVE-2020-27761 [LOW] CWE-190 CVE-2020-27761: WritePALMImage() in /coders/palm.c used size_t casts in several areas of a calculation which could l
WritePALMImage() in /coders/palm.c used size_t casts in several areas of a calculation which could lead to values outside the range of representable type `unsigned long` undefined behavior when a crafted input file was processed by ImageMagick. The patch casts to `ssize_t` instead to avoid this issue. Red Hat Product Security marked the Severity as Low
nvd
CVE-2020-25675P4LOWCVSS 3.3v9.02020-12-08
CVE-2020-25675 [LOW] CWE-190 CVE-2020-25675: In the CropImage() and CropImageToTiles() routines of MagickCore/transform.c, rounding calculations
In the CropImage() and CropImageToTiles() routines of MagickCore/transform.c, rounding calculations performed on unconstrained pixel offsets was causing undefined behavior in the form of integer overflow and out-of-range values as reported by UndefinedBehaviorSanitizer. Such issues could cause a negative impact to application availability or other probl
nvd
CVE-2021-36086P4LOWCVSS 3.3v11.02021-07-01
CVE-2021-36086 [LOW] CWE-416 CVE-2021-36086: The CIL compiler in SELinux 3.2 has a use-after-free in cil_reset_classpermission (called from cil_r
The CIL compiler in SELinux 3.2 has a use-after-free in cil_reset_classpermission (called from cil_reset_classperms_set and cil_reset_classperms_list).
nvd
CVE-2018-13053P4LOWCVSS 3.3v8.02018-07-02
CVE-2018-13053 [LOW] CWE-190 CVE-2018-13053: The alarm_timer_nsleep function in kernel/time/alarmtimer.c in the Linux kernel through 4.17.3 has a
The alarm_timer_nsleep function in kernel/time/alarmtimer.c in the Linux kernel through 4.17.3 has an integer overflow via a large relative timeout because ktime_add_safe is not used.
nvd
CVE-2016-2057P4LOWCVSS 3.3v8.02016-04-13
CVE-2016-2057 [LOW] CWE-264 CVE-2016-2057: lib/xymond_ipc.c in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 use weak permissions (666) for an un
lib/xymond_ipc.c in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 use weak permissions (666) for an unspecified IPC message queue, which allows local users to inject arbitrary messages by writing to that queue.
nvd