cbcvebase.

Debian Linux vulnerabilities

9,953 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358

Vulnerabilities

Page 50 of 498
CVE-2020-6072P3CRITICALCVSS 9.8v9.02020-03-24
CVE-2020-6072 [CRITICAL] CWE-415 CVE-2020-6072: An exploitable code execution vulnerability exists in the label-parsing functionality of Videolabs l An exploitable code execution vulnerability exists in the label-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing compressed labels in mDNS messages, the rr_decode function's return value is not checked, leading to a double free that could be exploited to execute arbitrary code. An attacker can send an mDNS message to trigger this v
nvd
CVE-2008-4796P3CRITICALCVSS 10.0v4.0v5.02008-10-30
CVE-2008-4796 [CRITICAL] CWE-78 CVE-2008-4796: The _httpsrequest function (Snoopy/Snoopy.class.php) in Snoopy 1.2.3 and earlier, as used in (1) amp The _httpsrequest function (Snoopy/Snoopy.class.php) in Snoopy 1.2.3 and earlier, as used in (1) ampache, (2) libphp-snoopy, (3) mahara, (4) mediamate, (5) opendb, (6) pixelpost, and possibly other products, allows remote attackers to execute arbitrary commands via shell metacharacters in https URLs.
nvd
CVE-2016-5771P3CRITICALCVSS 9.8v8.02016-08-07
CVE-2016-5771 [CRITICAL] CWE-416 CVE-2016-5771: spl_array.c in the SPL extension in PHP before 5.5.37 and 5.6.x before 5.6.23 improperly interacts w spl_array.c in the SPL extension in PHP before 5.5.37 and 5.6.x before 5.6.23 improperly interacts with the unserialize implementation and garbage collection, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and application crash) via crafted serialized data.
nvd
CVE-2017-0356P3CRITICALCVSS 9.8v7.0v8.02018-04-13
CVE-2017-0356 [CRITICAL] CVE-2017-0356: A flaw, similar to to CVE-2016-9646, exists in ikiwiki before 3.20170111, in the passwordauth plugin A flaw, similar to to CVE-2016-9646, exists in ikiwiki before 3.20170111, in the passwordauth plugin's use of CGI::FormBuilder, allowing an attacker to bypass authentication via repeated parameters.
nvd
CVE-2016-5419P3HIGHCVSS 7.5v8.02016-08-10
CVE-2016-5419 [HIGH] CWE-310 CVE-2016-5419: curl and libcurl before 7.50.1 do not prevent TLS session resumption when the client certificate has curl and libcurl before 7.50.1 do not prevent TLS session resumption when the client certificate has changed, which allows remote attackers to bypass intended restrictions by resuming a session.
nvd
CVE-2019-9517P3HIGHCVSS 7.5v9.0v10.02019-08-13
CVE-2019-9517 [HIGH] CWE-400 CVE-2019-9517: Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially lead Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens the HTTP/2 window so the peer can send without constraint; however, they leave the TCP window closed so the peer cannot actually write (many of) the bytes on the wire. The attacker then sends a stream of requ
nvd
CVE-2018-1999010P3CRITICALCVSS 9.8v8.02018-07-23
CVE-2018-1999010 [CRITICAL] CWE-125 CVE-2018-1999010: FFmpeg before commit cced03dd667a5df6df8fd40d8de0bff477ee02e8 contains multiple out of array access FFmpeg before commit cced03dd667a5df6df8fd40d8de0bff477ee02e8 contains multiple out of array access vulnerabilities in the mms protocol that can result in attackers accessing out of bound data. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in cced03dd667a5df6df8fd40d8de0bff477ee02e8
nvd
CVE-2019-17559P3CRITICALCVSS 9.8v10.02020-03-23
CVE-2019-17559 [CRITICAL] CWE-444 CVE-2019-17559: There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and scheme parsing. Upgrade to versions 7.1.9 and 8.0.6 or later versions.
nvd
CVE-2019-17565P3CRITICALCVSS 9.8v10.02020-03-23
CVE-2019-17565 [CRITICAL] CWE-444 CVE-2019-17565: There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and chunked encoding. Upgrade to versions 7.1.9 and 8.0.6 or later versions.
nvd
CVE-2020-11996P3HIGHCVSS 7.5v9.0v10.02020-06-26
CVE-2020-11996 [HIGH] CVE-2020-11996: A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 to 10.0.0-M5, 9.0.0. A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 to 10.0.0-M5, 9.0.0.M1 to 9.0.35 and 8.5.0 to 8.5.55 could trigger high CPU usage for several seconds. If a sufficient number of such requests were made on concurrent HTTP/2 connections, the server could become unresponsive.
nvd
CVE-2019-18823P3CRITICALCVSS 9.8v9.0v10.02020-04-27
CVE-2019-18823 [CRITICAL] CWE-287 CVE-2019-18823: HTCondor up to and including stable series 8.8.6 and development series 8.9.4 has Incorrect Access C HTCondor up to and including stable series 8.8.6 and development series 8.9.4 has Incorrect Access Control. It is possible to use a different authentication method to submit a job than the administrator has specified. If the administrator has configured the READ or WRITE methods to include CLAIMTOBE, then it is possible to impersonate another user
nvd
CVE-2016-1244P3HIGHCVSS 8.8v7.0v8.02016-10-03
CVE-2016-1244 [HIGH] CWE-20 CVE-2016-1244: The extractTree function in unADF allows remote attackers to execute arbitrary code via shell metach The extractTree function in unADF allows remote attackers to execute arbitrary code via shell metacharacters in a directory name in an adf file.
nvd
CVE-2022-26495P3CRITICALCVSS 9.8v9.0v10.0+1 more2022-03-06
CVE-2022-26495 [CRITICAL] CWE-190 CVE-2022-26495: In nbd-server in nbd before 3.24, there is an integer overflow with a resultant heap-based buffer ov In nbd-server in nbd before 3.24, there is an integer overflow with a resultant heap-based buffer overflow. A value of 0xffffffff in the name length field will cause a zero-sized buffer to be allocated for the name, resulting in a write to a dangling pointer. This issue exists for the NBD_OPT_INFO, NBD_OPT_GO, and NBD_OPT_EXPORT_NAME messages.
nvd
CVE-2018-5968P3HIGHCVSS 8.1v8.0v9.02018-01-22
CVE-2018-5968 [HIGH] CVE-2018-5968: FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 and CVE-2017-17485 deserialization flaws. This is exploitable via two different gadgets that bypass a blacklist.
nvd
CVE-2016-8863P3CRITICALCVSS 9.8v8.02017-03-07
CVE-2016-8863 [CRITICAL] CWE-119 CVE-2016-8863: Heap-based buffer overflow in the create_url_list function in gena/gena_device.c in Portable UPnP SD Heap-based buffer overflow in the create_url_list function in gena/gena_device.c in Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a valid URI followed by an invalid one in the CALLBACK header of an SUBSCRIBE request.
nvd
CVE-2019-18928P3CRITICALCVSS 9.8v9.02019-11-15
CVE-2019-18928 [CRITICAL] CVE-2019-18928: Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP req Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection.
nvd
CVE-2016-3630P3HIGHCVSS 8.8v7.0v8.02016-04-13
CVE-2016-3630 [HIGH] CWE-19 CVE-2016-3630: The binary delta decoder in Mercurial before 3.7.3 allows remote attackers to execute arbitrary code The binary delta decoder in Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a (1) clone, (2) push, or (3) pull command, related to (a) a list sizing rounding error and (b) short records.
nvd
CVE-2022-21797P3CRITICALCVSS 9.8v10.02022-09-26
CVE-2022-21797 [CRITICAL] CWE-94 CVE-2022-21797: The package joblib from 0 and before 1.2.0 are vulnerable to Arbitrary Code Execution via the pre_di The package joblib from 0 and before 1.2.0 are vulnerable to Arbitrary Code Execution via the pre_dispatch flag in Parallel() class due to the eval() statement.
nvd
CVE-2018-7033P3CRITICALCVSS 9.8v7.0v8.0+1 more2018-03-15
CVE-2018-7033 [CRITICAL] CWE-89 CVE-2018-7033: SchedMD Slurm before 17.02.10 and 17.11.x before 17.11.5 allows SQL Injection attacks against SlurmD SchedMD Slurm before 17.02.10 and 17.11.x before 17.11.5 allows SQL Injection attacks against SlurmDBD.
nvd
CVE-2018-1000805P3HIGHCVSS 8.8v8.0v9.02018-10-08
CVE-2018-1000805 [HIGH] CWE-863 CVE-2018-1000805: Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a Incorrect Access Contr Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a Incorrect Access Control vulnerability in SSH server that can result in RCE. This attack appear to be exploitable via network connectivity.
nvd
Debian Linux vulnerabilities | cvebase