Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 51 of 498
CVE-2016-4422P3CRITICALCVSS 9.8v8.02016-05-06
CVE-2016-4422 [CRITICAL] CWE-287 CVE-2016-4422: The pam_sm_authenticate function in pam_sshauth.c in libpam-sshauth might allow context-dependent at
The pam_sm_authenticate function in pam_sshauth.c in libpam-sshauth might allow context-dependent attackers to bypass authentication or gain privileges via a system user account.
nvd
CVE-2019-9518P3HIGHCVSS 7.5v9.0v10.02019-08-13
CVE-2019-9518 [HIGH] CWE-400 CVE-2019-9518: Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a deni
Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The attacker sends a stream of frames with an empty payload and without the end-of-stream flag. These frames can be DATA, HEADERS, CONTINUATION and/or PUSH_PROMISE. The peer spends time processing each frame disproportionate to attack bandw
nvd
CVE-2022-24407P3HIGHCVSS 8.8v9.0v10.0+1 more2022-02-24
CVE-2022-24407 [HIGH] CWE-89 CVE-2022-24407: In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a
In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement.
nvd
CVE-2016-0766P3HIGHCVSS 8.8v7.0v8.02016-02-17
CVE-2016-0766 [HIGH] CWE-264 CVE-2016-0766: PostgreSQL before 9.1.20, 9.2.x before 9.2.15, 9.3.x before 9.3.11, 9.4.x before 9.4.6, and 9.5.x be
PostgreSQL before 9.1.20, 9.2.x before 9.2.15, 9.3.x before 9.3.11, 9.4.x before 9.4.6, and 9.5.x before 9.5.1 does not properly restrict access to unspecified custom configuration settings (GUCS) for PL/Java, which allows attackers to gain privileges via unspecified vectors.
nvd
CVE-2022-45062P3CRITICALCVSS 9.8v11.02022-11-09
CVE-2022-45062 [CRITICAL] CWE-88 CVE-2022-45062: In Xfce xfce4-settings before 4.16.4 and 4.17.x before 4.17.1, there is an argument injection vulner
In Xfce xfce4-settings before 4.16.4 and 4.17.x before 4.17.1, there is an argument injection vulnerability in xfce4-mime-helper.
nvd
CVE-2014-6601P3CRITICALCVSS 10.0v7.0v8.02015-01-21
CVE-2014-6601 [CRITICAL] CVE-2014-6601: Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect c
Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.
nvd
CVE-2023-41074P3HIGHCVSS 8.8v11.0v12.02023-09-27
CVE-2023-41074 [HIGH] CVE-2023-41074: The issue was addressed with improved checks. This issue is fixed in tvOS 17, Safari 17, watchOS 10,
The issue was addressed with improved checks. This issue is fixed in tvOS 17, Safari 17, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. Processing web content may lead to arbitrary code execution.
nvd
CVE-2005-2700P3CRITICALCVSS 10.0v3.0v3.12005-09-06
CVE-2005-2700 [CRITICAL] CVE-2005-2700: ssl_engine_kernel.c in mod_ssl before 2.8.24, when using "SSLVerifyClient optional" in the global vi
ssl_engine_kernel.c in mod_ssl before 2.8.24, when using "SSLVerifyClient optional" in the global virtual host configuration, does not properly enforce "SSLVerifyClient require" in a per-location context, which allows remote attackers to bypass intended access restrictions.
nvd
CVE-2022-32207P3CRITICALCVSS 9.8v11.02022-07-07
CVE-2022-32207 [CRITICAL] CWE-840 CVE-2022-32207: When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomi
When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file accessible to more users than inten
nvd
CVE-2018-10907P3HIGHCVSS 8.8v8.0v9.02018-09-04
CVE-2018-10907 [HIGH] CWE-121 CVE-2018-10907: It was found that glusterfs server is vulnerable to multiple stack based buffer overflows due to fun
It was found that glusterfs server is vulnerable to multiple stack based buffer overflows due to functions in server-rpc-fopc.c allocating fixed size buffers using 'alloca(3)'. An authenticated attacker could exploit this by mounting a gluster volume and sending a string longer that the fixed buffer size to cause crash or potential code execution.
nvd
CVE-2019-10126P3CRITICALCVSS 9.8v8.0v9.02019-06-14
CVE-2019-10126 [CRITICAL] CWE-122 CVE-2019-10126: A flaw was found in the Linux kernel. A heap based buffer overflow in mwifiex_uap_parse_tail_ies fun
A flaw was found in the Linux kernel. A heap based buffer overflow in mwifiex_uap_parse_tail_ies function in drivers/net/wireless/marvell/mwifiex/ie.c might lead to memory corruption and possibly other consequences.
nvd
CVE-2020-5208P3HIGHCVSS 8.8v8.0v9.02020-02-05
CVE-2020-5208 [HIGH] CWE-120 CVE-2020-5208: It's been found that multiple functions in ipmitool before 1.8.19 neglect proper checking of the dat
It's been found that multiple functions in ipmitool before 1.8.19 neglect proper checking of the data received from a remote LAN party, which may lead to buffer overflows and potentially to remote code execution on the ipmitool side. This is especially dangerous if ipmitool is run as a privileged user. This problem is fixed in version 1.8.19.
nvd
CVE-2019-16746P3CRITICALCVSS 9.8v8.02019-09-24
CVE-2019-16746 [CRITICAL] CWE-120 CVE-2019-16746: An issue was discovered in net/wireless/nl80211.c in the Linux kernel through 5.2.17. It does not ch
An issue was discovered in net/wireless/nl80211.c in the Linux kernel through 5.2.17. It does not check the length of variable elements in a beacon head, leading to a buffer overflow.
nvd
CVE-2015-5346P3HIGHCVSS 8.1v7.0v8.02016-02-25
CVE-2015-5346 [HIGH] CVE-2015-5346: Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before
Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are used for deployments of multiple versions of the same web application, might allow remote attackers to hijack web sessions by leveraging use of a requestedSessionSSL field for an unintended request, related to Coyote
nvd
CVE-2018-6056P3HIGHCVSS 8.8v8.0v9.02019-01-09
CVE-2018-6056 [HIGH] CWE-704 CVE-2018-6056: Type confusion could lead to a heap out-of-bounds write in V8 in Google Chrome prior to 64.0.3282.16
Type confusion could lead to a heap out-of-bounds write in V8 in Google Chrome prior to 64.0.3282.168 allowing a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
nvd
CVE-2018-7556P3CRITICALCVSS 9.1v7.02018-02-28
CVE-2018-7556 [CRITICAL] CWE-200 CVE-2018-7556: LimeSurvey 2.6.x before 2.6.7, 2.7x.x before 2.73.1, and 3.x before 3.4.2 mishandles application/con
LimeSurvey 2.6.x before 2.6.7, 2.7x.x before 2.73.1, and 3.x before 3.4.2 mishandles application/controller/InstallerController.php after installation, which allows remote attackers to access the configuration file.
nvd
CVE-2021-30934P3HIGHCVSS 8.8v10.0v11.02021-08-24
CVE-2021-30934 [HIGH] CWE-120 CVE-2021-30934: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in tvOS 15.
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2018-18312P3CRITICALCVSS 9.8v9.02018-12-05
CVE-2018-18312 [CRITICAL] CWE-119 CVE-2018-18312: Perl before 5.26.3 and 5.28.0 before 5.28.1 has a buffer overflow via a crafted regular expression t
Perl before 5.26.3 and 5.28.0 before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.
nvd
CVE-2015-5165P3CRITICALCVSS 9.3v7.0v8.02015-08-12
CVE-2015-5165 [CRITICAL] CWE-908 CVE-2015-5165: The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x
The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to read process heap memory via unspecified vectors.
nvd
CVE-2019-9516P3MEDIUMCVSS 6.5v9.0v10.02019-08-13
CVE-2019-9516 [MEDIUM] CWE-400 CVE-2019-9516: Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of serv
Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with a 0-length header name and 0-length header value, optionally Huffman encoded into 1-byte or greater headers. Some implementations allocate memory for these headers and keep the allocation alive until the
nvd