Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 52 of 498
CVE-2019-9213P3MEDIUMCVSS 5.5PoCv8.02019-03-05
CVE-2019-9213 [MEDIUM] CWE-476 CVE-2019-9213: In the Linux kernel before 4.20.14, expand_downwards in mm/mmap.c lacks a check for the mmap minimum
In the Linux kernel before 4.20.14, expand_downwards in mm/mmap.c lacks a check for the mmap minimum address, which makes it easier for attackers to exploit kernel NULL pointer dereferences on non-SMAP platforms. This is related to a capability check for the wrong task.
nvd
CVE-2016-4024P3CRITICALCVSS 9.8v7.0v8.02016-05-13
CVE-2016-4024 [CRITICAL] CWE-119 CVE-2016-4024: Integer overflow in imlib2 before 1.4.9 on 32-bit platforms allows remote attackers to execute arbit
Integer overflow in imlib2 before 1.4.9 on 32-bit platforms allows remote attackers to execute arbitrary code via large dimensions in an image, which triggers an out-of-bounds heap memory write operation.
nvd
CVE-2022-29500P3HIGHCVSS 8.8v11.02022-05-05
CVE-2022-29500 [HIGH] CVE-2022-29500: SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Information Disclos
SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Information Disclosure.
nvd
CVE-2021-3682P3HIGHCVSS 8.5v9.0v10.0+1 more2021-08-05
CVE-2021-3682 [HIGH] CWE-763 CVE-2021-3682: A flaw was found in the USB redirector device emulation of QEMU in versions prior to 6.1.0-rc2. It o
A flaw was found in the USB redirector device emulation of QEMU in versions prior to 6.1.0-rc2. It occurs when dropping packets during a bulk transfer from a SPICE client due to the packet queue being full. A malicious SPICE client could use this flaw to make QEMU call free() with faked heap chunk metadata, resulting in a crash of QEMU or potential code
nvd
CVE-2023-51385P3MEDIUMCVSS 6.5v10.0v11.0+1 more2023-12-18
CVE-2023-51385 [MEDIUM] CWE-78 CVE-2023-51385: In ssh in OpenSSH before 9.6, OS command injection might occur if a user name or host name has shell
In ssh in OpenSSH before 9.6, OS command injection might occur if a user name or host name has shell metacharacters, and this name is referenced by an expansion token in certain situations. For example, an untrusted Git repository can have a submodule with shell metacharacters in a user name or host name.
nvd
CVE-2021-26117P3HIGHCVSS 7.5v9.02021-01-27
CVE-2021-26117 [HIGH] CWE-287 CVE-2021-26117: The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server
The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is used to verify a valid users password in error, resulting in no check on the password.
nvd
CVE-2019-10172P3HIGHCVSS 7.5v8.0v9.02019-11-18
CVE-2019-10172 [HIGH] CVE-2019-10172: A flaw was found in org.codehaus.jackson:jackson-mapper-asl:1.9.x libraries. XML external entity vul
A flaw was found in org.codehaus.jackson:jackson-mapper-asl:1.9.x libraries. XML external entity vulnerabilities similar CVE-2016-3720 also affects codehaus jackson-mapper-asl libraries but in different classes.
nvd
CVE-2019-16223P3MEDIUMCVSS 5.4PoCv8.0v9.0+1 more2019-09-11
CVE-2019-16223 [MEDIUM] CWE-79 CVE-2019-16223: WordPress before 5.2.3 allows XSS in post previews by authenticated users.
WordPress before 5.2.3 allows XSS in post previews by authenticated users.
nvd
CVE-2020-12279P3CRITICALCVSS 9.8v9.02020-04-27
CVE-2020-12279 [CRITICAL] CVE-2020-12279: An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. checkout.c mishandles equiv
An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. checkout.c mishandles equivalent filenames that exist because of NTFS short names. This may allow remote code execution when cloning a repository. This issue is similar to CVE-2019-1353.
nvd
CVE-2009-4017P4MEDIUMCVSS 5.0PoCv4.0v5.0+1 more2009-11-24
CVE-2009-4017 [MEDIUM] CWE-770 CVE-2009-4017: PHP before 5.2.12 and 5.3.x before 5.3.1 does not restrict the number of temporary files created whe
PHP before 5.2.12 and 5.3.x before 5.3.1 does not restrict the number of temporary files created when handling a multipart/form-data POST request, which allows remote attackers to cause a denial of service (resource exhaustion), and makes it easier for remote attackers to exploit local file inclusion vulnerabilities, via multiple requests, related to
nvd
CVE-2016-1243P3CRITICALCVSS 9.8v7.0v8.02016-10-03
CVE-2016-1243 [CRITICAL] CWE-119 CVE-2016-1243: Stack-based buffer overflow in the extractTree function in unADF allows remote attackers to execute
Stack-based buffer overflow in the extractTree function in unADF allows remote attackers to execute arbitrary code via a long pathname.
nvd
CVE-2019-14540P3CRITICALCVSS 9.8v8.0v9.0+1 more2019-09-15
CVE-2019-14540 [CRITICAL] CWE-502 CVE-2019-14540: A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariConfig.
nvd
CVE-2021-32739P3HIGHCVSS 8.8v9.02021-07-15
CVE-2021-32739 [HIGH] CWE-267 CVE-2021-32739: Icinga is a monitoring system which checks the availability of network resources, notifies users of
Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. From version 2.4.0 through version 2.12.4, a vulnerability exists that may allow privilege escalation for authenticated API users. With a read-ony user's credentials, an attacker can view most attrib
nvd
CVE-2012-2237P3MEDIUMCVSS 6.1PoCv6.02019-12-17
CVE-2012-2237 [MEDIUM] CWE-79 CVE-2012-2237: Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.4.x before 1.4.3 and 1.5.x before 1.
Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.4.x before 1.4.3 and 1.5.x before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) javascript innerHTML as used when generating login forms, (2) links or (3) resources URLs, and (4) the Display name in a user profile.
nvd
CVE-2022-23852P3CRITICALCVSS 9.8v9.02022-01-24
CVE-2022-23852 [CRITICAL] CWE-190 CVE-2022-23852: Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations
Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES.
nvd
CVE-2010-3848P4MEDIUMCVSS 6.9PoCv5.02010-12-30
CVE-2010-3848 [MEDIUM] CWE-787 CVE-2010-3848: Stack-based buffer overflow in the econet_sendmsg function in net/econet/af_econet.c in the Linux ke
Stack-based buffer overflow in the econet_sendmsg function in net/econet/af_econet.c in the Linux kernel before 2.6.36.2, when an econet address is configured, allows local users to gain privileges by providing a large number of iovec structures.
nvd
CVE-2014-2397P3CRITICALCVSS 9.3v6.0v7.0+1 more2014-04-16
CVE-2014-2397 [CRITICAL] CVE-2014-2397: Unspecified vulnerability in Oracle Java SE 7u51 and 8, and Java SE Embedded 7u51, allows remote att
Unspecified vulnerability in Oracle Java SE 7u51 and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.
nvd
CVE-2017-12178P3CRITICALCVSS 9.8v8.0v9.02018-01-24
CVE-2017-12178 [CRITICAL] CWE-391 CVE-2017-12178: xorg-x11-server before 1.19.5 had wrong extra length check in ProcXIChangeHierarchy function allowin
xorg-x11-server before 1.19.5 had wrong extra length check in ProcXIChangeHierarchy function allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
nvd
CVE-2017-17092P4MEDIUMCVSS 5.4PoCv7.0v8.0+1 more2017-12-02
CVE-2017-17092 [MEDIUM] CWE-79 CVE-2017-17092: wp-includes/functions.php in WordPress before 4.9.1 does not require the unfiltered_html capability
wp-includes/functions.php in WordPress before 4.9.1 does not require the unfiltered_html capability for upload of .js files, which might allow remote attackers to conduct XSS attacks via a crafted file.
nvd
CVE-2015-3209P3HIGHCVSS 7.5v7.0v8.02015-06-15
CVE-2015-3209 [HIGH] CWE-787 CVE-2015-3209: Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitr
Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending a packet with TXSTATUS_STARTPACKET set and then a crafted packet with TXSTATUS_DEVICEOWNS set.
nvd