cbcvebase.

Debian Linux vulnerabilities

9,953 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358

Vulnerabilities

Page 53 of 498
CVE-2017-16544P3HIGHCVSS 8.8v8.0v9.02017-11-20
CVE-2017-16544 [HIGH] CWE-94 CVE-2017-16544: In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab autocomplete featur In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab autocomplete feature of the shell, used to get a list of filenames in a directory, does not sanitize filenames and results in executing any escape sequence in the terminal. This could potentially result in code execution, arbitrary file writes, or other attacks.
nvd
CVE-2019-7164P3CRITICALCVSS 9.8v8.0v9.02019-02-20
CVE-2019-7164 [CRITICAL] CWE-89 CVE-2019-7164: SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter. SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter.
nvd
CVE-2019-9928P3HIGHCVSS 8.8v8.0v9.02019-04-24
CVE-2019-9928 [HIGH] CWE-787 CVE-2019-9928: GStreamer before 1.16.0 has a heap-based buffer overflow in the RTSP connection parser via a crafted GStreamer before 1.16.0 has a heap-based buffer overflow in the RTSP connection parser via a crafted response from a server, potentially allowing remote code execution.
nvd
CVE-2021-3144P3CRITICALCVSS 9.1v9.0v10.0+1 more2021-02-27
CVE-2021-3144 [CRITICAL] CWE-613 CVE-2021-3144: In SaltStack Salt before 3002.5, eauth tokens can be used once after expiration. (They might be used In SaltStack Salt before 3002.5, eauth tokens can be used once after expiration. (They might be used to run command against the salt master or minions.)
nvd
CVE-2022-22823P3CRITICALCVSS 9.8v10.0v11.02022-01-10
CVE-2022-22823 [CRITICAL] CWE-190 CVE-2022-22823: build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
nvd
CVE-2022-22824P3CRITICALCVSS 9.8v10.0v11.02022-01-10
CVE-2022-22824 [CRITICAL] CWE-190 CVE-2022-22824: defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
nvd
CVE-2022-22817P3CRITICALCVSS 9.8v9.0v10.0+1 more2022-01-10
CVE-2022-22817 [CRITICAL] CVE-2022-22817: PIL.ImageMath.eval in Pillow before 9.0.0 allows evaluation of arbitrary expressions, such as ones t PIL.ImageMath.eval in Pillow before 9.0.0 allows evaluation of arbitrary expressions, such as ones that use the Python exec method. A lambda expression could also be used.
nvd
CVE-2019-9641P3CRITICALCVSS 9.8v8.0v9.02019-03-09
CVE-2019-9641 [CRITICAL] CWE-908 CVE-2019-9641: An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x b An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in exif_process_IFD_in_TIFF.
nvd
CVE-2019-9023P3CRITICALCVSS 9.8v9.02019-02-22
CVE-2019-9023 [CRITICAL] CWE-125 CVE-2019-9023: An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x befo An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. A number of heap-based buffer over-read instances are present in mbstring regular expression functions when supplied with invalid multibyte data. These occur in ext/mbstring/oniguruma/regcomp.c, ext/mbstring/oniguruma/regexec.c, ext/mbstring
nvd
CVE-2020-10109P3CRITICALCVSS 9.8v9.02020-03-12
CVE-2020-10109 [CRITICAL] CWE-444 CVE-2020-10109: In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented wi In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with a content-length and a chunked encoding header, the content-length took precedence and the remainder of the request body was interpreted as a pipelined request.
nvd
CVE-2021-34552P3CRITICALCVSS 9.8v9.02021-07-13
CVE-2021-34552 [CRITICAL] CWE-120 CVE-2021-34552: Pillow through 8.2.0 and PIL (aka Python Imaging Library) through 1.1.7 allow an attacker to pass co Pillow through 8.2.0 and PIL (aka Python Imaging Library) through 1.1.7 allow an attacker to pass controlled parameters directly into a convert function to trigger a buffer overflow in Convert.c.
nvd
CVE-2018-6521P3CRITICALCVSS 9.8v7.0v8.0+1 more2018-02-02
CVE-2018-6521 [CRITICAL] CVE-2018-6521: The sqlauth module in SimpleSAMLphp before 1.15.2 relies on the MySQL utf8 charset, which truncates The sqlauth module in SimpleSAMLphp before 1.15.2 relies on the MySQL utf8 charset, which truncates queries upon encountering four-byte characters. There might be a scenario in which this allows remote attackers to bypass intended access restrictions.
nvd
CVE-2022-24999P3HIGHCVSS 7.5v10.02022-11-26
CVE-2022-24999 [HIGH] CWE-1321 CVE-2022-24999: qs before 6.10.3, as used in Express before 4.17.3 and other products, allows attackers to cause a N qs before 6.10.3, as used in Express before 4.17.3 and other products, allows attackers to cause a Node process hang for an Express application because an __ proto__ key can be used. In many typical Express use cases, an unauthenticated remote attacker can place the attack payload in the query string of the URL that is used to visit the application,
nvd
CVE-2016-9636P3CRITICALCVSS 9.8v8.02017-01-27
CVE-2016-9636 [CRITICAL] CWE-119 CVE-2016-9636: Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC d Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by providing a 'write count' that goes beyond the initialized buffer.
nvd
CVE-2021-21110P3CRITICALCVSS 9.6v10.02021-01-08
CVE-2021-21110 [CRITICAL] CWE-416 CVE-2021-21110: Use after free in safe browsing in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to Use after free in safe browsing in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2019-18425P3CRITICALCVSS 9.8v9.0v10.02019-10-31
CVE-2019-18425 [CRITICAL] CWE-269 CVE-2019-18425: An issue was discovered in Xen through 4.12.x allowing 32-bit PV guest OS users to gain guest OS pri An issue was discovered in Xen through 4.12.x allowing 32-bit PV guest OS users to gain guest OS privileges by installing and using descriptors. There is missing descriptor table limit checking in x86 PV emulation. When emulating certain PV guest operations, descriptor table accesses are performed by the emulating code. Such accesses should respec
nvd
CVE-2016-0749P3CRITICALCVSS 9.8v8.02016-06-09
CVE-2016-0749 [CRITICAL] CWE-119 CVE-2016-0749: The smartcard interaction in SPICE allows remote attackers to cause a denial of service (QEMU-KVM pr The smartcard interaction in SPICE allows remote attackers to cause a denial of service (QEMU-KVM process crash) or possibly execute arbitrary code via vectors related to connecting to a guest VM, which triggers a heap-based buffer overflow.
nvd
CVE-2020-28039P3CRITICALCVSS 9.1v9.0v10.02020-11-02
CVE-2020-28039 [CRITICAL] CVE-2020-28039: is_protected_meta in wp-includes/meta.php in WordPress before 5.5.2 allows arbitrary file deletion b is_protected_meta in wp-includes/meta.php in WordPress before 5.5.2 allows arbitrary file deletion because it does not properly determine whether a meta key is considered protected.
nvd
CVE-2023-6816P3CRITICALCVSS 9.8v10.02024-01-18
CVE-2023-6816 [CRITICAL] CWE-787 CVE-2023-6816: A flaw was found in X.Org server. Both DeviceFocusEvent and the XIQueryPointer reply contain a bit f A flaw was found in X.Org server. Both DeviceFocusEvent and the XIQueryPointer reply contain a bit for each logical button currently down. Buttons can be arbitrarily mapped to any value up to 255, but the X.Org Server was only allocating space for the device's particular number of buttons, leading to a heap overflow if a bigger value was used.
nvd
CVE-2019-12900P3CRITICALCVSS 9.8v8.02019-06-19
CVE-2019-12900 [CRITICAL] CWE-787 CVE-2019-12900: BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.
nvd
Debian Linux vulnerabilities | cvebase