cbcvebase.

Debian Linux vulnerabilities

9,953 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358

Vulnerabilities

Page 56 of 498
CVE-2017-7895P3CRITICALCVSS 9.8v8.0v9.02017-04-28
CVE-2017-7895 [CRITICAL] CWE-119 CVE-2017-7895: The NFSv2 and NFSv3 server implementations in the Linux kernel through 4.10.13 lack certain checks f The NFSv2 and NFSv3 server implementations in the Linux kernel through 4.10.13 lack certain checks for the end of a buffer, which allows remote attackers to trigger pointer-arithmetic errors or possibly have unspecified other impact via crafted requests, related to fs/nfsd/nfs3xdr.c and fs/nfsd/nfsxdr.c.
nvd
CVE-2018-16395P3CRITICALCVSS 9.8v8.0v9.02018-11-16
CVE-2018-16395 [CRITICAL] CVE-2018-16395: An issue was discovered in the OpenSSL library in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x befor An issue was discovered in the OpenSSL library in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x before 2.6.0-preview3. When two OpenSSL::X509::Name objects are compared using ==, depending on the ordering, non-equal objects may return true. When the first argument is one character longer than the second, or the second argument conta
nvd
CVE-2022-24810P3HIGHCVSS 8.8v10.02024-04-16
CVE-2022-24810 [HIGH] CWE-476 CVE-2022-24810: net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can use a malformed OID in a SET to the nsVacmAccessTable to cause a NULL pointer dereference. Version 5.9.2 contains a patch. Users should use strong SNMPv3 credentials and avoid sharing the credentials. Those
nvd
CVE-2016-2338P3CRITICALCVSS 9.8v8.02022-09-29
CVE-2016-2338 [CRITICAL] CWE-787 CVE-2016-2338: An exploitable heap overflow vulnerability exists in the Psych::Emitter start_document function of R An exploitable heap overflow vulnerability exists in the Psych::Emitter start_document function of Ruby. In Psych::Emitter start_document function heap buffer "head" allocation is made based on tags array length. Specially constructed object passed as element of tags array can increase this array size after mentioned allocation and cause heap overfl
nvd
CVE-2022-39286P3HIGHCVSS 8.8v10.0v11.02022-10-26
CVE-2022-39286 [HIGH] CWE-250 CVE-2022-39286: Jupyter Core is a package for the core common functionality of Jupyter projects. Jupyter Core prior Jupyter Core is a package for the core common functionality of Jupyter projects. Jupyter Core prior to version 4.11.2 contains an arbitrary code execution vulnerability in `jupyter_core` that stems from `jupyter_core` executing untrusted files in CWD. This vulnerability allows one user to run code as another. Version 4.11.2 contains a patch for this is
nvd
CVE-2021-32687P3HIGHCVSS 7.5v10.0v11.02021-10-04
CVE-2021-32687 [HIGH] CWE-190 CVE-2021-32687: Redis is an open source, in-memory database that persists on disk. An integer overflow bug affecting Redis is an open source, in-memory database that persists on disk. An integer overflow bug affecting all versions of Redis can be exploited to corrupt the heap and potentially be used to leak arbitrary contents of the heap or trigger remote code execution. The vulnerability involves changing the default set-max-intset-entries configuration parameter t
nvd
CVE-2023-6186P3HIGHCVSS 8.8v11.0v12.02023-12-11
CVE-2023-6186 [HIGH] CWE-281 CVE-2023-6186: Insufficient macro permission validation of The Document Foundation LibreOffice allows an attacker t Insufficient macro permission validation of The Document Foundation LibreOffice allows an attacker to execute built-in macros without warning. In affected versions LibreOffice supports hyperlinks with macro or similar built-in command targets that can be executed when activated without warning the user.
nvd
CVE-2022-48565P3CRITICALCVSS 9.8v10.02023-08-22
CVE-2022-48565 [CRITICAL] CWE-611 CVE-2022-48565: An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no lo An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist files to avoid XML vulnerabilities.
nvd
CVE-2021-32627P3HIGHCVSS 7.5v10.0v11.02021-10-04
CVE-2021-32627 [HIGH] CWE-190 CVE-2021-32627: Redis is an open source, in-memory database that persists on disk. In affected versions an integer o Redis is an open source, in-memory database that persists on disk. In affected versions an integer overflow bug in Redis can be exploited to corrupt the heap and potentially result with remote code execution. The vulnerability involves changing the default proto-max-bulk-len and client-query-buffer-limit configuration parameters to very large values a
nvd
CVE-2021-21225P3HIGHCVSS 8.8v10.02021-04-26
CVE-2021-21225 [HIGH] CWE-787 CVE-2021-21225: Out of bounds memory access in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker t Out of bounds memory access in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-17368P3CRITICALCVSS 9.8v9.0v10.02020-08-11
CVE-2020-17368 [CRITICAL] CWE-78 CVE-2020-17368: Firejail through 0.9.62 mishandles shell metacharacters during use of the --output or --output-stder Firejail through 0.9.62 mishandles shell metacharacters during use of the --output or --output-stderr option, which may lead to command injection.
nvd
CVE-2019-9021P3CRITICALCVSS 9.8v9.02019-02-22
CVE-2019-9021 [CRITICAL] CVE-2019-9021: An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x befo An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. A heap-based buffer over-read in PHAR reading functions in the PHAR extension may allow an attacker to read allocated or unallocated memory past the actual data when trying to parse the file name, a different vulnerability than CVE-2018-20783. This
nvd
CVE-2022-31163P3HIGHCVSS 8.1v10.02022-07-22
CVE-2022-31163 [HIGH] CWE-22 CVE-2022-31163: TZInfo is a Ruby library that provides access to time zone data and allows times to be converted usi TZInfo is a Ruby library that provides access to time zone data and allows times to be converted using time zone rules. Versions prior to 0.36.1, as well as those prior to 1.2.10 when used with the Ruby data source tzinfo-data, are vulnerable to relative path traversal. With the Ruby data source, time zones are defined in Ruby files. There is one file
nvd
CVE-2020-10108P3CRITICALCVSS 9.8v9.02020-03-12
CVE-2020-10108 [CRITICAL] CWE-444 CVE-2020-10108: In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented wi In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with two content-length headers, it ignored the first header. When the second content-length value was set to zero, the request body was interpreted as a pipelined request.
nvd
CVE-2016-6254P3CRITICALCVSS 9.1v8.02016-08-19
CVE-2016-6254 [CRITICAL] CWE-119 CVE-2016-6254: Heap-based buffer overflow in the parse_packet function in network.c in collectd before 5.4.3 and 5. Heap-based buffer overflow in the parse_packet function in network.c in collectd before 5.4.3 and 5.x before 5.5.2 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted network packet.
nvd
CVE-2020-12284P3CRITICALCVSS 9.8v10.02020-04-28
CVE-2020-12284 [CRITICAL] CWE-787 CVE-2020-12284: cbs_jpeg_split_fragment in libavcodec/cbs_jpeg.c in FFmpeg 4.1 and 4.2.2 has a heap-based buffer ove cbs_jpeg_split_fragment in libavcodec/cbs_jpeg.c in FFmpeg 4.1 and 4.2.2 has a heap-based buffer overflow during JPEG_MARKER_SOS handling because of a missing length check.
nvd
CVE-2020-12460P3CRITICALCVSS 9.8v9.02020-07-27
CVE-2020-12460 [CRITICAL] CWE-787 CVE-2020-12460: OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 has improper null termination in the function OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 has improper null termination in the function opendmarc_xml_parse that can result in a one-byte heap overflow in opendmarc_xml when parsing a specially crafted DMARC aggregate report. This can cause remote memory corruption when a '\0' byte overwrites the heap metadata of the next chunk and its
nvd
CVE-2017-15275P3HIGHCVSS 7.5v8.0v9.02017-11-27
CVE-2017-15275 [HIGH] CWE-119 CVE-2017-15275: Samba before 4.7.3 might allow remote attackers to obtain sensitive information by leveraging failur Samba before 4.7.3 might allow remote attackers to obtain sensitive information by leveraging failure of the server to clear allocated heap memory.
nvd
CVE-2016-1245P3CRITICALCVSS 9.8v8.02017-02-22
CVE-2016-1245 [CRITICAL] CWE-119 CVE-2016-1245: It was discovered that the zebra daemon in Quagga before 1.0.20161017 suffered from a stack-based bu It was discovered that the zebra daemon in Quagga before 1.0.20161017 suffered from a stack-based buffer overflow when processing IPv6 Neighbor Discovery messages. The root cause was relying on BUFSIZ to be compatible with a message size; however, BUFSIZ is system-dependent.
nvd
CVE-2024-10224P3HIGHCVSS 7.8v11.02024-11-19
CVE-2024-10224 [HIGH] CWE-78 CVE-2024-10224: Qualys discovered that if unsanitized input was used with the library Modules::ScanDeps, before vers Qualys discovered that if unsanitized input was used with the library Modules::ScanDeps, before version 1.36 a local attacker could possibly execute arbitrary shell commands by open()ing a "pesky pipe" (such as passing "commands|" as a filename) or by passing arbitrary strings to eval().
nvd
Debian Linux vulnerabilities | cvebase