Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 58 of 498
CVE-2017-10346P3CRITICALCVSS 9.6v7.0v8.0+1 more2017-10-19
CVE-2017-10346 [CRITICAL] CVE-2017-10346: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot).
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Success
nvd
CVE-2016-3069P3HIGHCVSS 8.8v7.0v8.02016-04-13
CVE-2016-3069 [HIGH] CWE-20 CVE-2016-3069: Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted name when con
Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted name when converting a Git repository.
nvd
CVE-2015-2775P3HIGHCVSS 7.6v7.02015-04-13
CVE-2015-2775 [HIGH] CWE-22 CVE-2015-2775: Directory traversal vulnerability in GNU Mailman before 2.1.20, when not using a static alias, allow
Directory traversal vulnerability in GNU Mailman before 2.1.20, when not using a static alias, allows remote attackers to execute arbitrary files via a .. (dot dot) in a list name.
nvd
CVE-2021-43303P3CRITICALCVSS 9.8v9.0v10.0+1 more2022-02-16
CVE-2021-43303 [CRITICAL] CWE-120 CVE-2021-43303: Buffer overflow in PJSUA API when calling pjsua_call_dump. An attacker-controlled 'buffer' argument
Buffer overflow in PJSUA API when calling pjsua_call_dump. An attacker-controlled 'buffer' argument may cause a buffer overflow, since supplying an output buffer smaller than 128 characters may overflow the output buffer, regardless of the 'maxlen' argument supplied
nvd
CVE-2018-8780P3CRITICALCVSS 9.1v7.0v8.0+1 more2018-04-03
CVE-2018-8780 [CRITICAL] CWE-22 CVE-2018-8780: In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview
In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, the Dir.open, Dir.new, Dir.entries and Dir.empty? methods do not check NULL characters. When using the corresponding method, unintentional directory traversal may be performed.
nvd
CVE-2015-3194P3HIGHCVSS 7.5v7.0v8.02015-12-06
CVE-2015-3194 [HIGH] CWE-476 CVE-2015-3194: crypto/rsa/rsa_ameth.c in OpenSSL 1.0.1 before 1.0.1q and 1.0.2 before 1.0.2e allows remote attacker
crypto/rsa/rsa_ameth.c in OpenSSL 1.0.1 before 1.0.1q and 1.0.2 before 1.0.2e allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an RSA PSS ASN.1 signature that lacks a mask generation function parameter.
nvd
CVE-2015-2806P3CRITICALCVSS 10.0v7.02015-04-10
CVE-2015-2806 [CRITICAL] CWE-119 CVE-2015-2806: Stack-based buffer overflow in asn1_der_decoding in libtasn1 before 4.4 allows remote attackers to h
Stack-based buffer overflow in asn1_der_decoding in libtasn1 before 4.4 allows remote attackers to have unspecified impact via unknown vectors.
nvd
CVE-2017-1000158P3CRITICALCVSS 9.8v7.0v8.0+1 more2017-11-17
CVE-2017-1000158 [CRITICAL] CWE-190 CVE-2017-1000158: CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape
CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringobject.c, resulting in heap-based buffer overflow (and possible arbitrary code execution)
nvd
CVE-2021-20204P3CRITICALCVSS 9.8v9.02021-05-06
CVE-2021-20204 [CRITICAL] CWE-119 CVE-2021-20204: A heap memory corruption problem (use after free) can be triggered in libgetdata v0.10.0 when proces
A heap memory corruption problem (use after free) can be triggered in libgetdata v0.10.0 when processing maliciously crafted dirfile databases. This degrades the confidentiality, integrity and availability of third-party software that uses libgetdata as a library. This vulnerability may lead to arbitrary code execution or privilege escalation depe
nvd
CVE-2021-21348P3HIGHCVSS 7.5v9.0v10.0+1 more2021-03-23
CVE-2021-21348 [HIGH] CWE-400 CVE-2021-21348: XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to occupy a thread that consumes maximum CPU time and will never return. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited t
nvd
CVE-2021-43845P3CRITICALCVSS 9.1v9.0v10.0+1 more2021-12-27
CVE-2021-43845 [CRITICAL] CWE-125 CVE-2021-43845: PJSIP is a free and open source multimedia communication library. In version 2.11.1 and prior, if in
PJSIP is a free and open source multimedia communication library. In version 2.11.1 and prior, if incoming RTCP XR message contain block, the data field is not checked against the received packet size, potentially resulting in an out-of-bound read access. This affects all users that use PJMEDIA and RTCP XR. A malicious actor can send a RTCP XR mes
nvd
CVE-2021-23336P3MEDIUMCVSS 5.9v9.02021-02-15
CVE-2021-23336 [MEDIUM] CWE-444 CVE-2021-23336: The package python/cpython from 0 and before 3.6.13, from 3.7.0 and before 3.7.10, from 3.8.0 and be
The package python/cpython from 0 and before 3.6.13, from 3.7.0 and before 3.7.10, from 3.8.0 and before 3.8.8, from 3.9.0 and before 3.9.2 are vulnerable to Web Cache Poisoning via urllib.parse.parse_qsl and urllib.parse.parse_qs by using a vector called parameter cloaking. When the attacker can separate query parameters using a semicolon (;), they
nvd
CVE-2013-6890P4MEDIUMCVSS 5.0PoCv6.0v7.0+1 more2013-12-23
CVE-2013-6890 [MEDIUM] CWE-287 CVE-2013-6890: denyhosts 2.6 uses an incorrect regular expression when analyzing authentication logs, which allows
denyhosts 2.6 uses an incorrect regular expression when analyzing authentication logs, which allows remote attackers to cause a denial of service (incorrect block of IP addresses) via crafted login names.
nvd
CVE-2019-13485P3CRITICALCVSS 9.8v8.02019-08-27
CVE-2019-13485 [CRITICAL] CWE-787 CVE-2019-13485: In Xymon through 4.3.28, a stack-based buffer overflow vulnerability exists in the history viewer co
In Xymon through 4.3.28, a stack-based buffer overflow vulnerability exists in the history viewer component via a long hostname or service parameter to history.c.
nvd
CVE-2022-32212P3HIGHCVSS 8.1v10.0v11.02022-07-14
CVE-2022-32212 [HIGH] CWE-284 CVE-2022-32212: A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.20.0, <18.5.0 due to a
A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.20.0, <18.5.0 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding attacks.
nvd
CVE-2021-20001P3CRITICALCVSS 9.8v9.0v10.0+1 more2022-02-11
CVE-2021-20001 [CRITICAL] CWE-276 CVE-2021-20001: It was discovered, that debian-edu-config, a set of configuration files used for the Debian Edu blen
It was discovered, that debian-edu-config, a set of configuration files used for the Debian Edu blend, before 2.12.16 configured insecure permissions for the user web shares (~/public_html), which could result in privilege escalation.
nvd
CVE-2012-4188P3CRITICALCVSS 9.3v6.02012-10-10
CVE-2012-4188 [CRITICAL] CWE-119 CVE-2012-4188: Heap-based buffer overflow in the Convolve3x3 function in Mozilla Firefox before 16.0, Firefox ESR 1
Heap-based buffer overflow in the Convolve3x3 function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2012-4186P3CRITICALCVSS 9.3v6.02012-10-10
CVE-2012-4186 [CRITICAL] CWE-119 CVE-2012-4186: Heap-based buffer overflow in the nsWaveReader::DecodeAudioData function in Mozilla Firefox before 1
Heap-based buffer overflow in the nsWaveReader::DecodeAudioData function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2016-9577P3HIGHCVSS 8.8v8.02018-07-27
CVE-2016-9577 [HIGH] CWE-20 CVE-2016-9577: A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An authent
A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An authenticated attacker could send crafted messages to the SPICE server causing a heap overflow leading to a crash or possible code execution.
nvd
CVE-2018-18284P3HIGHCVSS 8.6v8.0v9.02018-10-19
CVE-2018-18284 [HIGH] CVE-2018-18284: Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via v
Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving the 1Policy operator.
nvd