cbcvebase.

Debian Linux vulnerabilities

9,953 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358

Vulnerabilities

Page 59 of 498
CVE-2018-5381P3HIGHCVSS 7.5v7.0v8.0+1 more2018-02-19
CVE-2018-5381 [HIGH] CWE-228 CVE-2018-5381: The Quagga BGP daemon (bgpd) prior to version 1.2.3 has a bug in its parsing of "Capabilities" in BG The Quagga BGP daemon (bgpd) prior to version 1.2.3 has a bug in its parsing of "Capabilities" in BGP OPEN messages, in the bgp_packet.c:bgp_capability_msg_parse function. The parser can enter an infinite loop on invalid capabilities if a Multi-Protocol capability does not have a recognized AFI/SAFI, causing a denial of service.
nvd
CVE-2021-20322P3HIGHCVSS 7.4v9.0v10.02022-02-18
CVE-2021-20322 [HIGH] CWE-330 CVE-2021-20322: A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Lin A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functionality was found to allow the ability to quickly scan open UDP ports. This flaw allows an off-path remote user to effectively bypass the source port UDP randomization. The highest threat from this vulnerability is to confidentiality and
nvd
CVE-2015-5252P3HIGHCVSS 7.2v7.0v8.02015-12-29
CVE-2015-5252 [HIGH] CWE-264 CVE-2015-5252: vfs.c in smbd in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, when s vfs.c in smbd in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, when share names with certain substring relationships exist, allows remote attackers to bypass intended file-access restrictions via a symlink that points outside of a share.
nvd
CVE-2021-27229P3HIGHCVSS 8.8v9.02021-02-16
CVE-2021-27229 [HIGH] CWE-59 CVE-2021-27229: Mumble before 1.3.4 allows remote code execution if a victim navigates to a crafted URL on a server Mumble before 1.3.4 allows remote code execution if a victim navigates to a crafted URL on a server list and clicks on the Open Webpage text.
nvd
CVE-2019-19920P3HIGHCVSS 8.8v8.0v9.0+1 more2019-12-22
CVE-2019-19920 [HIGH] CVE-2019-19920: sa-exim 4.2.1 allows attackers to execute arbitrary code if they can write a .cf file or a rule. Thi sa-exim 4.2.1 allows attackers to execute arbitrary code if they can write a .cf file or a rule. This occurs because Greylisting.pm relies on eval (rather than direct parsing and/or use of the taint feature). This issue is similar to CVE-2018-11805.
nvd
CVE-2020-2604P3HIGHCVSS 8.1v8.0v9.02020-01-15
CVE-2020-2604 [HIGH] CWE-502 CVE-2020-2604: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1; Java SE Embedded: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embed
nvd
CVE-2019-17133P3CRITICALCVSS 9.8v8.02019-10-04
CVE-2019-17133 [CRITICAL] CWE-120 CVE-2019-17133: In the Linux kernel through 5.3.2, cfg80211_mgd_wext_giwessid in net/wireless/wext-sme.c does not re In the Linux kernel through 5.3.2, cfg80211_mgd_wext_giwessid in net/wireless/wext-sme.c does not reject a long SSID IE, leading to a Buffer Overflow.
nvd
CVE-2002-1581P4MEDIUMCVSS 5.0PoCv3.02004-12-06
CVE-2002-1581 [MEDIUM] CVE-2002-1581: Directory traversal vulnerability in nph-mr.cgi in Mailreader.com 2.3.20 through 2.3.31 allows remot Directory traversal vulnerability in nph-mr.cgi in Mailreader.com 2.3.20 through 2.3.31 allows remote attackers to view arbitrary files via .. (dot dot) sequences and a null byte (%00) in the configLanguage parameter.
nvd
CVE-2023-4428P3HIGHCVSS 8.1v11.0v12.02023-08-23
CVE-2023-4428 [HIGH] CWE-125 CVE-2023-4428: Out of bounds memory access in CSS in Google Chrome prior to 116.0.5845.110 allowed a remote attacke Out of bounds memory access in CSS in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2018-6797P3CRITICALCVSS 9.8v8.0v9.02018-04-17
CVE-2018-6797 [CRITICAL] CWE-787 CVE-2018-6797: An issue was discovered in Perl 5.18 through 5.26. A crafted regular expression can cause a heap-bas An issue was discovered in Perl 5.18 through 5.26. A crafted regular expression can cause a heap-based buffer overflow, with control over the bytes written.
nvd
CVE-2021-3850P3CRITICALCVSS 9.1v9.02022-01-25
CVE-2021-3850 [CRITICAL] CWE-305 CVE-2021-3850: Authentication Bypass by Primary Weakness in GitHub repository adodb/adodb prior to 5.20.21. Authentication Bypass by Primary Weakness in GitHub repository adodb/adodb prior to 5.20.21.
nvd
CVE-2025-3155P3HIGHCVSS 7.4v11.02025-04-03
CVE-2025-3155 [HIGH] CWE-601 CVE-2025-3155: A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitr A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment.
nvd
CVE-2017-18026P3HIGHCVSS 8.8v9.02018-01-10
CVE-2017-18026 [HIGH] CVE-2017-18026: Redmine before 3.2.9, 3.3.x before 3.3.6, and 3.4.x before 3.4.4 does not block the --config and --d Redmine before 3.2.9, 3.3.x before 3.3.6, and 3.4.x before 3.4.4 does not block the --config and --debugger flags to the Mercurial hg program, which allows remote attackers to execute arbitrary commands (through the Mercurial adapter) via vectors involving a branch whose name begins with a --config= or --debugger= substring, a related issue to CVE-2017-17536.
nvd
CVE-2019-11071P3HIGHCVSS 8.8v9.02019-04-10
CVE-2019-11071 [HIGH] CWE-20 CVE-2019-11071: SPIP 3.1 before 3.1.10 and 3.2 before 3.2.4 allows authenticated visitors to execute arbitrary code SPIP 3.1 before 3.1.10 and 3.2 before 3.2.4 allows authenticated visitors to execute arbitrary code on the host server because var_memotri is mishandled.
nvd
CVE-2014-4699P4MEDIUMCVSS 6.9PoCv7.02014-07-09
CVE-2014-4699 [MEDIUM] CWE-362 CVE-2014-4699: The Linux kernel before 3.15.4 on Intel processors does not properly restrict use of a non-canonical The Linux kernel before 3.15.4 on Intel processors does not properly restrict use of a non-canonical value for the saved RIP address in the case of a system call that does not use IRET, which allows local users to leverage a race condition and gain privileges, or cause a denial of service (double fault), via a crafted application that makes ptrace and
nvd
CVE-2025-37924P3HIGHCVSS 7.8v11.02025-05-20
CVE-2025-37924 [HIGH] CWE-416 CVE-2025-37924: In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in ke In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in kerberos authentication Setting sess->user = NULL was introduced to fix the dangling pointer created by ksmbd_free_user. However, it is possible another thread could be operating on the session and make use of sess->user after it has been passed to ksmbd_
nvd
CVE-2019-16255P3HIGHCVSS 8.1v8.0v9.02019-11-26
CVE-2019-16255 [HIGH] CWE-94 CVE-2019-16255: Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows code injection if the first Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows code injection if the first argument (aka the "command" argument) to Shell#[] or Shell#test in lib/shell.rb is untrusted data. An attacker can exploit this to call an arbitrary Ruby method.
nvd
CVE-2021-1844P3HIGHCVSS 8.8v10.02021-04-02
CVE-2021-1844 [HIGH] CWE-787 CVE-2021-1844: A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 14.4.1 A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 14.4.1 and iPadOS 14.4.1, Safari 14.0.3 (v. 14610.4.3.1.7 and 15610.4.3.1.7), watchOS 7.3.2, macOS Big Sur 11.2.3. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2021-30851P3HIGHCVSS 8.8v10.0v11.02021-08-24
CVE-2021-30851 [HIGH] CWE-787 CVE-2021-30851: A memory corruption vulnerability was addressed with improved locking. This issue is fixed in Safari A memory corruption vulnerability was addressed with improved locking. This issue is fixed in Safari 15, tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Processing maliciously crafted web content may lead to code execution.
nvd
CVE-2018-16839P3CRITICALCVSS 9.8v8.0v9.02018-10-31
CVE-2018-16839 [CRITICAL] CWE-122 CVE-2018-16839: Curl versions 7.33.0 through 7.61.1 are vulnerable to a buffer overrun in the SASL authentication co Curl versions 7.33.0 through 7.61.1 are vulnerable to a buffer overrun in the SASL authentication code that may lead to denial of service.
nvd
Debian Linux vulnerabilities | cvebase