cbcvebase.

Debian Linux vulnerabilities

9,953 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358

Vulnerabilities

Page 60 of 498
CVE-2017-1000116P3CRITICALCVSS 9.8v8.0v9.02017-10-05
CVE-2017-1000116 [CRITICAL] CWE-78 CVE-2017-1000116: Mercurial prior to 4.3 did not adequately sanitize hostnames passed to ssh, leading to possible shel Mercurial prior to 4.3 did not adequately sanitize hostnames passed to ssh, leading to possible shell-injection attacks.
nvd
CVE-2022-24903P3HIGHCVSS 8.1v9.0v10.0+1 more2022-05-06
CVE-2022-24903 [HIGH] CWE-120 CVE-2022-24903: Rsyslog is a rocket-fast system for log processing. Modules for TCP syslog reception have a potentia Rsyslog is a rocket-fast system for log processing. Modules for TCP syslog reception have a potential heap buffer overflow when octet-counted framing is used. This can result in a segfault or some other malfunction. As of our understanding, this vulnerability can not be used for remote code execution. But there may still be a slight chance for experts
nvd
CVE-2022-27223P3HIGHCVSS 8.8v9.02022-03-16
CVE-2022-27223 [HIGH] CWE-129 CVE-2022-27223: In drivers/usb/gadget/udc/udc-xilinx.c in the Linux kernel before 5.16.12, the endpoint index is not In drivers/usb/gadget/udc/udc-xilinx.c in the Linux kernel before 5.16.12, the endpoint index is not validated and might be manipulated by the host for out-of-array access.
nvd
CVE-2016-2054P3CRITICALCVSS 9.8v8.02016-04-13
CVE-2016-2054 [CRITICAL] CWE-119 CVE-2016-2054: Multiple buffer overflows in xymond/xymond.c in xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.2 Multiple buffer overflows in xymond/xymond.c in xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a long filename, involving handling a "config" command.
nvd
CVE-2023-39353P3CRITICALCVSS 9.1v10.02023-08-31
CVE-2023-39353 [CRITICAL] CWE-125 CVE-2023-39353: FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache lic FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions are subject to a missing offset validation leading to Out Of Bound Read. In the `libfreerdp/codec/rfx.c` file there is no offset validation in `tile->quantIdxY`, `tile->quantIdxCb`, and `tile->quantIdxCr`. As a result crafted
nvd
CVE-2014-8990P3HIGHCVSS 7.5v7.02014-12-05
CVE-2014-8990 [HIGH] CWE-77 CVE-2014-8990: default-rsyncssh.lua in Lsyncd 2.1.5 and earlier allows remote attackers to execute arbitrary comman default-rsyncssh.lua in Lsyncd 2.1.5 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a filename.
nvd
CVE-2020-1927P3MEDIUMCVSS 6.1v9.0v10.02020-04-02
CVE-2020-1927 [MEDIUM] CWE-601 CVE-2020-1927: In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to b In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request URL.
nvd
CVE-2013-7325P3HIGHCVSS 8.8v7.0v8.0+3 more2019-12-03
CVE-2013-7325 [HIGH] CVE-2013-7325: An issue exists in uscan in devscripts before 2.13.19, which could let a remote malicious user execu An issue exists in uscan in devscripts before 2.13.19, which could let a remote malicious user execute arbitrary code via a crafted tarball.
nvd
CVE-2014-2709P3HIGHCVSS 7.5v7.0v8.02014-04-23
CVE-2014-2709 [HIGH] CVE-2014-2709: lib/rrd.php in Cacti 0.8.7g, 0.8.8b, and earlier allows remote attackers to execute arbitrary comman lib/rrd.php in Cacti 0.8.7g, 0.8.8b, and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in unspecified parameters.
nvd
CVE-2021-43304P3HIGHCVSS 8.8v10.02022-03-14
CVE-2021-43304 [HIGH] CWE-122 CVE-2021-43304: Heap buffer overflow in Clickhouse's LZ4 compression codec when parsing a malicious query. There is Heap buffer overflow in Clickhouse's LZ4 compression codec when parsing a malicious query. There is no verification that the copy operations in the LZ4::decompressImpl loop and especially the arbitrary copy operation wildCopy(op, ip, copy_end), don’t exceed the destination buffer’s limits.
nvd
CVE-2014-8157P3HIGHCVSS 7.5v7.02015-01-26
CVE-2014-8157 [HIGH] CWE-189 CVE-2014-8157: Off-by-one error in the jpc_dec_process_sot function in JasPer 1.900.1 and earlier allows remote att Off-by-one error in the jpc_dec_process_sot function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted JPEG 2000 image, which triggers a heap-based buffer overflow.
nvd
CVE-2018-14350P3CRITICALCVSS 9.8v8.0v9.02018-07-17
CVE-2018-14350 [CRITICAL] CWE-787 CVE-2018-14350: An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/message.c has a st An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/message.c has a stack-based buffer overflow for a FETCH response with a long INTERNALDATE field.
nvd
CVE-2022-32886P3HIGHCVSS 8.8v10.0v11.02022-09-20
CVE-2022-32886 [HIGH] CWE-787 CVE-2022-32886: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Safari 1 A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Safari 16, iOS 16, iOS 15.7 and iPadOS 15.7. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2020-10018P3CRITICALCVSS 9.8v10.02020-03-02
CVE-2020-10018 [CRITICAL] CWE-416 CVE-2020-10018: WebKitGTK through 2.26.4 and WPE WebKit through 2.26.4 (which are the versions right before 2.28.0) WebKitGTK through 2.26.4 and WPE WebKit through 2.26.4 (which are the versions right before 2.28.0) contains a memory corruption issue (use-after-free) that may lead to arbitrary code execution. This issue has been fixed in 2.28.0 with improved memory handling.
nvd
CVE-2022-3550P3HIGHCVSS 8.8v10.0v11.02022-10-17
CVE-2022-3550 [HIGH] CWE-119 CVE-2022-3550: A vulnerability classified as critical was found in X.org Server. Affected by this vulnerability is A vulnerability classified as critical was found in X.org Server. Affected by this vulnerability is the function _GetCountedString of the file xkb/xkb.c. The manipulation leads to buffer overflow. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-211051.
nvd
CVE-2017-5897P3CRITICALCVSS 9.8v8.02017-03-23
CVE-2017-5897 [CRITICAL] CWE-125 CVE-2017-5897: The ip6gre_err function in net/ipv6/ip6_gre.c in the Linux kernel allows remote attackers to have un The ip6gre_err function in net/ipv6/ip6_gre.c in the Linux kernel allows remote attackers to have unspecified impact via vectors involving GRE flags in an IPv6 packet, which trigger an out-of-bounds access.
nvd
CVE-2022-42902P3HIGHCVSS 8.8v10.0v11.02022-10-13
CVE-2022-42902 [HIGH] CWE-94 CVE-2022-42902: In Linaro Automated Validation Architecture (LAVA) before 2022.10, there is dynamic code execution i In Linaro Automated Validation Architecture (LAVA) before 2022.10, there is dynamic code execution in lava_server/lavatable.py. Due to improper input sanitization, an anonymous user can force the lava-server-gunicorn service to execute user-provided code on the server.
nvd
CVE-2020-8265P3HIGHCVSS 8.1v10.02021-01-06
CVE-2020-8265 [HIGH] CWE-416 CVE-2020-8265: Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 are vulnerable to a use-after-free bug in Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 are vulnerable to a use-after-free bug in its TLS implementation. When writing to a TLS enabled socket, node::StreamBase::Write calls node::TLSWrap::DoWrite with a freshly allocated WriteWrap object as first argument. If the DoWrite method does not return an error, this object is passed back to th
nvd
CVE-2021-33909P3HIGHCVSS 7.8v9.0v10.02021-07-20
CVE-2021-33909 [HIGH] CWE-190 CVE-2021-33909: fs/seq_file.c in the Linux kernel 3.16 through 5.13.x before 5.13.4 does not properly restrict seq b fs/seq_file.c in the Linux kernel 3.16 through 5.13.x before 5.13.4 does not properly restrict seq buffer allocations, leading to an integer overflow, an Out-of-bounds Write, and escalation to root by an unprivileged user, aka CID-8cae8cd89f05.
nvd
CVE-2020-1934P3MEDIUMCVSS 5.3v9.0v10.02020-04-01
CVE-2020-1934 [MEDIUM] CWE-908 CVE-2020-1934: In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server.
nvd
Debian Linux vulnerabilities | cvebase