Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 61 of 498
CVE-2019-3858P3CRITICALCVSS 9.1v8.02019-03-21
CVE-2019-3858 [CRITICAL] CWE-125 CVE-2019-3858: An out of bounds read flaw was discovered in libssh2 before 1.8.1 when a specially crafted SFTP pack
An out of bounds read flaw was discovered in libssh2 before 1.8.1 when a specially crafted SFTP packet is received from the server. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.
nvd
CVE-2015-0395P3CRITICALCVSS 9.3v7.0v8.02015-01-21
CVE-2015-0395 [CRITICAL] CVE-2015-0395: Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to
Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.
nvd
CVE-2022-26498P3HIGHCVSS 7.5v10.0v11.02022-04-15
CVE-2022-26498 [HIGH] CWE-400 CVE-2022-26498: An issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it is possible to download
An issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it is possible to download files that are not certificates. These files could be much larger than what one would expect to download, leading to Resource Exhaustion. This is fixed in 16.25.2, 18.11.2, and 19.3.2.
nvd
CVE-2019-20041P3CRITICALCVSS 9.8v8.0v9.0+1 more2019-12-27
CVE-2019-20041 [CRITICAL] CWE-20 CVE-2019-20041: wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon na
wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing attackers to bypass input sanitization, as demonstrated by the javascript: substring.
nvd
CVE-2018-19360P3CRITICALCVSS 9.8v8.02019-01-02
CVE-2018-19360 [CRITICAL] CWE-502 CVE-2018-19360: FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leve
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the axis2-transport-jms class from polymorphic deserialization.
nvd
CVE-2018-19361P3CRITICALCVSS 9.8v8.0v9.02019-01-02
CVE-2018-19361 [CRITICAL] CWE-502 CVE-2018-19361: FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leve
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the openjpa class from polymorphic deserialization.
nvd
CVE-2018-19362P3CRITICALCVSS 9.8v8.02019-01-02
CVE-2018-19362 [CRITICAL] CWE-502 CVE-2018-19362: FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leve
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the jboss-common-core class from polymorphic deserialization.
nvd
CVE-2019-11049P3CRITICALCVSS 9.8v10.02019-12-23
CVE-2019-11049 [CRITICAL] CWE-415 CVE-2019-11049: In PHP versions 7.3.x below 7.3.13 and 7.4.0 on Windows, when supplying custom headers to mail() fun
In PHP versions 7.3.x below 7.3.13 and 7.4.0 on Windows, when supplying custom headers to mail() function, due to mistake introduced in commit 78f4b4a2dcf92ddbccea1bb95f8390a18ac3342e, if the header is supplied in lowercase, this can result in double-freeing certain memory locations.
nvd
CVE-2017-12179P3CRITICALCVSS 9.8v8.0v9.02018-01-24
CVE-2017-12179 [CRITICAL] CWE-391 CVE-2017-12179: xorg-x11-server before 1.19.5 was vulnerable to integer overflow in (S)ProcXIBarrierReleasePointer f
xorg-x11-server before 1.19.5 was vulnerable to integer overflow in (S)ProcXIBarrierReleasePointer functions allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
nvd
CVE-2017-12177P3CRITICALCVSS 9.8v8.0v9.02018-01-24
CVE-2017-12177 [CRITICAL] CWE-391 CVE-2017-12177: xorg-x11-server before 1.19.5 was vulnerable to integer overflow in ProcDbeGetVisualInfo function al
xorg-x11-server before 1.19.5 was vulnerable to integer overflow in ProcDbeGetVisualInfo function allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
nvd
CVE-2018-14359P3CRITICALCVSS 9.8v8.0v9.02018-07-17
CVE-2018-14359 [CRITICAL] CWE-120 CVE-2018-14359: An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They have a buffer over
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They have a buffer overflow via base64 data.
nvd
CVE-2022-31084P3HIGHCVSS 8.1v11.02022-06-27
CVE-2022-31084 [HIGH] CWE-88 CVE-2022-31084: LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings)
LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 There are cases where LAM instantiates objects from arbitrary classes. An attacker can inject the first constructor argument. This can lead to code execution if non-LAM classes are instantiated that
nvd
CVE-2019-9020P3CRITICALCVSS 9.8v9.02019-02-22
CVE-2019-9020 [CRITICAL] CWE-125 CVE-2019-9020: An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x befo
An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. Invalid input to the function xmlrpc_decode() can lead to an invalid memory access (heap out of bounds read or read after free). This is related to xml_elem_parse_buf in ext/xmlrpc/libxmlrpc/xml_element.c.
nvd
CVE-2018-14352P3CRITICALCVSS 9.8v8.0v9.02018-07-17
CVE-2018-14352 [CRITICAL] CWE-787 CVE-2018-14352: An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap_quote_string in im
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap_quote_string in imap/util.c does not leave room for quote characters, leading to a stack-based buffer overflow.
nvd
CVE-2016-7446P3CRITICALCVSS 9.8v8.02017-02-06
CVE-2016-7446 [CRITICAL] CVE-2016-7446: Buffer overflow in the MVG and SVG rendering code in GraphicsMagick 1.3.24 allows remote attackers t
Buffer overflow in the MVG and SVG rendering code in GraphicsMagick 1.3.24 allows remote attackers to have unspecified impact via unknown vectors. Note: This vulnerability exists due to an incomplete patch for CVE-2016-2317.
nvd
CVE-2021-41099P3HIGHCVSS 7.5v10.0v11.02021-10-04
CVE-2021-41099 [HIGH] CWE-190 CVE-2021-41099: Redis is an open source, in-memory database that persists on disk. An integer overflow bug in the un
Redis is an open source, in-memory database that persists on disk. An integer overflow bug in the underlying string library can be used to corrupt the heap and potentially result with denial of service or remote code execution. The vulnerability involves changing the default proto-max-bulk-len configuration parameter to a very large value and construc
nvd
CVE-2020-6468P3HIGHCVSS 8.8v10.02020-05-21
CVE-2020-6468 [HIGH] CWE-787 CVE-2020-6468: Type confusion in V8 in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to potentially
Type confusion in V8 in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-2684P3MEDIUMCVSS 5.9v8.0v9.02019-04-23
CVE-2019-2684 [MEDIUM] CVE-2019-2684: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supp
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 7u211, 8u202, 11.0.2 and 12; Java SE Embedded: 8u201. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful
nvd
CVE-2022-32213P3MEDIUMCVSS 6.5v11.02022-07-14
CVE-2022-32213 [MEDIUM] CWE-444 CVE-2022-32213: The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding headers and can lead to HTTP Request Smuggling (HRS).
nvd
CVE-2019-3856P3HIGHCVSS 8.8v8.0v9.02019-03-25
CVE-2019-3856 [HIGH] CWE-190 CVE-2019-3856: An integer overflow flaw, which could lead to an out of bounds write, was discovered in libssh2 befo
An integer overflow flaw, which could lead to an out of bounds write, was discovered in libssh2 before 1.8.1 in the way keyboard prompt requests are parsed. A remote attacker who compromises a SSH server may be able to execute code on the client system when a user connects to the server.
nvd