cbcvebase.

Debian Linux vulnerabilities

9,953 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358

Vulnerabilities

Page 62 of 498
CVE-2019-3857P3HIGHCVSS 8.8v8.0v9.02019-03-25
CVE-2019-3857 [HIGH] CWE-190 CVE-2019-3857: An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets with an exit signal are parsed. A remote attacker who compromises a SSH server may be able to execute code on the client system when a user connects to the server.
nvd
CVE-2020-7788P3CRITICALCVSS 9.8v9.02020-12-11
CVE-2020-7788 [CRITICAL] CWE-1321 CVE-2020-7788: This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an applica This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on the application. This can be exploited further depending on the context.
nvd
CVE-2022-0572P3HIGHCVSS 7.8v9.0v10.02022-02-14
CVE-2022-0572 [HIGH] CWE-122 CVE-2022-0572: Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
nvd
CVE-2018-19873P3CRITICALCVSS 9.8v8.0v9.02018-12-26
CVE-2018-19873 [CRITICAL] CWE-119 CVE-2018-19873: An issue was discovered in Qt before 5.11.3. QBmpHandler has a buffer overflow via BMP data. An issue was discovered in Qt before 5.11.3. QBmpHandler has a buffer overflow via BMP data.
nvd
CVE-2017-17434P3CRITICALCVSS 9.8v8.0v9.02017-12-06
CVE-2017-17434 [CRITICAL] CVE-2017-17434: The daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, does not check for fnamecmp file The daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, does not check for fnamecmp filenames in the daemon_filter_list data structure (in the recv_files function in receiver.c) and also does not apply the sanitize_paths protection mechanism to pathnames found in "xname follows" strings (in the read_ndx_and_attrs function in rsync.c), which al
nvd
CVE-2017-20005P3CRITICALCVSS 9.8v9.02021-06-06
CVE-2017-20005 [CRITICAL] CWE-190 CVE-2017-20005: NGINX before 1.13.6 has a buffer overflow for years that exceed four digits, as demonstrated by a fi NGINX before 1.13.6 has a buffer overflow for years that exceed four digits, as demonstrated by a file with a modification date in 1969 that causes an integer overflow (or a false modification date far in the future), when encountered by the autoindex module.
nvd
CVE-2016-9634P3CRITICALCVSS 9.8v8.02017-01-27
CVE-2016-9634 [CRITICAL] CWE-119 CVE-2016-9634: Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC d Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via the start_line parameter.
nvd
CVE-2016-9635P3CRITICALCVSS 9.8v8.02017-01-27
CVE-2016-9635 [CRITICAL] CWE-119 CVE-2016-9635: Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC d Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by providing a 'skip count' that goes beyond initialized buffer.
nvd
CVE-2020-35636P3CRITICALCVSS 9.8v10.02021-03-04
CVE-2020-35636 [CRITICAL] CWE-129 CVE-2020-35636: A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL- A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1 in Nef_S2/SNC_io_parser.h SNC_io_parser::read_sface() sfh->volume() OOB read. A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lead to code execution. An attacker can provide malicious input
nvd
CVE-2021-20190P3HIGHCVSS 8.1v9.02021-01-19
CVE-2021-20190 [HIGH] CWE-502 CVE-2021-20190: A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between s A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
nvd
CVE-2018-12023P3HIGHCVSS 7.5v9.02019-03-21
CVE-2018-12023 [HIGH] CWE-502 CVE-2018-12023: An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When De An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Oracle JDBC jar in the classpath, and an attacker can provide an LDAP service to access, it is possible to make the service execute a malicious payload.
nvd
CVE-2024-33599P3HIGHCVSS 8.1v10.02024-05-06
CVE-2024-33599 [HIGH] CWE-121 CVE-2024-33599: nscd: Stack-based buffer overflow in netgroup cache If the Name Service Cache Daemon's (nscd) fixed nscd: Stack-based buffer overflow in netgroup cache If the Name Service Cache Daemon's (nscd) fixed size cache is exhausted by client requests then a subsequent client request for netgroup data may result in a stack-based buffer overflow. This flaw was introduced in glibc 2.15 when the cache was added to nscd. This vulnerability is only present in th
nvd
CVE-2018-1000076P3CRITICALCVSS 9.8v7.02018-03-13
CVE-2018-1000076 [CRITICAL] CWE-347 CVE-2018-1000076: RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 se RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Improper Verification of Cryptographic Signature vulnerability in package.rb that can result in a mis-signed gem could be installed, as the tar
nvd
CVE-2017-18264P3CRITICALCVSS 9.8v8.02018-05-01
CVE-2017-18264 [CRITICAL] CVE-2017-18264: An issue was discovered in libraries/common.inc.php in phpMyAdmin 4.0 before 4.0.10.20, 4.4.x, 4.6.x An issue was discovered in libraries/common.inc.php in phpMyAdmin 4.0 before 4.0.10.20, 4.4.x, 4.6.x, and 4.7.0 prereleases. The restrictions caused by $cfg['Servers'][$i]['AllowNoPassword'] = false are bypassed under certain PHP versions (e.g., version 5). This can allow the login of users who have no password set even if the administrator has set $cfg['
nvd
CVE-2019-14897P3CRITICALCVSS 9.8v8.02019-11-29
CVE-2019-14897 [CRITICAL] CWE-121 CVE-2019-14897: A stack-based buffer overflow was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi A stack-based buffer overflow was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip driver. An attacker is able to cause a denial of service (system crash) or, possibly execute arbitrary code, when a STA works in IBSS mode (allows connecting stations together without the use of an AP) and connects to another STA.
nvd
CVE-2016-3068P3HIGHCVSS 8.8v7.0v8.02016-04-13
CVE-2016-3068 [HIGH] CWE-20 CVE-2016-3068: Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted git ext:: URL Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted git ext:: URL when cloning a subrepository.
nvd
CVE-2012-3571P4MEDIUMCVSS 6.1PoCv6.0v7.02012-07-25
CVE-2012-3571 [MEDIUM] CWE-119 CVE-2012-3571: ISC DHCP 4.1.2 through 4.2.4 and 4.1-ESV before 4.1-ESV-R6 allows remote attackers to cause a denial ISC DHCP 4.1.2 through 4.2.4 and 4.1-ESV before 4.1-ESV-R6 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a malformed client identifier.
nvd
CVE-2022-37601P3CRITICALCVSS 9.8v10.02022-10-12
CVE-2022-37601 [CRITICAL] CWE-1321 CVE-2022-37601: Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils vi Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable in parseQuery.js. This affects all versions prior to 1.4.1 and 2.0.3.
nvd
CVE-2020-36328P3CRITICALCVSS 9.8v9.0v10.02021-05-21
CVE-2020-36328 [CRITICAL] CWE-787 CVE-2020-36328: A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPD A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check for buffer size. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
nvd
CVE-2015-0242P3HIGHCVSS 8.8v7.0v8.02020-01-27
CVE-2015-0242 [HIGH] CWE-787 CVE-2015-0242: Stack-based buffer overflow in the *printf function implementations in PostgreSQL before 9.0.19, 9.1 Stack-based buffer overflow in the *printf function implementations in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1, when running on a Windows system, allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a floating point number wit
nvd
Debian Linux vulnerabilities | cvebase