Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 64 of 498
CVE-2019-9278P3HIGHCVSS 8.8v8.0v9.0+1 more2019-09-27
CVE-2019-9278 [HIGH] CWE-190 CVE-2019-9278: In libexif, there is a possible out of bounds write due to an integer overflow. This could lead to r
In libexif, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalation of privilege in the media content provider with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112537774
nvd
CVE-2013-4365P3HIGHCVSS 7.5v6.0v7.02013-10-17
CVE-2013-4365 [HIGH] CWE-787 CVE-2013-4365: Heap-based buffer overflow in the fcgid_header_bucket_read function in fcgid_bucket.c in the mod_fcg
Heap-based buffer overflow in the fcgid_header_bucket_read function in fcgid_bucket.c in the mod_fcgid module before 2.3.9 for the Apache HTTP Server allows remote attackers to have an unspecified impact via unknown vectors.
nvd
CVE-2016-9602P3HIGHCVSS 8.8v8.02018-04-26
CVE-2016-9602 [HIGH] CWE-59 CVE-2016-9602: Qemu before version 2.9 is vulnerable to an improper link following when built with the VirtFS. A pr
Qemu before version 2.9 is vulnerable to an improper link following when built with the VirtFS. A privileged user inside guest could use this flaw to access host file system beyond the shared folder and potentially escalating their privileges on a host.
nvd
CVE-2019-5481P3CRITICALCVSS 9.8v9.0v10.02019-09-16
CVE-2019-5481 [CRITICAL] CWE-415 CVE-2019-5481: Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.
Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.
nvd
CVE-2021-3518P3HIGHCVSS 8.8v9.02021-05-18
CVE-2021-3518 [HIGH] CWE-416 CVE-2021-3518: There's a flaw in libxml2 in versions before 2.9.11. An attacker who is able to submit a crafted fil
There's a flaw in libxml2 in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by an application linked with libxml2 could trigger a use-after-free. The greatest impact from this flaw is to confidentiality, integrity, and availability.
nvd
CVE-2023-40569P3CRITICALCVSS 9.8v10.02023-08-31
CVE-2023-40569 [CRITICAL] CWE-787 CVE-2023-40569: FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache lic
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions are subject to an Out-Of-Bounds Write in the `progressive_decompress` function. This issue is likely down to incorrect calculations of the `nXSrc` and `nYSrc` variables. This issue has been addressed in versions 2.11.0 and 3.
nvd
CVE-2015-6831P3HIGHCVSS 7.3v7.0v8.02016-01-19
CVE-2015-6831 [HIGH] CWE-416 CVE-2015-6831: Multiple use-after-free vulnerabilities in SPL in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x
Multiple use-after-free vulnerabilities in SPL in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 allow remote attackers to execute arbitrary code via vectors involving (1) ArrayObject, (2) SplObjectStorage, and (3) SplDoublyLinkedList, which are mishandled during unserialization.
nvd
CVE-2015-1877P3HIGHCVSS 8.8v7.0v8.02021-06-02
CVE-2015-1877 [HIGH] CWE-77 CVE-2015-1877: The open_generic_xdg_mime function in xdg-open in xdg-utils 1.1.0 rc1 in Debian, when using dash, do
The open_generic_xdg_mime function in xdg-open in xdg-utils 1.1.0 rc1 in Debian, when using dash, does not properly handle local variables, which allows remote attackers to execute arbitrary commands via a crafted file.
nvd
CVE-2020-36188P3HIGHCVSS 8.1v9.02021-01-06
CVE-2020-36188 [HIGH] CWE-502 CVE-2020-36188: FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadg
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.JNDIConnectionSource.
nvd
CVE-2024-0808P3CRITICALCVSS 9.8v11.02024-01-24
CVE-2024-0808 [CRITICAL] CWE-191 CVE-2024-0808: Integer underflow in WebUI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to pote
Integer underflow in WebUI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via a malicious file. (Chromium security severity: High)
nvd
CVE-2022-35409P3CRITICALCVSS 9.1v10.02022-07-15
CVE-2022-35409 [CRITICAL] CWE-125 CVE-2022-35409: An issue was discovered in Mbed TLS before 2.28.1 and 3.x before 3.2.0. In some configurations, an u
An issue was discovered in Mbed TLS before 2.28.1 and 3.x before 3.2.0. In some configurations, an unauthenticated attacker can send an invalid ClientHello message to a DTLS server that causes a heap-based buffer over-read of up to 255 bytes. This can cause a server crash or possibly information disclosure based on error responses. Affected config
nvd
CVE-2016-4002P3CRITICALCVSS 9.8v8.02016-04-26
CVE-2016-4002 [CRITICAL] CWE-120 CVE-2016-4002: Buffer overflow in the mipsnet_receive function in hw/net/mipsnet.c in QEMU, when the guest NIC is c
Buffer overflow in the mipsnet_receive function in hw/net/mipsnet.c in QEMU, when the guest NIC is configured to accept large packets, allows remote attackers to cause a denial of service (memory corruption and QEMU crash) or possibly execute arbitrary code via a packet larger than 1514 bytes.
nvd
CVE-2018-17937P3HIGHCVSS 8.8v8.0v9.02019-03-13
CVE-2018-17937 [HIGH] CWE-121 CVE-2018-17937: gpsd versions 2.90 to 3.17 and microjson versions 1.0 to 1.3, an open source project, allow a stack-
gpsd versions 2.90 to 3.17 and microjson versions 1.0 to 1.3, an open source project, allow a stack-based buffer overflow, which may allow remote attackers to execute arbitrary code on embedded platforms via traffic on Port 2947/TCP or crafted JSON inputs.
nvd
CVE-2018-18314P3CRITICALCVSS 9.8v9.02018-12-07
CVE-2018-18314 [CRITICAL] CWE-119 CVE-2018-18314: Perl before 5.26.3 has a buffer overflow via a crafted regular expression that triggers invalid writ
Perl before 5.26.3 has a buffer overflow via a crafted regular expression that triggers invalid write operations.
nvd
CVE-2024-27053P3CRITICALCVSS 9.1v10.02024-05-01
CVE-2024-27053 [CRITICAL] CWE-476 CVE-2024-27053: In the Linux kernel, the following vulnerability has been resolved: wifi: wilc1000: fix RCU usage i
In the Linux kernel, the following vulnerability has been resolved:
wifi: wilc1000: fix RCU usage in connect path
With lockdep enabled, calls to the connect function from cfg802.11 layer
lead to the following warning:
WARNING: suspicious RCU usage
6.7.0-rc1-wt+ #333 Not tainted
drivers/net/wireless/microchip/wilc1000/hif.c:386
suspicious rcu_der
nvd
CVE-2025-26466P3MEDIUMCVSS 5.9v11.0v12.0+1 more2025-02-28
CVE-2025-26466 [MEDIUM] CWE-770 CVE-2025-26466: A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet
A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet is allocated in a memory buffer and stored in a queue of packages. It is only freed when the server/client key exchange has finished. A malicious client may keep sending such packages, leading to an uncontrolled increase in memory consumption on the
nvd
CVE-2023-40181P3CRITICALCVSS 9.1v10.02023-08-31
CVE-2023-40181 [CRITICAL] CWE-125 CVE-2023-40181: FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache lic
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions are subject to an Integer-Underflow leading to Out-Of-Bound Read in the `zgfx_decompress_segment` function. In the context of `CopyMemory`, it's possible to read data beyond the transmitted packet range and likely cause a cra
nvd
CVE-2021-25215P3HIGHCVSS 7.5v9.0v10.02021-04-29
CVE-2021-25215 [HIGH] CWE-617 CVE-2021-25215: In BIND 9.0.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1
In BIND 9.0.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.11 of the BIND 9.17 development branch, when a vulnerable version of named receives a query for a record triggering the flaw described above, the named process wi
nvd
CVE-2019-11831P3CRITICALCVSS 9.8v8.0v9.02019-05-09
CVE-2019-11831 [CRITICAL] CWE-22 CVE-2019-11831: The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TY
The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal, which allows attackers to bypass a deserialization protection mechanism, as demonstrated by a phar:///path/bad.phar/../good.phar URL.
nvd
CVE-2015-8011P3CRITICALCVSS 9.8v9.0v10.02020-01-28
CVE-2015-8011 [CRITICAL] CWE-120 CVE-2015-8011: Buffer overflow in the lldp_decode function in daemon/protocols/lldp.c in lldpd before 0.8.0 allows
Buffer overflow in the lldp_decode function in daemon/protocols/lldp.c in lldpd before 0.8.0 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via vectors involving large management addresses and TLV boundaries.
nvd