Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 65 of 498
CVE-2023-5996P3HIGHCVSS 8.8v11.0v12.02023-11-08
CVE-2023-5996 [HIGH] CWE-416 CVE-2023-5996: Use after free in WebAudio in Google Chrome prior to 119.0.6045.123 allowed a remote attacker to pot
Use after free in WebAudio in Google Chrome prior to 119.0.6045.123 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2017-2518P3CRITICALCVSS 9.8v8.02017-05-22
CVE-2017-2518 [CRITICAL] CWE-416 CVE-2017-2518: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "SQLite" component. It allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via
nvd
CVE-2020-29074P3HIGHCVSS 8.8v9.0v10.02020-11-25
CVE-2020-29074 [HIGH] CWE-732 CVE-2020-29074: scan.c in x11vnc 0.9.16 uses IPC_CREAT|0777 in shmget calls, which allows access by actors other tha
scan.c in x11vnc 0.9.16 uses IPC_CREAT|0777 in shmget calls, which allows access by actors other than the current user.
nvd
CVE-2019-17669P3CRITICALCVSS 9.8v8.0v9.0+1 more2019-10-17
CVE-2019-17669 [CRITICAL] CWE-918 CVE-2019-17669: WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation
WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation does not consider the interpretation of a name as a series of hex characters.
nvd
CVE-2021-43305P3HIGHCVSS 8.8v10.02022-03-14
CVE-2021-43305 [HIGH] CVE-2021-43305: Heap buffer overflow in Clickhouse's LZ4 compression codec when parsing a malicious query. There is
Heap buffer overflow in Clickhouse's LZ4 compression codec when parsing a malicious query. There is no verification that the copy operations in the LZ4::decompressImpl loop and especially the arbitrary copy operation wildCopy(op, ip, copy_end), don’t exceed the destination buffer’s limits. This issue is very similar to CVE-2021-43304, but the vulnerable copy o
nvd
CVE-2020-25722P3HIGHCVSS 8.8v9.0v10.02022-02-18
CVE-2020-25722 [HIGH] CWE-863 CVE-2020-25722: Multiple flaws were found in the way samba AD DC implemented access and conformance checking of stor
Multiple flaws were found in the way samba AD DC implemented access and conformance checking of stored data. An attacker could use this flaw to cause total domain compromise.
nvd
CVE-2021-1788P3HIGHCVSS 8.8v10.02021-04-02
CVE-2021-1788 [HIGH] CWE-416 CVE-2021-1788: A use after free issue was addressed with improved memory management. This issue is fixed in macOS B
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, tvOS 14.4, watchOS 7.3, iOS 14.4 and iPadOS 14.4, Safari 14.0.3. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2023-45363P3HIGHCVSS 7.5v11.0v12.02023-10-09
CVE-2023-45363 [HIGH] CWE-835 CVE-2023-45363: An issue was discovered in ApiPageSet.php in MediaWiki before 1.35.12, 1.36.x through 1.39.x before
An issue was discovered in ApiPageSet.php in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. It allows attackers to cause a denial of service (unbounded loop and RequestTimeoutException) when querying pages redirected to other variants with redirects and converttitles set.
nvd
CVE-2022-0711P3HIGHCVSS 7.5v11.02022-03-02
CVE-2022-0711 [HIGH] CWE-835 CVE-2022-0711: A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header. Th
A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header. This flaw could allow an attacker to send crafted HTTP response packets which lead to an infinite loop, eventually resulting in a denial of service condition. The highest threat from this vulnerability is availability.
nvd
CVE-2018-6914P3HIGHCVSS 7.5v7.0v8.0+1 more2018-04-03
CVE-2018-6914 [HIGH] CWE-22 CVE-2018-6914: Directory traversal vulnerability in the Dir.mktmpdir method in the tmpdir library in Ruby before 2.
Directory traversal vulnerability in the Dir.mktmpdir method in the tmpdir library in Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1 might allow attackers to create arbitrary directories or files via a .. (dot dot) in the prefix argument.
nvd
CVE-2018-14599P3CRITICALCVSS 9.8v8.02018-08-24
CVE-2018-14599 [CRITICAL] CWE-193 CVE-2018-14599: An issue was discovered in libX11 through 1.6.5. The function XListExtensions in ListExt.c is vulner
An issue was discovered in libX11 through 1.6.5. The function XListExtensions in ListExt.c is vulnerable to an off-by-one error caused by malicious server responses, leading to DoS or possibly unspecified other impact.
nvd
CVE-2018-0488P3CRITICALCVSS 9.8v8.0v9.02018-02-13
CVE-2018-0488 [CRITICAL] CWE-787 CVE-2018-0488: ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0, when the truncated HMAC extension and C
ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0, when the truncated HMAC extension and CBC are used, allows remote attackers to execute arbitrary code or cause a denial of service (heap corruption) via a crafted application packet within a TLS or DTLS session.
nvd
CVE-2015-2788P3CRITICALCVSS 10.0v7.02015-04-14
CVE-2015-2788 [CRITICAL] CWE-119 CVE-2015-2788: Multiple stack-based buffer overflows in the ib_fill_isqlda function in dbdimp.c in DBD-Firebird bef
Multiple stack-based buffer overflows in the ib_fill_isqlda function in dbdimp.c in DBD-Firebird before 1.19 allow remote attackers to have unspecified impact via unknown vectors that trigger an error condition, related to binding octets to columns.
nvd
CVE-2010-1437P4HIGHCVSS 7.0PoCv5.02010-05-07
CVE-2010-1437 [HIGH] CWE-362 CVE-2010-1437: Race condition in the find_keyring_by_name function in security/keys/keyring.c in the Linux kernel 2
Race condition in the find_keyring_by_name function in security/keys/keyring.c in the Linux kernel 2.6.34-rc5 and earlier allows local users to cause a denial of service (memory corruption and system crash) or possibly have unspecified other impact via keyctl session commands that trigger access to a dead keyring that is undergoing deletion by the key_c
nvd
CVE-2017-2520P3CRITICALCVSS 9.8v8.02017-05-22
CVE-2017-2520 [CRITICAL] CWE-787 CVE-2017-2520: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "SQLite" component. It allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via
nvd
CVE-2018-19475P3HIGHCVSS 7.8v8.0v9.02018-11-23
CVE-2018-19475 [HIGH] CVE-2018-19475: psi/zdevice2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access
psi/zdevice2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because available stack space is not checked when the device remains the same.
nvd
CVE-2017-8105P3CRITICALCVSS 9.8v8.02017-04-24
CVE-2017-8105 [CRITICAL] CWE-787 CVE-2017-8105: FreeType 2 before 2017-03-24 has an out-of-bounds write caused by a heap-based buffer overflow relat
FreeType 2 before 2017-03-24 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_decoder_parse_charstrings function in psaux/t1decode.c.
nvd
CVE-2018-5704P3CRITICALCVSS 9.6v8.0v9.02018-01-16
CVE-2018-5704 [CRITICAL] CWE-134 CVE-2018-5704: Open On-Chip Debugger (OpenOCD) 0.10.0 does not block attempts to use HTTP POST for sending data to
Open On-Chip Debugger (OpenOCD) 0.10.0 does not block attempts to use HTTP POST for sending data to 127.0.0.1 port 4444, which allows remote attackers to conduct cross-protocol scripting attacks, and consequently execute arbitrary commands, via a crafted web site.
nvd
CVE-2018-1000178P3CRITICALCVSS 9.8v7.0v8.0+1 more2018-05-08
CVE-2018-1000178 [CRITICAL] CWE-787 CVE-2018-1000178: A heap corruption of type CWE-120 exists in quassel version 0.12.4 in quasselcore in void DataStream
A heap corruption of type CWE-120 exists in quassel version 0.12.4 in quasselcore in void DataStreamPeer::processMessage(const QByteArray &msg) datastreampeer.cpp line 62 that allows an attacker to execute code remotely.
nvd
CVE-1999-0730P4CRITICALCVSS 10.0PoCv4.01999-06-12
CVE-1999-0730 [CRITICAL] CVE-1999-0730: The zsoelim program in the Debian man-db package allows local users to overwrite files via a symlink
The zsoelim program in the Debian man-db package allows local users to overwrite files via a symlink attack.
nvd