cbcvebase.

Debian Linux vulnerabilities

9,953 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358

Vulnerabilities

Page 66 of 498
CVE-2019-13764P3HIGHCVSS 8.8v9.0v10.02019-12-10
CVE-2019-13764 [HIGH] CWE-843 CVE-2019-13764: Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to pot Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6383P3HIGHCVSS 8.8v9.0v10.02020-02-27
CVE-2020-6383 [HIGH] CWE-843 CVE-2020-6383: Type confusion in V8 in Google Chrome prior to 80.0.3987.116 allowed a remote attacker to potentiall Type confusion in V8 in Google Chrome prior to 80.0.3987.116 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2016-6525P3CRITICALCVSS 9.8v8.02016-09-22
CVE-2016-6525 [CRITICAL] CWE-119 CVE-2016-6525: Heap-based buffer overflow in the pdf_load_mesh_params function in pdf/pdf-shade.c in MuPDF allows r Heap-based buffer overflow in the pdf_load_mesh_params function in pdf/pdf-shade.c in MuPDF allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a large decode array.
nvd
CVE-2021-21996P3HIGHCVSS 7.5v9.0v10.0+1 more2021-09-08
CVE-2021-21996 [HIGH] CVE-2021-21996: An issue was discovered in SaltStack Salt before 3003.3. A user who has control of the source, and s An issue was discovered in SaltStack Salt before 3003.3. A user who has control of the source, and source_hash URLs can gain full file system access as root on a salt minion.
nvd
CVE-2016-5772P3CRITICALCVSS 9.8v8.02016-08-07
CVE-2016-5772 [CRITICAL] CWE-415 CVE-2016-5772: Double free vulnerability in the php_wddx_process_data function in wddx.c in the WDDX extension in P Double free vulnerability in the php_wddx_process_data function in wddx.c in the WDDX extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted XML data that is mishandled in a wddx_deserialize call.
nvd
CVE-2017-12166P3CRITICALCVSS 9.8v9.02017-10-04
CVE-2017-12166 [CRITICAL] CWE-787 CVE-2017-12166: OpenVPN versions before 2.3.3 and 2.4.x before 2.4.4 are vulnerable to a buffer overflow vulnerabili OpenVPN versions before 2.3.3 and 2.4.x before 2.4.4 are vulnerable to a buffer overflow vulnerability when key-method 1 is used, possibly resulting in code execution.
nvd
CVE-2020-26154P3CRITICALCVSS 9.8v9.0v10.02020-09-30
CVE-2020-26154 [CRITICAL] CWE-120 CVE-2020-26154: url.cpp in libproxy through 0.4.15 is prone to a buffer overflow when PAC is enabled, as demonstrate url.cpp in libproxy through 0.4.15 is prone to a buffer overflow when PAC is enabled, as demonstrated by a large PAC file that is delivered without a Content-length header.
nvd
CVE-2015-2320P3CRITICALCVSS 9.8v7.02018-01-08
CVE-2015-2320 [CRITICAL] CWE-295 CVE-2015-2320: The TLS stack in Mono before 3.12.1 allows remote attackers to have unspecified impact via vectors r The TLS stack in Mono before 3.12.1 allows remote attackers to have unspecified impact via vectors related to client-side SSLv2 fallback.
nvd
CVE-2019-16239P3CRITICALCVSS 9.8v8.0v9.0+1 more2019-09-17
CVE-2019-16239 [CRITICAL] CWE-120 CVE-2019-16239: process_http_response in OpenConnect before 8.05 has a Buffer Overflow when a malicious server uses process_http_response in OpenConnect before 8.05 has a Buffer Overflow when a malicious server uses HTTP chunked encoding with crafted chunk sizes.
nvd
CVE-2017-14064P3CRITICALCVSS 9.8v8.0v9.02017-08-31
CVE-2017-14064 [CRITICAL] CWE-119 CVE-2017-14064: Ruby through 2.2.7, 2.3.x through 2.3.4, and 2.4.x through 2.4.1 can expose arbitrary memory during Ruby through 2.2.7, 2.3.x through 2.3.4, and 2.4.x through 2.4.1 can expose arbitrary memory during a JSON.generate call. The issues lies in using strdup in ext/json/ext/generator/generator.c, which will stop after encountering a '\0' byte, returning a pointer to a string of length zero, which is not the length stored in space_len.
nvd
CVE-2019-15926P3CRITICALCVSS 9.1v8.02019-09-04
CVE-2019-15926 [CRITICAL] CWE-125 CVE-2019-15926: An issue was discovered in the Linux kernel before 5.2.3. Out of bounds access exists in the functio An issue was discovered in the Linux kernel before 5.2.3. Out of bounds access exists in the functions ath6kl_wmi_pstream_timeout_event_rx and ath6kl_wmi_cac_event_rx in the file drivers/net/wireless/ath/ath6kl/wmi.c.
nvd
CVE-2010-0395P3CRITICALCVSS 9.3v5.0v6.02010-06-10
CVE-2010-0395 [CRITICAL] CVE-2010-0395: OpenOffice.org 2.x and 3.0 before 3.2.1 allows user-assisted remote attackers to bypass Python macro OpenOffice.org 2.x and 3.0 before 3.2.1 allows user-assisted remote attackers to bypass Python macro security restrictions and execute arbitrary Python code via a crafted OpenDocument Text (ODT) file that triggers code execution when the macro directory structure is previewed.
nvd
CVE-2019-3846P3HIGHCVSS 8.8v8.0v9.02019-06-03
CVE-2019-3846 [HIGH] CWE-122 CVE-2019-3846: A flaw that allowed an attacker to corrupt memory and possibly escalate privileges was found in the A flaw that allowed an attacker to corrupt memory and possibly escalate privileges was found in the mwifiex kernel module while connecting to a malicious wireless network.
nvd
CVE-2015-8104P3CRITICALCVSS 10.0v7.0v8.0+1 more2015-11-16
CVE-2015-8104 [CRITICAL] CWE-399 CVE-2015-8104: The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS us The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host OS panic or hang) by triggering many #DB (aka Debug) exceptions, related to svm.c.
nvd
CVE-2022-37452P3CRITICALCVSS 9.8v10.02022-08-07
CVE-2022-37452 [CRITICAL] CWE-787 CVE-2022-37452: Exim before 4.95 has a heap-based buffer overflow for the alias list in host_name_lookup in host.c w Exim before 4.95 has a heap-based buffer overflow for the alias list in host_name_lookup in host.c when sender_host_name is set.
nvd
CVE-2015-3331P3CRITICALCVSS 9.3v7.0v8.02015-05-27
CVE-2015-3331 [CRITICAL] CWE-119 CVE-2015-3331: The __driver_rfc4106_decrypt function in arch/x86/crypto/aesni-intel_glue.c in the Linux kernel befo The __driver_rfc4106_decrypt function in arch/x86/crypto/aesni-intel_glue.c in the Linux kernel before 3.19.3 does not properly determine the memory locations used for encrypted data, which allows context-dependent attackers to cause a denial of service (buffer overflow and system crash) or possibly execute arbitrary code by triggering a crypto API
nvd
CVE-2018-1336P3HIGHCVSS 7.5v8.0v9.02018-08-02
CVE-2018-1336 [HIGH] CWE-835 CVE-2018-1336: An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an in An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.7, 8.5.0 to 8.5.30, 8.0.0.RC1 to 8.0.51, and 7.0.28 to 7.0.86.
nvd
CVE-2022-24713P3HIGHCVSS 7.5v9.0v10.0+1 more2022-03-08
CVE-2022-24713 [HIGH] CWE-400 CVE-2022-24713: regex is an implementation of regular expressions for the Rust language. The regex crate features bu regex is an implementation of regular expressions for the Rust language. The regex crate features built-in mitigations to prevent denial of service attacks caused by untrusted regexes, or untrusted input matched by trusted regexes. Those (tunable) mitigations already provide sane defaults to prevent attacks. This guarantee is documented and it's consi
nvd
CVE-2020-1944P3CRITICALCVSS 9.8v10.02020-03-23
CVE-2020-1944 [CRITICAL] CWE-444 CVE-2020-1944: There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and Transfer-Encoding and Content length headers. Upgrade to versions 7.1.9 and 8.0.6 or later versions.
nvd
CVE-2017-7375P3CRITICALCVSS 9.8v7.0v8.0+1 more2018-02-19
CVE-2017-7375 [CRITICAL] CWE-611 CVE-2017-7375: A flaw in libxml2 allows remote XML entity inclusion with default parser flags (i.e., when the calle A flaw in libxml2 allows remote XML entity inclusion with default parser flags (i.e., when the caller did not request entity substitution, DTD validation, external DTD subset loading, or default DTD attributes). Depending on the context, this may expose a higher-risk attack surface in libxml2 not usually reachable with default parser flags, and expo
nvd
Debian Linux vulnerabilities | cvebase