Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 67 of 498
CVE-2015-0243P3HIGHCVSS 8.8v7.0v8.02020-01-27
CVE-2015-0243 [HIGH] CWE-120 CVE-2015-0243: Multiple buffer overflows in contrib/pgcrypto in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.
Multiple buffer overflows in contrib/pgcrypto in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allow remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.
nvd
CVE-2020-2803P3HIGHCVSS 8.3v8.0v9.0+1 more2020-04-15
CVE-2020-2803 [HIGH] CVE-2020-2803: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Sup
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful
nvd
CVE-2020-27745P3CRITICALCVSS 9.8v9.0v10.02020-11-27
CVE-2020-27745 [CRITICAL] CWE-120 CVE-2020-27745: Slurm before 19.05.8 and 20.x before 20.02.6 has an RPC Buffer Overflow in the PMIx MPI plugin.
Slurm before 19.05.8 and 20.x before 20.02.6 has an RPC Buffer Overflow in the PMIx MPI plugin.
nvd
CVE-2021-22940P3HIGHCVSS 7.5v10.02021-08-16
CVE-2021-22940 [HIGH] CWE-416 CVE-2021-22940: Node.js before 16.6.1, 14.17.5, and 12.22.5 is vulnerable to a use after free attack where an attack
Node.js before 16.6.1, 14.17.5, and 12.22.5 is vulnerable to a use after free attack where an attacker might be able to exploit the memory corruption, to change process behavior.
nvd
CVE-2021-31872P3CRITICALCVSS 9.8v9.02021-04-30
CVE-2021-31872 [CRITICAL] CWE-190 CVE-2021-31872: An issue was discovered in klibc before 2.0.9. Multiple possible integer overflows in the cpio comma
An issue was discovered in klibc before 2.0.9. Multiple possible integer overflows in the cpio command on 32-bit systems may result in a buffer overflow or other security impact.
nvd
CVE-2019-13455P3CRITICALCVSS 9.8v8.02019-08-27
CVE-2019-13455 [CRITICAL] CWE-787 CVE-2019-13455: In Xymon through 4.3.28, a stack-based buffer overflow vulnerability exists in the alert acknowledgm
In Xymon through 4.3.28, a stack-based buffer overflow vulnerability exists in the alert acknowledgment CGI tool because of expansion in acknowledge.c.
nvd
CVE-2022-0582P3CRITICALCVSS 9.8v9.02022-02-14
CVE-2022-0582 [CRITICAL] CWE-476 CVE-2022-0582: Unaligned access in the CSN.1 protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 all
Unaligned access in the CSN.1 protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file
nvd
CVE-2021-23518P3CRITICALCVSS 9.8v10.02022-01-21
CVE-2021-23518 [CRITICAL] CWE-1321 CVE-2021-23518: The package cached-path-relative before 1.1.0 are vulnerable to Prototype Pollution via the cache va
The package cached-path-relative before 1.1.0 are vulnerable to Prototype Pollution via the cache variable that is set as {} instead of Object.create(null) in the cachedPathRelative function, which allows access to the parent prototype properties when the object is used to create the cached relative path. When using the origin path as __proto__,
nvd
CVE-2021-20307P3CRITICALCVSS 9.8v9.02021-04-05
CVE-2021-20307 [CRITICAL] CWE-134 CVE-2021-20307: Format string vulnerability in panoFileOutputNamesCreate() in libpano13 2.9.20~rc2+dfsg-3 and earlie
Format string vulnerability in panoFileOutputNamesCreate() in libpano13 2.9.20~rc2+dfsg-3 and earlier can lead to read and write arbitrary memory values.
nvd
CVE-2022-36227P3CRITICALCVSS 9.8v10.02022-11-22
CVE-2022-36227 [CRITICAL] CWE-476 CVE-2022-36227: In libarchive before 3.6.2, the software does not check for an error after calling calloc function t
In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the discoverer cites this CWE-476 remark but third parties dispute the code-execution impact: "In rare circumstances, when NULL is e
nvd
CVE-2021-3694P3CRITICALCVSS 9.6v10.0v11.02021-08-23
CVE-2021-3694 [CRITICAL] CWE-79 CVE-2021-3694: LedgerSMB does not sufficiently HTML-encode error messages sent to the browser. By sending a special
LedgerSMB does not sufficiently HTML-encode error messages sent to the browser. By sending a specially crafted URL to an authenticated user, this flaw can be abused for remote code execution and information disclosure.
nvd
CVE-2023-1998P4MEDIUMCVSS 5.6PoCv10.02023-04-21
CVE-2023-1998 [MEDIUM] CWE-1303 CVE-2023-1998: The Linux kernel allows userspace processes to enable mitigations by calling prctl with PR_SET_SPECU
The Linux kernel allows userspace processes to enable mitigations by calling prctl with PR_SET_SPECULATION_CTRL which disables the speculation feature as well as by using seccomp. We had noticed that on VMs of at least one major cloud provider, the kernel still left the victim process exposed to attacks in some cases even after enabling the spectre-B
nvd
CVE-2022-41639P3CRITICALCVSS 9.8v11.02022-12-22
CVE-2022-41639 [CRITICAL] CWE-122 CVE-2022-41639: A heap based buffer overflow vulnerability exists in tile decoding code of TIFF image parser in Open
A heap based buffer overflow vulnerability exists in tile decoding code of TIFF image parser in OpenImageIO master-branch-9aeece7a and v2.3.19.0. A specially-crafted TIFF file can lead to an out of bounds memory corruption, which can result in arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
nvd
CVE-2017-10086P3CRITICALCVSS 9.6v9.02017-08-08
CVE-2017-10086 [CRITICAL] CVE-2017-10086: Vulnerability in the Java SE component of Oracle Java SE (subcomponent: JavaFX). Supported versions
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: JavaFX). Supported versions that are affected are Java SE: 7u141 and 8u131. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than the attac
nvd
CVE-2018-12022P3HIGHCVSS 7.5v9.02019-03-21
CVE-2018-12022 [HIGH] CWE-502 CVE-2018-12022: An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When De
An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Jodd-db jar (for database access for the Jodd framework) in the classpath, and an attacker can provide an LDAP service to access, it is possible to make the servic
nvd
CVE-2018-12015P3HIGHCVSS 7.5v8.0v9.02018-06-07
CVE-2018-12015 [HIGH] CWE-59 CVE-2018-12015: In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traver
In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary files, via an archive file containing a symlink and a regular file with the same name.
nvd
CVE-2022-41837P3CRITICALCVSS 9.8v11.02022-12-22
CVE-2022-41837 [CRITICAL] CWE-562 CVE-2022-41837: An out-of-bounds write vulnerability exists in the OpenImageIO::add_exif_item_to_spec functionality
An out-of-bounds write vulnerability exists in the OpenImageIO::add_exif_item_to_spec functionality of OpenImageIO Project OpenImageIO v2.4.4.2. Specially-crafted exif metadata can lead to stack-based memory corruption. An attacker can provide a malicious file to trigger this vulnerability.
nvd
CVE-2017-14482P3HIGHCVSS 8.8v8.02017-09-14
CVE-2017-14482 [HIGH] CVE-2017-14482: GNU Emacs before 25.3 allows remote attackers to execute arbitrary code via email with crafted "Cont
GNU Emacs before 25.3 allows remote attackers to execute arbitrary code via email with crafted "Content-Type: text/enriched" data containing an x-display XML element that specifies execution of shell commands, related to an unsafe text/enriched extension in lisp/textmodes/enriched.el, and unsafe Gnus support for enriched and richtext inline MIME objects in li
nvd
CVE-2022-4338P3CRITICALCVSS 9.8v11.02023-01-10
CVE-2022-4338 [CRITICAL] CWE-125 CVE-2022-4338: An integer underflow in Organization Specific TLV was found in various versions of OpenvSwitch.
An integer underflow in Organization Specific TLV was found in various versions of OpenvSwitch.
nvd
CVE-2026-25506P3HIGHCVSS 7.8v11.02026-02-10
CVE-2026-25506 [HIGH] CWE-787 CVE-2026-25506: MUNGE is an authentication service for creating and validating user credentials. From 0.5 to 0.5.17,
MUNGE is an authentication service for creating and validating user credentials. From 0.5 to 0.5.17, local attacker can exploit a buffer overflow vulnerability in munged (the MUNGE authentication daemon) to leak cryptographic key material from process memory. With the leaked key material, the attacker could forge arbitrary MUNGE credentials to imperso
nvd