cbcvebase.

Debian Linux vulnerabilities

9,953 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358

Vulnerabilities

Page 68 of 498
CVE-2021-21201P3CRITICALCVSS 9.6v10.02021-04-26
CVE-2021-21201 [CRITICAL] CWE-416 CVE-2021-21201: Use after free in permissions in Google Chrome prior to 90.0.4430.72 allowed a remote attacker who h Use after free in permissions in Google Chrome prior to 90.0.4430.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2020-7060P3CRITICALCVSS 9.1v8.02020-02-10
CVE-2020-7060 [CRITICAL] CWE-125 CVE-2020-7060: When using certain mbstring functions to convert multibyte encodings, in PHP versions 7.2.x below 7. When using certain mbstring functions to convert multibyte encodings, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.3.14 and 7.4.x below 7.4.2 it is possible to supply data that will cause function mbfl_filt_conv_big5_wchar to read past the allocated buffer. This may lead to information disclosure or crash.
nvd
CVE-2021-30547P3HIGHCVSS 8.8v9.0v10.02021-06-15
CVE-2021-30547 [HIGH] CWE-787 CVE-2021-30547: Out of bounds write in ANGLE in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to po Out of bounds write in ANGLE in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
nvd
CVE-2023-39355P3CRITICALCVSS 9.8v10.02023-08-31
CVE-2023-39355 [CRITICAL] CWE-416 CVE-2023-39355: FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache lic FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Versions of FreeRDP on the 3.x release branch before beta3 are subject to a Use-After-Free in processing `RDPGFX_CMDID_RESETGRAPHICS` packets. If `context->maxPlaneSize` is 0, `context->planesBuffer` will be freed. However, without updating `c
nvd
CVE-2019-10185P3HIGHCVSS 8.6v8.02019-07-31
CVE-2019-10185 [HIGH] CWE-22 CVE-2019-10185: It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attac It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attacker could use this flaw to write files to arbitrary locations. This could also be used to replace the main running application and, possibly, break out of the sandbox.
nvd
CVE-2022-39956P3CRITICALCVSS 9.8v10.02022-09-20
CVE-2022-39956 [CRITICAL] CWE-863 CVE-2022-39956: The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass for HTTP multipar The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass for HTTP multipart requests by submitting a payload that uses a character encoding scheme via the Content-Type or the deprecated Content-Transfer-Encoding multipart MIME header fields that will not be decoded and inspected by the web application firewall engine and
nvd
CVE-2020-6096P3HIGHCVSS 8.1v10.02020-04-01
CVE-2020-6096 [HIGH] CWE-195 CVE-2020-6096: An exploitable signed comparison vulnerability exists in the ARMv7 memcpy() implementation of GNU gl An exploitable signed comparison vulnerability exists in the ARMv7 memcpy() implementation of GNU glibc 2.30.9000. Calling memcpy() (on ARMv7 targets that utilize the GNU glibc implementation) with a negative value for the 'num' parameter results in a signed comparison vulnerability. If an attacker underflows the 'num' parameter to memcpy(), this vulner
nvd
CVE-2010-0136P3CRITICALCVSS 9.3v4.0v5.02010-02-16
CVE-2010-0136 [CRITICAL] CWE-77 CVE-2010-0136: OpenOffice.org (OOo) 2.0.4, 2.4.1, and 3.1.1 does not properly enforce Visual Basic for Applications OpenOffice.org (OOo) 2.0.4, 2.4.1, and 3.1.1 does not properly enforce Visual Basic for Applications (VBA) macro security settings, which allows remote attackers to run arbitrary macros via a crafted document.
nvd
CVE-2022-23480P3CRITICALCVSS 9.8v11.02022-12-09
CVE-2022-23480 [CRITICAL] CWE-120 CVE-2022-23480: xrdp is an open source project which provides a graphical login to remote machines using Microsoft R xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a buffer over flow in devredir_proc_client_devlist_announce_req() function. There are no known workarounds for this issue. Users are advised to upgrade.
nvd
CVE-2022-23479P3CRITICALCVSS 9.8v11.02022-12-09
CVE-2022-23479 [CRITICAL] CWE-120 CVE-2022-23479: xrdp is an open source project which provides a graphical login to remote machines using Microsoft R xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a buffer over flow in xrdp_mm_chan_data_in() function. There are no known workarounds for this issue. Users are advised to upgrade.
nvd
CVE-2013-6365P4MEDIUMCVSS 5.3PoCv8.0v9.0+1 more2019-11-05
CVE-2013-6365 [MEDIUM] CWE-352 CVE-2013-6365: Horde Groupware Web mail 5.1.2 has CSRF with requests to change permissions Horde Groupware Web mail 5.1.2 has CSRF with requests to change permissions
nvd
CVE-2018-14651P3HIGHCVSS 8.8v8.02018-10-31
CVE-2018-14651 [HIGH] CVE-2018-14651: It was found that the fix for CVE-2018-10927, CVE-2018-10928, CVE-2018-10929, CVE-2018-10930, and CV It was found that the fix for CVE-2018-10927, CVE-2018-10928, CVE-2018-10929, CVE-2018-10930, and CVE-2018-10926 was incomplete. A remote, authenticated attacker could use one of these flaws to execute arbitrary code, create arbitrary files, or cause denial of service on glusterfs server nodes via symlinks to relative paths.
nvd
CVE-2025-0838P3CRITICALCVSS 9.8v11.02025-02-21
CVE-2025-0838 [CRITICAL] CWE-190 CVE-2025-0838: There exists a heap buffer overflow vulnerable in Abseil-cpp. The sized constructors, reserve(), and There exists a heap buffer overflow vulnerable in Abseil-cpp. The sized constructors, reserve(), and rehash() methods of absl::{flat,node}hash{set,map} did not impose an upper bound on their size argument. As a result, it was possible for a caller to pass a very large size that would cause an integer overflow when computing the size of the container
nvd
CVE-2020-36331P3CRITICALCVSS 9.1v9.0v10.02021-05-21
CVE-2020-36331 [CRITICAL] CWE-125 CVE-2020-36331: A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function Ch A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkAssignData. The highest threat from this vulnerability is to data confidentiality and to the service availability.
nvd
CVE-2016-4029P3HIGHCVSS 8.6v8.02016-08-07
CVE-2016-4029 [HIGH] CWE-918 CVE-2016-4029: WordPress before 4.5 does not consider octal and hexadecimal IP address formats when determining an WordPress before 4.5 does not consider octal and hexadecimal IP address formats when determining an intranet address, which allows remote attackers to bypass an intended SSRF protection mechanism via a crafted address.
nvd
CVE-2020-36330P3CRITICALCVSS 9.1v9.0v10.02021-05-21
CVE-2020-36330 [CRITICAL] CWE-125 CVE-2020-36330: A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function Ch A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkVerifyAndAssign. The highest threat from this vulnerability is to data confidentiality and to the service availability.
nvd
CVE-2017-15710P3HIGHCVSS 7.5v7.0v8.0+1 more2018-03-26
CVE-2017-15710 [HIGH] CWE-787 CVE-2017-15710: In Apache httpd 2.0.23 to 2.0.65, 2.2.0 to 2.2.34, and 2.4.0 to 2.4.29, mod_authnz_ldap, if configur In Apache httpd 2.0.23 to 2.0.65, 2.2.0 to 2.2.34, and 2.4.0 to 2.4.29, mod_authnz_ldap, if configured with AuthLDAPCharsetConfig, uses the Accept-Language header value to lookup the right charset encoding when verifying the user's credentials. If the header value is not present in the charset conversion table, a fallback mechanism is used to truncate
nvd
CVE-2022-40146P3HIGHCVSS 7.5v10.02022-09-22
CVE-2022-40146 [HIGH] CWE-918 CVE-2022-40146: Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to access files using a Jar url. This issue affects Apache XML Graphics Batik 1.14.
nvd
CVE-2011-3630P3HIGHCVSS 8.8v8.0v9.0+1 more2019-11-26
CVE-2011-3630 [HIGH] CWE-787 CVE-2011-3630: Hardlink before 0.1.2 suffer from multiple stack-based buffer overflow flaws because of the way dire Hardlink before 0.1.2 suffer from multiple stack-based buffer overflow flaws because of the way directory trees with deeply nested directories are processed. A remote attacker could provide a specially-crafted directory tree, and trick the local user into consolidating it, leading to hardlink executable crash, or, potentially arbitrary code execution wi
nvd
CVE-2020-36184P3HIGHCVSS 8.1v9.02021-01-06
CVE-2020-36184 [HIGH] CWE-502 CVE-2020-36184: FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadg FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.PerUserPoolDataSource.
nvd
Debian Linux vulnerabilities | cvebase