Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 69 of 498
CVE-2017-9735P3HIGHCVSS 7.5v9.02017-06-16
CVE-2017-9735 [HIGH] CWE-203 CVE-2017-9735: Jetty through 9.4.x is prone to a timing channel in util/security/Password.java, which makes it easi
Jetty through 9.4.x is prone to a timing channel in util/security/Password.java, which makes it easier for remote attackers to obtain access by observing elapsed times before rejection of incorrect passwords.
nvd
CVE-2017-15407P3HIGHCVSS 8.8v9.02018-08-28
CVE-2017-15407 [HIGH] CWE-787 CVE-2017-15407: Out-of-bounds Write in the QUIC networking stack in Google Chrome prior to 63.0.3239.84 allowed a re
Out-of-bounds Write in the QUIC networking stack in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to gain code execution via a malicious server.
nvd
CVE-2014-0446P3HIGHCVSS 7.5v6.0v7.0+1 more2014-04-16
CVE-2014-0446 [HIGH] CVE-2014-0446: Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8, and Java SE Embedded 7u51, al
Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.
nvd
CVE-2017-9324P3HIGHCVSS 8.8v8.0v9.02017-06-12
CVE-2017-9324 [HIGH] CWE-269 CVE-2017-9324: In Open Ticket Request System (OTRS) 3.3.x through 3.3.16, 4.x through 4.0.23, and 5.x through 5.0.1
In Open Ticket Request System (OTRS) 3.3.x through 3.3.16, 4.x through 4.0.23, and 5.x through 5.0.19, an attacker with agent permission is capable of opening a specific URL in a browser to gain administrative privileges / full access. Afterward, all system settings can be read and changed. The URLs in question contain index.pl?Action=Installer with ;Su
nvd
CVE-2023-40188P3CRITICALCVSS 9.1v10.02023-08-31
CVE-2023-40188 [CRITICAL] CWE-125 CVE-2023-40188: FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache lic
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions are subject to an Out-Of-Bounds Read in the `general_LumaToYUV444` function. This Out-Of-Bounds Read occurs because processing is done on the `in` variable without checking if it contains data of sufficient length. Insufficie
nvd
CVE-2018-10915P3HIGHCVSS 7.5v8.0v9.02018-08-09
CVE-2018-10915 [HIGH] CWE-89 CVE-2018-10915: A vulnerability was found in libpq, the default PostgreSQL client library where libpq failed to prop
A vulnerability was found in libpq, the default PostgreSQL client library where libpq failed to properly reset its internal state between connections. If an affected version of libpq was used with "host" or "hostaddr" connection parameters from untrusted input, attackers could bypass client-side connection security features, obtain access to higher pri
nvd
CVE-2020-7059P3CRITICALCVSS 9.1v8.02020-02-10
CVE-2020-7059 [CRITICAL] CWE-125 CVE-2020-7059: When using fgetss() function to read data with stripping tags, in PHP versions 7.2.x below 7.2.27, 7
When using fgetss() function to read data with stripping tags, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.3.14 and 7.4.x below 7.4.2 it is possible to supply data that will cause this function to read past the allocated buffer. This may lead to information disclosure or crash.
nvd
CVE-2023-4352P3HIGHCVSS 8.8v11.0v12.02023-08-15
CVE-2023-4352 [HIGH] CWE-843 CVE-2023-4352: Type confusion in V8 in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentiall
Type confusion in V8 in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2016-10149P3HIGHCVSS 7.5v8.02017-03-24
CVE-2016-10149 [HIGH] CWE-611 CVE-2016-10149: XML External Entity (XXE) vulnerability in PySAML2 4.4.0 and earlier allows remote attackers to read
XML External Entity (XXE) vulnerability in PySAML2 4.4.0 and earlier allows remote attackers to read arbitrary files via a crafted SAML XML request or response.
nvd
CVE-2018-1311P3HIGHCVSS 8.1v9.0v10.02019-12-18
CVE-2018-1311 [HIGH] CWE-416 CVE-2018-1311: The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the s
The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external DTDs. This flaw has not been addressed in the maintained version of the library and has no current mitigation other than to disable DTD processing. This can be accomplished via the DOM using a standard parser feature, or via SAX using
nvd
CVE-2020-35491P3HIGHCVSS 8.1v9.02020-12-17
CVE-2020-35491 [HIGH] CWE-502 CVE-2020-35491: FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadg
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.SharedPoolDataSource.
nvd
CVE-2020-10938P3CRITICALCVSS 9.8v8.0v9.0+1 more2020-03-24
CVE-2020-10938 [CRITICAL] CWE-190 CVE-2020-10938: GraphicsMagick before 1.3.35 has an integer overflow and resultant heap-based buffer overflow in Huf
GraphicsMagick before 1.3.35 has an integer overflow and resultant heap-based buffer overflow in HuffmanDecodeImage in magick/compress.c.
nvd
CVE-2013-4559P3HIGHCVSS 7.6v6.0v7.0+1 more2013-11-20
CVE-2013-4559 [HIGH] CWE-264 CVE-2013-4559: lighttpd before 1.4.33 does not check the return value of the (1) setuid, (2) setgid, or (3) setgrou
lighttpd before 1.4.33 does not check the return value of the (1) setuid, (2) setgid, or (3) setgroups functions, which might cause lighttpd to run as root if it is restarted and allows remote attackers to gain privileges, as demonstrated by multiple calls to the clone function that cause setuid to fail when the user process limit is reached.
nvd
CVE-2021-0326P3HIGHCVSS 7.5v9.0v10.02021-02-10
CVE-2021-0326 [HIGH] CWE-787 CVE-2021-0326: In p2p_copy_client_info of p2p.c, there is a possible out of bounds write due to a missing bounds ch
In p2p_copy_client_info of p2p.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution if the target device is performing a Wi-Fi Direct search, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android
nvd
CVE-2021-35472P3HIGHCVSS 8.8v10.02021-07-30
CVE-2021-35472 [HIGH] CWE-307 CVE-2021-35472: An issue was discovered in LemonLDAP::NG before 2.0.12. Session cache corruption can lead to authori
An issue was discovered in LemonLDAP::NG before 2.0.12. Session cache corruption can lead to authorization bypass or spoofing. By running a loop that makes many authentication attempts, an attacker might alternately be authenticated as one of two different users.
nvd
CVE-2017-17480P3CRITICALCVSS 9.8v8.0v9.02017-12-08
CVE-2017-17480 [CRITICAL] CWE-787 CVE-2017-17480: In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtovolume function in jp3d/
In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtovolume function in jp3d/convert.c. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly remote code execution.
nvd
CVE-2021-30641P3MEDIUMCVSS 5.3v9.0v10.02021-06-10
CVE-2021-30641 [MEDIUM] CVE-2021-30641: Apache HTTP Server versions 2.4.39 to 2.4.46 Unexpected matching behavior with 'MergeSlashes OFF'
Apache HTTP Server versions 2.4.39 to 2.4.46 Unexpected matching behavior with 'MergeSlashes OFF'
nvd
CVE-2019-16335P3CRITICALCVSS 9.8v8.0v9.0+1 more2019-09-15
CVE-2019-16335 [CRITICAL] CVE-2019-16335: A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariDataSource. This is a different vulnerability than CVE-2019-14540.
nvd
CVE-2021-26675P3HIGHCVSS 8.8v9.0v10.02021-02-09
CVE-2021-26675 [HIGH] CWE-787 CVE-2021-26675: A stack-based buffer overflow in dnsproxy in ConnMan before 1.39 could be used by network adjacent a
A stack-based buffer overflow in dnsproxy in ConnMan before 1.39 could be used by network adjacent attackers to execute code.
nvd
CVE-2019-17267P3CRITICALCVSS 9.8v8.02019-10-07
CVE-2019-17267 [CRITICAL] CWE-502 CVE-2019-17267: A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to net.sf.ehcache.hibernate.EhcacheJtaTransactionManagerLookup.
nvd