cbcvebase.

Debian Linux vulnerabilities

9,953 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358

Vulnerabilities

Page 70 of 498
CVE-2022-24801P3HIGHCVSS 8.1v9.02022-04-04
CVE-2022-24801 [HIGH] CWE-444 CVE-2022-24801: Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to vers Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to version 22.4.0rc1, the Twisted Web HTTP 1.1 server, located in the `twisted.web.http` module, parsed several HTTP request constructs more leniently than permitted by RFC 7230. This non-conformant parsing can lead to desync if requests pass through multiple
nvd
CVE-2022-21476P3HIGHCVSS 7.5v9.0v10.0+1 more2022-04-19
CVE-2022-21476 [HIGH] CWE-284 CVE-2022-21476: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (co Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle GraalVM Enterprise Edition: 20.3.5, 21.3.1 and 22.0.0.2. Easily exploitable vulnerability allows unauthenticated attacker with networ
nvd
CVE-2015-0411P3HIGHCVSS 7.5v7.02015-01-21
CVE-2015-0411 [HIGH] CVE-2015-0411: Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier, and 5.6.21 and earlier, allows Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier, and 5.6.21 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Server : Security : Encryption.
nvd
CVE-2020-11008P3HIGHCVSS 7.5v8.02020-04-21
CVE-2020-11008 [HIGH] CWE-20 CVE-2020-11008: Affected versions of Git have a vulnerability whereby Git can be tricked into sending private creden Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker. This bug is similar to CVE-2020-5260(GHSA-qm7j-c969-7j4q). The fix for that bug still left the door open for an exploit where _some_ credential is leaked (but the attacker cannot control which one). Git uses ext
nvd
CVE-2015-7703P3HIGHCVSS 7.5v7.0v8.0+1 more2017-07-24
CVE-2015-7703 [HIGH] CWE-20 CVE-2015-7703: The "pidfile" or "driftfile" directives in NTP ntpd 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77, w The "pidfile" or "driftfile" directives in NTP ntpd 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77, when ntpd is configured to allow remote configuration, allows remote attackers with an IP address that is allowed to send configuration requests, and with knowledge of the remote configuration password to write to arbitrary files via the :config command.
nvd
CVE-2016-7447P3CRITICALCVSS 9.8v8.02017-02-06
CVE-2016-7447 [CRITICAL] CWE-119 CVE-2016-7447: Heap-based buffer overflow in the EscapeParenthesis function in GraphicsMagick before 1.3.25 allows Heap-based buffer overflow in the EscapeParenthesis function in GraphicsMagick before 1.3.25 allows remote attackers to have unspecified impact via unknown vectors.
nvd
CVE-2020-12693P3HIGHCVSS 8.1v9.0v10.02020-05-21
CVE-2020-12693 [HIGH] CVE-2020-12693: Slurm 19.05.x before 19.05.7 and 20.02.x before 20.02.3, in the rare case where Message Aggregation Slurm 19.05.x before 19.05.7 and 20.02.x before 20.02.3, in the rare case where Message Aggregation is enabled, allows Authentication Bypass via an Alternate Path or Channel. A race condition allows a user to launch a process as an arbitrary user.
nvd
CVE-2014-2483P3CRITICALCVSS 9.3v7.02014-07-17
CVE-2014-2483 [CRITICAL] CVE-2014-2483: Unspecified vulnerability in the Java SE component in Oracle Java SE Java SE 7u60 and OpenJDK 7 allo Unspecified vulnerability in the Java SE component in Oracle Java SE Java SE 7u60 and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2014-4223. NOTE: the previous information is from the July 2014 CPU. Oracle has not commented on another ve
nvd
CVE-2018-14358P3CRITICALCVSS 9.8v8.0v9.02018-07-17
CVE-2018-14358 [CRITICAL] CWE-787 CVE-2018-14358: An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/message.c has a st An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/message.c has a stack-based buffer overflow for a FETCH response with a long RFC822.SIZE field.
nvd
CVE-2022-22576P3HIGHCVSS 8.1v10.0v11.02022-05-26
CVE-2022-22576 [HIGH] CWE-287 CVE-2022-22576: An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might a An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL-enabled protocols: SMPTP(S), IMAP(S), POP3(S) and LDAP(S) (openldap only
nvd
CVE-2019-5010P3HIGHCVSS 7.5v9.02019-10-31
CVE-2019-5010 [HIGH] CWE-476 CVE-2019-5010: An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org P An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org Python 2.7.11 / 3.6.6. A specially crafted X509 certificate can cause a NULL pointer dereference, resulting in a denial of service. An attacker can initiate or accept TLS connections using crafted certificates to trigger this vulnerability.
nvd
CVE-2020-5312P3CRITICALCVSS 9.8v9.0v10.02020-01-03
CVE-2020-5312 [CRITICAL] CWE-120 CVE-2020-5312: libImaging/PcxDecode.c in Pillow before 6.2.2 has a PCX P mode buffer overflow. libImaging/PcxDecode.c in Pillow before 6.2.2 has a PCX P mode buffer overflow.
nvd
CVE-2018-16657P3CRITICALCVSS 9.8v8.0v9.02018-09-07
CVE-2018-16657 [CRITICAL] CWE-476 CVE-2018-16657: In Kamailio before 5.0.7 and 5.1.x before 5.1.4, a crafted SIP message with an invalid Via header ca In Kamailio before 5.0.7 and 5.1.x before 5.1.4, a crafted SIP message with an invalid Via header causes a segmentation fault and crashes Kamailio. The reason is missing input validation in the crcitt_string_array core function for calculating a CRC hash for To tags. (An additional error is present in the check_via_address core function: this func
nvd
CVE-2018-3149P3HIGHCVSS 8.3v8.0v9.02018-10-17
CVE-2018-3149 [HIGH] CVE-2018-3149: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: J Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JNDI). Supported versions that are affected are Java SE: 6u201, 7u191, 8u182 and 11; Java SE Embedded: 8u181; JRockit: R28.3.19. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Ja
nvd
CVE-2020-12695P3HIGHCVSS 7.5v9.0v10.02020-06-08
CVE-2020-12695 [HIGH] CWE-276 CVE-2020-12695: The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue.
nvd
CVE-2019-18676P3HIGHCVSS 7.5v9.0v10.02019-11-26
CVE-2019-18676 [HIGH] CWE-787 CVE-2019-18676: An issue was discovered in Squid 3.x and 4.x through 4.8. Due to incorrect input validation, there i An issue was discovered in Squid 3.x and 4.x through 4.8. Due to incorrect input validation, there is a heap-based buffer overflow that can result in Denial of Service to all clients using the proxy. Severity is high due to this vulnerability occurring before normal security checks; any remote client that can reach the proxy port can trivially perform
nvd
CVE-2018-10923P3HIGHCVSS 8.1v8.0v9.02018-09-04
CVE-2018-10923 [HIGH] CWE-20 CVE-2018-10923: It was found that the "mknod" call derived from mknod(2) can create files pointing to devices on a g It was found that the "mknod" call derived from mknod(2) can create files pointing to devices on a glusterfs server node. An authenticated attacker could use this to create an arbitrary device and read data from any device attached to the glusterfs server node.
nvd
CVE-2016-0797P3HIGHCVSS 7.5v7.0v8.02016-03-03
CVE-2016-0797 [HIGH] CVE-2016-0797: Multiple integer overflows in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g allow remote attac Multiple integer overflows in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g allow remote attackers to cause a denial of service (heap memory corruption or NULL pointer dereference) or possibly have unspecified other impact via a long digit string that is mishandled by the (1) BN_dec2bn or (2) BN_hex2bn function, related to crypto/bn/bn.h and crypto/bn/bn_
nvd
CVE-2017-18190P3HIGHCVSS 7.5v7.0v8.02018-02-16
CVE-2017-18190 [HIGH] CWE-290 CVE-2017-18190: A localhost.localdomain whitelist entry in valid_host() in scheduler/client.c in CUPS before 2.2.2 a A localhost.localdomain whitelist entry in valid_host() in scheduler/client.c in CUPS before 2.2.2 allows remote attackers to execute arbitrary IPP commands by sending POST requests to the CUPS daemon in conjunction with DNS rebinding. The localhost.localdomain name is often resolved via a DNS server (neither the OS nor the web browser is responsible
nvd
CVE-2021-28834P3CRITICALCVSS 9.8v10.02021-03-19
CVE-2021-28834 [CRITICAL] CVE-2021-28834: Kramdown before 2.3.1 does not restrict Rouge formatters to the Rouge::Formatters namespace, and thu Kramdown before 2.3.1 does not restrict Rouge formatters to the Rouge::Formatters namespace, and thus arbitrary classes can be instantiated.
nvd
Debian Linux vulnerabilities | cvebase