cbcvebase.

Debian Linux vulnerabilities

9,953 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358

Vulnerabilities

Page 72 of 498
CVE-2019-13273P3CRITICALCVSS 9.8v8.02019-08-27
CVE-2019-13273 [CRITICAL] CWE-787 CVE-2019-13273: In Xymon through 4.3.28, a buffer overflow vulnerability exists in the csvinfo CGI script. The overf In Xymon through 4.3.28, a buffer overflow vulnerability exists in the csvinfo CGI script. The overflow may be exploited by sending a crafted GET request that triggers an sprintf of the srcdb parameter.
nvd
CVE-2019-13734P3HIGHCVSS 8.8v9.0v10.02019-12-10
CVE-2019-13734 [HIGH] CWE-787 CVE-2019-13734: Out of bounds write in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to po Out of bounds write in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2016-8743P3HIGHCVSS 7.5v8.0v9.02017-07-27
CVE-2016-8743 [HIGH] CVE-2016-8743: Apache HTTP Server, in all releases prior to 2.2.32 and 2.4.25, was liberal in the whitespace accept Apache HTTP Server, in all releases prior to 2.2.32 and 2.4.25, was liberal in the whitespace accepted from requests and sent in response lines and headers. Accepting these different behaviors represented a security concern when httpd participates in any chain of proxies or interacts with back-end application servers, either through mod_proxy or using conventio
nvd
CVE-2017-12150P3HIGHCVSS 7.4v8.0v9.02018-07-26
CVE-2017-12150 [HIGH] CWE-300 CVE-2017-12150: It was found that samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8 did not enforce " It was found that samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8 did not enforce "SMB signing" when certain configuration options were enabled. A remote attacker could launch a man-in-the-middle attack and retrieve information in plain-text.
nvd
CVE-2024-29944P3HIGHCVSS 8.4v10.02024-03-22
CVE-2024-29944 [HIGH] CWE-830 CVE-2024-29944: An attacker was able to inject an event handler into a privileged object that would allow arbitrary An attacker was able to inject an event handler into a privileged object that would allow arbitrary JavaScript execution in the parent process. Note: This vulnerability affects Desktop Firefox only, it does not affect mobile versions of Firefox. This vulnerability affects Firefox < 124.0.1 and Firefox ESR < 115.9.1.
nvd
CVE-2012-5829P3CRITICALCVSS 9.3v6.0v7.02012-11-21
CVE-2012-5829 [CRITICAL] CWE-787 CVE-2012-5829: Heap-based buffer overflow in the nsWindow::OnExposeEvent function in Mozilla Firefox before 17.0, F Heap-based buffer overflow in the nsWindow::OnExposeEvent function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2014-1486P3CRITICALCVSS 9.8v7.02014-02-06
CVE-2014-1486 [CRITICAL] CWE-416 CVE-2014-1486: Use-after-free vulnerability in the imgRequestProxy function in Mozilla Firefox before 27.0, Firefox Use-after-free vulnerability in the imgRequestProxy function in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to execute arbitrary code via vectors involving unspecified Content-Type values for image data.
nvd
CVE-2018-6085P3HIGHCVSS 8.8v8.0v9.02018-12-04
CVE-2018-6085 [HIGH] CWE-416 CVE-2018-6085: Re-entry of a destructor in Networking Disk Cache in Google Chrome prior to 66.0.3359.117 allowed a Re-entry of a destructor in Networking Disk Cache in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code via a crafted HTML page.
nvd
CVE-2020-22669P3CRITICALCVSS 9.8v10.02022-09-02
CVE-2020-22669 [CRITICAL] CWE-89 CVE-2020-22669: Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerabi Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability. Attackers can use the comment characters and variable assignments in the SQL syntax to bypass Modsecurity WAF protection and implement SQL injection attacks on Web applications.
nvd
CVE-2023-51714P3CRITICALCVSS 9.8v10.02023-12-24
CVE-2023-51714 [CRITICAL] CWE-190 CVE-2023-51714: An issue was discovered in the HTTP2 implementation in Qt before 5.15.17, 6.x before 6.2.11, 6.3.x t An issue was discovered in the HTTP2 implementation in Qt before 5.15.17, 6.x before 6.2.11, 6.3.x through 6.5.x before 6.5.4, and 6.6.x before 6.6.2. network/access/http2/hpacktable.cpp has an incorrect HPack integer overflow check.
nvd
CVE-2018-6596P3CRITICALCVSS 9.1v9.02018-02-03
CVE-2018-6596 [CRITICAL] CWE-200 CVE-2018-6596: webhooks/base.py in Anymail (aka django-anymail) before 1.2.1 is prone to a timing attack vulnerabil webhooks/base.py in Anymail (aka django-anymail) before 1.2.1 is prone to a timing attack vulnerability on the WEBHOOK_AUTHORIZATION secret, which allows remote attackers to post arbitrary e-mail tracking events.
nvd
CVE-2022-23477P3CRITICALCVSS 9.8v11.02022-12-09
CVE-2022-23477 [CRITICAL] CWE-120 CVE-2022-23477: xrdp is an open source project which provides a graphical login to remote machines using Microsoft R xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a buffer over flow in audin_send_open() function. There are no known workarounds for this issue. Users are advised to upgrade.
nvd
CVE-2022-23478P3CRITICALCVSS 9.8v11.02022-12-09
CVE-2022-23478 [CRITICAL] CWE-787 CVE-2022-23478: xrdp is an open source project which provides a graphical login to remote machines using Microsoft R xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Out of Bound Write in xrdp_mm_trans_process_drdynvc_channel_open() function. There are no known workarounds for this issue. Users are advised to upgrade.
nvd
CVE-2019-18792P3CRITICALCVSS 9.1v8.02020-01-06
CVE-2019-18792 [CRITICAL] CWE-436 CVE-2019-18792: An issue was discovered in Suricata 5.0.0. It is possible to bypass/evade any tcp based signature by An issue was discovered in Suricata 5.0.0. It is possible to bypass/evade any tcp based signature by overlapping a TCP segment with a fake FIN packet. The fake FIN packet is injected just before the PUSH ACK packet we want to bypass. The PUSH ACK packet (containing the data) will be ignored by Suricata because it overlaps the FIN packet (the seque
nvd
CVE-2022-23468P3CRITICALCVSS 9.8v11.02022-12-09
CVE-2022-23468 [CRITICAL] CWE-120 CVE-2022-23468: xrdp is an open source project which provides a graphical login to remote machines using Microsoft R xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a buffer over flow in xrdp_login_wnd_create() function. There are no known workarounds for this issue. Users are advised to upgrade.
nvd
CVE-2016-10195P3CRITICALCVSS 9.8v8.02017-03-15
CVE-2016-10195 [CRITICAL] CWE-125 CVE-2016-10195: The name_parse function in evdns.c in libevent before 2.1.6-beta allows remote attackers to have uns The name_parse function in evdns.c in libevent before 2.1.6-beta allows remote attackers to have unspecified impact via vectors involving the label_len variable, which triggers an out-of-bounds stack read.
nvd
CVE-2012-1185P3HIGHCVSS 7.8v6.02012-06-05
CVE-2012-1185 [HIGH] CVE-2012-1185: Multiple integer overflows in (1) magick/profile.c or (2) magick/property.c in ImageMagick 6.7.5 and Multiple integer overflows in (1) magick/profile.c or (2) magick/property.c in ImageMagick 6.7.5 and earlier allow remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via crafted offset value in the ResolutionUnit tag in the EXIF IFD0 of an image. NOTE: this vulnerability exists because of an incomplete fix for
nvd
CVE-2018-18500P3CRITICALCVSS 9.8v8.0v9.02019-02-05
CVE-2018-18500 [CRITICAL] CWE-416 CVE-2018-18500: A use-after-free vulnerability can occur while parsing an HTML5 stream in concert with custom HTML e A use-after-free vulnerability can occur while parsing an HTML5 stream in concert with custom HTML elements. This results in the stream parser object being freed while still in use, leading to a potentially exploitable crash. This vulnerability affects Thunderbird < 60.5, Firefox ESR < 60.5, and Firefox < 65.
nvd
CVE-2020-5529P3HIGHCVSS 8.1v9.02020-02-11
CVE-2020-5529 [HIGH] CWE-665 CVE-2020-5529: HtmlUnit prior to 2.37.0 contains code execution vulnerabilities. HtmlUnit initializes Rhino engine HtmlUnit prior to 2.37.0 contains code execution vulnerabilities. HtmlUnit initializes Rhino engine improperly, hence a malicious JavScript code can execute arbitrary Java code on the application. Moreover, when embedded in Android application, Android-specific initialization of Rhino engine is done in an improper way, hence a malicious JavaScript code c
nvd
CVE-2020-6402P3HIGHCVSS 8.8v9.0v10.02020-02-11
CVE-2020-6402 [HIGH] CWE-20 CVE-2020-6402: Insufficient policy enforcement in downloads in Google Chrome on OS X prior to 80.0.3987.87 allowed Insufficient policy enforcement in downloads in Google Chrome on OS X prior to 80.0.3987.87 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension.
nvd
Debian Linux vulnerabilities | cvebase