cbcvebase.

Debian Linux vulnerabilities

9,953 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358

Vulnerabilities

Page 73 of 498
CVE-2024-37371P3CRITICALCVSS 9.1v11.0v12.02024-06-28
CVE-2024-37371 [CRITICAL] CWE-125 CVE-2024-37371: In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can cause invalid memory reads during GSS me In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can cause invalid memory reads during GSS message token handling by sending message tokens with invalid length fields.
nvd
CVE-2016-6211P3HIGHCVSS 8.8v8.02016-09-09
CVE-2016-6211 [HIGH] CWE-264 CVE-2016-6211: The User module in Drupal 7.x before 7.44 allows remote authenticated users to gain privileges via v The User module in Drupal 7.x before 7.44 allows remote authenticated users to gain privileges via vectors involving contributed or custom code that triggers a rebuild of the user profile form.
nvd
CVE-2018-12565P3HIGHCVSS 8.8v9.02018-06-19
CVE-2018-12565 [HIGH] CWE-20 CVE-2018-12565: An issue was discovered in Linaro LAVA before 2018.5.post1. Because of use of yaml.load() instead of An issue was discovered in Linaro LAVA before 2018.5.post1. Because of use of yaml.load() instead of yaml.safe_load() when parsing user data, remote code execution can occur.
nvd
CVE-2022-32206P3MEDIUMCVSS 6.5v10.0v11.02022-07-07
CVE-2022-32206 [MEDIUM] CWE-770 CVE-2022-32206: curl < 7.84.0 supports "chained" HTTP compression algorithms, meaning that a serverresponse can be c curl < 7.84.0 supports "chained" HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with different algorithms. The number of acceptable "links" in this "decompression chain" was unbounded, allowing a malicious server to insert a virtually unlimited number of compression steps.The use of such a
nvd
CVE-2007-2442P3CRITICALCVSS 10.0v3.1v4.02007-06-26
CVE-2007-2442 [CRITICAL] CWE-824 CVE-2007-2442: The gssrpc__svcauth_gssapi function in the RPC library in MIT Kerberos 5 (krb5) 1.6.1 and earlier mi The gssrpc__svcauth_gssapi function in the RPC library in MIT Kerberos 5 (krb5) 1.6.1 and earlier might allow remote attackers to execute arbitrary code via a zero-length RPC credential, which causes kadmind to free an uninitialized pointer during cleanup.
nvd
CVE-2018-12086P3HIGHCVSS 7.5v9.02018-09-14
CVE-2018-12086 [HIGH] CWE-787 CVE-2018-12086: Buffer overflow in OPC UA applications allows remote attackers to trigger a stack overflow with care Buffer overflow in OPC UA applications allows remote attackers to trigger a stack overflow with carefully structured requests.
nvd
CVE-2020-9951P3HIGHCVSS 8.8v10.02020-10-16
CVE-2020-9951 [HIGH] CWE-416 CVE-2020-9951: A use after free issue was addressed with improved memory management. This issue is fixed in Safari A use after free issue was addressed with improved memory management. This issue is fixed in Safari 14.0. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2016-1522P3HIGHCVSS 8.8v7.0v8.02016-02-13
CVE-2016-1522 [HIGH] CWE-119 CVE-2016-1522: Code.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR Code.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not consider recursive load calls during a size check, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly execute arbitrary code via a crafted Graphite smart font.
nvd
CVE-2012-2239P3CRITICALCVSS 9.1v6.02012-11-24
CVE-2012-2239 [CRITICAL] CWE-611 CVE-2012-2239: Mahara 1.4.x before 1.4.4 and 1.5.x before 1.5.3 allows remote attackers to read arbitrary files or Mahara 1.4.x before 1.4.4 and 1.5.x before 1.5.3 allows remote attackers to read arbitrary files or create TCP connections via an XML external entity (XXE) injection attack, as demonstrated by reading config.php.
nvd
CVE-2019-18423P3HIGHCVSS 8.8v9.0v10.02019-10-31
CVE-2019-18423 [HIGH] CWE-193 CVE-2019-18423: An issue was discovered in Xen through 4.12.x allowing ARM guest OS users to cause a denial of servi An issue was discovered in Xen through 4.12.x allowing ARM guest OS users to cause a denial of service via a XENMEM_add_to_physmap hypercall. p2m->max_mapped_gfn is used by the functions p2m_resolve_translation_fault() and p2m_get_entry() to sanity check guest physical frame. The rest of the code in the two functions will assume that there is a valid
nvd
CVE-2016-2376P3HIGHCVSS 8.1v8.02017-01-06
CVE-2016-2376 [HIGH] CWE-119 CVE-2016-2376: A buffer overflow vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially cra A buffer overflow vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent from the server could potentially result in arbitrary code execution. A malicious server or an attacker who intercepts the network traffic can send an invalid size for a packet which will trigger a buffer overflow.
nvd
CVE-2018-6139P3HIGHCVSS 8.8v9.02019-01-09
CVE-2018-6139 [HIGH] CWE-20 CVE-2018-6139: Insufficient target checks on the chrome.debugger API in DevTools in Google Chrome prior to 67.0.339 Insufficient target checks on the chrome.debugger API in DevTools in Google Chrome prior to 67.0.3396.62 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension.
nvd
CVE-2019-11036P3CRITICALCVSS 9.1v8.0v9.0+1 more2019-05-03
CVE-2019-11036 [CRITICAL] CWE-126 CVE-2019-11036: When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.29, 7.2.x below 7.2.18 When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.29, 7.2.x below 7.2.18 and 7.3.x below 7.3.5 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to information disclosure or crash.
nvd
CVE-2014-2427P3HIGHCVSS 7.5v6.0v7.0+1 more2014-04-16
CVE-2014-2427 [HIGH] CVE-2014-2427: Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8, and Java SE Embedded 7u51, al Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Sound.
nvd
CVE-2020-9948P3HIGHCVSS 8.8v10.02020-10-16
CVE-2020-9948 [HIGH] CWE-843 CVE-2020-9948: A type confusion issue was addressed with improved memory handling. This issue is fixed in Safari 14 A type confusion issue was addressed with improved memory handling. This issue is fixed in Safari 14.0. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2020-24616P3HIGHCVSS 8.1v9.02020-08-25
CVE-2020-24616 [HIGH] CWE-502 CVE-2020-24616: FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadg FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource (aka Anteros-DBCP).
nvd
CVE-2016-4609P3CRITICALCVSS 9.8v8.02016-07-22
CVE-2016-4609 [CRITICAL] CVE-2016-4609: libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud befo libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2016-4607, CVE-2016-460
nvd
CVE-2016-4610P3CRITICALCVSS 9.8v8.02016-07-22
CVE-2016-4610 [CRITICAL] CVE-2016-4610: libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud befo libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2016-4607, CVE-2016-460
nvd
CVE-2015-8560P3HIGHCVSS 7.3v8.02016-04-14
CVE-2015-8560 [HIGH] CVE-2015-8560: Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.4.0 and Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.4.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via a ; (semicolon) character in a print job, a different vulnerability than CVE-2015-8327.
nvd
CVE-2022-46342P3HIGHCVSS 8.8v11.02022-12-14
CVE-2022-46342 [HIGH] CWE-416 CVE-2022-46342: A vulnerability was found in X.Org. This security flaw occurs because the handler for the XvdiSelect A vulnerability was found in X.Org. This security flaw occurs because the handler for the XvdiSelectVideoNotify request may write to memory after it has been freed. This issue can lead to local privileges elevation on systems where the X se
nvd
Debian Linux vulnerabilities | cvebase