Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 75 of 498
CVE-2018-5146P3HIGHCVSS 8.8v7.0v8.0+1 more2018-06-11
CVE-2018-5146 [HIGH] CWE-787 CVE-2018-5146: An out of bounds memory write while processing Vorbis audio data was reported through the Pwn2Own co
An out of bounds memory write while processing Vorbis audio data was reported through the Pwn2Own contest. This vulnerability affects Firefox < 59.0.1, Firefox ESR < 52.7.2, and Thunderbird < 52.7.
nvd
CVE-2017-16845P3CRITICALCVSS 10.0v8.0v9.02017-11-17
CVE-2017-16845 [CRITICAL] CWE-20 CVE-2017-16845: hw/input/ps2.c in Qemu does not validate 'rptr' and 'count' values during guest migration, leading t
hw/input/ps2.c in Qemu does not validate 'rptr' and 'count' values during guest migration, leading to out-of-bounds access.
nvd
CVE-2016-9956P3HIGHCVSS 7.5v8.02017-02-22
CVE-2016-9956 [HIGH] CWE-284 CVE-2016-9956: The route manager in FlightGear before 2016.4.4 allows remote attackers to write to arbitrary files
The route manager in FlightGear before 2016.4.4 allows remote attackers to write to arbitrary files via a crafted Nasal script.
nvd
CVE-2023-50447P3HIGHCVSS 8.1v10.02024-01-19
CVE-2023-50447 [HIGH] CVE-2023-50447: Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the environment paramet
Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the environment parameter, a different vulnerability than CVE-2022-22817 (which was about the expression parameter).
nvd
CVE-2018-14349P3CRITICALCVSS 9.8v8.0v9.02018-07-17
CVE-2018-14349 [CRITICAL] CWE-20 CVE-2018-14349: An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/command.c mishandl
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/command.c mishandles a NO response without a message.
nvd
CVE-2021-21295P3MEDIUMCVSS 5.9v10.02021-03-09
CVE-2021-21295 [MEDIUM] CWE-444 CVE-2021-21295: Netty is an open-source, asynchronous event-driven network application framework for rapid developme
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.60.Final there is a vulnerability that enables request smuggling. If a Content-Length header is present in the original HTTP/2 req
nvd
CVE-2013-7088P3CRITICALCVSS 9.8v8.0v9.0+1 more2019-11-15
CVE-2013-7088 [CRITICAL] CWE-120 CVE-2013-7088: ClamAV before 0.97.7 has buffer overflow in the libclamav component
ClamAV before 0.97.7 has buffer overflow in the libclamav component
nvd
CVE-2016-0755P3HIGHCVSS 7.3v7.02016-01-29
CVE-2016-0755 [HIGH] CVE-2016-0755: The ConnectionExists function in lib/url.c in libcurl before 7.47.0 does not properly re-use NTLM-au
The ConnectionExists function in lib/url.c in libcurl before 7.47.0 does not properly re-use NTLM-authenticated proxy connections, which might allow remote attackers to authenticate as other users via a request, a similar issue to CVE-2014-0015.
nvd
CVE-2015-0241P3HIGHCVSS 8.8v7.0v8.02020-01-27
CVE-2015-0241 [HIGH] CWE-120 CVE-2015-0241: The to_char function in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x be
The to_char function in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a (1) large number of digits when processing a numeric formatting template, which triggers a buffer over-read,
nvd
CVE-2018-19206P3MEDIUMCVSS 6.1v9.02018-11-12
CVE-2018-19206 [MEDIUM] CWE-79 CVE-2018-19206: steps/mail/func.inc in Roundcube before 1.3.8 has XSS via crafted use of <svg><style>, as demonstrat
steps/mail/func.inc in Roundcube before 1.3.8 has XSS via crafted use of , as demonstrated by an onload attribute in a BODY element, within an HTML attachment.
nvd
CVE-2020-25638P3HIGHCVSS 7.4v9.0v10.02020-12-02
CVE-2020-25638 [HIGH] CWE-89 CVE-2020-25638: A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection
A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SQL comments of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. The highest th
nvd
CVE-2019-10081P3HIGHCVSS 7.5v9.0v10.02019-08-15
CVE-2019-10081 [HIGH] CWE-787 CVE-2019-10081: HTTP/2 (2.4.20 through 2.4.39) very early pushes, for example configured with "H2PushResource", coul
HTTP/2 (2.4.20 through 2.4.39) very early pushes, for example configured with "H2PushResource", could lead to an overwrite of memory in the pushing request's pool, leading to crashes. The memory copied is that of the configured push link header values, not data supplied by the client.
nvd
CVE-2019-3883P3HIGHCVSS 7.5v8.02019-04-17
CVE-2019-3883 [HIGH] CWE-772 CVE-2019-3883: In 389-ds-base up to version 1.4.1.2, requests are handled by workers threads. Each sockets will be
In 389-ds-base up to version 1.4.1.2, requests are handled by workers threads. Each sockets will be waited by the worker for at most 'ioblocktimeout' seconds. However this timeout applies only for un-encrypted requests. Connections using SSL/TLS are not taking this timeout into account during reads, and may hang longer.An unauthenticated attacker could r
nvd
CVE-2018-14360P3CRITICALCVSS 9.8v8.0v9.02018-07-17
CVE-2018-14360 [CRITICAL] CWE-787 CVE-2018-14360: An issue was discovered in NeoMutt before 2018-07-16. nntp_add_group in newsrc.c has a stack-based b
An issue was discovered in NeoMutt before 2018-07-16. nntp_add_group in newsrc.c has a stack-based buffer overflow because of incorrect sscanf usage.
nvd
CVE-2017-14152P3HIGHCVSS 8.8v8.0v9.02017-09-05
CVE-2017-14152 [HIGH] CWE-787 CVE-2017-14152: A mishandled zero case was discovered in opj_j2k_set_cinema_parameters in lib/openjp2/j2k.c in OpenJ
A mishandled zero case was discovered in opj_j2k_set_cinema_parameters in lib/openjp2/j2k.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service (heap-based buffer overflow affecting opj_write_bytes_LE in lib/openjp2/cio.c and opj_j2k_write_sot in lib/openjp2/j2k.c) or possibly remote code exec
nvd
CVE-2024-4453P3HIGHCVSS 7.8v10.02024-05-22
CVE-2024-4453 [HIGH] CWE-190 CVE-2024-4453: GStreamer EXIF Metadata Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerabi
GStreamer EXIF Metadata Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.
The specific flaw exists w
nvd
CVE-2017-7865P3CRITICALCVSS 9.8v8.02017-04-14
CVE-2017-7865 [CRITICAL] CWE-787 CVE-2017-7865: FFmpeg before 2017-01-24 has an out-of-bounds write caused by a heap-based buffer overflow related t
FFmpeg before 2017-01-24 has an out-of-bounds write caused by a heap-based buffer overflow related to the ipvideo_decode_block_opcode_0xA function in libavcodec/interplayvideo.c and the avcodec_align_dimensions2 function in libavcodec/utils.c.
nvd
CVE-2021-20308P3CRITICALCVSS 9.8v9.02021-04-05
CVE-2021-20308 [CRITICAL] CVE-2021-20308: Integer overflow in the htmldoc 1.9.11 and before may allow attackers to execute arbitrary code and
Integer overflow in the htmldoc 1.9.11 and before may allow attackers to execute arbitrary code and cause a denial of service that is similar to CVE-2017-9181.
nvd
CVE-2018-1320P3HIGHCVSS 7.5v8.02019-01-07
CVE-2018-1320 [HIGH] CWE-295 CVE-2018-1320: Apache Thrift Java client library versions 0.5.0 through 0.11.0 can bypass SASL negotiation isComple
Apache Thrift Java client library versions 0.5.0 through 0.11.0 can bypass SASL negotiation isComplete validation in the org.apache.thrift.transport.TSaslTransport class. An assert used to determine if the SASL handshake had successfully completed could be disabled in production settings making the validation incomplete.
nvd
CVE-2026-3497P3HIGHCVSS 7.5v11.02026-03-12
CVE-2026-3497 [HIGH] CWE-908 CVE-2026-3497: Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerabilit
Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerability affects the GSSAPI patches added by various Linux distributions and does not affect the OpenSSH upstream project itself. The usage of sshpkt_disconnect() on an error, which does not terminate the process, allows an attacker to send an unexpected GSSAPI
nvd