cbcvebase.

Debian Linux vulnerabilities

9,953 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358

Vulnerabilities

Page 76 of 498
CVE-2018-19052P3HIGHCVSS 7.5v9.02018-11-07
CVE-2018-19052 [HIGH] CWE-22 CVE-2018-19052: An issue was discovered in mod_alias_physical_handler in mod_alias.c in lighttpd before 1.4.50. Ther An issue was discovered in mod_alias_physical_handler in mod_alias.c in lighttpd before 1.4.50. There is potential ../ path traversal of a single directory above an alias target, with a specific mod_alias configuration where the matched alias lacks a trailing '/' character, but the alias target filesystem path does have a trailing '/' character.
nvd
CVE-2007-0957P3CRITICALCVSS 9.0v3.1v4.02007-04-06
CVE-2007-0957 [CRITICAL] CWE-787 CVE-2007-0957: Stack-based buffer overflow in the krb5_klog_syslog function in the kadm5 library, as used by the Ke Stack-based buffer overflow in the krb5_klog_syslog function in the kadm5 library, as used by the Kerberos administration daemon (kadmind) and Key Distribution Center (KDC), in MIT krb5 before 1.6.1 allows remote authenticated users to execute arbitrary code and modify the Kerberos key database via crafted arguments, possibly involving certain forma
nvd
CVE-2020-9355P3CRITICALCVSS 9.8v9.0v10.02020-02-23
CVE-2020-9355 [CRITICAL] CVE-2020-9355: danfruehauf NetworkManager-ssh before 1.2.11 allows privilege escalation because extra options are m danfruehauf NetworkManager-ssh before 1.2.11 allows privilege escalation because extra options are mishandled.
nvd
CVE-2022-0318P3CRITICALCVSS 9.8v10.02022-01-21
CVE-2022-0318 [CRITICAL] CWE-122 CVE-2022-0318: Heap-based Buffer Overflow in vim/vim prior to 8.2. Heap-based Buffer Overflow in vim/vim prior to 8.2.
nvd
CVE-2020-24361P3CRITICALCVSS 9.8v9.02020-08-16
CVE-2020-24361 [CRITICAL] CWE-273 CVE-2020-24361: SNMPTT before 1.4.2 allows attackers to execute shell code via EXEC, PREXEC, or unknown_trap_exec. SNMPTT before 1.4.2 allows attackers to execute shell code via EXEC, PREXEC, or unknown_trap_exec.
nvd
CVE-2012-4180P3CRITICALCVSS 9.3v6.02012-10-10
CVE-2012-4180 [CRITICAL] CWE-119 CVE-2012-4180: Heap-based buffer overflow in the nsHTMLEditor::IsPrevCharInNodeWhitespace function in Mozilla Firef Heap-based buffer overflow in the nsHTMLEditor::IsPrevCharInNodeWhitespace function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2019-5052P3HIGHCVSS 8.8v8.02019-07-03
CVE-2019-5052 [HIGH] CWE-190 CVE-2019-5052: An exploitable integer overflow vulnerability exists when loading a PCX file in SDL2_image 2.0.4. A An exploitable integer overflow vulnerability exists when loading a PCX file in SDL2_image 2.0.4. A specially crafted file can cause an integer overflow, resulting in too little memory being allocated, which can lead to a buffer overflow and potential code execution. An attacker can provide a specially crafted image file to trigger this vulnerability.
nvd
CVE-2011-2897P3CRITICALCVSS 9.8v8.0v9.0+1 more2019-11-12
CVE-2011-2897 [CRITICAL] CWE-20 CVE-2011-2897: gdk-pixbuf through 2.31.1 has GIF loader buffer overflow when initializing decompression tables due gdk-pixbuf through 2.31.1 has GIF loader buffer overflow when initializing decompression tables due to an input validation flaw
nvd
CVE-2020-16011P3CRITICALCVSS 9.6v10.02020-11-03
CVE-2020-16011 [CRITICAL] CWE-787 CVE-2020-16011: Heap buffer overflow in UI in Google Chrome on Windows prior to 86.0.4240.183 allowed a remote attac Heap buffer overflow in UI in Google Chrome on Windows prior to 86.0.4240.183 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2019-13486P3CRITICALCVSS 9.8v8.02019-08-27
CVE-2019-13486 [CRITICAL] CWE-787 CVE-2019-13486: In Xymon through 4.3.28, a stack-based buffer overflow exists in the status-log viewer component bec In Xymon through 4.3.28, a stack-based buffer overflow exists in the status-log viewer component because of expansion in svcstatus.c.
nvd
CVE-2021-45960P3HIGHCVSS 8.8v10.0v11.02022-01-01
CVE-2021-45960 [HIGH] CWE-682 CVE-2021-45960: In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory).
nvd
CVE-2017-12376P3HIGHCVSS 7.8v7.02018-01-26
CVE-2017-12376 [HIGH] CWE-119 CVE-2017-12376: ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unau ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or potentially execute arbitrary code on an affected device. The vulnerability is due to improper input validation checking mechanisms when handling Portable Document Format (.pdf
nvd
CVE-2011-1028P3CRITICALCVSS 9.8v8.0v9.0+1 more2019-11-20
CVE-2011-1028 [CRITICAL] CWE-20 CVE-2011-1028: The $smarty.template variable in Smarty3 allows attackers to possibly execute arbitrary PHP code via The $smarty.template variable in Smarty3 allows attackers to possibly execute arbitrary PHP code via the sysplugins/smarty_internal_compile_private_special_variable.php file.
nvd
CVE-2022-37616P3CRITICALCVSS 9.8v10.02022-10-11
CVE-2022-37616 [CRITICAL] CWE-1321 CVE-2022-37616: A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published a A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package before 0.8.3 for Node.js via the p variable. NOTE: the vendor states "we are in the process of marking this report as invalid"; however, some third parties takes the position that "A prototype injection/Prototype pollution
nvd
CVE-2011-2766P3HIGHCVSS 7.5v5.0v6.0+1 more2011-09-23
CVE-2011-2766 [HIGH] CWE-287 CVE-2011-2766: The FCGI (aka Fast CGI) module 0.70 through 0.73 for Perl, as used by CGI::Fast, uses environment va The FCGI (aka Fast CGI) module 0.70 through 0.73 for Perl, as used by CGI::Fast, uses environment variable values from one request during processing of a later request, which allows remote attackers to bypass authentication via crafted HTTP headers.
nvd
CVE-2016-4578P4MEDIUMCVSS 5.5PoCv8.02016-05-23
CVE-2016-4578 [MEDIUM] CWE-200 CVE-2016-4578: sound/core/timer.c in the Linux kernel through 4.6 does not initialize certain r1 data structures, w sound/core/timer.c in the Linux kernel through 4.6 does not initialize certain r1 data structures, which allows local users to obtain sensitive information from kernel stack memory via crafted use of the ALSA timer interface, related to the (1) snd_timer_user_ccallback and (2) snd_timer_user_tinterrupt functions.
nvd
CVE-2019-13115P3HIGHCVSS 8.1v8.0v9.02019-07-16
CVE-2019-13115 [HIGH] CWE-125 CVE-2019-13115: In libssh2 before 1.9.0, kex_method_diffie_hellman_group_exchange_sha256_key_exchange in kex.c has a In libssh2 before 1.9.0, kex_method_diffie_hellman_group_exchange_sha256_key_exchange in kex.c has an integer overflow that could lead to an out-of-bounds read in the way packets are read from the server. A remote attacker who compromises a SSH server may be able to disclose sensitive information or cause a denial of service condition on the client sy
nvd
CVE-2022-23806P3CRITICALCVSS 9.1v9.02022-02-11
CVE-2022-23806 [CRITICAL] CWE-252 CVE-2022-23806: Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x before 1.17.7 can incorrectly ret Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x before 1.17.7 can incorrectly return true in situations with a big.Int value that is not a valid field element.
nvd
CVE-2016-10160P3CRITICALCVSS 9.8v8.02017-01-24
CVE-2016-10160 [CRITICAL] CWE-193 CVE-2016-10160: Off-by-one error in the phar_parse_pharfile function in ext/phar/phar.c in PHP before 5.6.30 and 7.0 Off-by-one error in the phar_parse_pharfile function in ext/phar/phar.c in PHP before 5.6.30 and 7.0.x before 7.0.15 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted PHAR archive with an alias mismatch.
nvd
CVE-2021-30164P3CRITICALCVSS 9.8v9.02021-04-06
CVE-2021-30164 [CRITICAL] CVE-2021-30164: Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to bypass the add_issue_notes permissio Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to bypass the add_issue_notes permission requirement by leveraging the Issues API.
nvd
Debian Linux vulnerabilities | cvebase