Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 79 of 498
CVE-2019-13726P3HIGHCVSS 8.8v9.0v10.02019-12-10
CVE-2019-13726 [HIGH] CWE-119 CVE-2019-13726: Buffer overflow in password manager in Google Chrome prior to 79.0.3945.79 allowed a remote attacker
Buffer overflow in password manager in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code via a crafted HTML page.
nvd
CVE-2009-4013P3CRITICALCVSS 9.8v4.0v5.02010-02-02
CVE-2009-4013 [CRITICAL] CWE-22 CVE-2009-4013: Multiple directory traversal vulnerabilities in Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.
Multiple directory traversal vulnerabilities in Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 allow remote attackers to overwrite arbitrary files or obtain sensitive information via vectors involving (1) control field names, (2) control field values, and (3) control files of patch systems.
nvd
CVE-2024-47685P3CRITICALCVSS 9.1v11.02024-10-21
CVE-2024-47685 [CRITICAL] CWE-908 CVE-2024-47685: In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_reject_ipv6: fix
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_reject_ipv6: fix nf_reject_ip6_tcphdr_put()
syzbot reported that nf_reject_ip6_tcphdr_put() was possibly sending
garbage on the four reserved tcp bits (th->res1)
Use skb_put_zero() to clear the whole TCP header,
as done in nf_reject_ip_tcphdr_put()
BUG: KMSAN: unin
nvd
CVE-2021-31542P3HIGHCVSS 7.5v9.02021-05-05
CVE-2021-31542 [HIGH] CWE-22 CVE-2021-31542: In Django 2.2 before 2.2.21, 3.1 before 3.1.9, and 3.2 before 3.2.1, MultiPartParser, UploadedFile,
In Django 2.2 before 2.2.21, 3.1 before 3.1.9, and 3.2 before 3.2.1, MultiPartParser, UploadedFile, and FieldFile allowed directory traversal via uploaded files with suitably crafted file names.
nvd
CVE-2019-13725P3HIGHCVSS 8.8v9.0v10.02019-12-10
CVE-2019-13725 [HIGH] CWE-416 CVE-2019-13725: Use-after-free in Bluetooth in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to exec
Use-after-free in Bluetooth in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code via a crafted HTML page.
nvd
CVE-2018-14593P3HIGHCVSS 8.8v8.0v9.02018-08-04
CVE-2018-14593 [HIGH] CVE-2018-14593: An issue was discovered in Open Ticket Request System (OTRS) 6.0.x through 6.0.9, 5.0.x through 5.0.
An issue was discovered in Open Ticket Request System (OTRS) 6.0.x through 6.0.9, 5.0.x through 5.0.28, and 4.0.x through 4.0.30. An attacker who is logged into OTRS as an agent may escalate their privileges by accessing a specially crafted URL.
nvd
CVE-2019-13735P3HIGHCVSS 8.8v9.0v10.02019-12-10
CVE-2019-13735 [HIGH] CWE-787 CVE-2019-13735: Out of bounds write in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker t
Out of bounds write in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
nvd
CVE-2022-0204P3HIGHCVSS 8.8v10.02022-03-10
CVE-2022-0204 [HIGH] CWE-119 CVE-2022-0204: A heap overflow vulnerability was found in bluez in versions prior to 5.63. An attacker with local n
A heap overflow vulnerability was found in bluez in versions prior to 5.63. An attacker with local network access could pass specially crafted files causing an application to halt or crash, leading to a denial of service.
nvd
CVE-2019-13565P3HIGHCVSS 7.5v8.02019-07-26
CVE-2019-13565 [HIGH] CVE-2019-13565: An issue was discovered in OpenLDAP 2.x before 2.4.48. When using SASL authentication and session en
An issue was discovered in OpenLDAP 2.x before 2.4.48. When using SASL authentication and session encryption, and relying on the SASL security layers in slapd access controls, it is possible to obtain access that would otherwise be denied via a simple bind for any identity covered in those ACLs. After the first SASL bind is completed, the sasl_ssf value is re
nvd
CVE-2014-2414P3HIGHCVSS 7.5v6.0v7.0+1 more2014-04-16
CVE-2014-2414 [HIGH] CVE-2014-2414: Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows rem
Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JAXB.
nvd
CVE-2014-0451P3HIGHCVSS 7.5v6.0v7.0+1 more2014-04-16
CVE-2014-0451 [HIGH] CVE-2014-0451: Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8, and Java SE Embedded 7u51, al
Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT, a different vulnerability than CVE-2014-2412.
nvd
CVE-2014-2412P3HIGHCVSS 7.5v6.0v7.0+1 more2014-04-16
CVE-2014-2412 [HIGH] CVE-2014-2412: Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, SE 7u51, and 8, and Java SE Embedded 7u51,
Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, SE 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT, a different vulnerability than CVE-2014-0451.
nvd
CVE-2023-3550P3CRITICALCVSS 9.0v10.0v11.02023-09-25
CVE-2023-3550 [CRITICAL] CWE-79 CVE-2023-3550: Mediawiki v1.40.0 does not validate namespaces used in XML files. Therefore, if the instance admini
Mediawiki v1.40.0 does not validate namespaces used in XML files.
Therefore, if the instance administrator allows XML file uploads,
a remote attacker with a low-privileged user account can use this
exploit to become an administrator by sending a malicious link to
the instance administrator.
nvd
CVE-2022-23493P3CRITICALCVSS 9.1v11.02022-12-09
CVE-2022-23493 [CRITICAL] CWE-125 CVE-2022-23493: xrdp is an open source project which provides a graphical login to remote machines using Microsoft R
xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP).
xrdp < v0.9.21 contain a Out of Bound Read in xrdp_mm_trans_process_drdynvc_channel_close() function. There are no known workarounds for this issue. Users are advised to upgrade.
nvd
CVE-2019-14439P3HIGHCVSS 7.5v8.0v9.0+1 more2019-07-30
CVE-2019-14439 [HIGH] CWE-502 CVE-2019-14439: A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occ
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the logback jar in the classpath.
nvd
CVE-2023-4354P3HIGHCVSS 8.8v11.0v12.02023-08-15
CVE-2023-4354 [HIGH] CWE-787 CVE-2023-4354: Heap buffer overflow in Skia in Google Chrome prior to 116.0.5845.96 allowed a remote attacker who h
Heap buffer overflow in Skia in Google Chrome prior to 116.0.5845.96 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2016-3171P3HIGHCVSS 8.1v7.0v8.02016-04-12
CVE-2016-3171 [HIGH] CWE-19 CVE-2016-3171: Drupal 6.x before 6.38, when used with PHP before 5.4.45, 5.5.x before 5.5.29, or 5.6.x before 5.6.1
Drupal 6.x before 6.38, when used with PHP before 5.4.45, 5.5.x before 5.5.29, or 5.6.x before 5.6.13, might allow remote attackers to execute arbitrary code via vectors related to session data truncation.
nvd
CVE-2020-12783P3HIGHCVSS 7.5v8.0v9.0+1 more2020-05-11
CVE-2020-12783 [HIGH] CWE-125 CVE-2020-12783: Exim through 4.93 has an out-of-bounds read in the SPA authenticator that could result in SPA/NTLM a
Exim through 4.93 has an out-of-bounds read in the SPA authenticator that could result in SPA/NTLM authentication bypass in auths/spa.c and auths/auth-spa.c.
nvd
CVE-2021-22946P3HIGHCVSS 7.5v9.0v10.0+1 more2021-09-29
CVE-2021-22946 [HIGH] CWE-325 CVE-2021-22946: A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to
A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-reqd` on the command line or`CURLOPT_USE_SSL` set to `CURLUSESSL_CONTROL` or `CURLUSESSL_ALL` withlibcurl). This requirement could be bypassed if the server would return a properly crafted but perfectly legitimate re
nvd
CVE-2023-5857P3HIGHCVSS 8.8v11.0v12.02023-11-01
CVE-2023-5857 [HIGH] CVE-2023-5857: Inappropriate implementation in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote
Inappropriate implementation in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to potentially execute arbitrary code via a malicious file. (Chromium security severity: Medium)
nvd