Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 80 of 498
CVE-2013-2852P4MEDIUMCVSS 6.9PoCv6.02013-06-07
CVE-2013-2852 [MEDIUM] CWE-134 CVE-2013-2852: Format string vulnerability in the b43_request_firmware function in drivers/net/wireless/b43/main.c
Format string vulnerability in the b43_request_firmware function in drivers/net/wireless/b43/main.c in the Broadcom B43 wireless driver in the Linux kernel through 3.9.4 allows local users to gain privileges by leveraging root access and including format string specifiers in an fwpostfix modprobe parameter, leading to improper construction of an error
nvd
CVE-2023-5472P3HIGHCVSS 8.8v11.0v12.02023-10-25
CVE-2023-5472 [HIGH] CWE-416 CVE-2023-5472: Use after free in Profiles in Google Chrome prior to 118.0.5993.117 allowed a remote attacker to pot
Use after free in Profiles in Google Chrome prior to 118.0.5993.117 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2015-3166P3CRITICALCVSS 9.8v7.0v8.0+1 more2019-11-20
CVE-2015-3166 [CRITICAL] CWE-119 CVE-2015-3166: The snprintf implementation in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9
The snprintf implementation in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 does not properly handle system-call errors, which allows attackers to obtain sensitive information or have other unspecified impact via unknown vectors, as demonstrated by an out-of-memory error.
nvd
CVE-2019-17670P3CRITICALCVSS 9.8v8.0v9.0+1 more2019-10-17
CVE-2019-17670 [CRITICAL] CWE-918 CVE-2019-17670: WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because Windows paths
WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because Windows paths are mishandled during certain validation of relative URLs.
nvd
CVE-2017-1000410P3HIGHCVSS 7.5v8.0v9.02017-12-07
CVE-2017-1000410 [HIGH] CVE-2017-1000410: The Linux kernel version 3.3-rc1 and later is affected by a vulnerability lies in the processing of
The Linux kernel version 3.3-rc1 and later is affected by a vulnerability lies in the processing of incoming L2CAP commands - ConfigRequest, and ConfigResponse messages. This info leak is a result of uninitialized stack variables that may be returned to an attacker in their uninitialized state. By manipulating the code flows that precede the handling of th
nvd
CVE-2017-2295P3HIGHCVSS 8.2v8.02017-07-05
CVE-2017-2295 [HIGH] CWE-502 CVE-2017-2295: Versions of Puppet prior to 4.10.1 will deserialize data off the wire (from the agent to the server,
Versions of Puppet prior to 4.10.1 will deserialize data off the wire (from the agent to the server, in this case) with a attacker-specified format. This could be used to force YAML deserialization in an unsafe manner, which would lead to remote code execution. This change constrains the format of data on the wire to PSON or safely decoded YAML.
nvd
CVE-2017-8028P3HIGHCVSS 8.1v8.02017-11-27
CVE-2017-8028 [HIGH] CWE-287 CVE-2017-8028: In Pivotal Spring-LDAP versions 1.3.0 - 2.3.1, when connected to some LDAP servers, when no addition
In Pivotal Spring-LDAP versions 1.3.0 - 2.3.1, when connected to some LDAP servers, when no additional attributes are bound, and when using LDAP BindAuthenticator with org.springframework.ldap.core.support.DefaultTlsDirContextAuthenticationStrategy as the authentication strategy, and setting userSearch, authentication is allowed with an arbitrary passwo
nvd
CVE-2022-21699P3HIGHCVSS 8.8v9.0v10.0+1 more2022-01-19
CVE-2022-21699 [HIGH] CWE-250 CVE-2022-21699: IPython (Interactive Python) is a command shell for interactive computing in multiple programming la
IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python programming language. Affected versions are subject to an arbitrary code execution vulnerability achieved by not properly managing cross user temporary files. This vulnerability allows one user to run code as
nvd
CVE-2021-21261P3HIGHCVSS 8.8v10.02021-01-14
CVE-2021-21261 [HIGH] CWE-74 CVE-2021-21261: Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux.
Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. A bug was discovered in the `flatpak-portal` service that can allow sandboxed applications to execute arbitrary code on the host system (a sandbox escape). This sandbox-escape bug is present in versions from 0.11.4 and before fixed versions 1.8.5 and 1.
nvd
CVE-2018-18498P3CRITICALCVSS 9.8v8.0v9.02019-02-28
CVE-2018-18498 [CRITICAL] CWE-190 CVE-2018-18498: A potential vulnerability leading to an integer overflow can occur during buffer size calculations f
A potential vulnerability leading to an integer overflow can occur during buffer size calculations for images when a raw value is used instead of the checked value. This leads to a possible out-of-bounds write. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64.
nvd
CVE-2025-27516P3HIGHCVSS 8.8v11.02025-03-05
CVE-2025-27516 [HIGH] CWE-1336 CVE-2025-27516: Jinja is an extensible templating engine. Prior to 3.1.6, an oversight in how the Jinja sandboxed en
Jinja is an extensible templating engine. Prior to 3.1.6, an oversight in how the Jinja sandboxed environment interacts with the |attr filter allows an attacker that controls the content of a template to execute arbitrary Python code. To exploit the vulnerability, an attacker needs to control the content of a template. Whether that is the case depend
nvd
CVE-2019-9499P3HIGHCVSS 8.1v8.02019-04-17
CVE-2019-9499 [HIGH] CWE-346 CVE-2019-9499: The implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a crypto library missi
The implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. An attacker may complete authentication, session key and control of the data connection with a client. Both hostapd with SAE support and wpa_supp
nvd
CVE-2019-9898P3CRITICALCVSS 9.8v8.0v9.02019-03-21
CVE-2019-9898 [CRITICAL] CWE-330 CVE-2019-9898: Potential recycling of random numbers used in cryptography exists within PuTTY before 0.71.
Potential recycling of random numbers used in cryptography exists within PuTTY before 0.71.
nvd
CVE-2017-17833P3CRITICALCVSS 9.8v7.02018-04-23
CVE-2017-17833 [CRITICAL] CWE-119 CVE-2017-17833: OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue whi
OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue which may manifest itself as a denial-of-service or a remote code-execution vulnerability.
nvd
CVE-2019-7165P3CRITICALCVSS 9.8v8.0v9.02019-07-03
CVE-2019-7165 [CRITICAL] CWE-119 CVE-2019-7165: A buffer overflow in DOSBox 0.74-2 allows attackers to execute arbitrary code.
A buffer overflow in DOSBox 0.74-2 allows attackers to execute arbitrary code.
nvd
CVE-2022-43599P3HIGHCVSS 8.1v11.02022-12-22
CVE-2022-43599 [HIGH] CWE-122 CVE-2022-43599: Multiple code execution vulnerabilities exist in the IFFOutput::close() functionality of OpenImageIO
Multiple code execution vulnerabilities exist in the IFFOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to a heap buffer overflow. An attacker can provide malicious input to trigger these vulnerabilities.This vulnerability arises when the `xmax` variable is set to 0xFFFF and `m
nvd
CVE-2014-1557P3CRITICALCVSS 9.3v6.0v7.02014-07-23
CVE-2014-1557 [CRITICAL] CWE-94 CVE-2014-1557: The ConvolveHorizontally function in Skia, as used in Mozilla Firefox before 31.0, Firefox ESR 24.x
The ConvolveHorizontally function in Skia, as used in Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7, does not properly handle the discarding of image data during function execution, which allows remote attackers to execute arbitrary code by triggering prolonged image scaling, as demonstrated by scaling of a hig
nvd
CVE-2020-11612P3HIGHCVSS 7.5v9.0v10.02020-04-07
CVE-2020-11612 [HIGH] CWE-770 CVE-2020-11612: The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a
The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte stream. An attacker could send a large ZlibEncoded byte stream to the Netty server, forcing the server to allocate all of its free memory to a single decoder.
nvd
CVE-2022-43602P3HIGHCVSS 8.1v11.02022-12-22
CVE-2022-43602 [HIGH] CWE-122 CVE-2022-43602: Multiple code execution vulnerabilities exist in the IFFOutput::close() functionality of OpenImageIO
Multiple code execution vulnerabilities exist in the IFFOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to a heap buffer overflow. An attacker can provide malicious input to trigger these vulnerabilities.This vulnerability arises when the `ymax` variable is set to 0xFFFF and `m
nvd
CVE-2010-3450P3CRITICALCVSS 9.3v5.0v6.02011-01-28
CVE-2010-3450 [CRITICAL] CWE-22 CVE-2010-3450: Multiple directory traversal vulnerabilities in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow re
Multiple directory traversal vulnerabilities in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow remote attackers to overwrite arbitrary files via a .. (dot dot) in an entry in (1) an XSLT JAR filter description file, (2) an Extension (aka OXT) file, or unspecified other (3) JAR or (4) ZIP files.
nvd