Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 84 of 498
CVE-2018-6174P3HIGHCVSS 8.8v9.02019-01-09
CVE-2018-6174 [HIGH] CWE-190 CVE-2018-6174: Integer overflows in Swiftshader in Google Chrome prior to 68.0.3440.75 potentially allowed a remote
Integer overflows in Swiftshader in Google Chrome prior to 68.0.3440.75 potentially allowed a remote attacker to execute arbitrary code via a crafted HTML page.
nvd
CVE-2022-23484P3CRITICALCVSS 9.8v11.02022-12-09
CVE-2022-23484 [CRITICAL] CWE-190 CVE-2022-23484: xrdp is an open source project which provides a graphical login to remote machines using Microsoft R
xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP).
xrdp < v0.9.21 contain a Integer Overflow in xrdp_mm_process_rail_update_window_text() function. There are no known workarounds for this issue. Users are advised to upgrade.
nvd
CVE-2019-5086P3HIGHCVSS 8.8v9.02019-11-21
CVE-2019-5086 [HIGH] CWE-680 CVE-2019-5086: An exploitable integer overflow vulnerability exists in the flattenIncrementally function in the xcf
An exploitable integer overflow vulnerability exists in the flattenIncrementally function in the xcf2png and xcf2pnm binaries of xcftools, version 1.0.7. An integer overflow can occur while walking through tiles that could be exploited to corrupt memory and execute arbitrary code. In order to trigger this vulnerability, a victim would need to open a spe
nvd
CVE-2020-8623P3HIGHCVSS 7.5v9.0v10.02020-08-21
CVE-2020-8623 [HIGH] CWE-617 CVE-2020-8623: In BIND 9.10.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.10.5-S1 -> 9.11.21-S1
In BIND 9.10.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.10.5-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker that can reach a vulnerable system with a specially crafted query packet can trigger a crash. To be vulnerable, the system must: * be running BIND that was built with "--enable-native-pkcs11" * be signin
nvd
CVE-2018-16844P3HIGHCVSS 7.5v9.02018-11-07
CVE-2018-16844 [HIGH] CWE-400 CVE-2018-16844: nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can
nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive CPU usage. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'http2' option of the 'listen' directive is used in a configuration file.
nvd
CVE-2021-38002P3CRITICALCVSS 9.6v10.0v11.02021-11-23
CVE-2021-38002 [CRITICAL] CWE-416 CVE-2021-38002: Use after free in Web Transport in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to
Use after free in Web Transport in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2020-6463P3HIGHCVSS 8.8v9.0v10.02020-05-21
CVE-2020-6463 [HIGH] CWE-416 CVE-2020-6463: Use after free in ANGLE in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to potenti
Use after free in ANGLE in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6524P3HIGHCVSS 8.8v10.02020-07-22
CVE-2020-6524 [HIGH] CWE-787 CVE-2020-6524: Heap buffer overflow in WebAudio in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to
Heap buffer overflow in WebAudio in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2023-2156P3HIGHCVSS 7.5v10.02023-05-09
CVE-2023-2156 [HIGH] CWE-617 CVE-2023-2156: A flaw was found in the networking subsystem of the Linux kernel within the handling of the RPL prot
A flaw was found in the networking subsystem of the Linux kernel within the handling of the RPL protocol. This issue results from the lack of proper handling of user-supplied data, which can lead to an assertion failure. This may allow an unauthenticated remote attacker to create a denial of service condition on the system.
nvd
CVE-2020-8161P3HIGHCVSS 8.6v9.0v10.02020-07-02
CVE-2020-8161 [HIGH] CWE-548 CVE-2020-8161: A directory traversal vulnerability exists in rack < 2.2.0 that allows an attacker perform directory
A directory traversal vulnerability exists in rack < 2.2.0 that allows an attacker perform directory traversal vulnerability in the Rack::Directory app that is bundled with Rack which could result in information disclosure.
nvd
CVE-2022-22826P3HIGHCVSS 8.8v10.0v11.02022-01-10
CVE-2022-22826 [HIGH] CWE-190 CVE-2022-22826: nextScaffoldPart in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
nextScaffoldPart in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
nvd
CVE-2022-22827P3HIGHCVSS 8.8v10.0v11.02022-01-10
CVE-2022-22827 [HIGH] CWE-190 CVE-2022-22827: storeAtts in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
storeAtts in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
nvd
CVE-2021-46848P3CRITICALCVSS 9.1v10.02022-10-24
CVE-2021-46848 [CRITICAL] CWE-193 CVE-2021-46848: GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simp
GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der.
nvd
CVE-2018-14653P3HIGHCVSS 8.8v8.0v9.02018-10-31
CVE-2018-14653 [HIGH] CWE-122 CVE-2018-14653: The Gluster file system through versions 4.1.4 and 3.12 is vulnerable to a heap-based buffer overflo
The Gluster file system through versions 4.1.4 and 3.12 is vulnerable to a heap-based buffer overflow in the '__server_getspec' function via the 'gf_getspec_req' RPC message. A remote authenticated attacker could exploit this to cause a denial of service or other potential unspecified impact.
nvd
CVE-2020-14061P3HIGHCVSS 8.1v8.02020-06-14
CVE-2020-14061 [HIGH] CWE-502 CVE-2020-14061: FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadg
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oracle.jms.AQjmsQueueConnectionFactory, oracle.jms.AQjmsXATopicConnectionFactory, oracle.jms.AQjmsTopicConnectionFactory, oracle.jms.AQjmsXAQueueConnectionFactory, and oracle.jms.AQjmsXAConnectionFactory (aka weblogic/oracle-a
nvd
CVE-2019-11815P3HIGHCVSS 8.1v8.0v9.02019-05-08
CVE-2019-11815 [HIGH] CWE-362 CVE-2019-11815: An issue was discovered in rds_tcp_kill_sock in net/rds/tcp.c in the Linux kernel before 5.0.8. Ther
An issue was discovered in rds_tcp_kill_sock in net/rds/tcp.c in the Linux kernel before 5.0.8. There is a race condition leading to a use-after-free, related to net namespace cleanup.
nvd
CVE-2019-5762P3HIGHCVSS 8.8v9.02019-02-19
CVE-2019-5762 [HIGH] CWE-119 CVE-2019-5762: Inappropriate memory management when caching in PDFium in Google Chrome prior to 72.0.3626.81 allowe
Inappropriate memory management when caching in PDFium in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file.
nvd
CVE-2019-5756P3HIGHCVSS 8.8v9.02019-02-19
CVE-2019-5756 [HIGH] CWE-416 CVE-2019-5756: Inappropriate memory management when caching in PDFium in Google Chrome prior to 72.0.3626.81 allowe
Inappropriate memory management when caching in PDFium in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file.
nvd
CVE-2011-3631P3HIGHCVSS 8.8v8.0v9.0+1 more2019-11-26
CVE-2011-3631 [HIGH] CWE-190 CVE-2011-3631: Hardlink before 0.1.2 has multiple integer overflows leading to heap-based buffer overflows because
Hardlink before 0.1.2 has multiple integer overflows leading to heap-based buffer overflows because of the way string lengths concatenation is done in the calculation of the required memory space to be used. A remote attacker could provide a specially-crafted directory tree and trick the local user into consolidating it, leading to hardlink executable cr
nvd
CVE-2018-3839P3HIGHCVSS 8.8v8.0v9.02018-04-10
CVE-2018-3839 [HIGH] CWE-787 CVE-2018-3839: An exploitable code execution vulnerability exists in the XCF image rendering functionality of Simpl
An exploitable code execution vulnerability exists in the XCF image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A specially crafted XCF image can cause an out-of-bounds write on the heap, resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability.
nvd