Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 91 of 498
CVE-2014-1609P3HIGHCVSS 7.5v7.02014-03-20
CVE-2014-1609 [HIGH] CWE-89 CVE-2014-1609: Multiple SQL injection vulnerabilities in MantisBT before 1.2.16 allow remote attackers to execute a
Multiple SQL injection vulnerabilities in MantisBT before 1.2.16 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to the (1) mc_project_get_attachments function in api/soap/mc_project_api.php; the (2) news_get_limited_rows function in core/news_api.php; the (3) summary_print_by_enum, (4) summary_print_by_age, (5) summar
nvd
CVE-2018-14351P3CRITICALCVSS 9.8v8.0v9.02018-07-17
CVE-2018-14351 [CRITICAL] CWE-20 CVE-2018-14351: An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/command.c mishandl
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/command.c mishandles a long IMAP status mailbox literal count size.
nvd
CVE-2017-14041P3HIGHCVSS 8.8v8.0v9.02017-08-30
CVE-2017-14041 [HIGH] CWE-787 CVE-2017-14041: A stack-based buffer overflow was discovered in the pgxtoimage function in bin/jp2/convert.c in Open
A stack-based buffer overflow was discovered in the pgxtoimage function in bin/jp2/convert.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly remote code execution.
nvd
CVE-2017-6891P3HIGHCVSS 8.8v8.02017-05-22
CVE-2017-6891 [HIGH] CWE-787 CVE-2017-6891: Two errors in the "asn1_find_node()" function (lib/parser_aux.c) within GnuTLS libtasn1 version 4.10
Two errors in the "asn1_find_node()" function (lib/parser_aux.c) within GnuTLS libtasn1 version 4.10 can be exploited to cause a stacked-based buffer overflow by tricking a user into processing a specially crafted assignments file via the e.g. asn1Coding utility.
nvd
CVE-2019-17042P3CRITICALCVSS 9.8v9.02019-10-07
CVE-2019-17042 [CRITICAL] CWE-20 CVE-2019-17042: An issue was discovered in Rsyslog v8.1908.0. contrib/pmcisconames/pmcisconames.c has a heap overflo
An issue was discovered in Rsyslog v8.1908.0. contrib/pmcisconames/pmcisconames.c has a heap overflow in the parser for Cisco log messages. The parser tries to locate a log message delimiter (in this case, a space or a colon), but fails to account for strings that do not satisfy this constraint. If the string does not match, then the variable lenMs
nvd
CVE-2024-2607P3HIGHCVSS 8.1v10.02024-03-19
CVE-2024-2607 [HIGH] CWE-123 CVE-2024-2607: Return registers were overwritten which could have allowed an attacker to execute arbitrary code. *N
Return registers were overwritten which could have allowed an attacker to execute arbitrary code. *Note:* This issue only affected Armv7-A systems. Other operating systems are unaffected. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
nvd
CVE-2020-25696P3HIGHCVSS 7.5v9.02020-11-23
CVE-2020-25696 [HIGH] CWE-183 CVE-2020-25696: A flaw was found in the psql interactive terminal of PostgreSQL in versions before 13.1, before 12.5
A flaw was found in the psql interactive terminal of PostgreSQL in versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. If an interactive psql session uses \gset when querying a compromised server, the attacker can execute arbitrary code as the operating system account running psql. The highest threat from th
nvd
CVE-2018-1000005P3CRITICALCVSS 9.1v8.0v9.02018-01-24
CVE-2018-1000005 [CRITICAL] CWE-125 CVE-2018-1000005: libcurl 7.49.0 to and including 7.57.0 contains an out bounds read in code handling HTTP/2 trailers.
libcurl 7.49.0 to and including 7.57.0 contains an out bounds read in code handling HTTP/2 trailers. It was reported (https://github.com/curl/curl/pull/2231) that reading an HTTP/2 trailer could mess up future trailers since the stored size was one byte less than required. The problem is that the code that creates HTTP/1-like headers from the
nvd
CVE-2019-6690P3HIGHCVSS 7.5v8.0v9.02019-03-21
CVE-2019-6690 [HIGH] CWE-20 CVE-2019-6690: python-gnupg 0.4.3 allows context-dependent attackers to trick gnupg to decrypt other ciphertext tha
python-gnupg 0.4.3 allows context-dependent attackers to trick gnupg to decrypt other ciphertext than intended. To perform the attack, the passphrase to gnupg must be controlled by the adversary and the ciphertext should be trusted. Related to a "CWE-20: Improper Input Validation" issue affecting the affect functionality component.
nvd
CVE-2022-39261P3HIGHCVSS 7.5v10.0v11.02022-09-28
CVE-2022-39261 [HIGH] CWE-22 CVE-2022-39261: Twig is a template language for PHP. Versions 1.x prior to 1.44.7, 2.x prior to 2.15.3, and 3.x prio
Twig is a template language for PHP. Versions 1.x prior to 1.44.7, 2.x prior to 2.15.3, and 3.x prior to 3.4.3 encounter an issue when the filesystem loader loads templates for which the name is a user input. It is possible to use the `source` or `include` statement to read arbitrary files from outside the templates' directory when using a namespace li
nvd
CVE-2019-11627P3CRITICALCVSS 9.8v8.02019-04-30
CVE-2019-11627 [CRITICAL] CWE-78 CVE-2019-11627: gpg-key2ps in signing-party 1.1.x and 2.x before 2.10-1 contains an unsafe shell call enabling shell
gpg-key2ps in signing-party 1.1.x and 2.x before 2.10-1 contains an unsafe shell call enabling shell injection via a User ID.
nvd
CVE-2006-4343P4MEDIUMCVSS 4.3PoCv3.12006-09-28
CVE-2006-4343 [MEDIUM] CWE-476 CVE-2006-4343: The get_server_hello function in the SSLv2 client code in OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before
The get_server_hello function in the SSLv2 client code in OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions allows remote servers to cause a denial of service (client crash) via unknown vectors that trigger a null pointer dereference.
nvd
CVE-2017-1000421P3CRITICALCVSS 9.8v7.0v8.0+1 more2018-01-02
CVE-2017-1000421 [CRITICAL] CWE-416 CVE-2017-1000421: Gifsicle gifview 1.89 and older is vulnerable to a use-after-free in the read_gif function resulting
Gifsicle gifview 1.89 and older is vulnerable to a use-after-free in the read_gif function resulting potential code execution
nvd
CVE-2017-12424P3CRITICALCVSS 9.8v9.02017-08-04
CVE-2017-12424 [CRITICAL] CWE-119 CVE-2017-12424: In shadow before 4.5, the newusers tool could be made to manipulate internal data structures in ways
In shadow before 4.5, the newusers tool could be made to manipulate internal data structures in ways unintended by the authors. Malformed input may lead to crashes (with a buffer overflow or other memory corruption) or other unspecified behaviors. This crosses a privilege boundary in, for example, certain web-hosting environments in which a Contro
nvd
CVE-2016-0746P3CRITICALCVSS 9.8v7.0v8.0+1 more2016-02-15
CVE-2016-0746 [CRITICAL] CWE-416 CVE-2016-0746: Use-after-free vulnerability in the resolver in nginx 0.6.18 through 1.8.0 and 1.9.x before 1.9.10 a
Use-after-free vulnerability in the resolver in nginx 0.6.18 through 1.8.0 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (worker process crash) or possibly have unspecified other impact via a crafted DNS response related to CNAME response processing.
nvd
CVE-2019-10220P3HIGHCVSS 8.8v8.02019-11-27
CVE-2019-10220 [HIGH] CWE-22 CVE-2019-10220: Linux kernel CIFS implementation, version 4.9.0 is vulnerable to a relative paths injection in direc
Linux kernel CIFS implementation, version 4.9.0 is vulnerable to a relative paths injection in directory entry lists.
nvd
CVE-2017-12869P3HIGHCVSS 7.5v7.0v8.0+1 more2017-09-01
CVE-2017-12869 [HIGH] CWE-20 CVE-2017-12869: The multiauth module in SimpleSAMLphp 1.14.13 and earlier allows remote attackers to bypass authenti
The multiauth module in SimpleSAMLphp 1.14.13 and earlier allows remote attackers to bypass authentication context restrictions and use an authentication source defined in config/authsources.php via vectors related to improper validation of user input.
nvd
CVE-2023-6377P3HIGHCVSS 7.8v10.0v11.0+1 more2023-12-13
CVE-2023-6377 [HIGH] CWE-125 CVE-2023-6377: A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touch
A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory reads and writes. This may allow local privilege escalation or possible remote code execution in cases where X11 forwarding is involved.
nvd
CVE-2018-10191P3CRITICALCVSS 9.8v9.02018-04-17
CVE-2018-10191 [CRITICAL] CWE-190 CVE-2018-10191: In versions of mruby up to and including 1.4.0, an integer overflow exists in src/vm.c::mrb_vm_exec(
In versions of mruby up to and including 1.4.0, an integer overflow exists in src/vm.c::mrb_vm_exec() when handling OP_GETUPVAR in the presence of deep scope nesting, resulting in a use-after-free. An attacker that can cause Ruby code to be run can use this to possibly execute arbitrary code.
nvd
CVE-2015-3258P3HIGHCVSS 7.5v7.1v8.02015-07-14
CVE-2015-3258 [HIGH] CWE-119 CVE-2015-3258: Heap-based buffer overflow in the WriteProlog function in filter/texttopdf.c in texttopdf in cups-fi
Heap-based buffer overflow in the WriteProlog function in filter/texttopdf.c in texttopdf in cups-filters before 1.0.70 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a small line size in a print job.
nvd