cbcvebase.

Debian Linux vulnerabilities

9,953 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358

Vulnerabilities

Page 92 of 498
CVE-2018-15494P3CRITICALCVSS 9.8v8.02018-08-18
CVE-2018-15494 [CRITICAL] CWE-116 CVE-2018-15494: In Dojo Toolkit before 1.14, there is unescaped string injection in dojox/Grid/DataGrid. In Dojo Toolkit before 1.14, there is unescaped string injection in dojox/Grid/DataGrid.
nvd
CVE-2017-8816P3CRITICALCVSS 9.8v8.0v9.02017-11-29
CVE-2017-8816 [CRITICAL] CWE-190 CVE-2017-8816: The NTLM authentication feature in curl and libcurl before 7.57.0 on 32-bit platforms allows attacke The NTLM authentication feature in curl and libcurl before 7.57.0 on 32-bit platforms allows attackers to cause a denial of service (integer overflow and resultant buffer overflow, and application crash) or possibly have unspecified other impact via vectors involving long user and password fields.
nvd
CVE-2019-9639P3HIGHCVSS 7.5v8.0v9.02019-03-09
CVE-2019-9639 [HIGH] CWE-908 CVE-2019-9639: An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x b An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in exif_process_IFD_in_MAKERNOTE because of mishandling the data_len variable.
nvd
CVE-2019-20788P3CRITICALCVSS 9.8v8.0v9.02020-04-23
CVE-2019-20788 [CRITICAL] CVE-2019-20788: libvncclient/cursor.c in LibVNCServer through 0.9.12 has a HandleCursorShape integer overflow and he libvncclient/cursor.c in LibVNCServer through 0.9.12 has a HandleCursorShape integer overflow and heap-based buffer overflow via a large height or width value. NOTE: this may overlap CVE-2019-15690.
nvd
CVE-2017-8807P3CRITICALCVSS 9.1v9.02017-11-16
CVE-2017-8807 [CRITICAL] CWE-119 CVE-2017-8807: vbf_stp_error in bin/varnishd/cache/cache_fetch.c in Varnish HTTP Cache 4.1.x before 4.1.9 and 5.x b vbf_stp_error in bin/varnishd/cache/cache_fetch.c in Varnish HTTP Cache 4.1.x before 4.1.9 and 5.x before 5.2.1 allows remote attackers to obtain sensitive information from process memory because a VFP_GetStorage buffer is larger than intended in certain circumstances involving -sfile Stevedore transient objects.
nvd
CVE-2016-6797P3HIGHCVSS 7.5v8.02017-08-10
CVE-2016-6797 [HIGH] CWE-863 CVE-2016-6797: The ResourceLinkFactory implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0. The ResourceLinkFactory implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not limit web application access to global JNDI resources to those resources explicitly linked to the web application. Therefore, it was possible for a web application to access any global JNDI resour
nvd
CVE-2019-19906P3HIGHCVSS 7.5v8.0v9.0+1 more2019-12-19
CVE-2019-19906 [HIGH] CWE-193 CVE-2019-19906: cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote deni cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in _sasl_add_string in common.c in cyrus-sasl.
nvd
CVE-2021-30846P3HIGHCVSS 7.8v10.0v11.02021-10-19
CVE-2021-30846 [HIGH] CWE-787 CVE-2021-30846: A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 14 A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, Safari 15, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2016-5423P3HIGHCVSS 8.3v8.02016-12-09
CVE-2016-5423 [HIGH] CWE-476 CVE-2016-5423: PostgreSQL before 9.1.23, 9.2.x before 9.2.18, 9.3.x before 9.3.14, 9.4.x before 9.4.9, and 9.5.x be PostgreSQL before 9.1.23, 9.2.x before 9.2.18, 9.3.x before 9.3.14, 9.4.x before 9.4.9, and 9.5.x before 9.5.4 allow remote authenticated users to cause a denial of service (NULL pointer dereference and server crash), obtain sensitive memory information, or possibly execute arbitrary code via (1) a CASE expression within the test value subexpression of
nvd
CVE-2020-9760P3CRITICALCVSS 9.8v8.0v9.02020-03-23
CVE-2020-9760 [CRITICAL] CWE-120 CVE-2020-9760: An issue was discovered in WeeChat before 2.7.1 (0.3.4 to 2.7 are affected). When a new IRC message An issue was discovered in WeeChat before 2.7.1 (0.3.4 to 2.7 are affected). When a new IRC message 005 is received with longer nick prefixes, a buffer overflow and possibly a crash can happen when a new mode is set for a nick.
nvd
CVE-2018-5158P3HIGHCVSS 8.8v7.0v8.0+1 more2018-06-11
CVE-2018-5158 [HIGH] CWE-94 CVE-2018-5158: The PDF viewer does not sufficiently sanitize PostScript calculator functions, allowing malicious Ja The PDF viewer does not sufficiently sanitize PostScript calculator functions, allowing malicious JavaScript to be injected through a crafted PDF file. This JavaScript can then be run with the permissions of the PDF viewer by its worker. This vulnerability affects Firefox ESR < 52.8 and Firefox < 60.
nvd
CVE-2018-8778P3HIGHCVSS 7.5v7.0v8.0+1 more2018-04-03
CVE-2018-8778 [HIGH] CWE-134 CVE-2018-8778: In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, an attacker controlling the unpacking format (similar to format string vulnerabilities) can trigger a buffer under-read in the String#unpack method, resulting in a massive and controlled information disclosure.
nvd
CVE-2019-18421P3HIGHCVSS 7.5v9.0v10.02019-10-31
CVE-2019-18421 [HIGH] CWE-362 CVE-2019-18421: An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to gain host OS privile An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to gain host OS privileges by leveraging race conditions in pagetable promotion and demotion operations. There are issues with restartable PV type change operations. To avoid using shadow pagetables for PV guests, Xen exposes the actual hardware pagetables to the guest. In or
nvd
CVE-2021-30984P3HIGHCVSS 7.5v10.0v11.02021-08-24
CVE-2021-30984 [HIGH] CWE-362 CVE-2021-30984: A race condition was addressed with improved state handling. This issue is fixed in tvOS 15.2, macOS A race condition was addressed with improved state handling. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2022-28044P3CRITICALCVSS 9.8v9.0v10.0+1 more2022-04-15
CVE-2022-28044 [CRITICAL] CWE-787 CVE-2022-28044: Irzip v0.640 was discovered to contain a heap memory corruption via the component lrzip.c:initialise Irzip v0.640 was discovered to contain a heap memory corruption via the component lrzip.c:initialise_control.
nvd
CVE-2019-13484P3CRITICALCVSS 9.8v8.02019-08-27
CVE-2019-13484 [CRITICAL] CWE-119 CVE-2019-13484: In Xymon through 4.3.28, a buffer overflow exists in the status-log viewer CGI because of &nbsp; exp In Xymon through 4.3.28, a buffer overflow exists in the status-log viewer CGI because of expansion in appfeed.c.
nvd
CVE-2019-25033P3CRITICALCVSS 9.8v9.02021-04-27
CVE-2019-25033 [CRITICAL] CWE-190 CVE-2019-25033: Unbound before 1.9.5 allows an integer overflow in the regional allocator via the ALIGN_UP macro. NO Unbound before 1.9.5 allows an integer overflow in the regional allocator via the ALIGN_UP macro. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
nvd
CVE-2014-1524P3CRITICALCVSS 9.8v7.0v8.02014-04-30
CVE-2014-1524 [CRITICAL] CWE-120 CVE-2014-1524: The nsXBLProtoImpl::InstallImplementation function in Mozilla Firefox before 29.0, Firefox ESR 24.x The nsXBLProtoImpl::InstallImplementation function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 does not properly check whether objects are XBL objects, which allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow) via crafted JavaScript code
nvd
CVE-2020-12658P3CRITICALCVSS 9.8v9.02020-12-31
CVE-2020-12658 [CRITICAL] CWE-667 CVE-2020-12658: gssproxy (aka gss-proxy) before 0.8.3 does not unlock cond_mutex before pthread exit in gp_worker_ma gssproxy (aka gss-proxy) before 0.8.3 does not unlock cond_mutex before pthread exit in gp_worker_main() in gp_workers.c. NOTE: An upstream comment states "We are already on a shutdown path when running the code in question, so a DoS there doesn't make any sense, and there has been no additional information provided us (as upstream) to indicate wh
nvd
CVE-2016-4738P3HIGHCVSS 8.8v8.0v9.02016-09-25
CVE-2016-4738 [HIGH] CWE-119 CVE-2016-4738: libxslt in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows remot libxslt in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
nvd
Debian Linux vulnerabilities | cvebase