Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 94 of 498
CVE-2017-2924P3HIGHCVSS 8.8v8.0v9.02018-04-24
CVE-2017-2924 [HIGH] CWE-787 CVE-2017-2924: An exploitable heap-based buffer overflow vulnerability exists in the read_legacy_biff function of F
An exploitable heap-based buffer overflow vulnerability exists in the read_legacy_biff function of FreeXL 1.0.3. A specially crafted XLS file can cause a memory corruption resulting in remote code execution. An attacker can send malicious XLS file to trigger this vulnerability.
nvd
CVE-2017-2923P3HIGHCVSS 8.8v8.0v9.02018-04-24
CVE-2017-2923 [HIGH] CWE-787 CVE-2017-2923: An exploitable heap based buffer overflow vulnerability exists in the 'read_biff_next_record functio
An exploitable heap based buffer overflow vulnerability exists in the 'read_biff_next_record function' of FreeXL 1.0.3. A specially crafted XLS file can cause a memory corruption resulting in remote code execution. An attacker can send malicious XLS file to trigger this vulnerability.
nvd
CVE-2020-36180P3HIGHCVSS 8.1v9.02021-01-07
CVE-2020-36180 [HIGH] CWE-502 CVE-2020-36180: FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadg
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.cpdsadapter.DriverAdapterCPDS.
nvd
CVE-2020-36182P3HIGHCVSS 8.1v9.02021-01-07
CVE-2020-36182 [HIGH] CWE-502 CVE-2020-36182: FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadg
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.cpdsadapter.DriverAdapterCPDS.
nvd
CVE-2020-36181P3HIGHCVSS 8.1v9.02021-01-06
CVE-2020-36181 [HIGH] CWE-502 CVE-2020-36181: FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadg
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.cpdsadapter.DriverAdapterCPDS.
nvd
CVE-2020-6457P3CRITICALCVSS 9.6v9.0v10.02020-05-21
CVE-2020-6457 [CRITICAL] CWE-416 CVE-2020-6457: Use after free in speech recognizer in Google Chrome prior to 81.0.4044.113 allowed a remote attacke
Use after free in speech recognizer in Google Chrome prior to 81.0.4044.113 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2017-1000450P3HIGHCVSS 8.8v7.0v8.0+1 more2018-01-02
CVE-2017-1000450 [HIGH] CWE-190 CVE-2017-1000450: In opencv/modules/imgcodecs/src/utils.cpp, functions FillUniColor and FillUniGray do not check the i
In opencv/modules/imgcodecs/src/utils.cpp, functions FillUniColor and FillUniGray do not check the input length, which can lead to integer overflow. If the image is from remote, may lead to remote code execution or denial of service. This affects Opencv 3.3 and earlier.
nvd
CVE-2019-8324P3HIGHCVSS 8.8v9.02019-06-17
CVE-2019-8324 [HIGH] CWE-94 CVE-2019-8324: An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem with a multi-line nam
An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem with a multi-line name is not handled correctly. Therefore, an attacker could inject arbitrary code to the stub line of gemspec, which is eval-ed by code in ensure_loadable_spec during the preinstall check.
nvd
CVE-2006-6942P4MEDIUMCVSS 6.8PoCv3.1v4.02007-01-19
CVE-2006-6942 [MEDIUM] CWE-79 CVE-2006-6942: Multiple cross-site scripting (XSS) vulnerabilities in PhpMyAdmin before 2.9.1.1 allow remote attack
Multiple cross-site scripting (XSS) vulnerabilities in PhpMyAdmin before 2.9.1.1 allow remote attackers to inject arbitrary HTML or web script via (1) a comment for a table name, as exploited through (a) db_operations.php, (2) the db parameter to (b) db_create.php, (3) the newname parameter to db_operations.php, the (4) query_history_latest, (5) query_
nvd
CVE-2020-36189P3HIGHCVSS 8.1v9.02021-01-06
CVE-2020-36189 [HIGH] CWE-502 CVE-2020-36189: FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadg
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.DriverManagerConnectionSource.
nvd
CVE-2018-18356P3HIGHCVSS 8.8v8.0v9.02018-12-11
CVE-2018-18356 [HIGH] CWE-190 CVE-2018-18356: An integer overflow in path handling lead to a use after free in Skia in Google Chrome prior to 71.0
An integer overflow in path handling lead to a use after free in Skia in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-21107P3CRITICALCVSS 9.6v10.02021-01-08
CVE-2021-21107 [CRITICAL] CWE-416 CVE-2021-21107: Use after free in drag and drop in Google Chrome on Linux prior to 87.0.4280.141 allowed a remote at
Use after free in drag and drop in Google Chrome on Linux prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2020-6390P3HIGHCVSS 8.8v9.0v10.02020-02-11
CVE-2020-6390 [HIGH] CWE-787 CVE-2020-6390: Out of bounds memory access in streams in Google Chrome prior to 80.0.3987.87 allowed a remote attac
Out of bounds memory access in streams in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2016-7072P3HIGHCVSS 7.5v8.02018-09-10
CVE-2016-7072 [HIGH] CWE-20 CVE-2016-7072: An issue has been found in PowerDNS Authoritative Server before 3.4.11 and 4.0.2 allowing a remote,
An issue has been found in PowerDNS Authoritative Server before 3.4.11 and 4.0.2 allowing a remote, unauthenticated attacker to cause a denial of service by opening a large number of TCP connections to the web server. If the web server runs out of file descriptors, it triggers an exception and terminates the whole PowerDNS process. While it's more complic
nvd
CVE-2022-27666P3HIGHCVSS 7.8v9.0v10.0+1 more2022-03-23
CVE-2022-27666 [HIGH] CWE-787 CVE-2022-27666: A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ip
A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c. This flaw allows a local attacker with a normal user privilege to overwrite kernel heap objects and may cause a local privilege escalation threat.
nvd
CVE-2021-38013P3CRITICALCVSS 9.6v10.0v11.02021-12-23
CVE-2021-38013 [CRITICAL] CWE-787 CVE-2021-38013: Heap buffer overflow in fingerprint recognition in Google Chrome on ChromeOS prior to 96.0.4664.45 a
Heap buffer overflow in fingerprint recognition in Google Chrome on ChromeOS prior to 96.0.4664.45 allowed a remote attacker who had compromised a WebUI renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2017-7656P3HIGHCVSS 7.5v9.02018-06-26
CVE-2017-7656 [HIGH] CWE-444 CVE-2017-7656: In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default confi
In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), HTTP/0.9 is handled poorly. An HTTP/1 style request line (i.e. method space URI space version) that declares a version of HTTP/0.9 was accepted and treated as a 0.9 request. If deployed behind an intermediary tha
nvd
CVE-2020-6513P3HIGHCVSS 8.8v10.02020-07-22
CVE-2020-6513 [HIGH] CWE-787 CVE-2020-6513: Heap buffer overflow in PDFium in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to p
Heap buffer overflow in PDFium in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
nvd
CVE-2017-15412P3HIGHCVSS 8.8v7.0v8.0+1 more2018-08-28
CVE-2017-15412 [HIGH] CWE-416 CVE-2017-15412: Use after free in libxml2 before 2.9.5, as used in Google Chrome prior to 63.0.3239.84 and other pro
Use after free in libxml2 before 2.9.5, as used in Google Chrome prior to 63.0.3239.84 and other products, allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-38714P3HIGHCVSS 8.8v9.02021-08-24
CVE-2021-38714 [HIGH] CWE-190 CVE-2021-38714: In Plib through 1.85, there is an integer overflow vulnerability that could result in arbitrary code
In Plib through 1.85, there is an integer overflow vulnerability that could result in arbitrary code execution. The vulnerability is found in ssgLoadTGA() function in src/ssg/ssgLoadTGA.cxx file.
nvd