Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 96 of 498
CVE-2018-2814P3HIGHCVSS 8.3v8.0v9.02018-04-19
CVE-2018-2814 [HIGH] CVE-2018-2814: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot).
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are affected are Java SE: 6u181, 7u171, 8u162 and 10; Java SE Embedded: 8u161. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful
nvd
CVE-2020-15972P3HIGHCVSS 8.8v10.02020-11-03
CVE-2020-15972 [HIGH] CWE-416 CVE-2020-15972: Use after free in audio in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentia
Use after free in audio in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2015-8779P3CRITICALCVSS 9.8v8.02016-04-19
CVE-2015-8779 [CRITICAL] CWE-119 CVE-2015-8779: Stack-based buffer overflow in the catopen function in the GNU C Library (aka glibc or libc6) before
Stack-based buffer overflow in the catopen function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long catalog name.
nvd
CVE-2019-12854P3HIGHCVSS 7.5v10.02019-08-15
CVE-2019-12854 [HIGH] CVE-2019-12854: Due to incorrect string termination, Squid cachemgr.cgi 4.0 through 4.7 may access unallocated memor
Due to incorrect string termination, Squid cachemgr.cgi 4.0 through 4.7 may access unallocated memory. On systems with memory access protections, this can cause the CGI process to terminate unexpectedly, resulting in a denial of service for all clients using it.
nvd
CVE-2017-14440P3HIGHCVSS 8.8v7.0v8.0+1 more2018-04-24
CVE-2017-14440 [HIGH] CWE-787 CVE-2017-14440: An exploitable code execution vulnerability exists in the ILBM image rendering functionality of SDL2
An exploitable code execution vulnerability exists in the ILBM image rendering functionality of SDL2_image-2.0.2. A specially crafted ILBM image can cause a stack overflow resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability.
nvd
CVE-2017-12122P3HIGHCVSS 8.8v7.0v8.0+1 more2018-04-24
CVE-2017-12122 [HIGH] CWE-787 CVE-2017-12122: An exploitable code execution vulnerability exists in the ILBM image rendering functionality of SDL2
An exploitable code execution vulnerability exists in the ILBM image rendering functionality of SDL2_image-2.0.2. A specially crafted ILBM image can cause a heap overflow resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability.
nvd
CVE-2017-14442P3HIGHCVSS 8.8v7.0v8.0+1 more2018-04-24
CVE-2017-14442 [HIGH] CWE-119 CVE-2017-14442: An exploitable code execution vulnerability exists in the BMP image rendering functionality of SDL2_
An exploitable code execution vulnerability exists in the BMP image rendering functionality of SDL2_image-2.0.2. A specially crafted BMP image can cause a stack overflow resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability.
nvd
CVE-2017-14448P3HIGHCVSS 8.8v8.0v9.02018-04-24
CVE-2017-14448 [HIGH] CWE-787 CVE-2017-14448: An exploitable code execution vulnerability exists in the XCF image rendering functionality of SDL2_
An exploitable code execution vulnerability exists in the XCF image rendering functionality of SDL2_image-2.0.2. A specially crafted XCF image can cause a heap overflow resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability.
nvd
CVE-2020-35635P3HIGHCVSS 8.8v10.02021-08-30
CVE-2020-35635 [HIGH] CWE-129 CVE-2020-35635: A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-
A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1 in Nef_S2/SNC_io_parser.h SNC_io_parser::read_sface() store_sm_boundary_item() Sloop_of OOB read. A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lead to code execution. An attacker can provide
nvd
CVE-2020-6831P3CRITICALCVSS 9.8v9.0v10.02020-05-26
CVE-2020-6831 [CRITICAL] CWE-787 CVE-2020-6831: A buffer overflow could occur when parsing and validating SCTP chunks in WebRTC. This could have led
A buffer overflow could occur when parsing and validating SCTP chunks in WebRTC. This could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird < 68.8.0.
nvd
CVE-2016-6801P3HIGHCVSS 8.8v8.02016-09-21
CVE-2016-6801 [HIGH] CWE-352 CVE-2016-6801: Cross-site request forgery (CSRF) vulnerability in the CSRF content-type check in Jackrabbit-Webdav
Cross-site request forgery (CSRF) vulnerability in the CSRF content-type check in Jackrabbit-Webdav in Apache Jackrabbit 2.4.x before 2.4.6, 2.6.x before 2.6.6, 2.8.x before 2.8.3, 2.10.x before 2.10.4, 2.12.x before 2.12.4, and 2.13.x before 2.13.3 allows remote attackers to hijack the authentication of unspecified victims for requests that create a res
nvd
CVE-2018-19540P3HIGHCVSS 8.8v8.02018-11-26
CVE-2018-19540 [HIGH] CWE-787 CVE-2018-19540: An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14
An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20, 1.900.21, 1.900.22, 1.900.23, 1.900.24, 1.900.25, 1.900.26, 1.900.27, 1.900.28, 1.900.29, 1.900.30, 1.900.31, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, 2.0.6, 2.0.7, 2.0.8, 2.0.9, 2.0.10, 2.0
nvd
CVE-2017-10116P3HIGHCVSS 8.3v8.0v9.02017-08-08
CVE-2017-10116 [HIGH] CVE-2017-10116: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: S
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131; JRockit: R28.3.14. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE,
nvd
CVE-2017-17476P3HIGHCVSS 8.8v7.0v8.0+1 more2017-12-20
CVE-2017-17476 [HIGH] CWE-200 CVE-2017-17476: Open Ticket Request System (OTRS) 4.0.x before 4.0.28, 5.0.x before 5.0.26, and 6.0.x before 6.0.3,
Open Ticket Request System (OTRS) 4.0.x before 4.0.28, 5.0.x before 5.0.26, and 6.0.x before 6.0.3, when cookie support is disabled, might allow remote attackers to hijack web sessions and consequently gain privileges via a crafted email.
nvd
CVE-2018-14346P3HIGHCVSS 8.8v8.0v9.02018-07-17
CVE-2018-14346 [HIGH] CWE-787 CVE-2018-14346: GNU Libextractor before 1.7 has a stack-based buffer overflow in ec_read_file_func (unzip.c).
GNU Libextractor before 1.7 has a stack-based buffer overflow in ec_read_file_func (unzip.c).
nvd
CVE-2019-16276P3HIGHCVSS 7.5v9.02019-09-30
CVE-2019-16276 [HIGH] CWE-444 CVE-2019-16276: Go before 1.12.10 and 1.13.x before 1.13.1 allow HTTP Request Smuggling.
Go before 1.12.10 and 1.13.x before 1.13.1 allow HTTP Request Smuggling.
nvd
CVE-2012-6639P3HIGHCVSS 8.8v8.0v9.0+1 more2019-11-25
CVE-2012-6639 [HIGH] CWE-269 CVE-2012-6639: An privilege elevation vulnerability exists in Cloud-init before 0.7.0 when requests to an untrusted
An privilege elevation vulnerability exists in Cloud-init before 0.7.0 when requests to an untrusted system are submitted for EC2 instance data.
nvd
CVE-2018-14647P3HIGHCVSS 7.5v8.0v9.02018-09-25
CVE-2018-14647 [HIGH] CWE-335 CVE-2018-14647: Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization. Thi
Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization. This could make it easy to conduct denial of service attacks against Expat by constructing an XML document that would cause pathological hash collisions in Expat's internal data structures, consuming large amounts CPU and RAM. The vulnerability exists in P
nvd
CVE-2020-6542P3HIGHCVSS 8.8v10.02020-09-21
CVE-2020-6542 [HIGH] CWE-416 CVE-2020-6542: Use after free in ANGLE in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potenti
Use after free in ANGLE in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2018-5127P3HIGHCVSS 8.8v7.0v8.0+1 more2018-06-11
CVE-2018-5127 [HIGH] CWE-119 CVE-2018-5127: A buffer overflow can occur when manipulating the SVG "animatedPathSegList" through script. This res
A buffer overflow can occur when manipulating the SVG "animatedPathSegList" through script. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.7, Firefox ESR < 52.7, and Firefox < 59.
nvd