VendorsDebiandebian_linuxall versions
Vulnerabilities

Debian Debian Linux

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10063CVEs
CVE-2022-48337
GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses the system C library function in its implementation of the etags program. For example, a victim may use the "etags -u *" command (suggested in the etags documentation) in a situation where the current working directory has contents that depend on untrusted input.
Published 2023-02-20 · Modified
9.8EPSS 0.016
CVE-2021-20001
It was discovered, that debian-edu-config, a set of configuration files used for the Debian Edu blend, before 2.12.16 configured insecure permissions for the user web shares (~/public_html), which could result in privilege escalation.
Published 2022-02-11 · Modified
9.8EPSS 0.016
CVE-2011-1028
The $smarty.template variable in Smarty3 allows attackers to possibly execute arbitrary PHP code via the sysplugins/smarty_internal_compile_private_special_variable.php file.
Published 2019-11-20 · Modified
9.8EPSS 0.016
CVE-2015-1276
Use-after-free vulnerability in content/browser/indexed_db/indexed_db_backing_store.cc in the IndexedDB implementation in Google Chrome before 44.0.2403.89 allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging an abort action before a certain write operation.
Published 2015-07-23 · Modified
9.8EPSS 0.016
CVE-2022-41837
An out-of-bounds write vulnerability exists in the OpenImageIO::add_exif_item_to_spec functionality of OpenImageIO Project OpenImageIO v2.4.4.2. Specially-crafted exif metadata can lead to stack-based memory corruption. An attacker can provide a malicious file to trigger this vulnerability.
Published 2022-12-23 · Modified
9.8EPSS 0.016
CVE-2020-8086
The mod_auth_ldap and mod_auth_ldap2 Community Modules through 2020-01-27 for Prosody incompletely verify the XMPP address passed to the is_admin() function. This grants remote entities admin-only functionality if their username matches the username of a local admin.
Published 2020-01-28 · Modified
9.8EPSS 0.016
CVE-2022-47629
Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL signature parser.
Published 2022-12-20 · Modified
9.8EPSS 0.016
CVE-2012-1577
lib/libc/stdlib/random.c in OpenBSD returns 0 when seeded with 0.
Published 2019-12-10 · Modified
9.8EPSS 0.016
CVE-2023-39352
Invalid offset validation leading to Out Of Bound Write in FreeRDP
Published 2023-08-31 · Modified
9.8EPSS 0.015
CVE-2007-0899
There is a possible heap overflow in libclamav/fsg.c before 0.100.0.
Published 2019-11-06 · Modified
9.8EPSS 0.015
CVE-2019-13273
In Xymon through 4.3.28, a buffer overflow vulnerability exists in the csvinfo CGI script. The overflow may be exploited by sending a crafted GET request that triggers an sprintf of the srcdb parameter.
Published 2019-08-27 · Modified
9.8EPSS 0.015
CVE-2023-40567
Out-Of-Bounds Write in FreeRDP
Published 2023-08-31 · Modified
9.8EPSS 0.015
CVE-2022-45062
In Xfce xfce4-settings before 4.16.4 and 4.17.x before 4.17.1, there is an argument injection vulnerability in xfce4-mime-helper.
Published 2022-11-09 · Modified
9.8EPSS 0.015
CVE-2023-5730
Memory safety bugs present in Firefox 118, Firefox ESR 115.3, and Thunderbird 115.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
Published 2023-10-24 · Modified
9.8EPSS 0.015
CVE-2008-7291
gri before 2.12.18 generates temporary files in an insecure way.
Published 2019-11-07 · Modified
9.8EPSS 0.014
CVE-2022-39955
Partial rule set bypass in OWASP ModSecurity Core Rule Set by submitting a specially crafted HTTP Content-Type header
Published 2022-09-20 · Modified
9.8EPSS 0.014
CVE-2025-68670
xrdp improperly checks bounds of domain string length, which leads to Stack-based Buffer Overflow
Published 2026-01-27 · Analyzed
9.8EPSS 0.014
CVE-2023-5176
Memory safety bugs present in Firefox 117, Firefox ESR 115.2, and Thunderbird 115.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.
Published 2023-09-27 · Modified
9.8EPSS 0.014
CVE-2024-47606
GHSL-2024-166: GStreamer Integer overflows in MP4/MOV demuxer and memory allocator that can lead to out-of-bounds writes
Published 2024-12-11 · Modified
9.8EPSS 0.014
CVE-2023-40186
IntegerOverflow leading to Out-Of-Bound Write Vulnerability in FreeRDP
Published 2023-08-31 · Modified
9.8EPSS 0.014
CVE-2013-1430
An issue was discovered in xrdp before 0.9.1. When successfully logging in using RDP into an xrdp session, the file ~/.vnc/sesman_${username}_passwd is created. Its content is the equivalent of the user's cleartext password, DES encrypted with a known key.
Published 2016-12-16 · Modified
9.8EPSS 0.013
CVE-2022-4338
An integer underflow in Organization Specific TLV was found in various versions of OpenvSwitch.
Published 2023-01-10 · Modified
9.8EPSS 0.013
CVE-2022-4337
An out-of-bounds read in Organization Specific TLV was found in various versions of OpenvSwitch.
Published 2023-01-10 · Modified
9.8EPSS 0.013
CVE-2020-22669
Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability. Attackers can use the comment characters and variable assignments in the SQL syntax to bypass Modsecurity WAF protection and implement SQL injection attacks on Web applications.
Published 2022-09-02 · Modified
9.8EPSS 0.013
CVE-2021-30164
Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to bypass the add_issue_notes permission requirement by leveraging the Issues API.
Published 2021-04-06 · Modified
9.8EPSS 0.013
CVE-2023-40569
Out-Of-Bounds Write in FreeRDP
Published 2023-08-31 · Modified
9.8EPSS 0.013
CVE-2024-36886
tipc: fix UAF in error path
Published 2024-05-30 · Modified
9.8EPSS 0.013
CVE-2018-8971
The Auth0 integration in GitLab before 10.3.9, 10.4.x before 10.4.6, and 10.5.x before 10.5.6 has an incorrect omniauth-auth0 configuration, leading to signing in unintended users.
Published 2018-03-24 · Modified
9.8EPSS 0.013
CVE-2022-39353
xmldom allows multiple root nodes in a DOM
Published 2022-11-02 · Modified
9.8EPSS 0.013
CVE-2011-0703
In gksu-polkit before 0.0.3, the source file for xauth may contain arbitrary commands that may allow an attacker to overtake an administrator X11 session.
Published 2019-11-15 · Modified
9.8EPSS 0.013
CVE-2023-39355
FreeRDP Use-After-Free in RDPGFX_CMDID_RESETGRAPHICS
Published 2023-08-31 · Modified
9.8EPSS 0.013
CVE-2024-52533
gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CONN_MSG_LEN is not sufficient for a trailing '\0' character.
Published 2024-11-11 · Analyzed
9.8EPSS 0.013
CVE-2009-5043
burn allows file names to escape via mishandled quotation marks
Published 2019-10-31 · Modified
9.8EPSS 0.012
CVE-2022-39956
Partial rule set bypass in OWASP ModSecurity Core Rule Set for HTTP multipart requests using character encoding in the Content-Type or Content-Transfer-Encoding header
Published 2022-09-20 · Modified
9.8EPSS 0.012
CVE-2021-40874
An issue was discovered in LemonLDAP::NG (aka lemonldap-ng) 2.0.13. When using the RESTServer plug-in to operate a REST password validation service (for another LemonLDAP::NG instance, for example) and using the Kerberos authentication method combined with another method with the Combination authentication plug-in, any password will be recognized as valid for an existing user.
Published 2022-07-17 · Modified
9.8EPSS 0.012
CVE-2025-37778
ksmbd: Fix dangling pointer in krb_authenticate
Published 2025-05-01 · Modified
9.8EPSS 0.011
CVE-2010-4533
offlineimap before 6.3.4 added support for SSL server certificate validation but it is still possible to use SSL v2 protocol, which is a flawed protocol with multiple security deficiencies.
Published 2019-11-13 · Modified
9.8EPSS 0.010
CVE-2022-23537
PJSIP vulnerable to heap buffer overflow when decoding STUN message
Published 2022-12-20 · Modified
9.8EPSS 0.010
CVE-2023-51714
An issue was discovered in the HTTP2 implementation in Qt before 5.15.17, 6.x before 6.2.11, 6.3.x through 6.5.x before 6.5.4, and 6.6.x before 6.6.2. network/access/http2/hpacktable.cpp has an incorrect HPack integer overflow check.
Published 2023-12-24 · Analyzed
9.8EPSS 0.010
CVE-2024-27388
SUNRPC: fix some memleaks in gssx_dec_option_array
Published 2024-05-01 · Modified
9.8EPSS 0.010
← Prev24 / 252Next →