VendorsDebiandebian_linux11.0
Vulnerabilities

Debian Debian Linux 11.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2060CVEs
CVE-2021-39923
Large loop in the PNRP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
Published 2021-11-19 · Modified
7.5EPSS 0.016
CVE-2025-3891
Mod_auth_openidc: dos via empty post in mod_auth_openidc with oidcpreservepost enabled
Published 2025-04-29 · Modified
7.5EPSS 0.016
CVE-2023-32067
0-byte UDP payload DoS in c-ares
Published 2023-05-25 · Modified
7.5EPSS 0.016
CVE-2021-3909
Infinite open connection causes OctoRPKI to hang forever
Published 2021-11-11 · Modified
7.5EPSS 0.016
CVE-2022-41881
Netty project is an event-driven asynchronous network application framework. In versions prior to 4.1.86.Final, a StackOverflowError can be raised when parsing a malformed crafted message due to an infinite recursion. This issue is patched in version 4.1.86.Final. There is no workaround, except using a custom HaProxyMessageDecoder.
Published 2022-12-12 · Modified
7.5EPSS 0.015
CVE-2022-3109
An issue was discovered in the FFmpeg package, where vp3_decode_frame in libavcodec/vp3.c lacks check of the return value of av_malloc() and will cause a null pointer dereference, impacting availability.
Published 2022-12-16 · Analyzed
7.5EPSS 0.015
CVE-2022-47184
Apache Traffic Server: The TRACE method can be use to disclose network information
Published 2023-06-14 · Modified
7.5EPSS 0.015
CVE-2021-43173
Hanging RRDP request
Published 2021-11-09 · Modified
7.5EPSS 0.015
CVE-2022-28203
A denial-of-service issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. When many files exist, requesting Special:NewFiles with actor as a condition can result in a very long running query.
Published 2022-09-19 · Modified
7.5EPSS 0.015
CVE-2021-3842
Inefficient Regular Expression Complexity in nltk/nltk
Published 2022-01-04 · Modified
7.5EPSS 0.015
CVE-2022-41999
A denial of service vulnerability exists in the DDS native tile reading functionality of OpenImageIO Project OpenImageIO v2.3.19.0 and v2.4.4.2. A specially-crafted .dds can lead to denial of service. An attacker can provide a malicious file to trigger this vulnerability.
Published 2022-12-23 · Modified
7.5EPSS 0.014
CVE-2022-45685
A stack overflow in Jettison before v1.5.2 allows attackers to cause a Denial of Service (DoS) via crafted JSON data.
Published 2022-12-13 · Modified
7.5EPSS 0.014
CVE-2022-45693
Jettison before v1.5.2 was discovered to contain a stack overflow via the map parameter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted string.
Published 2022-12-13 · Modified
7.5EPSS 0.014
CVE-2024-0567
Gnutls: rejects certificate chain with distributed trust
Published 2024-01-16 · Modified
7.5EPSS 0.014
CVE-2025-9086
Out of bounds read for cookie path
Published 2025-09-12 · Modified
7.5EPSS 0.014
CVE-2025-38191
ksmbd: fix null pointer dereference in destroy_previous_session
Published 2025-07-04 · Modified
7.5EPSS 0.013
CVE-2021-3910
NUL character in ROA causes OctoRPKI to crash
Published 2021-11-11 · Analyzed
7.5EPSS 0.013
CVE-2023-20900
A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html  in a target virtual machine may be able to elevate their privileges if that target virtual machine has been assigned a more privileged Guest Alias https://vdc-download.vmware.com/vmwb-repository/dcr-public/d1902b0e-d479-46bf-8ac9-cee0e31e8ec0/07ce8dbd-db48-4261-9b8f-c6d3ad8ba472/vim.vm.guest.AliasManager.html .
Published 2023-08-31 · Modified
7.5EPSS 0.013
CVE-2023-41358
An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c processes NLRIs if the attribute length is zero.
Published 2023-08-29 · Modified
7.5EPSS 0.013
CVE-2021-3761
OctoRPKI lacks contextual out-of-bounds check when validating RPKI ROA maxLength values
Published 2021-09-09 · Modified
7.5EPSS 0.012
CVE-2021-43174
gzip transfer encoding caused out-of-memory crash
Published 2021-11-09 · Modified
7.5EPSS 0.012
CVE-2023-5728
During garbage collection extra operations were performed on a object that should not be. This could have led to a potentially exploitable crash. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
Published 2023-10-24 · Modified
7.5EPSS 0.012
CVE-2022-41988
An information disclosure vulnerability exists in the OpenImageIO::decode_iptc_iim() functionality of OpenImageIO Project OpenImageIO v2.3.19.0. A specially-crafted TIFF file can lead to a disclosure of sensitive information. An attacker can provide a malicious file to trigger this vulnerability.
Published 2022-12-23 · Modified
7.5EPSS 0.012
CVE-2023-31137
MaraDNS Integer Underflow Vulnerability in DNS Packet Decompression
Published 2023-05-09 · Modified
7.5EPSS 0.011
CVE-2021-43114
FORT Validator versions prior to 1.5.2 will crash if an RPKI CA publishes an X.509 EE certificate. This will lead to RTR clients such as BGP routers to lose access to the RPKI VRP data set, effectively disabling Route Origin Validation.
Published 2021-11-09 · Modified
7.5EPSS 0.011
CVE-2020-20450
FFmpeg 4.2 is affected by null pointer dereference passed as argument to libavformat/aviobuf.c, which could cause a Denial of Service.
Published 2021-05-25 · Modified
7.5EPSS 0.011
CVE-2024-52006
Newline confusion in credential helpers can lead to credential exfiltration in git
Published 2025-01-14 · Analyzed
7.5EPSS 0.011
CVE-2023-39534
Malformed GAP submessage triggers assertion failure
Published 2023-08-11 · Modified
7.5EPSS 0.010
CVE-2023-39948
Uncaught fastcdr exception (Unexpected CDR type received) crashing fastdds
Published 2023-08-11 · Modified
7.5EPSS 0.010
CVE-2023-39949
Improper validation of sequence numbers leading to remotely reachable assertion failure
Published 2023-08-11 · Modified
7.5EPSS 0.010
CVE-2022-45060
An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1. An attacker may introduce characters through HTTP/2 pseudo-headers that are invalid in the context of an HTTP/1 request line, causing the Varnish server to produce invalid HTTP/1 requests to the backend. This could, in turn, be used to exploit vulnerabilities in a server behind the Varnish server. Note: the 6.0.x LTS series (before 6.0.11) is affected.
Published 2022-11-09 · Modified
7.5EPSS 0.010
CVE-2023-2135
Use after free in DevTools in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who convinced a user to enable specific preconditions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2023-04-19 · Modified
7.5EPSS 0.010
CVE-2021-33054
SOGo 2.x before 2.4.1 and 3.x through 5.x before 5.1.1 does not validate the signatures of any SAML assertions it receives. Any actor with network access to the deployment could impersonate users when SAML is the authentication method. (Only versions after 2.0.5a are affected.)
Published 2021-06-04 · Modified
7.5EPSS 0.010
CVE-2022-41916
Read one byte past a buffer when normalizing Unicode
Published 2022-11-15 · Modified
7.5EPSS 0.010
CVE-2023-4048
An out-of-bounds read could have led to an exploitable crash when parsing HTML with DOMParser in low memory situations. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.
Published 2023-08-01 · Modified
7.5EPSS 0.009
CVE-2025-21605
Redis DoS Vulnerability due to unlimited growth of output buffers abused by unauthenticated client
Published 2025-04-23 · Modified
7.5EPSS 0.009
CVE-2022-3623
Linux Kernel BPF gup.c follow_page_pte race condition
Published 2022-10-20 · Modified
7.5EPSS 0.008
CVE-2025-26699
An issue was discovered in Django 5.1 before 5.1.7, 5.0 before 5.0.13, and 4.2 before 4.2.20. The django.utils.text.wrap() method and wordwrap template filter are subject to a potential denial-of-service attack when used with very long strings.
Published 2025-03-06 · Analyzed
7.5EPSS 0.008
CVE-2021-37991
Race in V8 in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published 2021-11-02 · Modified
7.5EPSS 0.008
CVE-2026-23490
pyasn1 has a DoS vulnerability in decoder
Published 2026-01-16 · Modified
7.5EPSS 0.008
← Prev28 / 52Next →