← All vendors

debian

504 known vulnerabilities affecting debian products.

Products

debian_linux 504

Vulnerabilities by priority

CVEPriorityEPSSCVSSKEVWhat
CVE-2021-40438 Act now 100.0% 9.0 A crafted request uri-path can cause mod_proxy to forward the request to an orig…
CVE-2017-12617 Act now 100.0% 8.1 When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC…
CVE-2026-31431 Act now 99.9% 7.8 In the Linux kernel, the following vulnerability has been resolved: crypto: alg…
CVE-2020-1938 Act now 99.3% 9.8 When using the Apache JServ Protocol (AJP), care must be taken when trusting inc…
CVE-2018-7602 Act now 99.2% 9.8 A remote code execution vulnerability exists within multiple subsystems of Drupa…
CVE-2022-30333 Act now 99.1% 7.5 RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write t…
CVE-2012-0507 Act now 98.1% 9.8 Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora…
CVE-2016-8735 Act now 90.3% 9.8 Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7…
CVE-2024-1086 Act now 28.1% 7.8 A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables compon…
CVE-2024-9680 Act now 23.2% 9.8 An attacker was able to achieve code execution in the content process by exploit…
CVE-2025-38352 Act now 1.3% 7.8 In the Linux kernel, the following vulnerability has been resolved: posix-cpu-t…
CVE-2025-39682 Act now 0.5% 9.8 In the Linux kernel, the following vulnerability has been resolved: tls: fix ha…
CVE-2021-45105 High 100.0% 5.9 Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) di…
CVE-2020-13935 High 86.6% 7.5 The payload length in a WebSocket frame was not correctly validated in Apache To…
CVE-2021-33037 High 75.4% 5.3 Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did no…
CVE-2020-13934 High 64.1% 7.5 An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.…
CVE-2020-9484 High 56.6% 7.0 When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.…
CVE-2021-41182 Medium 39.4% 6.5 jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0…
CVE-2026-49975 Medium 34.3% 7.5 Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server'…
CVE-2019-10086 Medium 29.2% 7.3 In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added wh…
CVE-2021-24122 Medium 22.9% 5.9 When serving resources from a network location using the NTFS file system, Apach…
CVE-2020-36179 Medium 21.0% 8.1 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee…
CVE-2020-9548 Medium 18.3% 9.8 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee…
CVE-2021-25122 Medium 18.1% 7.5 When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1…
CVE-2023-1380 Medium 16.5% 7.1 A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net…
CVE-2020-35728 Medium 12.5% 8.1 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee…
CVE-2020-36188 Medium 10.9% 8.1 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee…
CVE-2026-9256 Medium 10.9% 8.1 NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_mo…
CVE-2020-36184 Medium 10.4% 8.1 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee…
CVE-2021-29425 Medium 10.2% 4.8 In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normaliz…
CVE-2020-35491 Medium 9.6% 8.1 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee…
CVE-2021-25329 Medium 9.5% 7.0 The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to …
CVE-2020-24616 Medium 9.4% 8.1 FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction betwee…
CVE-2018-15756 Medium 9.2% 7.5 Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x pr…
CVE-2020-14062 Medium 8.1% 8.1 FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction betwee…
CVE-2020-10673 Medium 8.0% 8.8 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee…
CVE-2020-35490 Medium 7.8% 8.1 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee…
CVE-2021-20190 Medium 7.5% 8.1 A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the i…
CVE-2021-40690 Medium 7.4% 7.5 All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.…
CVE-2020-24750 Medium 7.3% 8.1 FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction betwee…
CVE-2021-20322 Medium 6.8% 7.4 A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP …
CVE-2020-11113 Medium 6.3% 8.8 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee…
CVE-2022-27666 Medium 5.5% 7.8 A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ip…
CVE-2020-36185 Medium 5.2% 8.1 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee…
CVE-2020-36186 Medium 5.2% 8.1 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee…
CVE-2020-36187 Medium 5.2% 8.1 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee…
CVE-2020-36180 Medium 5.0% 8.1 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee…
CVE-2020-36181 Medium 5.0% 8.1 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee…
CVE-2020-36182 Medium 5.0% 8.1 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee…
CVE-2020-36183 Medium 4.9% 8.1 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee…
Page 1 of 11 Next →