Debian records
10,221 published records for vendor debian.
Researcher profile
- Entered KEV
- 123 · 1.2%
- Weaponized
- 201 · 2%
- Pre-auth RCE
- 752
- With a fix record
- 97.4%
- Median publish → KEV
- 362 days
Recurring classes
- CWE-416 Use After Free732
- CWE-787 Out-of-bounds Write730
- CWE-125 Out-of-bounds Read685
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer539
- CWE-20 Improper Input Validation500
- CWE-476 NULL Pointer Dereference476
The weakness classes this vendor ships most often: where to look.
CWEAll records
10,000+ records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
100Now | CVE-2021-44228Weaponized | Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpointsapache · log4j · CWE-20 | Critical10.0 | KEV | 100.0% | Dec 10, 2021 |
100Now | CVE-2022-0543Weaponized | It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escaperedis · redis · CWE-862 | Critical10.0 | KEV | 99.4% | Feb 18, 2022 |
100Now | CVE-2025-32433Weaponized | Erlang/OTP SSH Vulnerable to Pre-Authentication RCEerlang · erlang\/otp · CWE-306 | Critical10.0 | KEV | 98.8% | Apr 16, 2025 |
99Now | CVE-2014-6271Weaponized | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attacgnu · bash · CWE-78 | Critical9.8 | KEV | 100.0% | Sep 24, 2014 |
99Now | CVE-2012-1823Weaponized | sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle quephp · php · CWE-77 | Critical9.8 | KEV | 100.0% | May 11, 2012 |
99Now | CVE-2018-7600Weaponized | Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because odrupal · drupal · CWE-20 | Critical9.8 | KEV | 100.0% | Mar 29, 2018 |
99Now | CVE-2019-10149Weaponized | A flaw was found in Exim versions 4.87 to 4.91 (inclusive).exim · exim · CWE-78 | Critical9.8 | KEV | 100.0% | Jun 5, 2019 |
99Now | CVE-2014-7169Weaponized | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variablgnu · bash · CWE-78 | Critical9.8 | KEV | 99.9% | Sep 24, 2014 |
99Now | CVE-2025-24813Weaponized | Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUTapache · tomcat · CWE-44 | Critical9.8 | KEV | 99.9% | Mar 10, 2025 |
99Now | CVE-2023-46604Weaponized | Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attackapache · activemq · CWE-502 | Critical9.8 | KEV | 99.9% | Oct 27, 2023 |
99Now | CVE-2019-11043Weaponized | Underflow in PHP-FPM can lead to RCEphp · php · CWE-120 | Critical9.8 | KEV | 99.8% | Oct 28, 2019 |
99Now | CVE-2020-16846Weaponized | An issue was discovered in SaltStack Salt through 3002.saltstack · salt · CWE-78 | Critical9.8 | KEV | 99.6% | Nov 6, 2020 |
99Now | CVE-2017-7494Weaponized | Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious clisamba · samba · CWE-94 | Critical9.8 | KEV | 99.4% | May 30, 2017 |
99Now | CVE-2020-1938Weaponized | When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat.apache · geode | Critical9.8 | KEV | 99.3% | Feb 24, 2020 |
99Now | CVE-2018-7602Weaponized | Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004drupal · drupal · CWE-94 | Critical9.8 | KEV | 99.2% | Jul 19, 2018 |
99Now | CVE-2026-24061Weaponized | telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.gnu · inetutils · CWE-88 | Critical9.8 | KEV | 99.0% | Jan 21, 2026 |
99Now | CVE-2020-7247Weaponized | smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary coopenbsd · opensmtpd · CWE-78 | Critical9.8 | KEV | 99.0% | Jan 29, 2020 |
98Now | CVE-2012-0507Weaponized | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier,oracle · jre · CWE-843 | Critical9.8 | KEV | 98.1% | Jun 7, 2012 |
98Now | CVE-2020-11651Weaponized | An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2.saltstack · salt | Critical9.8 | KEV | 96.6% | Apr 30, 2020 |
98Now | CVE-2009-1151Weaponized | Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to injephpmyadmin · phpmyadmin · CWE-94 | Critical9.8 | KEV | 96.6% | Mar 26, 2009 |
97Now | CVE-2016-3427Weaponized | Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to afforacle · jdk · CWE-284 | Critical9.8 | KEV | 92.3% | Apr 21, 2016 |
96Now | CVE-2021-40438Weaponized | A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.resf · rocky linux · CWE-918 | Critical9.0 | KEV | 100.0% | Sep 16, 2021 |
96Now | CVE-2021-45046Weaponized | Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attackapache · log4j · CWE-917 | Critical9.0 | KEV | 100.0% | Dec 14, 2021 |
96Now | CVE-2016-8735Weaponized | Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x beforeapache · tomcat | Critical9.8 | KEV | 90.3% | Apr 6, 2017 |
95Now | CVE-2023-4863Weaponized | Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bogoogle · chrome · CWE-787 | High8.8 | KEV | 100.0% | Sep 12, 2023 |
- CVE-2021-44228100Now
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
CriticalCVSS 10.0KEVWeaponizedEPSS 100%apache · log4jDec 10, 2021
- CVE-2022-0543100Now
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape
CriticalCVSS 10.0KEVWeaponizedEPSS 99%redis · redisFeb 18, 2022
- CVE-2025-32433100Now
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
CriticalCVSS 10.0KEVWeaponizedEPSS 99%erlang · erlang\/otpApr 16, 2025
- CVE-2014-627199Now
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac
CriticalCVSS 9.8KEVWeaponizedEPSS 100%gnu · bashSep 24, 2014
- CVE-2012-182399Now
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle que
CriticalCVSS 9.8KEVWeaponizedEPSS 100%php · phpMay 11, 2012
- CVE-2018-760099Now
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because o
CriticalCVSS 9.8KEVWeaponizedEPSS 100%drupal · drupalMar 29, 2018
- CVE-2019-1014999Now
A flaw was found in Exim versions 4.87 to 4.91 (inclusive).
CriticalCVSS 9.8KEVWeaponizedEPSS 100%exim · eximJun 5, 2019
- CVE-2014-716999Now
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl
CriticalCVSS 9.8KEVWeaponizedEPSS 100%gnu · bashSep 24, 2014
- CVE-2025-2481399Now
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
CriticalCVSS 9.8KEVWeaponizedEPSS 100%apache · tomcatMar 10, 2025
- CVE-2023-4660499Now
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
CriticalCVSS 9.8KEVWeaponizedEPSS 100%apache · activemqOct 27, 2023
- CVE-2019-1104399Now
Underflow in PHP-FPM can lead to RCE
CriticalCVSS 9.8KEVWeaponizedEPSS 100%php · phpOct 28, 2019
- CVE-2020-1684699Now
An issue was discovered in SaltStack Salt through 3002.
CriticalCVSS 9.8KEVWeaponizedEPSS 100%saltstack · saltNov 6, 2020
- CVE-2017-749499Now
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious cli
CriticalCVSS 9.8KEVWeaponizedEPSS 99%samba · sambaMay 30, 2017
- CVE-2020-193899Now
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat.
CriticalCVSS 9.8KEVWeaponizedEPSS 99%apache · geodeFeb 24, 2020
- CVE-2018-760299Now
Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004
CriticalCVSS 9.8KEVWeaponizedEPSS 99%drupal · drupalJul 19, 2018
- CVE-2026-2406199Now
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.
CriticalCVSS 9.8KEVWeaponizedEPSS 99%gnu · inetutilsJan 21, 2026
- CVE-2020-724799Now
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary co
CriticalCVSS 9.8KEVWeaponizedEPSS 99%openbsd · opensmtpdJan 29, 2020
- CVE-2012-050798Now
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier,
CriticalCVSS 9.8KEVWeaponizedEPSS 98%oracle · jreJun 7, 2012
- CVE-2020-1165198Now
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2.
CriticalCVSS 9.8KEVWeaponizedEPSS 97%saltstack · saltApr 30, 2020
- CVE-2009-115198Now
Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inje
CriticalCVSS 9.8KEVWeaponizedEPSS 97%phpmyadmin · phpmyadminMar 26, 2009
- CVE-2016-342797Now
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to aff
CriticalCVSS 9.8KEVWeaponizedEPSS 92%oracle · jdkApr 21, 2016
- CVE-2021-4043896Now
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.
CriticalCVSS 9.0KEVWeaponizedEPSS 100%resf · rocky linuxSep 16, 2021
- CVE-2021-4504696Now
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
CriticalCVSS 9.0KEVWeaponizedEPSS 100%apache · log4jDec 14, 2021
- CVE-2016-873596Now
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before
CriticalCVSS 9.8KEVWeaponizedEPSS 90%apache · tomcatApr 6, 2017
- CVE-2023-486395Now
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bo
HighCVSS 8.8KEVWeaponizedEPSS 100%google · chromeSep 12, 2023