Skip to content
Noroxi

Debian records

10,221 published records for vendor debian.

Researcher profile

Entered KEV
123 · 1.2%
Weaponized
201 · 2%
Pre-auth RCE
752
With a fix record
97.4%
Median publish → KEV
362 days

All records

10,000+ records
  • Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints

    CriticalCVSS 10.0KEVWeaponizedEPSS 100%

    apache · log4jDec 10, 2021

  • It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape

    CriticalCVSS 10.0KEVWeaponizedEPSS 99%

    redis · redisFeb 18, 2022

  • Erlang/OTP SSH Vulnerable to Pre-Authentication RCE

    CriticalCVSS 10.0KEVWeaponizedEPSS 99%

    erlang · erlang\/otpApr 16, 2025

  • GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    gnu · bashSep 24, 2014

  • sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle que

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    php · phpMay 11, 2012

  • Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because o

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    drupal · drupalMar 29, 2018

  • A flaw was found in Exim versions 4.87 to 4.91 (inclusive).

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    exim · eximJun 5, 2019

  • GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    gnu · bashSep 24, 2014

  • Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    apache · tomcatMar 10, 2025

  • Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    apache · activemqOct 27, 2023

  • Underflow in PHP-FPM can lead to RCE

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    php · phpOct 28, 2019

  • An issue was discovered in SaltStack Salt through 3002.

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    saltstack · saltNov 6, 2020

  • Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious cli

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    samba · sambaMay 30, 2017

  • When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat.

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    apache · geodeFeb 24, 2020

  • Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    drupal · drupalJul 19, 2018

  • telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    gnu · inetutilsJan 21, 2026

  • smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary co

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    openbsd · opensmtpdJan 29, 2020

  • Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier,

    CriticalCVSS 9.8KEVWeaponizedEPSS 98%

    oracle · jreJun 7, 2012

  • An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2.

    CriticalCVSS 9.8KEVWeaponizedEPSS 97%

    saltstack · saltApr 30, 2020

  • Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inje

    CriticalCVSS 9.8KEVWeaponizedEPSS 97%

    phpmyadmin · phpmyadminMar 26, 2009

  • Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to aff

    CriticalCVSS 9.8KEVWeaponizedEPSS 92%

    oracle · jdkApr 21, 2016

  • A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.

    CriticalCVSS 9.0KEVWeaponizedEPSS 100%

    resf · rocky linuxSep 16, 2021

  • Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack

    CriticalCVSS 9.0KEVWeaponizedEPSS 100%

    apache · log4jDec 14, 2021

  • Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before

    CriticalCVSS 9.8KEVWeaponizedEPSS 90%

    apache · tomcatApr 6, 2017

  • Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bo

    HighCVSS 8.8KEVWeaponizedEPSS 100%

    google · chromeSep 12, 2023