Skip to content
COOEY

FAIL › dossier

debian

VENDOR

Dossier not yet built — the RAG curator builds one for players with ≥2 failure events. The failure history and sentiment below are live.
FAILURE HISTORY · 12
DATEEVENTSEVSUMMARY
2024-10-09 CVE-2024-9680 critical CVE-2024-9680: An attacker was able to achieve code execution in the content process by exploit
2023-08-22 CVE-2022-48174 critical CVE-2022-48174: There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In
2022-08-05 CVE-2022-37434 critical CVE-2022-37434: zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in infl
2021-12-10 CVE-2021-44228 critical CVE-2021-44228: Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12
2021-09-16 CVE-2021-40438 critical CVE-2021-40438: A crafted request uri-path can cause mod_proxy to forward the request to an orig
2020-03-02 CVE-2020-9548 critical CVE-2020-9548: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee
2020-03-02 CVE-2020-9546 critical CVE-2020-9546: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee
2020-02-24 CVE-2020-1938 critical CVE-2020-1938: When using the Apache JServ Protocol (AJP), care must be taken when trusting inc
2019-12-23 CVE-2019-11049 medium CVE-2019-11049: In PHP versions 7.3.x below 7.3.13 and 7.4.0 on Windows, when supplying custom h
2018-07-19 CVE-2018-7602 critical CVE-2018-7602: A remote code execution vulnerability exists within multiple subsystems of Drupa
2017-05-23 CVE-2016-9841 critical CVE-2016-9841: inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecif
2017-04-06 CVE-2016-8735 critical CVE-2016-8735: Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7
SENTIMENT · TRUSTED SOURCES
synthesisneutral+0.00
No sentiment expressed; sources are CVE databases or vendor pages without commentary on Debian's handling.
synthesisneutral+0.00
No coverage of CVE-2020-9546 vendor response or handling found in sources; sources are unrelated to the event.
synthesissevere-fallout-0.60
Critical RCE in Drupal core, actively exploited, but Debian is not the vendor; coverage lacks direct vendor response or praise.
Neutral; source is unrelated data breach settlement report.
"SitusAMC $5.3M Data Breach Settlement — $75 or Up to $5,000"
github.com ↗neutral+0.00
Neutral; GitHub page unrelated to CVE-2020-9548 or Debian.
cooey ↗neutral+0.00
Neutral; source only lists CVE details without vendor response or handling.
"FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shaded.com.zaxxer.hikari.HikariConfig (aka shaded hikari-config)."
app.opencve.io ↗neutral+0.00
Neutral; source is a CVE database listing unrelated to vendor handling.
"CVE-2020-35728 5 Debian , Fasterxml , Netapp and 2 more 42 Debian Linux , Jackson-databind , Service Level Manager and 39 more 2026-08-25 8.1 High FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool (aka embedded Xalan in org.glassfish.web/javax.servlet.jsp.j"
Neutral; source is unrelated data breach report.
"In mid-2026, hundreds of thousands of user records allegedly sourced from Golf Canada began circulating via Telegram."
Neutral; source is unrelated data breach report.
"In August 2026, clothing retailer Carhartt was the target of a ShinyHunters 'pay or leak' extortion campaign ."
Neutral; source is unrelated Oracle WebLogic flaw report.
"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation."
Neutral; source is unrelated HIPAA breach report.
"Tift Regional Health System Pays $1.2 Million to Settle Data Breach Lawsuit"
cooey ↗neutral+0.00
Neutral; CVE database entry only states the vulnerability without sentiment.
"FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-core)."
Neutral; CVE database page provides general info, no specific sentiment toward Debian.
SentinelOne ↗neutral+0.00
Neutral; Vendor security page, no mention of CVE-2020-9548 or Debian.
Neutral; Debian LTS page mentions other patches, no sentiment on CVE-2020-9548.
Neutral; Breach directory unrelated to CVE-2020-9548 or Debian.
app.opencve.io ↗neutral+0.00
Neutral; CVE database page unrelated to CVE-2020-9548 or Debian.
NVD ↗severe-fallout+0.00
Neutral government catalog page; no vendor-specific sentiment.
app.opencve.io ↗severe-fallout+0.00
Neutral search results page; no vendor-specific sentiment.
security.na.debian.org ↗severe-fallout+0.00
Neutral Debian security page; no specific CVE-2018-7602 sentiment.
www.cvefind.com ↗severe-fallout+0.00
Neutral CVE database page; no vendor-specific sentiment.
NVD ↗severe-fallout+0.00
Neutral government catalog page; no vendor-specific sentiment.
cooey ↗severe-fallout-0.80
Severely critical RCE actively exploited in Drupal core; vendor not directly addressed in text.
"A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being compromised. This vulnerability is related to Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-002. Both SA-CORE-2018-002 and this vulnerability are being exploi"
CISA ↗severe-fallout+0.00
Neutral government catalog page; no vendor-specific sentiment.