FAIL › dossier
debian
VENDORDossier not yet built — the RAG curator builds one for players with ≥2 failure events. The failure history and sentiment below are live.
FAILURE HISTORY · 12
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2024-10-09 | CVE-2024-9680 | critical | CVE-2024-9680: An attacker was able to achieve code execution in the content process by exploit |
| 2023-08-22 | CVE-2022-48174 | critical | CVE-2022-48174: There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In |
| 2022-08-05 | CVE-2022-37434 | critical | CVE-2022-37434: zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in infl |
| 2021-12-10 | CVE-2021-44228 | critical | CVE-2021-44228: Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12 |
| 2021-09-16 | CVE-2021-40438 | critical | CVE-2021-40438: A crafted request uri-path can cause mod_proxy to forward the request to an orig |
| 2020-03-02 | CVE-2020-9548 | critical | CVE-2020-9548: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee |
| 2020-03-02 | CVE-2020-9546 | critical | CVE-2020-9546: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee |
| 2020-02-24 | CVE-2020-1938 | critical | CVE-2020-1938: When using the Apache JServ Protocol (AJP), care must be taken when trusting inc |
| 2019-12-23 | CVE-2019-11049 | medium | CVE-2019-11049: In PHP versions 7.3.x below 7.3.13 and 7.4.0 on Windows, when supplying custom h |
| 2018-07-19 | CVE-2018-7602 | critical | CVE-2018-7602: A remote code execution vulnerability exists within multiple subsystems of Drupa |
| 2017-05-23 | CVE-2016-9841 | critical | CVE-2016-9841: inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecif |
| 2017-04-06 | CVE-2016-8735 | critical | CVE-2016-8735: Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7 |
SENTIMENT · TRUSTED SOURCES
synthesisneutral+0.00
No sentiment expressed; sources are CVE databases or vendor pages without commentary on Debian's handling.
synthesisneutral+0.00
No coverage of CVE-2020-9546 vendor response or handling found in sources; sources are unrelated to the event.
synthesissevere-fallout-0.60
Critical RCE in Drupal core, actively exploited, but Debian is not the vendor; coverage lacks direct vendor response or praise.
Neutral; source is unrelated data breach settlement report.
"SitusAMC $5.3M Data Breach Settlement — $75 or Up to $5,000"
Neutral; GitHub page unrelated to CVE-2020-9548 or Debian.
Neutral; source only lists CVE details without vendor response or handling.
"FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shaded.com.zaxxer.hikari.HikariConfig (aka shaded hikari-config)."
Neutral; source is a CVE database listing unrelated to vendor handling.
"CVE-2020-35728 5 Debian , Fasterxml , Netapp and 2 more 42 Debian Linux , Jackson-databind , Service Level Manager and 39 more 2026-08-25 8.1 High FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool (aka embedded Xalan in org.glassfish.web/javax.servlet.jsp.j"
Neutral; source is unrelated data breach report.
"In mid-2026, hundreds of thousands of user records allegedly sourced from Golf Canada began circulating via Telegram."
Neutral; source is unrelated data breach report.
"In August 2026, clothing retailer Carhartt was the target of a ShinyHunters 'pay or leak' extortion campaign ."
Neutral; source is unrelated Oracle WebLogic flaw report.
"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation."
Neutral; source is unrelated HIPAA breach report.
"Tift Regional Health System Pays $1.2 Million to Settle Data Breach Lawsuit"
Neutral; CVE database entry only states the vulnerability without sentiment.
"FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-core)."
Neutral; CVE database page provides general info, no specific sentiment toward Debian.
Neutral; Vendor security page, no mention of CVE-2020-9548 or Debian.
Neutral; Debian LTS page mentions other patches, no sentiment on CVE-2020-9548.
Neutral; Breach directory unrelated to CVE-2020-9548 or Debian.
Neutral; CVE database page unrelated to CVE-2020-9548 or Debian.
Neutral government catalog page; no vendor-specific sentiment.
Neutral search results page; no vendor-specific sentiment.
Neutral Debian security page; no specific CVE-2018-7602 sentiment.
Neutral CVE database page; no vendor-specific sentiment.
Neutral government catalog page; no vendor-specific sentiment.
Severely critical RCE actively exploited in Drupal core; vendor not directly addressed in text.
"A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being compromised. This vulnerability is related to Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-002. Both SA-CORE-2018-002 and this vulnerability are being exploi"
Neutral government catalog page; no vendor-specific sentiment.