Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 100 of 498
CVE-2023-4358P3HIGHCVSS 8.8v11.0v12.02023-08-15
CVE-2023-4358 [HIGH] CWE-416 CVE-2023-4358: Use after free in DNS in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potential
Use after free in DNS in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2015-1421P3CRITICALCVSS 10.0v7.0v8.02015-03-16
CVE-2015-1421 [CRITICAL] CVE-2015-1421: Use-after-free vulnerability in the sctp_assoc_update function in net/sctp/associola.c in the Linux
Use-after-free vulnerability in the sctp_assoc_update function in net/sctp/associola.c in the Linux kernel before 3.18.8 allows remote attackers to cause a denial of service (slab corruption and panic) or possibly have unspecified other impact by triggering an INIT collision that leads to improper handling of shared-key data.
nvd
CVE-2019-12520P3HIGHCVSS 7.5v9.0v10.02020-04-15
CVE-2019-12520 [HIGH] CWE-20 CVE-2019-12520: An issue was discovered in Squid through 4.7 and 5. When receiving a request, Squid checks its cache
An issue was discovered in Squid through 4.7 and 5. When receiving a request, Squid checks its cache to see if it can serve up a response. It does this by making a MD5 hash of the absolute URL of the request. If found, it servers the request. The absolute URL can include the decoded UserInfo (username and password) for certain protocols. This decoded i
nvd
CVE-2016-9900P3HIGHCVSS 7.5v9.02018-06-11
CVE-2016-9900 [HIGH] CWE-254 CVE-2016-9900: External resources that should be blocked when loaded by SVG images can bypass security restrictions
External resources that should be blocked when loaded by SVG images can bypass security restrictions through the use of "data:" URLs. This could allow for cross-domain data leakage. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
nvd
CVE-2018-1000301P3CRITICALCVSS 9.1v7.0v8.0+1 more2018-05-24
CVE-2018-1000301 [CRITICAL] CWE-125 CVE-2018-1000301: curl version curl 7.20.0 to and including curl 7.59.0 contains a CWE-126: Buffer Over-read vulnerabi
curl version curl 7.20.0 to and including curl 7.59.0 contains a CWE-126: Buffer Over-read vulnerability in denial of service that can result in curl can be tricked into reading data beyond the end of a heap based buffer used to store downloaded RTSP content.. This vulnerability appears to have been fixed in curl = 7.60.0.
nvd
CVE-2007-2834P3CRITICALCVSS 9.3v3.1v4.02007-09-18
CVE-2007-2834 [CRITICAL] CWE-190 CVE-2007-2834: Integer overflow in the TIFF parser in OpenOffice.org (OOo) before 2.3; and Sun StarOffice 6, 7, and
Integer overflow in the TIFF parser in OpenOffice.org (OOo) before 2.3; and Sun StarOffice 6, 7, and 8 Office Suite (StarSuite); allows remote attackers to execute arbitrary code via a TIFF file with crafted values of unspecified length fields, which triggers allocation of an incorrect amount of memory, resulting in a heap-based buffer overflow.
nvd
CVE-2019-13224P3CRITICALCVSS 9.8v8.02019-07-10
CVE-2019-13224 [CRITICAL] CWE-416 CVE-2019-13224: A use-after-free in onig_new_deluxe() in regext.c in Oniguruma 6.9.2 allows attackers to potentially
A use-after-free in onig_new_deluxe() in regext.c in Oniguruma 6.9.2 allows attackers to potentially cause information disclosure, denial of service, or possibly code execution by providing a crafted regular expression. The attacker provides a pair of a regex pattern and a string, with a multi-byte encoding that gets handled by onig_new_deluxe().
nvd
CVE-2012-3990P3CRITICALCVSS 9.3v6.02012-10-10
CVE-2012-3990 [CRITICAL] CWE-416 CVE-2012-3990: Use-after-free vulnerability in the IME State Manager implementation in Mozilla Firefox before 16.0,
Use-after-free vulnerability in the IME State Manager implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code via unspecified vectors, related to the nsIContent::GetNameSpaceID function.
nvd
CVE-2021-44730P3HIGHCVSS 8.8v10.0v11.02022-02-17
CVE-2021-44730 [HIGH] CWE-59 CVE-2021-44730: snapd 2.54.2 did not properly validate the location of the snap-confine binary. A local attacker who
snapd 2.54.2 did not properly validate the location of the snap-confine binary. A local attacker who can hardlink this binary to another location to cause snap-confine to execute other arbitrary binaries and hence gain privilege escalation. Fixed in snapd versions 2.54.3+18.04, 2.54.3+20.04 and 2.54.3+21.10.1
nvd
CVE-2012-4428P3HIGHCVSS 7.5v8.02019-12-02
CVE-2012-4428 [HIGH] CWE-125 CVE-2012-4428: openslp: SLPIntersectStringList()' Function has a DoS vulnerability
openslp: SLPIntersectStringList()' Function has a DoS vulnerability
nvd
CVE-2024-5696P3HIGHCVSS 8.6v10.02024-06-11
CVE-2024-5696 [HIGH] CWE-787 CVE-2024-5696: By manipulating the text in an `<input>` tag, an attacker could have caused corrupt memory lea
By manipulating the text in an ` ` tag, an attacker could have caused corrupt memory leading to a potentially exploitable crash. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
nvd
CVE-2014-1482P3HIGHCVSS 8.8v7.02014-02-06
CVE-2014-1482 [HIGH] CWE-787 CVE-2014-1482: RasterImage.cpp in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.
RasterImage.cpp in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 does not prevent access to discarded data, which allows remote attackers to execute arbitrary code or cause a denial of service (incorrect write operations) via crafted image data, as demonstrated by Goo Create.
nvd
CVE-2022-2196P3HIGHCVSS 8.8v10.02023-01-09
CVE-2022-2196 [HIGH] CWE-1188 CVE-2022-2196: A regression exists in the Linux Kernel within KVM: nVMX that allowed for speculative execution atta
A regression exists in the Linux Kernel within KVM: nVMX that allowed for speculative execution attacks. L2 can carry out Spectre v2 attacks on L1 due to L1 thinking it doesn't need retpolines or IBPB after running L2 due to KVM (L0) advertising eIBRS support to L1. An attacker at L2 with code execution can execute code on an indirect branch on the hos
nvd
CVE-2019-19948P3CRITICALCVSS 9.8v8.0v9.0+1 more2019-12-24
CVE-2019-19948 [CRITICAL] CWE-787 CVE-2019-19948: In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer overflow in the function WriteSGIImage of
In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer overflow in the function WriteSGIImage of coders/sgi.c.
nvd
CVE-2011-1408P3HIGHCVSS 8.2v8.0v9.0+1 more2019-10-29
CVE-2011-1408 [HIGH] CWE-59 CVE-2011-1408: ikiwiki before 3.20110608 allows remote attackers to hijack root's tty and run symlink attacks.
ikiwiki before 3.20110608 allows remote attackers to hijack root's tty and run symlink attacks.
nvd
CVE-2023-5363P3HIGHCVSS 7.5v12.02023-10-25
CVE-2023-5363 [HIGH] CWE-684 CVE-2023-5363: Issue summary: A bug has been identified in the processing of key and initialisation vector (IV) len
Issue summary: A bug has been identified in the processing of key and
initialisation vector (IV) lengths. This can lead to potential truncation
or overruns during the initialisation of some symmetric ciphers.
Impact summary: A truncation in the IV can result in non-uniqueness,
which could result in loss of confidentiality for some cipher modes.
When c
nvd
CVE-2018-11040P3HIGHCVSS 7.5v9.02018-06-25
CVE-2018-11040 [HIGH] CWE-829 CVE-2018-11040: Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported vers
Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported versions, allows web applications to enable cross-domain requests via JSONP (JSON with Padding) through AbstractJsonpResponseBodyAdvice for REST controllers and MappingJackson2JsonView for browser requests. Both are not enabled by default in Spring Framewor
nvd
CVE-2021-3407P3MEDIUMCVSS 5.5v9.02021-02-23
CVE-2021-3407 [MEDIUM] CWE-415 CVE-2021-3407: A flaw was found in mupdf 1.18.0. Double free of object during linearization may lead to memory corr
A flaw was found in mupdf 1.18.0. Double free of object during linearization may lead to memory corruption and other potential consequences.
nvd
CVE-2015-3195P3MEDIUMCVSS 5.3v7.0v8.02015-12-06
CVE-2015-3195 [MEDIUM] CWE-200 CVE-2015-3195: The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 befo
The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1q, and 1.0.2 before 1.0.2e mishandles errors caused by malformed X509_ATTRIBUTE data, which allows remote attackers to obtain sensitive information from process memory by triggering a decoding failure in a PKCS#7 or CMS appl
nvd
CVE-2018-7186P3CRITICALCVSS 9.8v7.02018-02-16
CVE-2018-7186 [CRITICAL] CWE-787 CVE-2018-7186: Leptonica before 1.75.3 does not limit the number of characters in a %s format argument to fscanf or
Leptonica before 1.75.3 does not limit the number of characters in a %s format argument to fscanf or sscanf, which allows remote attackers to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact via a long string, as demonstrated by the gplotRead and ptaReadStream functions.
nvd