Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 104 of 498
CVE-2023-4056P3CRITICALCVSS 9.8v10.0v11.0+1 more2023-08-01
CVE-2023-4056 [CRITICAL] CWE-787 CVE-2023-4056: Memory safety bugs present in Firefox 115, Firefox ESR 115.0, Firefox ESR 102.13, Thunderbird 115.0,
Memory safety bugs present in Firefox 115, Firefox ESR 115.0, Firefox ESR 102.13, Thunderbird 115.0, and Thunderbird 102.13. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and
nvd
CVE-2020-13112P3CRITICALCVSS 9.1v8.02020-05-21
CVE-2020-13112 [CRITICAL] CVE-2020-13112: An issue was discovered in libexif before 0.6.22. Several buffer over-reads in EXIF MakerNote handli
An issue was discovered in libexif before 0.6.22. Several buffer over-reads in EXIF MakerNote handling could lead to information disclosure and crashes. This is different from CVE-2020-0093.
nvd
CVE-2019-9638P3HIGHCVSS 7.5v8.0v9.02019-03-09
CVE-2019-9638 [HIGH] CWE-125 CVE-2019-9638: An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x b
An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in exif_process_IFD_in_MAKERNOTE because of mishandling the maker_note->offset relationship to value_len.
nvd
CVE-2024-20952P3HIGHCVSS 7.4v10.02024-01-16
CVE-2024-20952 [HIGH] CWE-284 CVE-2024-20952: Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition produ
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u391, 8u391-perf, 11.0.21, 17.0.9, 21.0.1; Oracle GraalVM for JDK: 17.0.9, 21.0.1; Oracle GraalVM Enterprise Edition: 20.3.12, 21.3.8 and 22.3.4. Diffi
nvd
CVE-2024-20918P3HIGHCVSS 7.4v10.02024-01-16
CVE-2024-20918 [HIGH] CWE-284 CVE-2024-20918: Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition produ
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u391, 8u391-perf, 11.0.21, 17.0.9, 21.0.1; Oracle GraalVM for JDK: 17.0.9, 21.0.1; Oracle GraalVM Enterprise Edition: 20.3.12, 21.3.8 and 22.3.4. Diffic
nvd
CVE-2020-6462P3CRITICALCVSS 9.6v9.0v10.02020-05-21
CVE-2020-6462 [CRITICAL] CWE-416 CVE-2020-6462: Use after free in task scheduling in Google Chrome prior to 81.0.4044.129 allowed a remote attacker
Use after free in task scheduling in Google Chrome prior to 81.0.4044.129 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2017-11359P4MEDIUMCVSS 5.5PoCv7.0v8.02017-07-31
CVE-2017-11359 [MEDIUM] CWE-369 CVE-2017-11359: The wavwritehdr function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a
The wavwritehdr function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted snd file, during conversion to a wav file.
nvd
CVE-2017-11332P4MEDIUMCVSS 5.5PoCv7.0v8.02017-07-31
CVE-2017-11332 [MEDIUM] CWE-369 CVE-2017-11332: The startread function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a de
The startread function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted wav file.
nvd
CVE-2015-2305P3MEDIUMCVSS 6.8v7.0v8.02015-03-30
CVE-2015-2305 [MEDIUM] CWE-190 CVE-2015-2305: Integer overflow in the regcomp implementation in the Henry Spencer BSD regex library (aka rxspencer
Integer overflow in the regcomp implementation in the Henry Spencer BSD regex library (aka rxspencer) alpha3.8.g5 on 32-bit platforms, as used in NetBSD through 6.1.5 and other products, might allow context-dependent attackers to execute arbitrary code via a large regular expression that leads to a heap-based buffer overflow.
nvd
CVE-2024-25714P3CRITICALCVSS 9.8v11.0v12.02024-02-11
CVE-2024-25714 [CRITICAL] CWE-203 CVE-2024-25714: In Rhonabwy through 1.1.13, HMAC signature verification uses a strcmp function that is vulnerable to
In Rhonabwy through 1.1.13, HMAC signature verification uses a strcmp function that is vulnerable to side-channel attacks, because it stops the comparison when the first difference is spotted in the two signatures. (The fix uses gnutls_memcmp, which has constant-time execution.)
nvd
CVE-2018-6090P3HIGHCVSS 8.8v8.0v9.02018-12-04
CVE-2018-6090 [HIGH] CWE-190 CVE-2018-6090: An integer overflow that lead to a heap buffer-overflow in Skia in Google Chrome prior to 66.0.3359.
An integer overflow that lead to a heap buffer-overflow in Skia in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
nvd
CVE-2026-25061P3HIGHCVSS 7.5v11.02026-01-29
CVE-2026-25061 [HIGH] CWE-787 CVE-2026-25061: tcpflow is a TCP/IP packet demultiplexer. In versions up to and including 1.61, wifipcap parses 802.
tcpflow is a TCP/IP packet demultiplexer. In versions up to and including 1.61, wifipcap parses 802.11 management frame elements and performs a length check on the wrong field when handling the TIM element. A crafted frame with a large TIM length can cause a 1-byte out-of-bounds write past `tim.bitmap[251]`. The overflow is small and DoS is the likely
nvd
CVE-2021-41990P3HIGHCVSS 7.5v10.0v11.02021-10-18
CVE-2021-41990 [HIGH] CWE-190 CVE-2021-41990: The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate wi
The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example, this can be triggered by an unrelated self-signed CA certificate sent by an initiator. Remote code execution cannot occur.
nvd
CVE-2020-6461P3CRITICALCVSS 9.6v9.0v10.02020-05-21
CVE-2020-6461 [CRITICAL] CWE-416 CVE-2020-6461: Use after free in storage in Google Chrome prior to 81.0.4044.129 allowed a remote attacker who had
Use after free in storage in Google Chrome prior to 81.0.4044.129 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2019-7637P3HIGHCVSS 8.8v8.0v9.02019-02-08
CVE-2019-7637 [HIGH] CWE-787 CVE-2019-7637: SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer overflow
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer overflow in SDL_FillRect in video/SDL_surface.c.
nvd
CVE-2017-2888P3HIGHCVSS 8.8v9.02017-10-11
CVE-2017-2888 [HIGH] CWE-190 CVE-2017-2888: An exploitable integer overflow vulnerability exists when creating a new RGB Surface in SDL 2.0.5. A
An exploitable integer overflow vulnerability exists when creating a new RGB Surface in SDL 2.0.5. A specially crafted file can cause an integer overflow resulting in too little memory being allocated which can lead to a buffer overflow and potential code execution. An attacker can provide a specially crafted image file to trigger this vulnerability.
nvd
CVE-2017-12862P3HIGHCVSS 8.8v8.0v9.02017-08-15
CVE-2017-12862 [HIGH] CWE-787 CVE-2017-12862: In modules/imgcodecs/src/grfmt_pxm.cpp, the length of buffer AutoBuffer _src is small than expected,
In modules/imgcodecs/src/grfmt_pxm.cpp, the length of buffer AutoBuffer _src is small than expected, which will cause copy buffer overflow later. If the image is from remote, may lead to remote code execution or denial of service. This affects Opencv 3.3 and earlier.
nvd
CVE-2020-36230P3HIGHCVSS 7.5v9.0v10.02021-01-26
CVE-2020-36230 [HIGH] CWE-617 CVE-2020-36230: A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure in slapd in the X.50
A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure in slapd in the X.509 DN parsing in decode.c ber_next_element, resulting in denial of service.
nvd
CVE-2019-5770P3HIGHCVSS 8.8v9.02019-02-19
CVE-2019-5770 [HIGH] CWE-125 CVE-2019-5770: Insufficient input validation in WebGL in Google Chrome prior to 72.0.3626.81 allowed a remote attac
Insufficient input validation in WebGL in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
nvd
CVE-2021-37981P3CRITICALCVSS 9.6v10.0v11.02021-11-02
CVE-2021-37981 [CRITICAL] CWE-787 CVE-2021-37981: Heap buffer overflow in Skia in Google Chrome prior to 95.0.4638.54 allowed a remote attacker who ha
Heap buffer overflow in Skia in Google Chrome prior to 95.0.4638.54 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd