cbcvebase.

Debian Linux vulnerabilities

9,953 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358

Vulnerabilities

Page 106 of 498
CVE-2020-6428P3HIGHCVSS 8.8v9.0v10.02020-03-23
CVE-2020-6428 [HIGH] CWE-787 CVE-2020-6428: Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potenti Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-43400P3CRITICALCVSS 9.1v10.02021-11-04
CVE-2021-43400 [CRITICAL] CWE-416 CVE-2021-43400: An issue was discovered in gatt-database.c in BlueZ 5.61. A use-after-free can occur when a client d An issue was discovered in gatt-database.c in BlueZ 5.61. A use-after-free can occur when a client disconnects during D-Bus processing of a WriteValue call.
nvd
CVE-2001-0111P4HIGHCVSS 7.2PoCv2.22001-03-12
CVE-2001-0111 [HIGH] CVE-2001-0111: Format string vulnerability in splitvt before 1.6.5 allows local users to execute arbitrary commands Format string vulnerability in splitvt before 1.6.5 allows local users to execute arbitrary commands via the -rcfile command line argument.
nvd
CVE-2020-6382P3HIGHCVSS 8.8v9.0v10.02020-02-11
CVE-2020-6382 [HIGH] CWE-843 CVE-2020-6382: Type confusion in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to pot Type confusion in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2016-2175P3HIGHCVSS 7.8v8.02016-06-01
CVE-2016-2175 [HIGH] CVE-2016-2175: Apache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly initialize the XML parsers, which Apache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly initialize the XML parsers, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted PDF.
nvd
CVE-2016-9063P3CRITICALCVSS 9.8v8.0v9.0+1 more2018-06-11
CVE-2016-9063 [CRITICAL] CWE-190 CVE-2016-9063: An integer overflow during the parsing of XML using the Expat library. This vulnerability affects Fi An integer overflow during the parsing of XML using the Expat library. This vulnerability affects Firefox < 50.
nvd
CVE-2022-41649P3CRITICALCVSS 9.1v11.02022-12-22
CVE-2022-41649 [CRITICAL] CWE-125 CVE-2022-41649: A heap out of bounds read vulnerability exists in the handling of IPTC data while parsing TIFF image A heap out of bounds read vulnerability exists in the handling of IPTC data while parsing TIFF images in OpenImageIO v2.3.19.0. A specially-crafted TIFF file can cause a read of adjacent heap memory, which can leak sensitive process information. An attacker can provide a malicious file to trigger this vulnerability.
nvd
CVE-2022-41674P3HIGHCVSS 8.1v10.0v11.02022-10-14
CVE-2022-41674 [HIGH] CWE-787 CVE-2022-41674: An issue was discovered in the Linux kernel before 5.19.16. Attackers able to inject WLAN frames cou An issue was discovered in the Linux kernel before 5.19.16. Attackers able to inject WLAN frames could cause a buffer overflow in the ieee80211_bss_info_update function in net/mac80211/scan.c.
nvd
CVE-2001-0193P4HIGHCVSS 7.2PoCv2.22001-05-03
CVE-2001-0193 [HIGH] CVE-2001-0193: Format string vulnerability in man in some Linux distributions allows local users to gain privileges Format string vulnerability in man in some Linux distributions allows local users to gain privileges via a malformed -l parameter.
nvd
CVE-2020-6416P3HIGHCVSS 8.8v9.0v10.02020-02-11
CVE-2020-6416 [HIGH] CWE-20 CVE-2020-6416: Insufficient data validation in streams in Google Chrome prior to 80.0.3987.87 allowed a remote atta Insufficient data validation in streams in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-5831P3HIGHCVSS 8.8v10.02019-06-27
CVE-2019-5831 [HIGH] CWE-787 CVE-2019-5831: Object lifecycle issue in V8 in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to pot Object lifecycle issue in V8 in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-13730P3HIGHCVSS 8.8v9.0v10.02019-12-10
CVE-2019-13730 [HIGH] CWE-787 CVE-2019-13730: Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to pot Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2012-0037P3MEDIUMCVSS 6.5v6.02012-06-17
CVE-2012-0037 [MEDIUM] CWE-611 CVE-2012-0037: Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice bef Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted XML external entity (XXE) declaration and reference in an RDF document.
nvd
CVE-2020-6534P3HIGHCVSS 8.8v10.02020-07-22
CVE-2020-6534 [HIGH] CWE-787 CVE-2020-6534: Heap buffer overflow in WebRTC in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to p Heap buffer overflow in WebRTC in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2017-12380P3HIGHCVSS 7.5v7.02018-01-26
CVE-2017-12380 [HIGH] CWE-476 CVE-2017-12380: ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unau ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper input validation checking mechanisms in mbox.c during certain mail parsing functions of the ClamAV software. An unauthe
nvd
CVE-2020-6525P3HIGHCVSS 8.8v10.02020-07-22
CVE-2020-6525 [HIGH] CWE-787 CVE-2020-6525: Heap buffer overflow in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to pot Heap buffer overflow in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6406P3HIGHCVSS 8.8v9.0v10.02020-02-11
CVE-2020-6406 [HIGH] CWE-416 CVE-2020-6406: Use after free in audio in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentia Use after free in audio in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-9232P3HIGHCVSS 7.5v8.0v9.0+1 more2019-09-27
CVE-2019-9232 [HIGH] CWE-125 CVE-2019-9232: In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-122675483
nvd
CVE-2020-6447P3HIGHCVSS 8.8v9.0v10.02020-04-13
CVE-2020-6447 [HIGH] CWE-125 CVE-2020-6447: Inappropriate implementation in developer tools in Google Chrome prior to 81.0.4044.92 allowed a rem Inappropriate implementation in developer tools in Google Chrome prior to 81.0.4044.92 allowed a remote attacker who had convinced the user to use devtools to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-3327P3HIGHCVSS 7.5v8.0v9.02020-05-13
CVE-2020-3327 [HIGH] CWE-20 CVE-2020-3327: A vulnerability in the ARJ archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.102 A vulnerability in the ARJ archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.102.2 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to a heap buffer overflow read. An attacker could exploit this vulnerability by sending a crafted ARJ file to an affec
nvd
Debian Linux vulnerabilities | cvebase