Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 126 of 498
CVE-2021-3246P3HIGHCVSS 8.8v9.0v10.02021-07-20
CVE-2021-3246 [HIGH] CWE-787 CVE-2021-3246: A heap buffer overflow vulnerability in msadpcm_decode_block of libsndfile 1.0.30 allows attackers t
A heap buffer overflow vulnerability in msadpcm_decode_block of libsndfile 1.0.30 allows attackers to execute arbitrary code via a crafted WAV file.
nvd
CVE-2025-62602P3HIGHCVSS 7.5v11.0v12.0+1 more2026-02-03
CVE-2025-62602 [HIGH] CWE-122 CVE-2025-62602: Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object
Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group
). Prior to versions 3.4.1, 3.3.1, and 2.6.11, when the security mode is enabled, modifying the DATA Submessage within an
SPDP packet sent by a publisher causes a heap buffer overflow, resulting in remote termination of Fast-DDS. If the
nvd
CVE-2016-4544P3CRITICALCVSS 9.8v8.02016-05-22
CVE-2016-4544 [CRITICAL] CWE-119 CVE-2016-4544: The exif_process_TIFF_in_JPEG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21,
The exif_process_TIFF_in_JPEG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not validate TIFF start data, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via crafted header data.
nvd
CVE-2019-13300P3HIGHCVSS 8.8v9.0v10.02019-07-05
CVE-2019-13300 [HIGH] CWE-787 CVE-2019-13300: ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/statistic.c in EvaluateImage
ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/statistic.c in EvaluateImages because of mishandling columns.
nvd
CVE-2021-21111P3CRITICALCVSS 9.6v10.02021-01-08
CVE-2021-21111 [CRITICAL] CWE-1021 CVE-2021-21111: Insufficient policy enforcement in WebUI in Google Chrome prior to 87.0.4280.141 allowed an attacker
Insufficient policy enforcement in WebUI in Google Chrome prior to 87.0.4280.141 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
nvd
CVE-2018-14648P3HIGHCVSS 7.5v8.02018-09-28
CVE-2018-14648 [HIGH] CWE-400 CVE-2018-14648: A flaw was found in 389 Directory Server. A specially crafted search query could lead to excessive C
A flaw was found in 389 Directory Server. A specially crafted search query could lead to excessive CPU consumption in the do_search() function. An unauthenticated attacker could use this flaw to provoke a denial of service.
nvd
CVE-2016-2828P3HIGHCVSS 8.8v8.02016-06-13
CVE-2016-2828 [HIGH] CVE-2016-2828: Use-after-free vulnerability in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows
Use-after-free vulnerability in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows remote attackers to execute arbitrary code via WebGL content that triggers texture access after destruction of the texture's recycle pool.
nvd
CVE-2020-10672P3HIGHCVSS 8.8v8.02020-03-18
CVE-2020-10672 [HIGH] CWE-502 CVE-2020-10672: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadg
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms).
nvd
CVE-2008-0017P3CRITICALCVSS 9.3v4.0v5.02008-11-13
CVE-2008-0017 [CRITICAL] CWE-119 CVE-2008-0017: The http-index-format MIME type parser (nsDirIndexParser) in Firefox 3.x before 3.0.4, Firefox 2.x b
The http-index-format MIME type parser (nsDirIndexParser) in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 does not check for an allocation failure, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP index response with a crafted 200 header, whic
nvd
CVE-2019-11505P3HIGHCVSS 8.8v8.0v9.0+1 more2019-04-24
CVE-2019-11505 [HIGH] CWE-787 CVE-2019-11505: In GraphicsMagick from version 1.3.8 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overf
In GraphicsMagick from version 1.3.8 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WritePDBImage of coders/pdb.c, which allows an attacker to cause a denial of service or possibly have unspecified other impact via a crafted image file. This is related to MagickBitStreamMSBWrite in magick/bit_stream.c.
nvd
CVE-2020-14195P3HIGHCVSS 8.1v8.02020-06-16
CVE-2020-14195 [HIGH] CWE-502 CVE-2020-14195: FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadg
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to org.jsecurity.realm.jndi.JndiRealmFactory (aka org.jsecurity).
nvd
CVE-2018-20151P3HIGHCVSS 7.5v8.0v9.02018-12-14
CVE-2018-20151 [HIGH] CWE-200 CVE-2018-20151: In WordPress before 4.9.9 and 5.x before 5.0.1, the user-activation page could be read by a search e
In WordPress before 4.9.9 and 5.x before 5.0.1, the user-activation page could be read by a search engine's web crawler if an unusual configuration were chosen. The search engine could then index and display a user's e-mail address and (rarely) the password that was generated by default.
nvd
CVE-2025-62231P3HIGHCVSS 7.3v11.02025-10-30
CVE-2025-62231 [HIGH] CWE-190 CVE-2025-62231: A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds check
A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds checking in the XkbSetCompatMap() function can cause an unsigned short overflow. If an attacker sends specially crafted input data, the value calculation may overflow, leading to memory corruption or a crash.
nvd
CVE-2016-8714P3HIGHCVSS 8.8v8.02017-03-10
CVE-2016-8714 [HIGH] CWE-120 CVE-2016-8714: An exploitable buffer overflow vulnerability exists in the LoadEncoding functionality of the R progr
An exploitable buffer overflow vulnerability exists in the LoadEncoding functionality of the R programming language version 3.3.0. A specially crafted R script can cause a buffer overflow resulting in a memory corruption. An attacker can send a malicious R script to trigger this vulnerability.
nvd
CVE-2021-37136P3HIGHCVSS 7.5v10.0v11.02021-10-19
CVE-2021-37136 [HIGH] CWE-400 CVE-2021-37136: The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed
The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression). All users of Bzip2Decoder are affected. The malicious input can trigger an OOME and so a DoS attack
nvd
CVE-2017-2816P3HIGHCVSS 8.8v7.02017-09-13
CVE-2017-2816 [HIGH] CWE-119 CVE-2017-2816: An exploitable buffer overflow vulnerability exists in the tag parsing functionality of LibOFX 0.9.1
An exploitable buffer overflow vulnerability exists in the tag parsing functionality of LibOFX 0.9.11. A specially crafted OFX file can cause a write out of bounds resulting in a buffer overflow on the stack. An attacker can construct a malicious OFX file to trigger this vulnerability.
nvd
CVE-2016-1516P3HIGHCVSS 8.8v8.0v9.02017-04-10
CVE-2016-1516 [HIGH] CWE-415 CVE-2016-1516: OpenCV 3.0.0 has a double free issue that allows attackers to execute arbitrary code.
OpenCV 3.0.0 has a double free issue that allows attackers to execute arbitrary code.
nvd
CVE-2019-12921P3MEDIUMCVSS 6.5v8.0v9.0+1 more2020-03-18
CVE-2019-12921 [MEDIUM] CWE-77 CVE-2019-12921: In GraphicsMagick before 1.3.32, the text filename component allows remote attackers to read arbitra
In GraphicsMagick before 1.3.32, the text filename component allows remote attackers to read arbitrary files via a crafted image because of TranslateTextEx for SVG.
nvd
CVE-2018-1000041P3HIGHCVSS 8.8v7.02018-02-09
CVE-2018-1000041 [HIGH] CVE-2018-1000041: GNOME librsvg version before commit c6ddf2ed4d768fd88adbea2b63f575cd523022ea contains a Improper inp
GNOME librsvg version before commit c6ddf2ed4d768fd88adbea2b63f575cd523022ea contains a Improper input validation vulnerability in rsvg-io.c that can result in the victim's Windows username and NTLM password hash being leaked to remote attackers through SMB. This attack appear to be exploitable via The victim must process a specially crafted SVG file cont
nvd
CVE-2003-0098P3CRITICALCVSS 10.0v2.2v3.02003-03-03
CVE-2003-0098 [CRITICAL] CVE-2003-0098: Unknown vulnerability in apcupsd before 3.8.6, and 3.10.x before 3.10.5, allows remote attackers to
Unknown vulnerability in apcupsd before 3.8.6, and 3.10.x before 3.10.5, allows remote attackers to gain root privileges, possibly via format strings in a request to a slave server.
nvd