Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 127 of 498
CVE-2018-6031P3HIGHCVSS 8.8v8.0v9.02018-09-25
CVE-2018-6031 [HIGH] CWE-416 CVE-2018-6031: Use after free in PDFium in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potent
Use after free in PDFium in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
nvd
CVE-2016-1834P3HIGHCVSS 7.8v8.02016-05-20
CVE-2016-1834 [HIGH] CWE-119 CVE-2016-1834: Heap-based buffer overflow in the xmlStrncat function in libxml2 before 2.9.4, as used in Apple iOS
Heap-based buffer overflow in the xmlStrncat function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted XML document.
nvd
CVE-2024-25082P3MEDIUMCVSS 6.5v10.02024-02-26
CVE-2024-25082 [MEDIUM] CWE-77 CVE-2024-25082: Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed
Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files.
nvd
CVE-2015-8778P3CRITICALCVSS 9.8v8.02016-04-19
CVE-2015-8778 [CRITICAL] CWE-119 CVE-2015-8778: Integer overflow in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent atta
Integer overflow in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via the size argument to the __hcreate_r function, which triggers out-of-bounds heap-memory access.
nvd
CVE-2022-23837P3HIGHCVSS 7.5v9.02022-01-21
CVE-2022-23837 [HIGH] CWE-770 CVE-2022-23837: In api.rb in Sidekiq before 5.2.10 and 6.4.0, there is no limit on the number of days when requestin
In api.rb in Sidekiq before 5.2.10 and 6.4.0, there is no limit on the number of days when requesting stats for the graph. This overloads the system, affecting the Web UI, and makes it unavailable to users.
nvd
CVE-2019-5827P3HIGHCVSS 8.8v9.0v10.02019-06-27
CVE-2019-5827 [HIGH] CWE-190 CVE-2019-5827: Integer overflow in SQLite via WebSQL in Google Chrome prior to 74.0.3729.131 allowed a remote attac
Integer overflow in SQLite via WebSQL in Google Chrome prior to 74.0.3729.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-15673P3HIGHCVSS 8.8v9.0v10.02020-10-01
CVE-2020-15673 [HIGH] CWE-416 CVE-2020-15673: Mozilla developers reported memory safety bugs present in Firefox 80 and Firefox ESR 78.2. Some of t
Mozilla developers reported memory safety bugs present in Firefox 80 and Firefox ESR 78.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and Firefox ESR < 78.3.
nvd
CVE-2019-5822P3HIGHCVSS 8.8v10.02019-06-27
CVE-2019-5822 [HIGH] CVE-2019-5822: Inappropriate implementation in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote attac
Inappropriate implementation in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass same origin policy via a crafted HTML page.
nvd
CVE-2020-11619P3HIGHCVSS 8.1v8.02020-04-07
CVE-2020-11619 [HIGH] CWE-502 CVE-2020-11619: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadg
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.springframework.aop.config.MethodLocatingFactoryBean (aka spring-aop).
nvd
CVE-2018-20549P3HIGHCVSS 8.8v8.02018-12-28
CVE-2018-20549 [HIGH] CWE-119 CVE-2018-20549: There is an illegal WRITE memory access at caca/file.c (function caca_file_read) in libcaca 0.99.bet
There is an illegal WRITE memory access at caca/file.c (function caca_file_read) in libcaca 0.99.beta19.
nvd
CVE-2019-5757P3HIGHCVSS 8.8v9.02019-02-19
CVE-2019-5757 [HIGH] CWE-704 CVE-2019-5757: An incorrect object type assumption in SVG in Google Chrome prior to 72.0.3626.81 allowed a remote a
An incorrect object type assumption in SVG in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page.
nvd
CVE-2018-6073P3HIGHCVSS 8.8v9.02018-11-14
CVE-2018-6073 [HIGH] CWE-787 CVE-2018-6073: A heap buffer overflow in WebGL in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to
A heap buffer overflow in WebGL in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.
nvd
CVE-2017-12374P3HIGHCVSS 7.5v7.02018-01-26
CVE-2017-12374 [HIGH] CWE-416 CVE-2017-12374: The ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an
The ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a lack of input validation checking mechanisms during certain mail parsing operations (mbox.c operations on bounce messages).
nvd
CVE-2020-6851P3HIGHCVSS 7.5v8.0v9.0+1 more2020-01-13
CVE-2020-6851 [HIGH] CWE-787 CVE-2020-6851: OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t
OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t1.c because of lack of opj_j2k_update_image_dimensions validation.
nvd
CVE-2017-5125P3HIGHCVSS 8.8v8.0v9.02018-02-07
CVE-2017-5125 [HIGH] CWE-119 CVE-2017-5125: Heap buffer overflow in Skia in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to pot
Heap buffer overflow in Skia in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2018-18337P3HIGHCVSS 8.8v9.02018-12-11
CVE-2018-18337 [HIGH] CWE-416 CVE-2018-18337: Incorrect handling of stylesheets leading to a use after free in Blink in Google Chrome prior to 71.
Incorrect handling of stylesheets leading to a use after free in Blink in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2017-5097P3HIGHCVSS 8.8v9.02017-10-27
CVE-2017-5097 [HIGH] CWE-20 CVE-2017-5097: Insufficient validation of untrusted input in Skia in Google Chrome prior to 60.0.3112.78 for Linux
Insufficient validation of untrusted input in Skia in Google Chrome prior to 60.0.3112.78 for Linux allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
nvd
CVE-2017-16548P3CRITICALCVSS 9.8v7.0v8.0+1 more2017-11-06
CVE-2017-16548 [CRITICAL] CWE-125 CVE-2017-16548: The receive_xattr function in xattrs.c in rsync 3.1.2 and 3.1.3-development does not check for a tra
The receive_xattr function in xattrs.c in rsync 3.1.2 and 3.1.3-development does not check for a trailing '\0' character in an xattr name, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact by sending crafted data to the daemon.
nvd
CVE-2021-43539P3HIGHCVSS 8.8v9.0v10.0+1 more2021-12-08
CVE-2021-43539 [HIGH] CWE-416 CVE-2021-43539: Failure to correctly record the location of live pointers across wasm instance calls resulted in a G
Failure to correctly record the location of live pointers across wasm instance calls resulted in a GC occurring within the call not tracing those live pointers. This could have led to a use-after-free causing a potentially exploitable crash. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
nvd
CVE-2018-6094P3HIGHCVSS 8.8v8.0v9.02018-12-04
CVE-2018-6094 [HIGH] CWE-787 CVE-2018-6094: Inline metadata in GarbageCollection in Google Chrome prior to 66.0.3359.117 allowed a remote attack
Inline metadata in GarbageCollection in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd