cbcvebase.

Debian Linux vulnerabilities

9,953 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358

Vulnerabilities

Page 134 of 498
CVE-2015-2155P3HIGHCVSS 7.5v7.0v8.02015-03-24
CVE-2015-2155 [HIGH] CVE-2015-2155: The force printer in tcpdump before 4.7.2 allows remote attackers to cause a denial of service (cras The force printer in tcpdump before 4.7.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.
nvd
CVE-2016-5314P3HIGHCVSS 8.8v8.0v9.02018-03-12
CVE-2016-5314 [HIGH] CWE-787 CVE-2016-5314: Buffer overflow in the PixarLogDecode function in tif_pixarlog.c in LibTIFF 4.0.6 and earlier allows Buffer overflow in the PixarLogDecode function in tif_pixarlog.c in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted TIFF image, as demonstrated by overwriting the vgetparent function pointer with rgb2ycbcr.
nvd
CVE-2022-31778P3HIGHCVSS 7.5v11.02022-08-10
CVE-2022-31778 [HIGH] CWE-20 CVE-2022-31778: Improper Input Validation vulnerability in handling the Transfer-Encoding header of Apache Traffic S Improper Input Validation vulnerability in handling the Transfer-Encoding header of Apache Traffic Server allows an attacker to poison the cache. This issue affects Apache Traffic Server 8.0.0 to 9.0.2.
nvd
CVE-2022-4283P3HIGHCVSS 7.8v11.02022-12-14
CVE-2022-4283 [HIGH] CWE-416 CVE-2022-4283: A vulnerability was found in X.Org. This security flaw occurs because the XkbCopyNames function left A vulnerability was found in X.Org. This security flaw occurs because the XkbCopyNames function left a dangling pointer to freed memory, resulting in out-of-bounds memory access on subsequent XkbGetKbdByName requests.. This issue can lead to local privileges elevation on systems where the X server is running privileged and remote code execution for ssh
nvd
CVE-2024-28130P3HIGHCVSS 7.5v10.02024-04-23
CVE-2024-28130 [HIGH] CWE-704 CVE-2024-28130: An incorrect type conversion vulnerability exists in the DVPSSoftcopyVOI_PList::createFromImage func An incorrect type conversion vulnerability exists in the DVPSSoftcopyVOI_PList::createFromImage functionality of OFFIS DCMTK 3.6.8. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
nvd
CVE-2023-4004P3HIGHCVSS 7.8v10.0v11.0+1 more2023-07-31
CVE-2023-4004 [HIGH] CWE-416 CVE-2023-4004: A use-after-free flaw was found in the Linux kernel's netfilter in the way a user triggers the nft_p A use-after-free flaw was found in the Linux kernel's netfilter in the way a user triggers the nft_pipapo_remove function with the element, without a NFT_SET_EXT_KEY_END. This issue could allow a local user to crash the system or potentially escalate their privileges on the system.
nvd
CVE-2021-29154P3HIGHCVSS 7.8v9.02021-04-08
CVE-2021-29154 [HIGH] CWE-77 CVE-2021-29154: BPF JIT compilers in the Linux kernel through 5.11.12 have incorrect computation of branch displacem BPF JIT compilers in the Linux kernel through 5.11.12 have incorrect computation of branch displacements, allowing them to execute arbitrary code within the kernel context. This affects arch/x86/net/bpf_jit_comp.c and arch/x86/net/bpf_jit_comp32.c.
nvd
CVE-2016-3616P3HIGHCVSS 8.8v8.02017-02-13
CVE-2016-3616 [HIGH] CWE-476 CVE-2016-3616: The cjpeg utility in libjpeg allows remote attackers to cause a denial of service (NULL pointer dere The cjpeg utility in libjpeg allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or execute arbitrary code via a crafted file.
nvd
CVE-2017-14039P3HIGHCVSS 8.8v8.0v9.02017-08-30
CVE-2017-14039 [HIGH] CWE-787 CVE-2017-14039: A heap-based buffer overflow was discovered in the opj_t2_encode_packet function in lib/openjp2/t2.c A heap-based buffer overflow was discovered in the opj_t2_encode_packet function in lib/openjp2/t2.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly unspecified other impact.
nvd
CVE-2020-27815P3HIGHCVSS 7.8v9.0v10.02021-05-26
CVE-2020-27815 [HIGH] CWE-119 CVE-2020-27815: A flaw was found in the JFS filesystem code in the Linux Kernel which allows a local attacker with t A flaw was found in the JFS filesystem code in the Linux Kernel which allows a local attacker with the ability to set extended attributes to panic the system, causing memory corruption or escalating privileges. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
nvd
CVE-2022-41741P3HIGHCVSS 7.8v10.0v11.02022-10-19
CVE-2022-41741 [HIGH] CWE-787 CVE-2022-41741: NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local attacker to corrupt NGINX worker memory, resulting in its termination or potential other impact using a spec
nvd
CVE-2019-7283P3HIGHCVSS 7.4v9.02019-01-31
CVE-2019-7283 [HIGH] CVE-2019-7283: An issue was discovered in rcp in NetKit through 0.17. For an rcp operation, the server chooses whic An issue was discovered in rcp in NetKit through 0.17. For an rcp operation, the server chooses which files/directories are sent to the client. However, the rcp client only performs cursory validation of the object name returned. A malicious rsh server (or Man-in-The-Middle attacker) can overwrite arbitrary files in a directory on the rcp client machine. This i
nvd
CVE-2021-3612P3HIGHCVSS 7.8v9.02021-07-09
CVE-2021-3612 [HIGH] CWE-20 CVE-2021-3612: An out-of-bounds memory write flaw was found in the Linux kernel's joystick devices subsystem in ver An out-of-bounds memory write flaw was found in the Linux kernel's joystick devices subsystem in versions before 5.9-rc1, in the way the user calls ioctl JSIOCSBTNMAP. This flaw allows a local user to crash the system or possibly escalate their privileges on the system. The highest threat from this vulnerability is to confidentiality, integrity, as well
nvd
CVE-2024-22201P3HIGHCVSS 7.5v10.02024-02-26
CVE-2024-22201 [HIGH] CWE-400 CVE-2024-22201: Jetty is a Java based web server and servlet engine. An HTTP/2 SSL connection that is established an Jetty is a Java based web server and servlet engine. An HTTP/2 SSL connection that is established and TCP congested will be leaked when it times out. An attacker can cause many connections to end up in this state, and the server may run out of file descriptors, eventually causing the server to stop accepting new connections from valid clients. The vul
nvd
CVE-2024-0567P3HIGHCVSS 7.5v11.02024-01-16
CVE-2024-0567 [HIGH] CWE-347 CVE-2024-0567: A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a certificate chain with cockpit-certificate-ensure. This flaw allows an unauthenticated, remote client or attacker to initiate a denial of service attack.
nvd
CVE-2014-9765P3HIGHCVSS 8.8v7.0v8.02016-04-19
CVE-2014-9765 [HIGH] CWE-119 CVE-2014-9765: Buffer overflow in the main_get_appheader function in xdelta3-main.h in xdelta3 before 3.0.9 allows Buffer overflow in the main_get_appheader function in xdelta3-main.h in xdelta3 before 3.0.9 allows remote attackers to execute arbitrary code via a crafted input file.
nvd
CVE-2019-0053P3HIGHCVSS 7.8v10.02019-07-11
CVE-2019-0053 [HIGH] CWE-121 CVE-2019-0053: Insufficient validation of environment variables in the telnet client supplied in Junos OS can lead Insufficient validation of environment variables in the telnet client supplied in Junos OS can lead to stack-based buffer overflows, which can be exploited to bypass veriexec restrictions on Junos OS. A stack-based overflow is present in the handling of environment variables when connecting via the telnet client to remote telnet servers. This issue only
nvd
CVE-2020-8086P3CRITICALCVSS 9.8v9.0v10.02020-01-28
CVE-2020-8086 [CRITICAL] CWE-863 CVE-2020-8086: The mod_auth_ldap and mod_auth_ldap2 Community Modules through 2020-01-27 for Prosody incompletely v The mod_auth_ldap and mod_auth_ldap2 Community Modules through 2020-01-27 for Prosody incompletely verify the XMPP address passed to the is_admin() function. This grants remote entities admin-only functionality if their username matches the username of a local admin.
nvd
CVE-2016-3062P3HIGHCVSS 8.8≤ 8.02016-06-16
CVE-2016-3062 [HIGH] CWE-119 CVE-2016-3062: The mov_read_dref function in libavformat/mov.c in Libav before 11.7 and FFmpeg before 0.11 allows r The mov_read_dref function in libavformat/mov.c in Libav before 11.7 and FFmpeg before 0.11 allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via the entries value in a dref box in an MP4 file.
nvd
CVE-2026-4775P3HIGHCVSS 7.8v11.02026-03-24
CVE-2026-4775 [HIGH] CWE-190 CVE-2026-4775: A flaw was found in the libtiff library. A remote attacker could exploit a signed integer overflow v A flaw was found in the libtiff library. A remote attacker could exploit a signed integer overflow vulnerability in the putcontig8bitYCbCr44tile function by providing a specially crafted TIFF file. This flaw can lead to an out-of-bounds heap write due to incorrect memory pointer calculations, potentially causing a denial of service (application crash) o
nvd
Debian Linux vulnerabilities | cvebase