Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 137 of 498
CVE-2018-15518P3HIGHCVSS 8.8v8.0v9.02018-12-26
CVE-2018-15518 [HIGH] CWE-415 CVE-2018-15518: QXmlStream in Qt 5.x before 5.11.3 has a double-free or corruption during parsing of a specially cra
QXmlStream in Qt 5.x before 5.11.3 has a double-free or corruption during parsing of a specially crafted illegal XML document.
nvd
CVE-2020-22015P3HIGHCVSS 8.8v9.0v10.02021-05-26
CVE-2020-22015 [HIGH] CWE-120 CVE-2020-22015: Buffer Overflow vulnerability in FFmpeg 4.2 in mov_write_video_tag due to the out of bounds in libav
Buffer Overflow vulnerability in FFmpeg 4.2 in mov_write_video_tag due to the out of bounds in libavformat/movenc.c, which could let a remote malicious user obtain sensitive information, cause a Denial of Service, or execute arbitrary code.
nvd
CVE-2022-37032P3CRITICALCVSS 9.1v10.0v11.02022-09-19
CVE-2022-37032 [CRITICAL] CWE-125 CVE-2022-37032: An out-of-bounds read in the BGP daemon of FRRouting FRR before 8.4 may lead to a segmentation fault
An out-of-bounds read in the BGP daemon of FRRouting FRR before 8.4 may lead to a segmentation fault and denial of service. This occurs in bgp_capability_msg_parse in bgpd/bgp_packet.c.
nvd
CVE-2018-19296P3HIGHCVSS 8.8v8.0v9.02018-11-16
CVE-2018-19296 [HIGH] CWE-502 CVE-2018-19296: PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack.
PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack.
nvd
CVE-2020-6381P3HIGHCVSS 8.8v9.0v10.02020-02-11
CVE-2020-6381 [HIGH] CWE-190 CVE-2020-6381: Integer overflow in JavaScript in Google Chrome on ChromeOS and Android prior to 80.0.3987.87 allowe
Integer overflow in JavaScript in Google Chrome on ChromeOS and Android prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2017-5029P3HIGHCVSS 8.8v8.0v9.02017-04-24
CVE-2017-5029 [HIGH] CWE-787 CVE-2017-5029: The xsltAddTextString function in transform.c in libxslt 1.1.29, as used in Blink in Google Chrome p
The xsltAddTextString function in transform.c in libxslt 1.1.29, as used in Blink in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android, lacked a check for integer overflow during a size calculation, which allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.
nvd
CVE-2018-16890P3HIGHCVSS 7.5v9.02019-02-06
CVE-2018-16890 [HIGH] CWE-125 CVE-2018-16890: libcurl versions from 7.36.0 to before 7.64.0 is vulnerable to a heap buffer out-of-bounds read. The
libcurl versions from 7.36.0 to before 7.64.0 is vulnerable to a heap buffer out-of-bounds read. The function handling incoming NTLM type-2 messages (`lib/vauth/ntlm.c:ntlm_decode_type2_target`) does not validate incoming data correctly and is subject to an integer overflow vulnerability. Using that overflow, a malicious or broken NTLM server could tr
nvd
CVE-2017-2862P3HIGHCVSS 7.8v8.02017-09-05
CVE-2017-2862 [HIGH] CWE-787 CVE-2017-2862: An exploitable heap overflow vulnerability exists in the gdk_pixbuf__jpeg_image_load_increment funct
An exploitable heap overflow vulnerability exists in the gdk_pixbuf__jpeg_image_load_increment functionality of Gdk-Pixbuf 2.36.6. A specially crafted jpeg file can cause a heap overflow resulting in remote code execution. An attacker can send a file or url to trigger this vulnerability.
nvd
CVE-2017-18123P3HIGHCVSS 8.6v7.02018-02-03
CVE-2017-18123 [HIGH] CWE-20 CVE-2017-18123: The call parameter of /lib/exe/ajax.php in DokuWiki through 2017-02-19e does not properly encode use
The call parameter of /lib/exe/ajax.php in DokuWiki through 2017-02-19e does not properly encode user input, which leads to a reflected file download vulnerability, and allows remote attackers to run arbitrary programs.
nvd
CVE-2015-1283P3MEDIUMCVSS 6.8v7.0v8.0+1 more2015-07-23
CVE-2015-1283 [MEDIUM] CWE-190 CVE-2015-1283: Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google C
Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.2403.89 and other products, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted XML data, a related issue to CVE-2015-2716.
nvd
CVE-2019-17498P3HIGHCVSS 8.1v8.0v9.02019-10-21
CVE-2019-17498 [HIGH] CWE-190 CVE-2019-17498: In libssh2 v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic in packet.c has an integer over
In libssh2 v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic in packet.c has an integer overflow in a bounds check, enabling an attacker to specify an arbitrary (out-of-bounds) offset for a subsequent memory read. A crafted SSH server may be able to disclose sensitive information or cause a denial of service condition on the client system when
nvd
CVE-2018-20004P3HIGHCVSS 8.8v8.02018-12-10
CVE-2018-20004 [HIGH] CWE-787 CVE-2018-20004: An issue has been found in Mini-XML (aka mxml) 2.12. It is a stack-based buffer overflow in mxml_wri
An issue has been found in Mini-XML (aka mxml) 2.12. It is a stack-based buffer overflow in mxml_write_node in mxml-file.c via vectors involving a double-precision floating point number and the '' substring, as demonstrated by testmxml.
nvd
CVE-2020-6455P3HIGHCVSS 8.8v9.0v10.02020-04-13
CVE-2020-6455 [HIGH] CWE-125 CVE-2020-6455: Out of bounds read in WebSQL in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to pot
Out of bounds read in WebSQL in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-6245P3HIGHCVSS 8.8v8.0v9.02019-01-13
CVE-2019-6245 [HIGH] CWE-787 CVE-2019-6245: An issue was discovered in Anti-Grain Geometry (AGG) 2.4 as used in SVG++ (aka svgpp) 1.2.3. In the
An issue was discovered in Anti-Grain Geometry (AGG) 2.4 as used in SVG++ (aka svgpp) 1.2.3. In the function agg::cell_aa::not_equal, dx is assigned to (x2 - x1). If dx >= dx_limit, which is (16384 << poly_subpixel_shift), this function will call itself recursively. There can be a situation where (x2 - x1) is always bigger than dx_limit during the recurs
nvd
CVE-2024-35845P3CRITICALCVSS 9.1v10.02024-05-17
CVE-2024-35845 [CRITICAL] CWE-134 CVE-2024-35845: In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: dbg-tlv: ensure
In the Linux kernel, the following vulnerability has been resolved:
wifi: iwlwifi: dbg-tlv: ensure NUL termination
The iwl_fw_ini_debug_info_tlv is used as a string, so we must
ensure the string is terminated correctly before using it.
nvd
CVE-2008-4058P3HIGHCVSS 7.5v4.02008-09-24
CVE-2008-4058 [HIGH] CWE-264 CVE-2008-4058: The XPConnect component in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before
The XPConnect component in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to "pollute XPCNativeWrappers" and execute arbitrary code with chrome privileges via vectors related to (1) chrome XBL and (2) chrome JS.
nvd
CVE-2020-21598P3HIGHCVSS 8.8v10.0v11.02021-09-16
CVE-2020-21598 [HIGH] CWE-787 CVE-2020-21598: libde265 v1.0.4 contains a heap buffer overflow in the ff_hevc_put_unweighted_pred_8_sse function, w
libde265 v1.0.4 contains a heap buffer overflow in the ff_hevc_put_unweighted_pred_8_sse function, which can be exploited via a crafted a file.
nvd
CVE-2019-5772P3HIGHCVSS 8.8v9.02019-02-19
CVE-2019-5772 [HIGH] CWE-416 CVE-2019-5772: Sharing of objects over calls into JavaScript runtime in PDFium in Google Chrome prior to 72.0.3626.
Sharing of objects over calls into JavaScript runtime in PDFium in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
nvd
CVE-2017-14449P3HIGHCVSS 8.8v8.0v9.02018-04-24
CVE-2017-14449 [HIGH] CWE-415 CVE-2017-14449: A double-Free vulnerability exists in the XCF image rendering functionality of SDL2_image-2.0.2. A s
A double-Free vulnerability exists in the XCF image rendering functionality of SDL2_image-2.0.2. A specially crafted XCF image can cause a Double-Free situation to occur. An attacker can display a specially crafted image to trigger this vulnerability.
nvd
CVE-2018-6141P3HIGHCVSS 8.8v9.02019-01-09
CVE-2018-6141 [HIGH] CWE-125 CVE-2018-6141: Insufficient validation of an image filter in Skia in Google Chrome prior to 67.0.3396.62 allowed a
Insufficient validation of an image filter in Skia in Google Chrome prior to 67.0.3396.62 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory read via a crafted HTML page.
nvd