cbcvebase.

Debian Linux vulnerabilities

9,953 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358

Vulnerabilities

Page 140 of 498
CVE-2021-38500P3HIGHCVSS 8.8v9.0v10.0+1 more2021-11-03
CVE-2021-38500 [HIGH] CVE-2021-38500: Mozilla developers reported memory safety bugs present in Firefox 92 and Firefox ESR 91.1. Some of t Mozilla developers reported memory safety bugs present in Firefox 92 and Firefox ESR 91.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 78.15, Thunderbird < 91.2, Firefox ESR < 91.2, Firefox ESR < 78.15, and
nvd
CVE-2021-43534P3HIGHCVSS 8.8v9.0v10.0+1 more2021-12-08
CVE-2021-43534 [HIGH] CWE-787 CVE-2021-43534: Mozilla developers and community members reported memory safety bugs present in Firefox 93 and Firef Mozilla developers and community members reported memory safety bugs present in Firefox 93 and Firefox ESR 91.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.
nvd
CVE-2017-7868P3HIGHCVSS 7.5v8.02017-04-14
CVE-2017-7868 [HIGH] CWE-787 CVE-2017-7868: International Components for Unicode (ICU) for C/C++ before 2017-02-13 has an out-of-bounds write ca International Components for Unicode (ICU) for C/C++ before 2017-02-13 has an out-of-bounds write caused by a heap-based buffer overflow related to the utf8TextAccess function in common/utext.cpp and the utext_moveIndex32* function.
nvd
CVE-2020-22035P3HIGHCVSS 8.8v10.02021-06-01
CVE-2020-22035 [HIGH] CWE-787 CVE-2020-22035: A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 in get_block_row at libavfilter/vf_b A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 in get_block_row at libavfilter/vf_bm3d.c, which might lead to memory corruption and other potential consequences.
nvd
CVE-2016-8707P3HIGHCVSS 7.8v8.02016-12-23
CVE-2016-8707 [HIGH] CWE-787 CVE-2016-8707: An exploitable out of bounds write exists in the handling of compressed TIFF images in ImageMagicks' An exploitable out of bounds write exists in the handling of compressed TIFF images in ImageMagicks's convert utility. A crafted TIFF document can lead to an out of bounds write which in particular circumstances could be leveraged into remote code execution. The vulnerability can be triggered through any user controlled TIFF that is handled by this func
nvd
CVE-2020-12823P3CRITICALCVSS 9.8v8.02020-05-12
CVE-2020-12823 [CRITICAL] CWE-120 CVE-2020-12823: OpenConnect 8.09 has a buffer overflow, causing a denial of service (application crash) or possibly OpenConnect 8.09 has a buffer overflow, causing a denial of service (application crash) or possibly unspecified other impact, via crafted certificate data to get_cert_name in gnutls.c.
nvd
CVE-2021-21165P3HIGHCVSS 8.8v10.02021-03-09
CVE-2021-21165 [HIGH] CWE-362 CVE-2021-21165: Data race in audio in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially e Data race in audio in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-21232P3HIGHCVSS 8.8v10.02021-04-30
CVE-2021-21232 [HIGH] CWE-416 CVE-2021-21232: Use after free in Dev Tools in Google Chrome prior to 90.0.4430.93 allowed a remote attacker to pote Use after free in Dev Tools in Google Chrome prior to 90.0.4430.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2023-6859P3HIGHCVSS 8.8v10.0v11.0+1 more2023-12-19
CVE-2023-6859 [HIGH] CWE-416 CVE-2023-6859: A use-after-free condition affected TLS socket creation when under memory pressure. This vulnerabili A use-after-free condition affected TLS socket creation when under memory pressure. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
nvd
CVE-2021-20277P3HIGHCVSS 7.5v9.0v10.02021-05-12
CVE-2021-20277 [HIGH] CWE-125 CVE-2021-20277: A flaw was found in Samba's libldb. Multiple, consecutive leading spaces in an LDAP attribute can le A flaw was found in Samba's libldb. Multiple, consecutive leading spaces in an LDAP attribute can lead to an out-of-bounds memory write, leading to a crash of the LDAP server process handling the request. The highest threat from this vulnerability is to system availability.
nvd
CVE-2020-15987P3HIGHCVSS 8.8v10.02020-11-03
CVE-2020-15987 [HIGH] CWE-416 CVE-2020-15987: Use after free in WebRTC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potenti Use after free in WebRTC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted WebRTC stream.
nvd
CVE-2020-25219P3HIGHCVSS 7.5v9.0v10.02020-09-09
CVE-2020-25219 [HIGH] CWE-674 CVE-2020-25219: url::recvline in url.cpp in libproxy 0.4.x through 0.4.15 allows a remote HTTP server to trigger unc url::recvline in url.cpp in libproxy 0.4.x through 0.4.15 allows a remote HTTP server to trigger uncontrolled recursion via a response composed of an infinite stream that lacks a newline character. This leads to stack exhaustion.
nvd
CVE-2018-10927P3HIGHCVSS 8.1v8.0v9.02018-09-04
CVE-2018-10927 [HIGH] CWE-20 CVE-2018-10927: A flaw was found in RPC request using gfs3_lookup_req in glusterfs server. An authenticated attacker A flaw was found in RPC request using gfs3_lookup_req in glusterfs server. An authenticated attacker could use this flaw to leak information and execute remote denial of service by crashing gluster brick process.
nvd
CVE-2018-1089P3HIGHCVSS 7.5v8.02018-05-09
CVE-2018-1089 [HIGH] CWE-122 CVE-2018-1089: 389-ds-base before versions 1.4.0.9, 1.3.8.1, 1.3.6.15 did not properly handle long search filters w 389-ds-base before versions 1.4.0.9, 1.3.8.1, 1.3.6.15 did not properly handle long search filters with characters needing escapes, possibly leading to buffer overflows. A remote, unauthenticated attacker could potentially use this flaw to make ns-slapd crash via a specially crafted LDAP request, thus resulting in denial of service.
nvd
CVE-2015-8949P3CRITICALCVSS 9.8v8.02016-08-19
CVE-2015-8949 [CRITICAL] CWE-416 CVE-2015-8949: Use-after-free vulnerability in the my_login function in DBD::mysql before 4.033_01 allows attackers Use-after-free vulnerability in the my_login function in DBD::mysql before 4.033_01 allows attackers to have unspecified impact by leveraging a call to mysql_errno after a failure of my_login.
nvd
CVE-2021-38005P3HIGHCVSS 8.8v10.0v11.02021-12-23
CVE-2021-38005 [HIGH] CWE-416 CVE-2021-38005: Use after free in loader in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potenti Use after free in loader in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-38006P3HIGHCVSS 8.8v10.0v11.02021-12-23
CVE-2021-38006 [HIGH] CWE-416 CVE-2021-38006: Use after free in storage foundation in Google Chrome prior to 96.0.4664.45 allowed a remote attacke Use after free in storage foundation in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6539P3HIGHCVSS 8.8v10.02020-09-21
CVE-2020-6539 [HIGH] CWE-416 CVE-2020-6539: Use after free in CSS in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potential Use after free in CSS in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-37997P3HIGHCVSS 8.8v10.0v11.02021-11-23
CVE-2021-37997 [HIGH] CWE-416 CVE-2021-37997: Use after free in Sign-In in Google Chrome prior to 95.0.4638.69 allowed a remote attacker who convi Use after free in Sign-In in Google Chrome prior to 95.0.4638.69 allowed a remote attacker who convinced a user to sign into Chrome to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-37986P3HIGHCVSS 8.8v10.0v11.02021-11-02
CVE-2021-37986 [HIGH] CWE-787 CVE-2021-37986: Heap buffer overflow in Settings in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to Heap buffer overflow in Settings in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to engage with Dev Tools to potentially exploit heap corruption via a crafted HTML page.
nvd
Debian Linux vulnerabilities | cvebase