Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 143 of 498
CVE-2017-7784P3CRITICALCVSS 9.8v8.0v9.02018-06-11
CVE-2017-7784 [CRITICAL] CWE-416 CVE-2017-7784: A use-after-free vulnerability can occur when reading an image observer during frame reconstruction
A use-after-free vulnerability can occur when reading an image observer during frame reconstruction after the observer has been freed. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
nvd
CVE-2016-9898P3CRITICALCVSS 9.8v9.02018-06-11
CVE-2016-9898 [CRITICAL] CWE-416 CVE-2016-9898: Use-after-free resulting in potentially exploitable crash when manipulating DOM subtrees in the Edit
Use-after-free resulting in potentially exploitable crash when manipulating DOM subtrees in the Editor. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
nvd
CVE-2022-40674P3HIGHCVSS 8.1v10.0v11.02022-09-14
CVE-2022-40674 [HIGH] CWE-416 CVE-2022-40674: libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.
libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.
nvd
CVE-2021-42717P3HIGHCVSS 7.5v9.0v10.0+1 more2021-12-07
CVE-2021-42717 [HIGH] CWE-674 CVE-2021-42717: ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects with
ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects with nesting tens-of-thousands deep could result in the web server being unable to service legitimate requests. Even a moderately large (e.g., 300KB) HTTP request can occupy one of the limited NGINX worker processes for minutes and consume almost all of the a
nvd
CVE-2020-3481P3HIGHCVSS 7.5v9.02020-07-20
CVE-2020-3481 [HIGH] CWE-476 CVE-2020-3481: A vulnerability in the EGG archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.102
A vulnerability in the EGG archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.102.0 - 0.102.3 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to a null pointer dereference. An attacker could exploit this vulnerability by sending a crafted EGG file t
nvd
CVE-2017-5429P3CRITICALCVSS 9.8v8.02018-06-11
CVE-2017-5429 [CRITICAL] CWE-119 CVE-2017-5429: Memory safety bugs were reported in Firefox 52, Firefox ESR 45.8, Firefox ESR 52, and Thunderbird 52
Memory safety bugs were reported in Firefox 52, Firefox ESR 45.8, Firefox ESR 52, and Thunderbird 52. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Fi
nvd
CVE-2020-15598P3HIGHCVSS 7.5v10.02020-10-06
CVE-2020-15598 [HIGH] CWE-835 CVE-2020-15598: Trustwave ModSecurity 3.x through 3.0.4 allows denial of service via a special request. NOTE: The di
Trustwave ModSecurity 3.x through 3.0.4 allows denial of service via a special request. NOTE: The discoverer reports "Trustwave has signaled they are disputing our claims." The CVE suggests that there is a security issue with how ModSecurity handles regular expressions that can result in a Denial of Service condition. The vendor does not consider this
nvd
CVE-2019-16159P3HIGHCVSS 7.5v10.02019-09-09
CVE-2019-16159 [HIGH] CWE-787 CVE-2019-16159: BIRD Internet Routing Daemon 1.6.x through 1.6.7 and 2.x through 2.0.5 has a stack-based buffer over
BIRD Internet Routing Daemon 1.6.x through 1.6.7 and 2.x through 2.0.5 has a stack-based buffer overflow. The BGP daemon's support for RFC 8203 administrative shutdown communication messages included an incorrect logical expression when checking the validity of an input message. Sending a shutdown communication with a sufficient message length causes
nvd
CVE-2018-12378P3CRITICALCVSS 9.8v8.0v9.02018-10-18
CVE-2018-12378 [CRITICAL] CWE-416 CVE-2018-12378: A use-after-free vulnerability can occur when an IndexedDB index is deleted while still in use by Ja
A use-after-free vulnerability can occur when an IndexedDB index is deleted while still in use by JavaScript code that is providing payload values to be stored. This results in a potentially exploitable crash. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.
nvd
CVE-2018-12377P3CRITICALCVSS 9.8v8.0v9.02018-10-18
CVE-2018-12377 [CRITICAL] CWE-416 CVE-2018-12377: A use-after-free vulnerability can occur when refresh driver timers are refreshed in some circumstan
A use-after-free vulnerability can occur when refresh driver timers are refreshed in some circumstances during shutdown when the timer is deleted while still in use. This results in a potentially exploitable crash. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.
nvd
CVE-2017-17499P3CRITICALCVSS 9.8v9.02017-12-11
CVE-2017-17499 [CRITICAL] CWE-416 CVE-2017-17499: ImageMagick before 6.9.9-24 and 7.x before 7.0.7-12 has a use-after-free in Magick::Image::read in M
ImageMagick before 6.9.9-24 and 7.x before 7.0.7-12 has a use-after-free in Magick::Image::read in Magick++/lib/Image.cpp.
nvd
CVE-2021-42388P3HIGHCVSS 8.1v10.02022-03-14
CVE-2021-42388 [HIGH] CWE-125 CVE-2021-42388: Heap out-of-bounds read in Clickhouse's LZ4 compression codec when parsing a malicious query. As par
Heap out-of-bounds read in Clickhouse's LZ4 compression codec when parsing a malicious query. As part of the LZ4::decompressImpl() loop, a 16-bit unsigned user-supplied value ('offset') is read from the compressed data. The offset is later used in the length of a copy operation, without checking the lower bounds of the source of the copy operation.
nvd
CVE-2021-42387P3HIGHCVSS 8.1v10.02022-03-14
CVE-2021-42387 [HIGH] CWE-125 CVE-2021-42387: Heap out-of-bounds read in Clickhouse's LZ4 compression codec when parsing a malicious query. As par
Heap out-of-bounds read in Clickhouse's LZ4 compression codec when parsing a malicious query. As part of the LZ4::decompressImpl() loop, a 16-bit unsigned user-supplied value ('offset') is read from the compressed data. The offset is later used in the length of a copy operation, without checking the upper bounds of the source of the copy operation.
nvd
CVE-2014-9746P3CRITICALCVSS 9.8v7.0v8.02016-06-07
CVE-2014-9746 [CRITICAL] CWE-20 CVE-2014-9746: The (1) t1_parse_font_matrix function in type1/t1load.c, (2) cid_parse_font_matrix function in cid/c
The (1) t1_parse_font_matrix function in type1/t1load.c, (2) cid_parse_font_matrix function in cid/cidload.c, (3) t42_parse_font_matrix function in type42/t42parse.c, and (4) ps_parser_load_field function in psaux/psobjs.c in FreeType before 2.5.4 do not check return values, which allows remote attackers to cause a denial of service (uninitialized me
nvd
CVE-2017-13687P3CRITICALCVSS 9.8v8.0v9.0+1 more2017-09-14
CVE-2017-13687 [CRITICAL] CWE-125 CVE-2017-13687: The Cisco HDLC parser in tcpdump before 4.9.2 has a buffer over-read in print-chdlc.c:chdlc_print().
The Cisco HDLC parser in tcpdump before 4.9.2 has a buffer over-read in print-chdlc.c:chdlc_print().
nvd
CVE-2017-7792P3CRITICALCVSS 9.8v8.0v9.02018-06-11
CVE-2017-7792 [CRITICAL] CWE-119 CVE-2017-7792: A buffer overflow will occur when viewing a certificate in the certificate manager if the certificat
A buffer overflow will occur when viewing a certificate in the certificate manager if the certificate has an extremely long object identifier (OID). This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
nvd
CVE-2023-31122P3HIGHCVSS 7.5v10.02023-10-23
CVE-2023-31122 [HIGH] CWE-125 CVE-2023-31122: Out-of-bounds Read vulnerability in mod_macro of Apache HTTP Server.This issue affects Apache HTTP S
Out-of-bounds Read vulnerability in mod_macro of Apache HTTP Server.This issue affects Apache HTTP Server: through 2.4.57.
nvd
CVE-2017-5380P3CRITICALCVSS 9.8v9.02018-06-11
CVE-2017-5380 [CRITICAL] CWE-416 CVE-2017-5380: A potential use-after-free found through fuzzing during DOM manipulation of SVG content. This vulner
A potential use-after-free found through fuzzing during DOM manipulation of SVG content. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
nvd
CVE-2020-12066P3HIGHCVSS 7.5v10.02020-04-22
CVE-2020-12066 [HIGH] CWE-20 CVE-2020-12066: CServer::SendMsg in engine/server/server.cpp in Teeworlds 0.7.x before 0.7.5 allows remote attackers
CServer::SendMsg in engine/server/server.cpp in Teeworlds 0.7.x before 0.7.5 allows remote attackers to shut down the server.
nvd
CVE-2019-15681P3HIGHCVSS 7.5v8.0v9.02019-10-29
CVE-2019-15681 [HIGH] CWE-665 CVE-2019-15681: LibVNC commit before d01e1bb4246323ba6fcee3b82ef1faa9b1dac82a contains a memory leak (CWE-655) in VN
LibVNC commit before d01e1bb4246323ba6fcee3b82ef1faa9b1dac82a contains a memory leak (CWE-655) in VNC server code, which allow an attacker to read stack memory and can be abused for information disclosure. Combined with another vulnerability, it can be used to leak stack memory and bypass ASLR. This attack appear to be exploitable via network connecti
nvd