cbcvebase.

Debian Linux vulnerabilities

9,953 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358

Vulnerabilities

Page 149 of 498
CVE-2023-39946P3HIGHCVSS 7.5v11.0v12.02023-08-11
CVE-2023-39946 [HIGH] CWE-122 CVE-2023-39946: eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Ma eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.11.1, 2.10.2, 2.9.2, and 2.6.6, heap can be overflowed by providing a PID_PROPERTY_LIST parameter that contains a CDR string with length larger than the size of actual content. In `eprosima::fastdds::dds::ParameterPro
nvd
CVE-2014-6052P3HIGHCVSS 7.5v7.02014-12-15
CVE-2014-6052 [HIGH] CWE-20 CVE-2014-6052: The HandleRFBServerMessage function in libvncclient/rfbproto.c in LibVNCServer 0.9.9 and earlier doe The HandleRFBServerMessage function in libvncclient/rfbproto.c in LibVNCServer 0.9.9 and earlier does not check certain malloc return values, which allows remote VNC servers to cause a denial of service (application crash) or possibly execute arbitrary code by specifying a large screen size in a (1) FramebufferUpdate, (2) ResizeFrameBuffer, or (3) PalmVN
nvd
CVE-2020-11111P3HIGHCVSS 8.8v8.02020-03-31
CVE-2020-11111 [HIGH] CWE-502 CVE-2020-11111: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadg FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms).
nvd
CVE-2018-17472P3CRITICALCVSS 9.6v9.02018-11-14
CVE-2018-17472 [CRITICAL] CWE-20 CVE-2018-17472: Incorrect handling of googlechrome:// URL scheme on iOS in Intents in Google Chrome prior to 70.0.35 Incorrect handling of googlechrome:// URL scheme on iOS in Intents in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to escape the sandbox via a crafted HTML page.
nvd
CVE-2021-25633P3HIGHCVSS 7.5v11.02021-10-11
CVE-2021-25633 [HIGH] CWE-295 CVE-2021-25633: LibreOffice supports digital signatures of ODF documents and macros within documents, presenting vis LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to create a digitally signed ODF document, by manipulating t
nvd
CVE-2012-0031P4MEDIUMCVSS 4.6PoCv5.0v6.0+1 more2012-01-18
CVE-2012-0031 [MEDIUM] CVE-2012-0031: scoreboard.c in the Apache HTTP Server 2.2.21 and earlier might allow local users to cause a denial scoreboard.c in the Apache HTTP Server 2.2.21 and earlier might allow local users to cause a denial of service (daemon crash during shutdown) or possibly have unspecified other impact by modifying a certain type field within a scoreboard shared memory segment, leading to an invalid call to the free function.
nvd
CVE-2017-9066P3HIGHCVSS 8.6v8.0v9.02017-05-18
CVE-2017-9066 [HIGH] CWE-918 CVE-2017-9066: In WordPress before 4.7.5, there is insufficient redirect validation in the HTTP class, leading to S In WordPress before 4.7.5, there is insufficient redirect validation in the HTTP class, leading to SSRF.
nvd
CVE-2016-9066P3HIGHCVSS 7.5v8.02018-06-11
CVE-2016-9066 [HIGH] CWE-119 CVE-2016-9066: A buffer overflow resulting in a potentially exploitable crash due to memory allocation issues when A buffer overflow resulting in a potentially exploitable crash due to memory allocation issues when handling large amounts of incoming data. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.
nvd
CVE-2007-0454P3HIGHCVSS 7.5v3.0v3.12007-02-06
CVE-2007-0454 [HIGH] CWE-134 CVE-2007-0454: Format string vulnerability in the afsacl.so VFS module in Samba 3.0.6 through 3.0.23d allows contex Format string vulnerability in the afsacl.so VFS module in Samba 3.0.6 through 3.0.23d allows context-dependent attackers to execute arbitrary code via format string specifiers in a filename on an AFS file system, which is not properly handled during Windows ACL mapping.
nvd
CVE-2019-20907P3HIGHCVSS 7.5v9.02020-07-13
CVE-2019-20907 [HIGH] CWE-835 CVE-2019-20907: In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation.
nvd
CVE-2019-7577P3HIGHCVSS 8.8v8.0v9.02019-02-07
CVE-2019-7577 [HIGH] CWE-125 CVE-2019-7577: SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer over-read in SDL_Lo SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer over-read in SDL_LoadWAV_RW in audio/SDL_wave.c.
nvd
CVE-2019-7573P3HIGHCVSS 8.8v8.0v9.02019-02-07
CVE-2019-7573 [HIGH] CWE-125 CVE-2019-7573: SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-rea SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c (inside the wNumCoef loop).
nvd
CVE-2020-12673P3HIGHCVSS 7.5v9.0v10.02020-08-12
CVE-2020-12673 [HIGH] CWE-125 CVE-2020-12673: In Dovecot before 2.3.11.3, sending a specially formatted NTLM request will crash the auth service b In Dovecot before 2.3.11.3, sending a specially formatted NTLM request will crash the auth service because of an out-of-bounds read.
nvd
CVE-2018-17958P3HIGHCVSS 7.5v8.0v9.02018-10-09
CVE-2018-17958 [HIGH] CWE-190 CVE-2018-17958: Qemu has a Buffer Overflow in rtl8139_do_receive in hw/net/rtl8139.c because an incorrect integer da Qemu has a Buffer Overflow in rtl8139_do_receive in hw/net/rtl8139.c because an incorrect integer data type is used.
nvd
CVE-2007-6415P3HIGHCVSS 8.5v3.1v4.02008-01-25
CVE-2007-6415 [HIGH] CWE-94 CVE-2007-6415: scponly 4.6 and earlier allows remote authenticated users to bypass intended restrictions and execut scponly 4.6 and earlier allows remote authenticated users to bypass intended restrictions and execute arbitrary code by invoking scp, as implemented by OpenSSH, with the -F and -o options.
nvd
CVE-2020-6062P3HIGHCVSS 7.5v9.0v10.02020-02-19
CVE-2020-6062 [HIGH] CWE-476 CVE-2020-6062: An exploitable denial-of-service vulnerability exists in the way CoTURN 4.5.1.1 web server parses PO An exploitable denial-of-service vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to server crash and denial of service. An attacker needs to send an HTTP request to trigger this vulnerability.
nvd
CVE-2021-33293P3CRITICALCVSS 9.1v9.02022-03-10
CVE-2021-33293 [CRITICAL] CWE-125 CVE-2021-33293: Panorama Tools libpano13 v2.9.20 was discovered to contain an out-of-bounds read in the function pan Panorama Tools libpano13 v2.9.20 was discovered to contain an out-of-bounds read in the function panoParserFindOLine() in parser.c.
nvd
CVE-2018-16842P3CRITICALCVSS 9.1v8.0v9.02018-10-31
CVE-2018-16842 [CRITICAL] CWE-125 CVE-2018-16842: Curl versions 7.14.1 through 7.61.1 are vulnerable to a heap-based buffer over-read in the tool_msgs Curl versions 7.14.1 through 7.61.1 are vulnerable to a heap-based buffer over-read in the tool_msgs.c:voutf() function that may result in information exposure and denial of service.
nvd
CVE-2017-9469P3HIGHCVSS 7.5v8.0v9.02017-06-07
CVE-2017-9469 [HIGH] CWE-119 CVE-2017-9469: In Irssi before 1.0.3, when receiving certain incorrectly quoted DCC files, it tries to find the ter In Irssi before 1.0.3, when receiving certain incorrectly quoted DCC files, it tries to find the terminating quote one byte before the allocated memory. Thus, remote attackers might be able to cause a crash.
nvd
CVE-2019-6486P3HIGHCVSS 8.2v8.0v9.02019-01-24
CVE-2019-6486 [HIGH] CWE-770 CVE-2019-6486: Go before 1.10.8 and 1.11.x before 1.11.5 mishandles P-521 and P-384 elliptic curves, which allows a Go before 1.10.8 and 1.11.x before 1.11.5 mishandles P-521 and P-384 elliptic curves, which allows attackers to cause a denial of service (CPU consumption) or possibly conduct ECDH private key recovery attacks.
nvd
Debian Linux vulnerabilities | cvebase