cbcvebase.

Debian Linux vulnerabilities

9,953 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358

Vulnerabilities

Page 150 of 498
CVE-2019-17675P3HIGHCVSS 8.8v8.0v9.0+1 more2019-10-17
CVE-2019-17675 [HIGH] CWE-352 CVE-2019-17675: WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, possibly leading to CSRF.
nvd
CVE-2012-1972P3CRITICALCVSS 10.0v6.0v7.02012-08-29
CVE-2012-1972 [CRITICAL] CWE-416 CVE-2012-1972: Use-after-free vulnerability in the nsHTMLEditor::CollapseAdjacentTextNodes function in Mozilla Fire Use-after-free vulnerability in the nsHTMLEditor::CollapseAdjacentTextNodes function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspeci
nvd
CVE-2019-10895P3HIGHCVSS 7.5v8.0v9.02019-04-09
CVE-2019-10895 [HIGH] CWE-125 CVE-2019-10895: In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the NetScaler file parser could crash. This In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the NetScaler file parser could crash. This was addressed in wiretap/netscaler.c by improving data validation.
nvd
CVE-2015-2740P3CRITICALCVSS 10.0v7.0v8.02015-07-06
CVE-2015-2740 [CRITICAL] CWE-119 CVE-2015-2740: Buffer overflow in the nsXMLHttpRequest::AppendToResponseText function in Mozilla Firefox before 39. Buffer overflow in the nsXMLHttpRequest::AppendToResponseText function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 might allow remote attackers to cause a denial of service or have unspecified other impact via unknown vectors.
nvd
CVE-2017-14122P3CRITICALCVSS 9.1v9.02017-09-03
CVE-2017-14122 [CRITICAL] CWE-125 CVE-2017-14122: unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a stack-based buffer over-read in unrarlib.c, unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a stack-based buffer over-read in unrarlib.c, related to ExtrFile and stricomp.
nvd
CVE-2019-11810P3HIGHCVSS 7.5v8.02019-05-07
CVE-2019-11810 [HIGH] CWE-416 CVE-2019-11810: An issue was discovered in the Linux kernel before 5.0.7. A NULL pointer dereference can occur when An issue was discovered in the Linux kernel before 5.0.7. A NULL pointer dereference can occur when megasas_create_frame_pool() fails in megasas_alloc_cmds() in drivers/scsi/megaraid/megaraid_sas_base.c. This causes a Denial of Service, related to a use-after-free.
nvd
CVE-2025-62230P3HIGHCVSS 7.3v11.02025-10-30
CVE-2025-62230 [HIGH] CWE-416 CVE-2025-62230: A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resour A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources, leading to a use-after-free condition. This can cause memory corruption or a crash when affected clients disconnect.
nvd
CVE-2017-18266P3HIGHCVSS 8.8v7.0v8.0+1 more2018-05-10
CVE-2017-18266 [HIGH] CWE-74 CVE-2017-18266: The open_envvar function in xdg-open in xdg-utils before 1.1.3 does not validate strings before laun The open_envvar function in xdg-open in xdg-utils before 1.1.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL, as demonstrated by %s in this environment variable.
nvd
CVE-2017-17969P3HIGHCVSS 7.8v7.0v8.0+1 more2018-01-30
CVE-2017-17969 [HIGH] CWE-787 CVE-2017-17969: Heap-based buffer overflow in the NCompress::NShrink::CDecoder::CodeReal method in 7-Zip before 18.0 Heap-based buffer overflow in the NCompress::NShrink::CDecoder::CodeReal method in 7-Zip before 18.00 and p7zip allows remote attackers to cause a denial of service (out-of-bounds write) or potentially execute arbitrary code via a crafted ZIP archive.
nvd
CVE-2014-9157P3HIGHCVSS 7.5v7.0v8.02014-12-03
CVE-2014-9157 [HIGH] CWE-134 CVE-2014-9157: Format string vulnerability in the yyerror function in lib/cgraph/scan.l in Graphviz allows remote a Format string vulnerability in the yyerror function in lib/cgraph/scan.l in Graphviz allows remote attackers to have unspecified impact via format string specifiers in unknown vectors, which are not properly handled in an error string.
nvd
CVE-2016-9843P3CRITICALCVSS 9.8v8.02017-05-23
CVE-2016-9843 [CRITICAL] CVE-2016-9843: The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unsp The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big-endian CRC calculation.
nvd
CVE-2001-1561P4HIGHCVSS 7.2PoCv2.22001-12-31
CVE-2001-1561 [HIGH] CVE-2001-1561: Buffer overflow in Xvt 2.1 in Debian Linux 2.2 allows local users to execute arbitrary code via long Buffer overflow in Xvt 2.1 in Debian Linux 2.2 allows local users to execute arbitrary code via long (1) -name and (2) -T arguments.
nvd
CVE-2019-18678P3MEDIUMCVSS 5.3v8.02019-11-26
CVE-2019-18678 [MEDIUM] CWE-444 CVE-2019-18678: An issue was discovered in Squid 3.x and 4.x through 4.8. It allows attackers to smuggle HTTP reques An issue was discovered in Squid 3.x and 4.x through 4.8. It allows attackers to smuggle HTTP requests through frontend software to a Squid instance that splits the HTTP Request pipeline differently. The resulting Response messages corrupt caches (between a client and Squid) with attacker-controlled content at arbitrary URLs. Effects are isolated to
nvd
CVE-2000-0607P4HIGHCVSS 7.2PoCv2.0v2.1+2 more2000-06-21
CVE-2000-0607 [HIGH] CVE-2000-0607: Buffer overflow in fld program in Kanji on Console (KON) package on Linux may allow local users to g Buffer overflow in fld program in Kanji on Console (KON) package on Linux may allow local users to gain root privileges via an input file containing long CHARSET_REGISTRY or CHARSET_ENCODING settings.
nvd
CVE-2018-21010P3HIGHCVSS 8.8v8.02019-09-05
CVE-2018-21010 [HIGH] CWE-787 CVE-2018-21010: OpenJPEG before 2.3.1 has a heap buffer overflow in color_apply_icc_profile in bin/common/color.c. OpenJPEG before 2.3.1 has a heap buffer overflow in color_apply_icc_profile in bin/common/color.c.
nvd
CVE-2016-1667P3HIGHCVSS 8.8v8.02016-05-14
CVE-2016-1667 [HIGH] CWE-284 CVE-2016-1667: The TreeScope::adoptIfNeeded function in WebKit/Source/core/dom/TreeScope.cpp in the DOM implementat The TreeScope::adoptIfNeeded function in WebKit/Source/core/dom/TreeScope.cpp in the DOM implementation in Blink, as used in Google Chrome before 50.0.2661.102, does not prevent script execution during node-adoption operations, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.
nvd
CVE-2020-11080P3HIGHCVSS 7.5v9.0v10.02020-06-03
CVE-2020-11080 [HIGH] CWE-707 CVE-2020-11080: In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of se In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of concept attack involves a malicious client constructing a SETTINGS frame with a length of 14,400 bytes (2400 individual settings entries) over and over again. The attack causes the CPU to spike at 100%. nghttp2 v1.41.0 fixes this vul
nvd
CVE-2017-1000422P3HIGHCVSS 8.8v7.0v8.0+1 more2018-01-02
CVE-2017-1000422 [HIGH] CWE-190 CVE-2017-1000422: Gnome gdk-pixbuf 2.36.8 and older is vulnerable to several integer overflow in the gif_get_lzw funct Gnome gdk-pixbuf 2.36.8 and older is vulnerable to several integer overflow in the gif_get_lzw function resulting in memory corruption and potential code execution
nvd
CVE-2019-13638P3HIGHCVSS 7.8v8.0v9.0+1 more2019-07-26
CVE-2019-13638 [HIGH] CVE-2019-13638: GNU patch through 2.7.6 is vulnerable to OS shell command injection that can be exploited by opening GNU patch through 2.7.6 is vulnerable to OS shell command injection that can be exploited by opening a crafted patch file that contains an ed style diff payload with shell metacharacters. The ed editor does not need to be present on the vulnerable system. This is different from CVE-2018-1000156.
nvd
CVE-2017-5133P3HIGHCVSS 8.8v8.0v9.02018-02-07
CVE-2017-5133 [HIGH] CWE-787 CVE-2017-5133: Off-by-one read/write on the heap in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote a Off-by-one read/write on the heap in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to corrupt memory and possibly leak information and potentially execute code via a crafted PDF file.
nvd
Debian Linux vulnerabilities | cvebase