Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 155 of 498
CVE-2017-5376P3CRITICALCVSS 9.8v9.02018-06-11
CVE-2017-5376 [CRITICAL] CWE-416 CVE-2017-5376: Use-after-free while manipulating XSL in XSLT documents. This vulnerability affects Thunderbird < 45
Use-after-free while manipulating XSL in XSLT documents. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
nvd
CVE-2018-12390P3CRITICALCVSS 9.8v8.0v9.02019-02-28
CVE-2018-12390 [CRITICAL] CWE-119 CVE-2018-12390: Mozilla developers and community members reported memory safety bugs present in Firefox 62 and Firef
Mozilla developers and community members reported memory safety bugs present in Firefox 62 and Firefox ESR 60.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 6
nvd
CVE-2018-12405P3CRITICALCVSS 9.8v8.0v9.02019-02-28
CVE-2018-12405 [CRITICAL] CWE-119 CVE-2018-12405: Mozilla developers and community members reported memory safety bugs present in Firefox 63 and Firef
Mozilla developers and community members reported memory safety bugs present in Firefox 63 and Firefox ESR 60.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox <
nvd
CVE-2019-7314P3CRITICALCVSS 9.8v8.02019-02-04
CVE-2019-7314 [CRITICAL] CWE-416 CVE-2019-7314: liblivemedia in Live555 before 2019.02.03 mishandles the termination of an RTSP stream after RTP/RTC
liblivemedia in Live555 before 2019.02.03 mishandles the termination of an RTSP stream after RTP/RTCP-over-RTSP has been set up, which could lead to a Use-After-Free error that causes the RTSP server to crash (Segmentation fault) or possibly have unspecified other impact.
nvd
CVE-2018-9261P3HIGHCVSS 7.5v7.0v8.0+1 more2018-04-04
CVE-2018-9261 [HIGH] CWE-834 CVE-2018-9261: In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the NBAP dissector could crash with a large loop th
In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the NBAP dissector could crash with a large loop that ends with a heap-based buffer overflow. This was addressed in epan/dissectors/packet-nbap.c by prohibiting the self-linking of DCH-IDs.
nvd
CVE-2018-20022P3HIGHCVSS 7.5v8.0v9.02018-12-19
CVE-2018-20022 [HIGH] CWE-665 CVE-2018-20022: LibVNC before 2f5b2ad1c6c99b1ac6482c95844a84d66bb52838 contains multiple weaknesses CWE-665: Imprope
LibVNC before 2f5b2ad1c6c99b1ac6482c95844a84d66bb52838 contains multiple weaknesses CWE-665: Improper Initialization vulnerability in VNC client code that allows attacker to read stack memory and can be abuse for information disclosure. Combined with another vulnerability, it can be used to leak stack memory layout and in bypassing ASLR
nvd
CVE-2018-5150P3CRITICALCVSS 9.8v7.0v8.0+1 more2018-06-11
CVE-2018-5150 [CRITICAL] CWE-119 CVE-2018-5150: Memory safety bugs were reported in Firefox 59, Firefox ESR 52.7, and Thunderbird 52.7. Some of thes
Memory safety bugs were reported in Firefox 59, Firefox ESR 52.7, and Thunderbird 52.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8
nvd
CVE-2017-5432P3CRITICALCVSS 9.8v8.02018-06-11
CVE-2017-5432 [CRITICAL] CWE-416 CVE-2017-5432: A use-after-free vulnerability occurs during certain text input selection resulting in a potentially
A use-after-free vulnerability occurs during certain text input selection resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2017-5435P3CRITICALCVSS 9.8v8.02018-06-11
CVE-2017-5435 [CRITICAL] CWE-416 CVE-2017-5435: A use-after-free vulnerability occurs during transaction processing in the editor during design mode
A use-after-free vulnerability occurs during transaction processing in the editor during design mode interactions. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2021-29457P3HIGHCVSS 7.8v9.0v10.02021-04-19
CVE-2021-29457 [HIGH] CWE-122 CVE-2021-29457: Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the me
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A heap buffer overflow was found in Exiv2 versions v0.27.3 and earlier. The heap overflow is triggered when Exiv2 is used to write metadata into a crafted image file. An attacker could potentially exploit the vulnerability to gain
nvd
CVE-2017-5446P3CRITICALCVSS 9.8v9.02018-06-11
CVE-2017-5446 [CRITICAL] CWE-125 CVE-2017-5446: An out-of-bounds read when an HTTP/2 connection to a servers sends "DATA" frames with incorrect data
An out-of-bounds read when an HTTP/2 connection to a servers sends "DATA" frames with incorrect data content. This leads to a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2018-12395P3HIGHCVSS 7.5v8.0v9.02019-02-28
CVE-2018-12395 [HIGH] CVE-2018-12395: By rewriting the Host: request headers using the webRequest API, a WebExtension can bypass domain re
By rewriting the Host: request headers using the webRequest API, a WebExtension can bypass domain restrictions through domain fronting. This would allow access to domains that share a host that are otherwise restricted. This vulnerability affects Firefox ESR < 60.3 and Firefox < 63.
nvd
CVE-2018-5099P3CRITICALCVSS 9.8v7.0v8.0+1 more2018-06-11
CVE-2018-5099 [CRITICAL] CWE-416 CVE-2018-5099: A use-after-free vulnerability can occur when the widget listener is holding strong references to br
A use-after-free vulnerability can occur when the widget listener is holding strong references to browser objects that have previously been freed, resulting in a potentially exploitable crash when these references are used. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.
nvd
CVE-2018-5103P3CRITICALCVSS 9.8v7.0v8.0+1 more2018-06-11
CVE-2018-5103 [CRITICAL] CWE-416 CVE-2018-5103: A use-after-free vulnerability can occur during mouse event handling due to issues with multiprocess
A use-after-free vulnerability can occur during mouse event handling due to issues with multiprocess support. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.
nvd
CVE-2021-21177P3MEDIUMCVSS 6.5v10.02021-03-09
CVE-2021-21177 [MEDIUM] CWE-732 CVE-2021-21177: Insufficient policy enforcement in Autofill in Google Chrome prior to 89.0.4389.72 allowed a remote
Insufficient policy enforcement in Autofill in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2017-5441P3CRITICALCVSS 9.8v9.02018-06-11
CVE-2017-5441 [CRITICAL] CWE-416 CVE-2017-5441: A use-after-free vulnerability when holding a selection during scroll events. This results in a pote
A use-after-free vulnerability when holding a selection during scroll events. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2022-27782P3HIGHCVSS 7.5v10.0v11.02022-06-02
CVE-2022-27782 [HIGH] CWE-840 CVE-2022-27782: libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been ch
libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse if one of them matches the setup. However, several TLS andSSH settings were left out from the configuration match che
nvd
CVE-2022-29248P3HIGHCVSS 8.1v11.02022-05-25
CVE-2022-29248 [HIGH] CWE-200 CVE-2022-29248: Guzzle is a PHP HTTP client. Guzzle prior to versions 6.5.6 and 7.4.3 contains a vulnerability with
Guzzle is a PHP HTTP client. Guzzle prior to versions 6.5.6 and 7.4.3 contains a vulnerability with the cookie middleware. The vulnerability is that it is not checked if the cookie domain equals the domain of the server which sets the cookie via the Set-Cookie header, allowing a malicious server to set cookies for unrelated domains. The cookie middlewa
nvd
CVE-2018-5148P3CRITICALCVSS 9.8v7.0v8.0+1 more2018-06-11
CVE-2018-5148 [CRITICAL] CWE-416 CVE-2018-5148: A use-after-free vulnerability can occur in the compositor during certain graphics operations when a
A use-after-free vulnerability can occur in the compositor during certain graphics operations when a raw pointer is used instead of a reference counted one. This results in a potentially exploitable crash. This vulnerability affects Firefox ESR < 52.7.3 and Firefox < 59.0.2.
nvd
CVE-2019-16163P3HIGHCVSS 7.5v8.02019-09-09
CVE-2019-16163 [HIGH] CWE-674 CVE-2019-16163: Oniguruma before 6.9.3 allows Stack Exhaustion in regcomp.c because of recursion in regparse.c.
Oniguruma before 6.9.3 allows Stack Exhaustion in regcomp.c because of recursion in regparse.c.
nvd