cbcvebase.

Debian Linux vulnerabilities

9,953 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358

Vulnerabilities

Page 157 of 498
CVE-2021-42097P3HIGHCVSS 8.0v10.02021-10-21
CVE-2021-42097 [HIGH] CWE-352 CVE-2021-42097: GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrf_token value is not specific GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrf_token value is not specific to a single user account. An attacker can obtain a value within the context of an unprivileged user account, and then use that value in a CSRF attack against an admin (e.g., for account takeover).
nvd
CVE-2019-3839P3HIGHCVSS 7.8v8.0v9.02019-05-16
CVE-2019-3839 [HIGH] CWE-648 CVE-2019-3839: It was found that in ghostscript some privileged operators remained accessible from various places a It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER. Ghostscript versions before 9.27 are vulnerable.
nvd
CVE-2023-23583P3HIGHCVSS 7.8v11.0v12.02023-11-14
CVE-2023-23583 [HIGH] CWE-1281 CVE-2023-23583: Sequence of processor instructions leads to unexpected behavior for some Intel(R) Processors may all Sequence of processor instructions leads to unexpected behavior for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege and/or information disclosure and/or denial of service via local access.
nvd
CVE-2017-7802P3CRITICALCVSS 9.8v8.0v9.02018-06-11
CVE-2017-7802 [CRITICAL] CWE-416 CVE-2017-7802: A use-after-free vulnerability can occur when manipulating the DOM during the resize event of an ima A use-after-free vulnerability can occur when manipulating the DOM during the resize event of an image element. If these elements have been freed due to a lack of strong references, a potentially exploitable crash may occur when the freed elements are accessed. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
nvd
CVE-2019-19950P3CRITICALCVSS 9.8v8.0v9.0+1 more2019-12-24
CVE-2019-19950 [CRITICAL] CWE-416 CVE-2019-19950: In GraphicsMagick 1.4 snapshot-20190403 Q8, there is a use-after-free in ThrowException and ThrowLog In GraphicsMagick 1.4 snapshot-20190403 Q8, there is a use-after-free in ThrowException and ThrowLoggedException of magick/error.c.
nvd
CVE-2017-11139P3CRITICALCVSS 9.8v9.02017-07-10
CVE-2017-11139 [CRITICAL] CWE-415 CVE-2017-11139: GraphicsMagick 1.3.26 has double free vulnerabilities in the ReadOneJNGImage() function in coders/pn GraphicsMagick 1.3.26 has double free vulnerabilities in the ReadOneJNGImage() function in coders/png.c.
nvd
CVE-2018-0496P3HIGHCVSS 7.5v8.02018-06-12
CVE-2018-0496 [HIGH] CWE-22 CVE-2018-0496: Directory traversal issues in the D-Mod extractor in DFArc and DFArc2 (as well as in RTsoft's Dink S Directory traversal issues in the D-Mod extractor in DFArc and DFArc2 (as well as in RTsoft's Dink Smallwood HD / ProtonSDK version) before 3.14 allow an attacker to overwrite arbitrary files on the user's system.
nvd
CVE-2018-5205P3HIGHCVSS 7.5v9.02018-01-06
CVE-2018-5205 [HIGH] CWE-134 CVE-2018-5205: When using incomplete escape codes, Irssi before 1.0.6 may access data beyond the end of the string. When using incomplete escape codes, Irssi before 1.0.6 may access data beyond the end of the string.
nvd
CVE-2017-5442P3CRITICALCVSS 9.8v9.02018-06-11
CVE-2017-5442 [CRITICAL] CWE-416 CVE-2017-5442: A use-after-free vulnerability during changes in style when manipulating DOM elements. This results A use-after-free vulnerability during changes in style when manipulating DOM elements. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2017-5472P3CRITICALCVSS 9.8v8.0v9.02018-06-11
CVE-2017-5472 [CRITICAL] CWE-416 CVE-2017-5472: A use-after-free vulnerability with the frameloader during tree reconstruction while regenerating CS A use-after-free vulnerability with the frameloader during tree reconstruction while regenerating CSS layout when attempting to use a node in the tree that no longer exists. This results in a potentially exploitable crash. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
nvd
CVE-2017-7756P3CRITICALCVSS 9.8v8.0v9.02018-06-11
CVE-2017-7756 [CRITICAL] CWE-416 CVE-2017-7756: A use-after-free and use-after-scope vulnerability when logging errors from headers for XML HTTP Req A use-after-free and use-after-scope vulnerability when logging errors from headers for XML HTTP Requests (XHR). This could result in a potentially exploitable crash. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
nvd
CVE-2022-3140P3MEDIUMCVSS 6.3v11.02022-10-11
CVE-2022-3140 [MEDIUM] CWE-20 CVE-2022-3140: LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePo LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In the affected versions of LibreOffice links using that scheme could be constructed to call internal macros with arbitrary arguments. Which when clicked on, or
nvd
CVE-2019-17545P3CRITICALCVSS 9.8v8.0v9.0+1 more2019-10-14
CVE-2019-17545 [CRITICAL] CWE-415 CVE-2019-17545: GDAL through 3.0.1 has a poolDestroy double free in OGRExpatRealloc in ogr/ogr_expat.cpp when the 10 GDAL through 3.0.1 has a poolDestroy double free in OGRExpatRealloc in ogr/ogr_expat.cpp when the 10MB threshold is exceeded.
nvd
CVE-2021-39240P3HIGHCVSS 7.5v11.02021-08-17
CVE-2021-39240 [HIGH] CVE-2021-39240: An issue was discovered in HAProxy 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3. It do An issue was discovered in HAProxy 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3. It does not ensure that the scheme and path portions of a URI have the expected characters. For example, the authority field (as observed on a target HTTP/2 server) might differ from what the routing rules were intended to achieve.
nvd
CVE-2021-20309P3HIGHCVSS 7.5v9.02021-05-11
CVE-2021-20309 [HIGH] CWE-369 CVE-2021-20309: A flaw was found in ImageMagick in versions before 7.0.11 and before 6.9.12, where a division by zer A flaw was found in ImageMagick in versions before 7.0.11 and before 6.9.12, where a division by zero in WaveImage() of MagickCore/visual-effects.c may trigger undefined behavior via a crafted image file submitted to an application using ImageMagick. The highest threat from this vulnerability is to system availability.
nvd
CVE-2016-0763P3MEDIUMCVSS 6.3v7.0v8.02016-02-25
CVE-2016-0763 [MEDIUM] CWE-264 CVE-2016-0763: The setGlobalContext method in org/apache/naming/factory/ResourceLinkFactory.java in Apache Tomcat 7 The setGlobalContext method in org/apache/naming/factory/ResourceLinkFactory.java in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M3 does not consider whether ResourceLinkFactory.setGlobalContext callers are authorized, which allows remote authenticated users to bypass intended SecurityManager restrictions and read or write
nvd
CVE-2022-30293P3HIGHCVSS 7.5v10.0v11.02022-05-06
CVE-2022-30293 [HIGH] CWE-787 CVE-2022-30293: In WebKitGTK through 2.36.0 (and WPE WebKit), there is a heap-based buffer overflow in WebCore::Text In WebKitGTK through 2.36.0 (and WPE WebKit), there is a heap-based buffer overflow in WebCore::TextureMapperLayer::setContentsLayer in WebCore/platform/graphics/texmap/TextureMapperLayer.cpp.
nvd
CVE-2023-22795P3HIGHCVSS 7.5v11.02023-02-09
CVE-2023-22795 [HIGH] CWE-400 CVE-2023-22795: A regular expression based DoS vulnerability in Action Dispatch <6.1.7.1 and <7.0.4.1 related to the A regular expression based DoS vulnerability in Action Dispatch <6.1.7.1 and <7.0.4.1 related to the If-None-Match header. A specially crafted HTTP If-None-Match header can cause the regular expression engine to enter a state of catastrophic backtracking, when on a version of Ruby below 3.2.0. This can cause the process to use large amounts of CPU and
nvd
CVE-2022-27386P3HIGHCVSS 7.5v10.02022-04-12
CVE-2022-27386 [HIGH] CWE-89 CVE-2022-27386: MariaDB Server v10.7 and below was discovered to contain a segmentation fault via the component sql/ MariaDB Server v10.7 and below was discovered to contain a segmentation fault via the component sql/sql_class.cc.
nvd
CVE-2013-1910P3CRITICALCVSS 9.8v8.0v9.0+1 more2019-10-31
CVE-2013-1910 [CRITICAL] CWE-20 CVE-2013-1910: yum does not properly handle bad metadata, which allows an attacker to cause a denial of service and yum does not properly handle bad metadata, which allows an attacker to cause a denial of service and possibly have other unspecified impact via a Trojan horse file in the metadata of a remote repository.
nvd
Debian Linux vulnerabilities | cvebase