Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 165 of 498
CVE-2018-11490P3HIGHCVSS 8.8v10.02018-05-26
CVE-2018-11490 [HIGH] CWE-129 CVE-2018-11490: The DGifDecompressLine function in dgif_lib.c in GIFLIB (possibly version 3.0.x), as later shipped i
The DGifDecompressLine function in dgif_lib.c in GIFLIB (possibly version 3.0.x), as later shipped in cgif.c in sam2p 0.49.4, has a heap-based buffer overflow because a certain "Private->RunningCode - 2" array index is not checked. This will lead to a denial of service or possibly unspecified other impact.
nvd
CVE-2015-3148P3MEDIUMCVSS 5.0v7.02015-04-24
CVE-2015-3148 [MEDIUM] CWE-284 CVE-2015-3148: cURL and libcurl 7.10.6 through 7.41.0 do not properly re-use authenticated Negotiate connections, w
cURL and libcurl 7.10.6 through 7.41.0 do not properly re-use authenticated Negotiate connections, which allows remote attackers to connect as other users via a request.
nvd
CVE-2015-3416P3HIGHCVSS 7.5v8.02015-04-24
CVE-2015-3416 [HIGH] CWE-190 CVE-2015-3416: The sqlite3VXPrintf function in printf.c in SQLite before 3.8.9 does not properly handle precision a
The sqlite3VXPrintf function in printf.c in SQLite before 3.8.9 does not properly handle precision and width values during floating-point conversions, which allows context-dependent attackers to cause a denial of service (integer overflow and stack-based buffer overflow) or possibly have unspecified other impact via large integers in a crafted printf fu
nvd
CVE-2019-0201P3MEDIUMCVSS 5.9v8.0v9.02019-05-23
CVE-2019-0201 [MEDIUM] CWE-862 CVE-2019-0201: An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s g
An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command doesn’t check any permission when retrieves the ACLs of the requested node and returns all information contained in the ACL Id field as plaintext string. DigestAuthenticationProvider overloads the Id field with the hash value that is use
nvd
CVE-2017-11173P3HIGHCVSS 8.8v9.02017-07-13
CVE-2017-11173 [HIGH] CVE-2017-11173: Missing anchor in generated regex for rack-cors before 0.4.1 allows a malicious third-party site to
Missing anchor in generated regex for rack-cors before 0.4.1 allows a malicious third-party site to perform CORS requests. If the configuration were intended to allow only the trusted example.com domain name and not the malicious example.net domain name, then example.com.example.net (as well as example.com-example.net) would be inadvertently allowed.
nvd
CVE-2019-10894P3HIGHCVSS 7.5v8.0v9.02019-04-09
CVE-2019-10894 [HIGH] CWE-617 CVE-2019-10894: In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the GSS-API dissector could crash. This was
In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the GSS-API dissector could crash. This was addressed in epan/dissectors/packet-gssapi.c by ensuring that a valid dissector is called.
nvd
CVE-2015-5194P3HIGHCVSS 7.5v7.0v8.02017-07-21
CVE-2015-5194 [HIGH] CWE-20 CVE-2015-5194: The log_config_command function in ntp_parser.y in ntpd in NTP before 4.2.7p42 allows remote attacke
The log_config_command function in ntp_parser.y in ntpd in NTP before 4.2.7p42 allows remote attackers to cause a denial of service (ntpd crash) via crafted logconfig commands.
nvd
CVE-2013-0155P3MEDIUMCVSS 6.4v6.02013-01-13
CVE-2013-0155 [MEDIUM] CWE-264 CVE-2013-0155: Ruby on Rails 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly co
Ruby on Rails 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass intended database-query restrictions and perform NULL checks or trigger missing WHERE clauses via a crafted
nvd
CVE-2012-0920P3HIGHCVSS 7.1v6.0v7.02012-06-05
CVE-2012-0920 [HIGH] CWE-399 CVE-2012-0920: Use-after-free vulnerability in Dropbear SSH Server 0.52 through 2012.54, when command restriction a
Use-after-free vulnerability in Dropbear SSH Server 0.52 through 2012.54, when command restriction and public key authentication are enabled, allows remote authenticated users to execute arbitrary code and bypass command restrictions via multiple crafted command requests, related to "channels concurrency."
nvd
CVE-2005-1796P3HIGHCVSS 7.5v3.0v3.12005-05-31
CVE-2005-1796 [HIGH] CVE-2005-1796: Format string vulnerability in the curses_msg function in the Ncurses interface (ec_curses.c) for Et
Format string vulnerability in the curses_msg function in the Ncurses interface (ec_curses.c) for Ettercap before 0.7.3 allows remote attackers to execute arbitrary code.
nvd
CVE-2016-7551P3HIGHCVSS 7.5v8.02017-04-17
CVE-2016-7551 [HIGH] CWE-399 CVE-2016-7551: chain_sip in Asterisk Open Source 11.x before 11.23.1 and 13.x 13.11.1 and Certified Asterisk 11.6 b
chain_sip in Asterisk Open Source 11.x before 11.23.1 and 13.x 13.11.1 and Certified Asterisk 11.6 before 11.6-cert15 and 13.8 before 13.8-cert3 allows remote attackers to cause a denial of service (port exhaustion).
nvd
CVE-2018-13302P3HIGHCVSS 8.8v9.02018-07-05
CVE-2018-13302 [HIGH] CWE-129 CVE-2018-13302: In FFmpeg 4.0.1, improper handling of frame types (other than EAC3_FRAME_TYPE_INDEPENDENT) that have
In FFmpeg 4.0.1, improper handling of frame types (other than EAC3_FRAME_TYPE_INDEPENDENT) that have multiple independent substreams in the handle_eac3 function in libavformat/movenc.c may trigger an out-of-array access while converting a crafted AVI file to MPEG4, leading to a denial of service or possibly unspecified other impact.
nvd
CVE-2018-20847P3HIGHCVSS 8.8v8.02019-06-26
CVE-2018-20847 [HIGH] CWE-190 CVE-2018-20847: An improper computation of p_tx0, p_tx1, p_ty0 and p_ty1 in the function opj_get_encoding_parameters
An improper computation of p_tx0, p_tx1, p_ty0 and p_ty1 in the function opj_get_encoding_parameters in openjp2/pi.c in OpenJPEG through 2.3.0 can lead to an integer overflow.
nvd
CVE-2019-17540P3HIGHCVSS 8.8v9.0v10.02019-10-14
CVE-2019-17540 [HIGH] CWE-787 CVE-2019-17540: ImageMagick before 7.0.8-54 has a heap-based buffer overflow in ReadPSInfo in coders/ps.c.
ImageMagick before 7.0.8-54 has a heap-based buffer overflow in ReadPSInfo in coders/ps.c.
nvd
CVE-2013-4391P3HIGHCVSS 7.5v7.02013-10-28
CVE-2013-4391 [HIGH] CWE-190 CVE-2013-4391: Integer overflow in the valid_user_field function in journal/journald-native.c in systemd allows rem
Integer overflow in the valid_user_field function in journal/journald-native.c in systemd allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large journal data field, which triggers a heap-based buffer overflow.
nvd
CVE-2017-12601P3HIGHCVSS 8.8v8.0v9.02017-08-07
CVE-2017-12601 [HIGH] CWE-120 CVE-2017-12601: OpenCV (Open Source Computer Vision Library) through 3.3 has a buffer overflow in the cv::BmpDecoder
OpenCV (Open Source Computer Vision Library) through 3.3 has a buffer overflow in the cv::BmpDecoder::readData function in modules/imgcodecs/src/grfmt_bmp.cpp when reading an image file by using cv::imread, as demonstrated by the 4-buf-overflow-readData-memcpy test case.
nvd
CVE-2024-23672P3MEDIUMCVSS 6.3v10.02024-03-13
CVE-2024-23672 [MEDIUM] CWE-459 CVE-2024-23672: Denial of Service via incomplete cleanup vulnerability in Apache Tomcat. It was possible for WebSock
Denial of Service via incomplete cleanup vulnerability in Apache Tomcat. It was possible for WebSocket clients to keep WebSocket connections open leading to increased resource consumption.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M16, from 10.1.0-M1 through 10.1.18, from 9.0.0-M1 through 9.0.85, from 8.5.0 through 8.5.98.
Olde
nvd
CVE-2015-8868P3HIGHCVSS 7.8v8.02016-05-06
CVE-2015-8868 [HIGH] CWE-119 CVE-2015-8868: Heap-based buffer overflow in the ExponentialFunction::ExponentialFunction function in Poppler befor
Heap-based buffer overflow in the ExponentialFunction::ExponentialFunction function in Poppler before 0.40.0 allows remote attackers to cause a denial of service (memory corruption and crash) or possibly execute arbitrary code via an invalid blend mode in the ExtGState dictionary in a crafted PDF document.
nvd
CVE-2016-3698P3HIGHCVSS 8.1v8.02016-06-13
CVE-2016-3698 [HIGH] CWE-284 CVE-2016-3698: libndp before 1.6, as used in NetworkManager, does not properly validate the origin of Neighbor Disc
libndp before 1.6, as used in NetworkManager, does not properly validate the origin of Neighbor Discovery Protocol (NDP) messages, which allows remote attackers to conduct man-in-the-middle attacks or cause a denial of service (network connectivity disruption) by advertising a node as a router from a non-local network.
nvd
CVE-2017-7752P3HIGHCVSS 8.8v8.0v9.02018-06-11
CVE-2017-7752 [HIGH] CWE-416 CVE-2017-7752: A use-after-free vulnerability during specific user interactions with the input method editor (IME)
A use-after-free vulnerability during specific user interactions with the input method editor (IME) in some languages due to how events are handled. This results in a potentially exploitable crash but would require specific user interaction to trigger. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
nvd