cbcvebase.

Debian Linux vulnerabilities

9,953 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358

Vulnerabilities

Page 166 of 498
CVE-2018-1301P3MEDIUMCVSS 5.9v7.0v8.0+1 more2018-03-26
CVE-2018-1301 [MEDIUM] CWE-119 CVE-2018-1301: A specially crafted request could have crashed the Apache HTTP Server prior to version 2.4.30, due t A specially crafted request could have crashed the Apache HTTP Server prior to version 2.4.30, due to an out of bound access after a size limit is reached by reading the HTTP header. This vulnerability is considered very hard if not impossible to trigger in non-debug mode (both log and build level), so it is classified as low risk for common server us
nvd
CVE-2017-7846P3HIGHCVSS 8.8v7.0v8.0+1 more2018-06-11
CVE-2017-7846 [HIGH] CWE-74 CVE-2017-7846: It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e. It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e.g. via "View -> Feed article -> Website" or in the standard format of "View -> Feed article -> default format". This vulnerability affects Thunderbird < 52.5.2.
nvd
CVE-2014-1477P3CRITICALCVSS 9.8v7.02014-02-06
CVE-2014-1477 [CRITICAL] CVE-2014-1477: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 27.0, Firefox E Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2018-5802P3HIGHCVSS 8.8v8.02018-12-07
CVE-2018-5802 [HIGH] CWE-125 CVE-2018-5802: An error within the "kodak_radc_load_raw()" function (internal/dcraw_common.cpp) related to the "buf An error within the "kodak_radc_load_raw()" function (internal/dcraw_common.cpp) related to the "buf" variable in LibRaw versions prior to 0.18.7 can be exploited to cause an out-of-bounds read memory access and subsequently cause a crash.
nvd
CVE-2017-12604P3HIGHCVSS 8.8v8.0v9.02017-08-07
CVE-2017-12604 [HIGH] CWE-787 CVE-2017-12604: OpenCV (Open Source Computer Vision Library) through 3.3 has an out-of-bounds write error in the Fil OpenCV (Open Source Computer Vision Library) through 3.3 has an out-of-bounds write error in the FillUniColor function in utils.cpp when reading an image file by using cv::imread.
nvd
CVE-2017-12606P3HIGHCVSS 8.8v8.0v9.02017-08-07
CVE-2017-12606 [HIGH] CWE-787 CVE-2017-12606: OpenCV (Open Source Computer Vision Library) through 3.3 has an out-of-bounds write error in the fun OpenCV (Open Source Computer Vision Library) through 3.3 has an out-of-bounds write error in the function FillColorRow4 in utils.cpp when reading an image file by using cv::imread.
nvd
CVE-2017-12605P3HIGHCVSS 8.8v8.0v9.02017-08-07
CVE-2017-12605 [HIGH] CWE-787 CVE-2017-12605: OpenCV (Open Source Computer Vision Library) through 3.3 has an out-of-bounds write error in the Fil OpenCV (Open Source Computer Vision Library) through 3.3 has an out-of-bounds write error in the FillColorRow8 function in utils.cpp when reading an image file by using cv::imread.
nvd
CVE-2017-12597P3HIGHCVSS 8.8v8.0v9.02017-08-07
CVE-2017-12597 [HIGH] CWE-787 CVE-2017-12597: OpenCV (Open Source Computer Vision Library) through 3.3 has an out-of-bounds write error in the fun OpenCV (Open Source Computer Vision Library) through 3.3 has an out-of-bounds write error in the function FillColorRow1 in utils.cpp when reading an image file by using cv::imread.
nvd
CVE-2017-16612P3HIGHCVSS 7.5v8.0v9.02017-12-01
CVE-2017-16612 [HIGH] CWE-190 CVE-2017-16612: libXcursor before 1.1.15 has various integer overflows that could lead to heap buffer overflows when libXcursor before 1.1.15 has various integer overflows that could lead to heap buffer overflows when processing malicious cursors, e.g., with programs like GIMP. It is also possible that an attack vector exists against the related code in cursor/xcursor.c in Wayland through 1.14.0.
nvd
CVE-2014-0118P3MEDIUMCVSS 4.3v7.0v8.02014-07-20
CVE-2014-0118 [MEDIUM] CWE-400 CVE-2014-0118: The deflate_in_filter function in mod_deflate.c in the mod_deflate module in the Apache HTTP Server The deflate_in_filter function in mod_deflate.c in the mod_deflate module in the Apache HTTP Server before 2.4.10, when request body decompression is enabled, allows remote attackers to cause a denial of service (resource consumption) via crafted request data that decompresses to a much larger size.
nvd
CVE-2018-9009P3HIGHCVSS 8.8v7.02018-03-25
CVE-2018-9009 [HIGH] CWE-416 CVE-2018-9009: In libming 0.4.8, there is a use-after-free in the decompileJUMP function of the decompile.c file. In libming 0.4.8, there is a use-after-free in the decompileJUMP function of the decompile.c file.
nvd
CVE-1999-0769P4HIGHCVSS 7.2PoCv2.1v2.21999-08-25
CVE-1999-0769 [HIGH] CVE-1999-0769: Vixie Cron on Linux systems allows local users to set parameters of sendmail commands via the MAILTO Vixie Cron on Linux systems allows local users to set parameters of sendmail commands via the MAILTO environmental variable.
nvd
CVE-2000-0107P4HIGHCVSS 7.2PoCv2.12000-02-01
CVE-2000-0107 [HIGH] CVE-2000-0107: Linux apcd program allows local attackers to modify arbitrary files via a symlink attack. Linux apcd program allows local attackers to modify arbitrary files via a symlink attack.
nvd
CVE-1999-0405P4HIGHCVSS 7.2PoCv2.0v2.0.51999-02-18
CVE-1999-0405 [HIGH] CVE-1999-0405: A buffer overflow in lsof allows local users to obtain root privilege. A buffer overflow in lsof allows local users to obtain root privilege.
nvd
CVE-2023-41360P3CRITICALCVSS 9.1v10.02023-08-29
CVE-2023-41360 [CRITICAL] CWE-125 CVE-2023-41360: An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c can read the initial byte of An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c can read the initial byte of the ORF header in an ahead-of-stream situation.
nvd
CVE-2017-5091P3HIGHCVSS 8.8v9.02017-10-27
CVE-2017-5091 [HIGH] CWE-416 CVE-2017-5091: A use after free in IndexedDB in Google Chrome prior to 60.0.3112.78 for Linux, Android, Windows, an A use after free in IndexedDB in Google Chrome prior to 60.0.3112.78 for Linux, Android, Windows, and Mac allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
nvd
CVE-2012-3959P3CRITICALCVSS 10.0v6.0v7.02012-08-29
CVE-2012-3959 [CRITICAL] CWE-416 CVE-2012-3959: Use-after-free vulnerability in the nsRangeUpdater::SelAdjDeleteNode function in Mozilla Firefox bef Use-after-free vulnerability in the nsRangeUpdater::SelAdjDeleteNode function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified ve
nvd
CVE-2017-17511P3HIGHCVSS 8.8v7.0v8.02017-12-14
CVE-2017-17511 [HIGH] CWE-74 CVE-2017-17511: KildClient 3.1.0 does not validate strings before launching the program specified by the BROWSER env KildClient 3.1.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL, related to prefs.c and worldgui.c.
nvd
CVE-2019-11711P3HIGHCVSS 8.8v8.02019-07-23
CVE-2019-11711 [HIGH] CVE-2019-11711: When an inner window is reused, it does not consider the use of document.domain for cross-origin pro When an inner window is reused, it does not consider the use of document.domain for cross-origin protections. If pages on different subdomains ever cooperatively use document.domain, then either page can abuse this to inject script into arbitrary pages on the other subdomain, even those that did not use document.domain to relax their origin security. This vul
nvd
CVE-2017-17527P3HIGHCVSS 8.8v8.0v9.0+1 more2017-12-14
CVE-2017-17527 [HIGH] CWE-74 CVE-2017-17527: delphi_gui/WWWBrowserRunnerDM.pas in PasDoc 0.14 does not validate strings before launching the prog delphi_gui/WWWBrowserRunnerDM.pas in PasDoc 0.14 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. NOTE: a software maintainer has indicated that the code referencing the BROWSER environment variable is never u
nvd
Debian Linux vulnerabilities | cvebase