Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 167 of 498
CVE-2018-16981P3HIGHCVSS 8.8v10.02018-09-12
CVE-2018-16981 [HIGH] CWE-787 CVE-2018-16981: stb stb_image.h 2.19, as used in catimg, Emscripten, and other products, has a heap-based buffer ove
stb stb_image.h 2.19, as used in catimg, Emscripten, and other products, has a heap-based buffer overflow in the stbi__out_gif_code function.
nvd
CVE-2017-5095P3HIGHCVSS 8.8v9.02017-10-27
CVE-2017-5095 [HIGH] CWE-787 CVE-2017-5095: Stack overflow in PDFium in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed
Stack overflow in PDFium in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed a remote attacker to potentially exploit stack corruption via a crafted PDF file.
nvd
CVE-2016-1676P3HIGHCVSS 8.8v8.02016-06-05
CVE-2016-1676 [HIGH] CWE-284 CVE-2016-1676: extensions/renderer/resources/binding.js in the extension bindings in Google Chrome before 51.0.2704
extensions/renderer/resources/binding.js in the extension bindings in Google Chrome before 51.0.2704.63 does not properly use prototypes, which allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
nvd
CVE-2018-6144P3HIGHCVSS 8.8v9.02019-01-09
CVE-2018-6144 [HIGH] CWE-787 CVE-2018-6144: Off-by-one error in PDFium in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perfo
Off-by-one error in PDFium in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform an out of bounds memory write via a crafted PDF file.
nvd
CVE-2020-16845P3HIGHCVSS 7.5v9.0v10.02020-08-06
CVE-2020-16845 [HIGH] CWE-835 CVE-2020-16845: Go before 1.13.15 and 14.x before 1.14.7 can have an infinite read loop in ReadUvarint and ReadVarin
Go before 1.13.15 and 14.x before 1.14.7 can have an infinite read loop in ReadUvarint and ReadVarint in encoding/binary via invalid inputs.
nvd
CVE-2017-5099P3HIGHCVSS 8.8v9.02017-10-27
CVE-2017-5099 [HIGH] CWE-20 CVE-2017-5099: Insufficient validation of untrusted input in PPAPI Plugins in Google Chrome prior to 60.0.3112.78 f
Insufficient validation of untrusted input in PPAPI Plugins in Google Chrome prior to 60.0.3112.78 for Mac allowed a remote attacker to potentially gain privilege elevation via a crafted HTML page.
nvd
CVE-2019-5820P3HIGHCVSS 8.8v10.02019-06-27
CVE-2019-5820 [HIGH] CWE-190 CVE-2019-5820: Integer overflow in PDFium in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to pote
Integer overflow in PDFium in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
nvd
CVE-2017-5092P3HIGHCVSS 8.8v9.02017-10-27
CVE-2017-5092 [HIGH] CWE-20 CVE-2017-5092: Insufficient validation of untrusted input in PPAPI Plugins in Google Chrome prior to 60.0.3112.78 f
Insufficient validation of untrusted input in PPAPI Plugins in Google Chrome prior to 60.0.3112.78 for Windows allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2023-52160P3MEDIUMCVSS 6.5v10.02024-02-22
CVE-2023-52160 [MEDIUM] CWE-287 CVE-2023-52160: The implementation of PEAP in wpa_supplicant through 2.10 allows authentication bypass. For a succes
The implementation of PEAP in wpa_supplicant through 2.10 allows authentication bypass. For a successful attack, wpa_supplicant must be configured to not verify the network's TLS certificate during Phase 1 authentication, and an eap_peap_decrypt vulnerability can then be abused to skip Phase 2 authentication. The attack vector is sending an EAP-TLV
nvd
CVE-2015-8710P3CRITICALCVSS 9.8v7.0v8.0+1 more2016-04-11
CVE-2015-8710 [CRITICAL] CWE-119 CVE-2015-8710: The htmlParseComment function in HTMLparser.c in libxml2 allows attackers to obtain sensitive inform
The htmlParseComment function in HTMLparser.c in libxml2 allows attackers to obtain sensitive information, cause a denial of service (out-of-bounds heap memory access and application crash), or possibly have unspecified other impact via an unclosed HTML comment.
nvd
CVE-2019-5821P3HIGHCVSS 8.8v10.02019-06-27
CVE-2019-5821 [HIGH] CWE-190 CVE-2019-5821: Integer overflow in PDFium in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to pote
Integer overflow in PDFium in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
nvd
CVE-2018-18359P3HIGHCVSS 8.8v9.02018-12-11
CVE-2018-18359 [HIGH] CWE-125 CVE-2018-18359: Incorrect handling of Reflect.construct in V8 in Google Chrome prior to 71.0.3578.80 allowed a remot
Incorrect handling of Reflect.construct in V8 in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
nvd
CVE-2010-3844P3HIGHCVSS 8.8v8.0v9.0+1 more2019-11-12
CVE-2010-3844 [HIGH] CWE-120 CVE-2010-3844: An unchecked sscanf() call in ettercap before 0.7.5 allows an insecure temporary settings file to ov
An unchecked sscanf() call in ettercap before 0.7.5 allows an insecure temporary settings file to overflow a static-sized buffer on the stack.
nvd
CVE-2018-6072P3HIGHCVSS 8.8v9.02018-11-14
CVE-2018-6072 [HIGH] CWE-190 CVE-2018-6072: An integer overflow leading to use after free in PDFium in Google Chrome prior to 65.0.3325.146 allo
An integer overflow leading to use after free in PDFium in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
nvd
CVE-2017-2669P3HIGHCVSS 7.5v8.02018-06-21
CVE-2017-2669 [HIGH] CWE-20 CVE-2017-2669: Dovecot before version 2.2.29 is vulnerable to a denial of service. When 'dict' passdb and userdb we
Dovecot before version 2.2.29 is vulnerable to a denial of service. When 'dict' passdb and userdb were used for user authentication, the username sent by the IMAP/POP3 client was sent through var_expand() to perform %variable expansion. Sending specially crafted %variable fields could result in excessive memory usage causing the process to crash (and res
nvd
CVE-2023-1992P3HIGHCVSS 7.5v10.0v12.02023-04-12
CVE-2023-1992 [HIGH] CWE-400 CVE-2023-1992: RPCoRDMA dissector crash in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service vi
RPCoRDMA dissector crash in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture file
nvd
CVE-2017-5122P3HIGHCVSS 8.8v9.02017-10-27
CVE-2017-5122 [HIGH] CWE-119 CVE-2017-5122: Inappropriate use of table size handling in V8 in Google Chrome prior to 61.0.3163.100 for Windows a
Inappropriate use of table size handling in V8 in Google Chrome prior to 61.0.3163.100 for Windows allowed a remote attacker to trigger out-of-bounds access via a crafted HTML page.
nvd
CVE-2020-6458P3HIGHCVSS 8.8v9.0v10.02020-05-21
CVE-2020-6458 [HIGH] CWE-125 CVE-2020-6458: Out of bounds read and write in PDFium in Google Chrome prior to 81.0.4044.122 allowed a remote atta
Out of bounds read and write in PDFium in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
nvd
CVE-2019-5806P3HIGHCVSS 8.8v10.02019-06-27
CVE-2019-5806 [HIGH] CWE-190 CVE-2019-5806: Integer overflow in ANGLE in Google Chrome on Windows prior to 74.0.3729.108 allowed a remote attack
Integer overflow in ANGLE in Google Chrome on Windows prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2008-2662P3CRITICALCVSS 10.0v4.02008-06-24
CVE-2008-2662 [CRITICAL] CWE-189 CVE-2008-2662: Multiple integer overflows in the rb_str_buf_append function in Ruby 1.8.4 and earlier, 1.8.5 before
Multiple integer overflows in the rb_str_buf_append function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 before 1.8.7-p22, and 1.9.0 before 1.9.0-2 allow context-dependent attackers to execute arbitrary code or cause a denial of service via unknown vectors that trigger memory corruption, a different issue than
nvd