cbcvebase.

Debian Linux vulnerabilities

9,953 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358

Vulnerabilities

Page 171 of 498
CVE-2018-10771P3CRITICALCVSS 9.8v9.02018-05-07
CVE-2018-10771 [CRITICAL] CWE-787 CVE-2018-10771: Stack-based buffer overflow in the get_key function in parse.c in abcm2ps through 8.13.20 allows rem Stack-based buffer overflow in the get_key function in parse.c in abcm2ps through 8.13.20 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
nvd
CVE-2017-5401P3CRITICALCVSS 9.8v9.02018-06-11
CVE-2017-5401 [CRITICAL] CWE-388 CVE-2017-5401: A crash triggerable by web content in which an "ErrorResult" references unassigned memory due to a l A crash triggerable by web content in which an "ErrorResult" references unassigned memory due to a logic error. The resulting crash may be exploitable. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
nvd
CVE-2017-2919P3HIGHCVSS 7.8v9.02017-11-20
CVE-2017-2919 [HIGH] CWE-787 CVE-2017-2919: An exploitable stack based buffer overflow vulnerability exists in the xls_getfcell function of libx An exploitable stack based buffer overflow vulnerability exists in the xls_getfcell function of libxls 1.3.4. A specially crafted XLS file can cause a memory corruption resulting in remote code execution. An attacker can send malicious XLS file to trigger this vulnerability
nvd
CVE-2017-2896P3HIGHCVSS 7.8v10.02017-11-20
CVE-2017-2896 [HIGH] CWE-787 CVE-2017-2896: An exploitable out-of-bounds write vulnerability exists in the xls_mergedCells function of libxls 1. An exploitable out-of-bounds write vulnerability exists in the xls_mergedCells function of libxls 1.4. . A specially crafted XLS file can cause a memory corruption resulting in remote code execution. An attacker can send malicious XLS file to trigger this vulnerability.
nvd
CVE-2010-3454P3CRITICALCVSS 9.3v5.0v6.02011-01-28
CVE-2010-3454 [CRITICAL] CWE-193 CVE-2010-3454: Multiple off-by-one errors in the WW8DopTypography::ReadFromMem function in oowriter in OpenOffice.o Multiple off-by-one errors in the WW8DopTypography::ReadFromMem function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted typography information in a Microsoft Word .DOC file that triggers an out-of-bounds write.
nvd
CVE-2022-42003P3HIGHCVSS 7.5v10.0v11.02022-10-02
CVE-2022-42003 [HIGH] CWE-502 CVE-2022-42003: In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur because of a lack of a check in primitive value deserializers to avoid deep wrapper array nesting, when the UNWRAP_SINGLE_VALUE_ARRAYS feature is enabled.
nvd
CVE-2018-5187P3CRITICALCVSS 9.8v8.0v9.02018-10-18
CVE-2018-5187 [CRITICAL] CWE-119 CVE-2018-5187: Memory safety bugs present in Firefox 60 and Firefox ESR 60. Some of these bugs showed evidence of m Memory safety bugs present in Firefox 60 and Firefox ESR 60. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60, Firefox ESR < 60.1, and Firefox < 61.
nvd
CVE-2019-16785P3HIGHCVSS 7.5v9.02019-12-20
CVE-2019-16785 [HIGH] CWE-444 CVE-2019-16785: Waitress through version 1.3.1 implemented a "MAY" part of the RFC7230 which states: "Although the l Waitress through version 1.3.1 implemented a "MAY" part of the RFC7230 which states: "Although the line terminator for the start-line and header fields is the sequence CRLF, a recipient MAY recognize a single LF as a line terminator and ignore any preceding CR." Unfortunately if a front-end server does not parse header fields with an LF the same way a
nvd
CVE-2020-12865P3HIGHCVSS 8.0v9.02020-06-24
CVE-2020-12865 [HIGH] CWE-787 CVE-2020-12865: A heap buffer overflow in SANE Backends before 1.0.30 may allow a malicious device connected to the A heap buffer overflow in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to execute arbitrary code, aka GHSL-2020-084.
nvd
CVE-2019-9854P3HIGHCVSS 7.8v8.0v9.0+1 more2019-09-06
CVE-2019-9854 [HIGH] CVE-2019-9854: LibreOffice has a feature where documents can specify that pre-installed macros can be executed on v LibreOffice has a feature where documents can specify that pre-installed macros can be executed on various script events such as mouse-over, document-open etc. Access is intended to be restricted to scripts under the share/Scripts/python, user/Scripts/python sub-directories of the LibreOffice install. Protection was added, to address CVE-2019-9852, to avoid a d
nvd
CVE-2019-9852P3HIGHCVSS 7.8v8.0v9.0+1 more2019-08-15
CVE-2019-9852 [HIGH] CWE-116 CVE-2019-9852: LibreOffice has a feature where documents can specify that pre-installed macros can be executed on v LibreOffice has a feature where documents can specify that pre-installed macros can be executed on various script events such as mouse-over, document-open etc. Access is intended to be restricted to scripts under the share/Scripts/python, user/Scripts/python sub-directories of the LibreOffice install. Protection was added, to address CVE-2018-16858, to
nvd
CVE-2020-28033P3HIGHCVSS 7.5v9.0v10.02020-11-02
CVE-2020-28033 [HIGH] CVE-2020-28033: WordPress before 5.5.2 mishandles embeds from disabled sites on a multisite network, as demonstrated WordPress before 5.5.2 mishandles embeds from disabled sites on a multisite network, as demonstrated by allowing a spam embed.
nvd
CVE-2017-7751P3CRITICALCVSS 9.8v8.0v9.02018-06-11
CVE-2017-7751 [CRITICAL] CWE-416 CVE-2017-7751: A use-after-free vulnerability with content viewer listeners that results in a potentially exploitab A use-after-free vulnerability with content viewer listeners that results in a potentially exploitable crash. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
nvd
CVE-2021-4206P3HIGHCVSS 8.2v10.0v11.02022-04-29
CVE-2021-4206 [HIGH] CWE-190 CVE-2021-4206: A flaw was found in the QXL display device emulation in QEMU. An integer overflow in the cursor_allo A flaw was found in the QXL display device emulation in QEMU. An integer overflow in the cursor_alloc() function can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. This flaw allows a malicious privileged guest user to crash the QEMU process on the host or potentially execute arbitrary code within the
nvd
CVE-2021-41054P3HIGHCVSS 7.5v9.02021-09-13
CVE-2021-41054 [HIGH] CWE-120 CVE-2021-41054: tftpd_file.c in atftp through 0.7.4 has a buffer overflow because buffer-size handling does not prop tftpd_file.c in atftp through 0.7.4 has a buffer overflow because buffer-size handling does not properly consider the combination of data, OACK, and other options.
nvd
CVE-2019-7548P3HIGHCVSS 7.8v8.0v9.02019-02-06
CVE-2019-7548 [HIGH] CWE-89 CVE-2019-7548: SQLAlchemy 1.2.17 has SQL Injection when the group_by parameter can be controlled. SQLAlchemy 1.2.17 has SQL Injection when the group_by parameter can be controlled.
nvd
CVE-2018-20023P3HIGHCVSS 7.5v8.0v9.02018-12-19
CVE-2018-20023 [HIGH] CWE-665 CVE-2018-20023: LibVNC before 8b06f835e259652b0ff026898014fc7297ade858 contains CWE-665: Improper Initialization vul LibVNC before 8b06f835e259652b0ff026898014fc7297ade858 contains CWE-665: Improper Initialization vulnerability in VNC Repeater client code that allows attacker to read stack memory and can be abuse for information disclosure. Combined with another vulnerability, it can be used to leak stack memory layout and in bypassing ASLR
nvd
CVE-2022-23946P3HIGHCVSS 7.8v9.0v10.0+1 more2022-02-04
CVE-2022-23946 [HIGH] CWE-121 CVE-2022-23946: A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon GCodeNum A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon GCodeNumber parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or excellon file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
nvd
CVE-2017-7779P3CRITICALCVSS 9.8v8.0v9.02018-06-11
CVE-2017-7779 [CRITICAL] CWE-119 CVE-2017-7779: Memory safety bugs were reported in Firefox 54, Firefox ESR 52.2, and Thunderbird 52.2. Some of thes Memory safety bugs were reported in Firefox 54, Firefox ESR 52.2, and Thunderbird 52.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
nvd
CVE-2023-4431P3HIGHCVSS 8.1v10.0v11.02023-08-23
CVE-2023-4431 [HIGH] CWE-125 CVE-2023-4431: Out of bounds memory access in Fonts in Google Chrome prior to 116.0.5845.110 allowed a remote attac Out of bounds memory access in Fonts in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
nvd
Debian Linux vulnerabilities | cvebase