cbcvebase.

Debian Linux vulnerabilities

9,953 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358

Vulnerabilities

Page 172 of 498
CVE-2017-7801P3CRITICALCVSS 9.8v8.0v9.02018-06-11
CVE-2017-7801 [CRITICAL] CWE-416 CVE-2017-7801: A use-after-free vulnerability can occur while re-computing layout for a "marquee" element during wi A use-after-free vulnerability can occur while re-computing layout for a "marquee" element during window resizing where the updated style object is freed while still in use. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
nvd
CVE-2021-46669P3HIGHCVSS 7.5v10.02022-02-01
CVE-2021-46669 [HIGH] CWE-416 CVE-2021-46669: MariaDB through 10.5.9 allows attackers to trigger a convert_const_to_int use-after-free when the BI MariaDB through 10.5.9 allows attackers to trigger a convert_const_to_int use-after-free when the BIGINT data type is used.
nvd
CVE-2022-23804P3HIGHCVSS 7.8v9.0v10.0+1 more2022-02-16
CVE-2022-23804 [HIGH] CWE-121 CVE-2022-23804: A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon ReadIJCo A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon ReadIJCoord coordinate parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or excellon file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
nvd
CVE-2022-23803P3HIGHCVSS 7.8v9.0v10.0+1 more2022-02-16
CVE-2022-23803 [HIGH] CWE-121 CVE-2022-23803: A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon ReadXYCo A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon ReadXYCoord coordinate parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or excellon file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
nvd
CVE-2019-16236P3HIGHCVSS 7.5v10.02019-09-11
CVE-2019-16236 [HIGH] CWE-862 CVE-2019-16236: Dino before 2019-09-10 does not check roster push authorization in module/roster/module.vala. Dino before 2019-09-10 does not check roster push authorization in module/roster/module.vala.
nvd
CVE-2021-33560P3HIGHCVSS 7.5v9.02021-06-08
CVE-2021-33560 [HIGH] CWE-203 CVE-2021-33560: Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponen Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm, and the window size is not chosen appropriately. This, for example, affects use of ElGamal in OpenPGP.
nvd
CVE-2024-41311P3HIGHCVSS 8.1v11.02024-10-15
CVE-2024-41311 [HIGH] CWE-125 CVE-2024-41311: In Libheif 1.17.6, insufficient checks in ImageOverlay::parse() decoding a heif file containing an o In Libheif 1.17.6, insufficient checks in ImageOverlay::parse() decoding a heif file containing an overlay image with forged offsets can lead to an out-of-bounds read and write.
nvd
CVE-2014-1508P3CRITICALCVSS 9.1v7.0v8.02014-03-19
CVE-2014-1508 [CRITICAL] CWE-125 CVE-2014-1508: The libxul.so!gfxContext::Polygon function in Mozilla Firefox before 28.0, Firefox ESR 24.x before 2 The libxul.so!gfxContext::Polygon function in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive information from process memory, cause a denial of service (out-of-bounds read and application crash), or possibly bypass the Same Origin Policy via ve
nvd
CVE-2015-2736P3CRITICALCVSS 9.3v7.0v8.02015-07-06
CVE-2015-2736 [CRITICAL] CWE-17 CVE-2015-2736: The nsZipArchive::BuildFileList function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31. The nsZipArchive::BuildFileList function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 accesses unintended memory locations, which allows remote attackers to have an unspecified impact via a crafted ZIP archive.
nvd
CVE-2018-5147P3CRITICALCVSS 9.8v7.0v8.0+1 more2018-06-11
CVE-2018-5147 [CRITICAL] CVE-2018-5147: The libtremor library has the same flaw as CVE-2018-5146. This library is used by Firefox in place o The libtremor library has the same flaw as CVE-2018-5146. This library is used by Firefox in place of libvorbis on Android and ARM platforms. This vulnerability affects Firefox ESR < 52.7.2 and Firefox < 59.0.1.
nvd
CVE-2020-17367P3HIGHCVSS 7.8v10.0v9.02020-08-11
CVE-2020-17367 [HIGH] CWE-88 CVE-2020-17367: Firejail through 0.9.62 does not honor the -- end-of-options indicator after the --output option, wh Firejail through 0.9.62 does not honor the -- end-of-options indicator after the --output option, which may lead to command injection.
nvd
CVE-2016-1232P3HIGHCVSS 7.5v7.0v8.02016-01-12
CVE-2016-1232 [HIGH] CVE-2016-1232: The mod_dialback module in Prosody before 0.9.9 does not properly generate random values for the sec The mod_dialback module in Prosody before 0.9.9 does not properly generate random values for the secret token for server-to-server dialback authentication, which makes it easier for attackers to spoof servers via a brute force attack.
nvd
CVE-2024-5629P3HIGHCVSS 8.1v10.02024-06-05
CVE-2024-5629 [HIGH] CWE-125 CVE-2024-5629: An out-of-bounds read in the 'bson' module of PyMongo 4.6.2 or earlier allows deserialization of mal An out-of-bounds read in the 'bson' module of PyMongo 4.6.2 or earlier allows deserialization of malformed BSON provided by a Server to raise an exception which may contain arbitrary application memory.
nvd
CVE-2017-8810P3HIGHCVSS 7.5v9.02017-11-15
CVE-2017-8810 [HIGH] CWE-200 CVE-2017-8810: MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2, when a private wiki is conf MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2, when a private wiki is configured, provides different error messages for failed login attempts depending on whether the username exists, which allows remote attackers to enumerate account names and conduct brute-force attacks via a series of requests.
nvd
CVE-2012-1155P3HIGHCVSS 7.5v6.02019-11-14
CVE-2012-1155 [HIGH] CWE-200 CVE-2012-1155: Moodle has a database activity export permission issue where the export function of the database act Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from groups the user does not belong to
nvd
CVE-2022-35410P3HIGHCVSS 7.5v10.0v11.02022-07-08
CVE-2022-35410 [HIGH] CWE-22 CVE-2022-35410: mat2 (aka metadata anonymisation toolkit) before 0.13.0 allows ../ directory traversal during the ZI mat2 (aka metadata anonymisation toolkit) before 0.13.0 allows ../ directory traversal during the ZIP archive cleaning process. This primarily affects mat2 web instances, in which clients could obtain sensitive information via a crafted archive.
nvd
CVE-2017-7793P3CRITICALCVSS 9.8v7.0v8.0+1 more2018-06-11
CVE-2017-7793 [CRITICAL] CWE-416 CVE-2017-7793: A use-after-free vulnerability can occur in the Fetch API when the worker or the associated window a A use-after-free vulnerability can occur in the Fetch API when the worker or the associated window are freed when still in use, resulting in a potentially exploitable crash. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.
nvd
CVE-2020-27844P3HIGHCVSS 7.8v9.02021-01-05
CVE-2020-27844 [HIGH] CWE-20 CVE-2020-27844: A flaw was found in openjpeg's src/lib/openjp2/t2.c in versions prior to 2.4.0. This flaw allows an A flaw was found in openjpeg's src/lib/openjp2/t2.c in versions prior to 2.4.0. This flaw allows an attacker to provide crafted input to openjpeg during conversion and encoding, causing an out-of-bounds write. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
nvd
CVE-2018-16741P3HIGHCVSS 7.8v8.0v9.02018-09-13
CVE-2018-16741 [HIGH] CWE-78 CVE-2018-16741: An issue was discovered in mgetty before 1.2.1. In fax/faxq-helper.c, the function do_activate() doe An issue was discovered in mgetty before 1.2.1. In fax/faxq-helper.c, the function do_activate() does not properly sanitize shell metacharacters to prevent command injection. It is possible to use the ||, &&, or > characters within a file created by the "faxq-helper activate " command.
nvd
CVE-2024-36886P3HIGHCVSS 7.8v10.02024-05-30
CVE-2024-36886 [HIGH] CWE-416 CVE-2024-36886: In the Linux kernel, the following vulnerability has been resolved: tipc: fix UAF in error path Sa In the Linux kernel, the following vulnerability has been resolved: tipc: fix UAF in error path Sam Page (sam4k) working with Trend Micro Zero Day Initiative reported a UAF in the tipc_buf_append() error path: BUG: KASAN: slab-use-after-free in kfree_skb_list_reason+0x47e/0x4c0 linux/net/core/skbuff.c:1183 Read of size 8 at addr ffff88804d2a7c80 by t
nvd
Debian Linux vulnerabilities | cvebase