Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 180 of 498
CVE-2021-39928P3HIGHCVSS 7.5v9.02021-11-18
CVE-2021-39928 [HIGH] CWE-476 CVE-2021-39928: NULL pointer exception in the IEEE 802.11 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17
NULL pointer exception in the IEEE 802.11 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
nvd
CVE-2009-5042P3CRITICALCVSS 9.1v8.0v9.0+1 more2019-10-31
CVE-2009-5042 [CRITICAL] CWE-668 CVE-2009-5042: python-docutils allows insecure usage of temporary files
python-docutils allows insecure usage of temporary files
nvd
CVE-2013-4243P3MEDIUMCVSS 6.8v6.0v7.02013-09-10
CVE-2013-4243 [MEDIUM] CWE-119 CVE-2013-4243: Heap-based buffer overflow in the readgifimage function in the gif2tiff tool in libtiff 4.0.3 and ea
Heap-based buffer overflow in the readgifimage function in the gif2tiff tool in libtiff 4.0.3 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted height and width values in a GIF image.
nvd
CVE-2010-3858P4MEDIUMCVSS 4.9PoCv5.02010-11-30
CVE-2010-3858 [MEDIUM] CWE-400 CVE-2010-3858: The setup_arg_pages function in fs/exec.c in the Linux kernel before 2.6.36, when CONFIG_STACK_GROWS
The setup_arg_pages function in fs/exec.c in the Linux kernel before 2.6.36, when CONFIG_STACK_GROWSDOWN is used, does not properly restrict the stack memory consumption of the (1) arguments and (2) environment for a 32-bit application on a 64-bit platform, which allows local users to cause a denial of service (system crash) via a crafted exec system
nvd
CVE-1999-0914P4HIGHCVSS 7.2PoCv1.1v1.2+3 more1999-01-03
CVE-1999-0914 [HIGH] CVE-1999-0914: Buffer overflow in the FTP client in the Debian GNU/Linux netstd package.
Buffer overflow in the FTP client in the Debian GNU/Linux netstd package.
nvd
CVE-2017-7651P3HIGHCVSS 7.5v7.0v8.0+1 more2018-04-24
CVE-2017-7651 [HIGH] CWE-789 CVE-2017-7651: In Eclipse Mosquitto 1.4.14, a user can shutdown the Mosquitto server simply by filling the RAM memo
In Eclipse Mosquitto 1.4.14, a user can shutdown the Mosquitto server simply by filling the RAM memory with a lot of connections with large payload. This can be done without authentications if occur in connection phase of MQTT protocol.
nvd
CVE-2020-6514P3MEDIUMCVSS 6.5v9.0v10.02020-07-22
CVE-2020-6514 [MEDIUM] CWE-200 CVE-2020-6514: Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in
Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to potentially exploit heap corruption via a crafted SCTP stream.
nvd
CVE-2018-1060P3HIGHCVSS 7.5v8.0v9.02018-06-18
CVE-2018-1060 [HIGH] CWE-20 CVE-2018-1060: python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic bac
python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in pop3lib's apop() method. An attacker could use this flaw to cause denial of service.
nvd
CVE-2016-1645P3HIGHCVSS 8.8v8.02016-03-13
CVE-2016-1645 [HIGH] CWE-119 CVE-2016-1645: Multiple integer signedness errors in the opj_j2k_update_image_data function in j2k.c in OpenJPEG, a
Multiple integer signedness errors in the opj_j2k_update_image_data function in j2k.c in OpenJPEG, as used in PDFium in Google Chrome before 49.0.2623.87, allow remote attackers to cause a denial of service (incorrect cast and out-of-bounds write) or possibly have unspecified other impact via crafted JPEG 2000 data.
nvd
CVE-2017-12603P3HIGHCVSS 8.8v8.0v9.02017-08-07
CVE-2017-12603 [HIGH] CWE-787 CVE-2017-12603: OpenCV (Open Source Computer Vision Library) through 3.3 has an invalid write in the cv::RLByteStrea
OpenCV (Open Source Computer Vision Library) through 3.3 has an invalid write in the cv::RLByteStream::getBytes function in modules/imgcodecs/src/bitstrm.cpp when reading an image file by using cv::imread, as demonstrated by the 2-opencv-heapoverflow-fseek test case.
nvd
CVE-2017-1000456P3HIGHCVSS 8.8v7.0v8.0+1 more2018-01-02
CVE-2017-1000456 [HIGH] CWE-119 CVE-2017-1000456: freedesktop.org libpoppler 0.60.1 fails to validate boundaries in TextPool::addWord, leading to over
freedesktop.org libpoppler 0.60.1 fails to validate boundaries in TextPool::addWord, leading to overflow in subsequent calculations.
nvd
CVE-2018-6358P3HIGHCVSS 8.8v7.02018-01-27
CVE-2018-6358 [HIGH] CWE-787 CVE-2018-6358: The printDefineFont2 function (util/listfdb.c) in libming through 0.4.8 is vulnerable to a heap-base
The printDefineFont2 function (util/listfdb.c) in libming through 0.4.8 is vulnerable to a heap-based buffer overflow, which may allow attackers to cause a denial of service or unspecified other impact via a crafted FDB file.
nvd
CVE-2019-15166P3HIGHCVSS 7.5v8.0v9.0+1 more2019-10-03
CVE-2019-15166 [HIGH] CWE-120 CVE-2019-15166: lmp_print_data_link_subobjs() in print-lmp.c in tcpdump before 4.9.3 lacks certain bounds checks.
lmp_print_data_link_subobjs() in print-lmp.c in tcpdump before 4.9.3 lacks certain bounds checks.
nvd
CVE-2018-1061P3HIGHCVSS 7.5v8.0v9.02018-06-19
CVE-2018-1061 [HIGH] CWE-20 CVE-2018-1061: python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic bac
python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in the difflib.IS_LINE_JUNK method. An attacker could use this flaw to cause denial of service.
nvd
CVE-2022-22707P3MEDIUMCVSS 5.9v10.0v11.02022-01-06
CVE-2022-22707 [MEDIUM] CWE-787 CVE-2022-22707: In lighttpd 1.4.46 through 1.4.63, the mod_extforward_Forwarded function of the mod_extforward plugi
In lighttpd 1.4.46 through 1.4.63, the mod_extforward_Forwarded function of the mod_extforward plugin has a stack-based buffer overflow (4 bytes representing -1), as demonstrated by remote denial of service (daemon crash) in a non-default configuration. The non-default configuration requires handling of the Forwarded header in a somewhat unusual man
nvd
CVE-2017-17514P3HIGHCVSS 8.8v7.0v8.0+2 more2017-12-14
CVE-2017-17514 [HIGH] CWE-74 CVE-2017-17514: boxes.c in nip2 8.4.0 does not validate strings before launching the program specified by the BROWSE
boxes.c in nip2 8.4.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. NOTE: a software maintainer indicates that this product does not use the BROWSER environment variable
nvd
CVE-2020-25863P3HIGHCVSS 7.5v9.02020-10-06
CVE-2020-25863 [HIGH] CVE-2020-25863: In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the MIME Multipart dissector coul
In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the MIME Multipart dissector could crash. This was addressed in epan/dissectors/packet-multipart.c by correcting the deallocation of invalid MIME parts.
nvd
CVE-2017-3302P3HIGHCVSS 7.5v8.02017-02-12
CVE-2017-3302 [HIGH] CWE-416 CVE-2017-3302: Crash in libmysqlclient.so in Oracle MySQL before 5.6.21 and 5.7.x before 5.7.5 and MariaDB through
Crash in libmysqlclient.so in Oracle MySQL before 5.6.21 and 5.7.x before 5.7.5 and MariaDB through 5.5.54, 10.0.x through 10.0.29, 10.1.x through 10.1.21, and 10.2.x through 10.2.3.
nvd
CVE-2022-26661P3MEDIUMCVSS 6.5v9.0v10.0+1 more2022-03-10
CVE-2022-26661 [MEDIUM] CWE-611 CVE-2022-26661: An XXE issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through
An XXE issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.5, and Tryton Application Platform (Command Line Client (proteus)) 5.x through 5.0.11, 6.x through 6.0.4, and 6.1.x and 6.2.x through 6.2.1. An authenticated user can make the server parse a crafted XML SEPA file
nvd
CVE-2020-36518P3HIGHCVSS 7.5v9.0v10.0+1 more2022-03-11
CVE-2020-36518 [HIGH] CWE-787 CVE-2020-36518: jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a lar
jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
nvd