cbcvebase.

Debian Linux vulnerabilities

9,953 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358

Vulnerabilities

Page 181 of 498
CVE-2017-17913P3HIGHCVSS 8.8v9.02017-12-27
CVE-2017-17913 [HIGH] CWE-125 CVE-2017-17913: In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a stack-based buffer over-read in WriteWEBPImag In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a stack-based buffer over-read in WriteWEBPImage in coders/webp.c, related to an incompatibility with libwebp versions, 0.5.0 and later, that use a different structure type.
nvd
CVE-2019-11045P3MEDIUMCVSS 5.9v8.0v9.0+1 more2019-12-23
CVE-2019-11045 [MEDIUM] CWE-170 CVE-2019-11045: In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP DirectoryIterator class accept In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP DirectoryIterator class accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to security vulnerabilities, e.g. in applications checking paths that the code is allowed to access.
nvd
CVE-2019-13616P3HIGHCVSS 8.1v9.0v10.02019-07-16
CVE-2019-13616 [HIGH] CWE-125 CVE-2019-13616: SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-rea SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in BlitNtoN in video/SDL_blit_N.c when called from SDL_SoftBlit in video/SDL_blit.c.
nvd
CVE-2008-0888P3CRITICALCVSS 9.3v4.02008-03-17
CVE-2008-0888 [CRITICAL] CWE-119 CVE-2008-0888: The NEEDBITS macro in the inflate_dynamic function in inflate.c for unzip can be invoked using inval The NEEDBITS macro in the inflate_dynamic function in inflate.c for unzip can be invoked using invalid buffers, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger a free of uninitialized or previously-freed data.
nvd
CVE-2021-41125P3MEDIUMCVSS 6.5v9.02021-10-06
CVE-2021-41125 [MEDIUM] CWE-200 CVE-2021-41125: Scrapy is a high-level web crawling and scraping framework for Python. If you use `HttpAuthMiddlewar Scrapy is a high-level web crawling and scraping framework for Python. If you use `HttpAuthMiddleware` (i.e. the `http_user` and `http_pass` spider attributes) for HTTP authentication, all requests will expose your credentials to the request target. This includes requests generated by Scrapy components, such as `robots.txt` requests sent by Scrapy w
nvd
CVE-2018-17469P3HIGHCVSS 8.8v9.02018-11-14
CVE-2018-17469 [HIGH] CWE-125 CVE-2018-17469: Incorrect handling of PDF filter chains in PDFium in Google Chrome prior to 70.0.3538.67 allowed a r Incorrect handling of PDF filter chains in PDFium in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to perform an out of bounds memory read via a crafted PDF file.
nvd
CVE-2021-21190P3HIGHCVSS 8.8v10.02021-03-09
CVE-2021-21190 [HIGH] CWE-908 CVE-2021-21190: Uninitialized data in PDFium in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to obt Uninitialized data in PDFium in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted PDF file.
nvd
CVE-2018-1000075P3HIGHCVSS 7.5v7.02018-03-13
CVE-2018-1000075 [HIGH] CWE-835 CVE-2018-1000075: RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 se RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a infinite loop caused by negative size vulnerability in ruby gem package tar header that can result in a negative size could cause an infinite loop.
nvd
CVE-2018-14463P3HIGHCVSS 7.5v8.0v9.0+1 more2019-10-03
CVE-2018-14463 [HIGH] CWE-125 CVE-2018-14463: The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 2, a different vulnerability than CVE-2019-15167.
nvd
CVE-2019-11455P3HIGHCVSS 8.1v8.02019-04-22
CVE-2019-11455 [HIGH] CWE-125 CVE-2019-11455: A buffer over-read in Util_urlDecode in util.c in Tildeslash Monit before 5.25.3 allows a remote aut A buffer over-read in Util_urlDecode in util.c in Tildeslash Monit before 5.25.3 allows a remote authenticated attacker to retrieve the contents of adjacent memory via manipulation of GET or POST parameters. The attacker can also cause a denial of service (application outage).
nvd
CVE-2018-8777P3HIGHCVSS 7.5v7.0v8.0+1 more2018-04-03
CVE-2018-8777 [HIGH] CWE-400 CVE-2018-8777: In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, an attacker can pass a large HTTP request with a crafted header to WEBrick server or a crafted body to WEBrick server/handler and cause a denial of service (memory consumption).
nvd
CVE-2017-5131P3HIGHCVSS 8.8v8.0v9.02018-02-07
CVE-2017-5131 [HIGH] CWE-190 CVE-2017-5131: An integer overflow in Skia in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to pote An integer overflow in Skia in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page, aka an out-of-bounds write.
nvd
CVE-2017-5043P3HIGHCVSS 8.8v8.0v9.02017-04-24
CVE-2017-5043 [HIGH] CWE-416 CVE-2017-5043: Chrome Apps in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac had a use after free Chrome Apps in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac had a use after free bug in GuestView, which allowed a remote attacker to perform an out of bounds memory read via a crafted Chrome extension.
nvd
CVE-2014-1479P3HIGHCVSS 7.5v7.02014-02-06
CVE-2014-1479 [HIGH] CVE-2014-1479: The System Only Wrapper (SOW) implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before The System Only Wrapper (SOW) implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 does not prevent certain cloning operations, which allows remote attackers to bypass intended restrictions on XUL content via vectors involving XBL content scopes.
nvd
CVE-2017-5114P3HIGHCVSS 8.8v9.0v10.02017-10-27
CVE-2017-5114 [HIGH] CWE-119 CVE-2017-5114: Inappropriate use of partition alloc in PDFium in Google Chrome prior to 61.0.3163.79 for Linux, Win Inappropriate use of partition alloc in PDFium in Google Chrome prior to 61.0.3163.79 for Linux, Windows, and Mac, and 61.0.3163.81 for Android, allowed a remote attacker to potentially exploit memory corruption via a crafted PDF file.
nvd
CVE-2012-4216P3CRITICALCVSS 9.3v6.0v7.02012-11-21
CVE-2012-4216 [CRITICAL] CWE-416 CVE-2012-4216: Use-after-free vulnerability in the gfxFont::GetFontEntry function in Mozilla Firefox before 17.0, F Use-after-free vulnerability in the gfxFont::GetFontEntry function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
nvd
CVE-2016-1627P3HIGHCVSS 8.8v8.02016-02-14
CVE-2016-1627 [HIGH] CWE-264 CVE-2016-1627: The Developer Tools (aka DevTools) subsystem in Google Chrome before 48.0.2564.109 does not validate The Developer Tools (aka DevTools) subsystem in Google Chrome before 48.0.2564.109 does not validate URL schemes and ensure that the remoteBase parameter is associated with a chrome-devtools-frontend.appspot.com URL, which allows remote attackers to bypass intended access restrictions via a crafted URL, related to browser/devtools/devtools_ui_bindings.c
nvd
CVE-2016-1622P3HIGHCVSS 8.8v8.02016-02-14
CVE-2016-1622 [HIGH] CWE-264 CVE-2016-1622: The Extensions subsystem in Google Chrome before 48.0.2564.109 does not prevent use of the Object.de The Extensions subsystem in Google Chrome before 48.0.2564.109 does not prevent use of the Object.defineProperty method to override intended extension behavior, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code.
nvd
CVE-2017-5113P3HIGHCVSS 8.8v9.0v10.02017-10-27
CVE-2017-5113 [HIGH] CWE-787 CVE-2017-5113: Math overflow in Skia in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.3 Math overflow in Skia in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.3163.81 for Android, allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2017-5111P3HIGHCVSS 8.8v9.0v10.02017-10-27
CVE-2017-5111 [HIGH] CWE-416 CVE-2017-5111: A use after free in PDFium in Google Chrome prior to 61.0.3163.79 for Linux, Windows, and Mac allowe A use after free in PDFium in Google Chrome prior to 61.0.3163.79 for Linux, Windows, and Mac allowed a remote attacker to potentially exploit memory corruption via a crafted PDF file.
nvd
Debian Linux vulnerabilities | cvebase