cbcvebase.

Debian Linux vulnerabilities

9,953 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358

Vulnerabilities

Page 183 of 498
CVE-2021-4185P3HIGHCVSS 7.5v9.02021-12-30
CVE-2021-4185 [HIGH] CWE-835 CVE-2021-4185: Infinite loop in the RTMPT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service Infinite loop in the RTMPT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
nvd
CVE-2021-4184P3HIGHCVSS 7.5v9.02021-12-30
CVE-2021-4184 [HIGH] CWE-835 CVE-2021-4184: Infinite loop in the BitTorrent DHT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial o Infinite loop in the BitTorrent DHT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
nvd
CVE-2019-10064P3HIGHCVSS 7.5v8.0v9.02020-02-28
CVE-2019-10064 [HIGH] CVE-2019-10064: hostapd before 2.6, in EAP mode, makes calls to the rand() and random() standard library functions w hostapd before 2.6, in EAP mode, makes calls to the rand() and random() standard library functions without any preceding srand() or srandom() call, which results in inappropriate use of deterministic values. This was fixed in conjunction with CVE-2016-10743.
nvd
CVE-2017-15099P3MEDIUMCVSS 6.5v9.02017-11-22
CVE-2017-15099 [MEDIUM] CWE-200 CVE-2017-15099: INSERT ... ON CONFLICT DO UPDATE commands in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, and 9. INSERT ... ON CONFLICT DO UPDATE commands in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, and 9.5.x before 9.5.10 disclose table contents that the invoker lacks privilege to read. These exploits affect only tables where the attacker lacks full read access but has both INSERT and UPDATE privileges. Exploits bypass row level security policies and
nvd
CVE-2018-8004P3MEDIUMCVSS 6.5v9.02018-08-29
CVE-2018-8004 [MEDIUM] CWE-444 CVE-2018-8004: There are multiple HTTP smuggling and cache poisoning issues when clients making malicious requests There are multiple HTTP smuggling and cache poisoning issues when clients making malicious requests interact with Apache Traffic Server (ATS). This affects versions 6.0.0 to 6.2.2 and 7.0.0 to 7.1.3. To resolve this issue users running 6.x should upgrade to 6.2.3 or later versions and 7.x users should upgrade to 7.1.4 or later versions.
nvd
CVE-2018-15910P3HIGHCVSS 7.8v8.0v9.02018-08-27
CVE-2018-15910 [HIGH] CWE-704 CVE-2018-15910: In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use a ty In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use a type confusion in the LockDistillerParams parameter to crash the interpreter or execute code.
nvd
CVE-2016-1568P3HIGHCVSS 8.8v7.0v8.02016-04-12
CVE-2016-1568 [HIGH] CWE-416 CVE-2016-1568: Use-after-free vulnerability in hw/ide/ahci.c in QEMU, when built with IDE AHCI Emulation support, a Use-after-free vulnerability in hw/ide/ahci.c in QEMU, when built with IDE AHCI Emulation support, allows guest OS users to cause a denial of service (instance crash) or possibly execute arbitrary code via an invalid AHCI Native Command Queuing (NCQ) AIO command.
nvd
CVE-2021-4181P3HIGHCVSS 7.5v9.02021-12-30
CVE-2021-4181 [HIGH] CWE-125 CVE-2021-4181: Crash in the Sysdig Event dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service Crash in the Sysdig Event dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
nvd
CVE-2021-21202P3HIGHCVSS 8.6v10.02021-04-26
CVE-2021-21202 [HIGH] CWE-416 CVE-2021-21202: Use after free in extensions in Google Chrome prior to 90.0.4430.72 allowed an attacker who convince Use after free in extensions in Google Chrome prior to 90.0.4430.72 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
nvd
CVE-2021-21207P3HIGHCVSS 8.6v10.02021-04-26
CVE-2021-21207 [HIGH] CWE-416 CVE-2021-21207: Use after free in IndexedDB in Google Chrome prior to 90.0.4430.72 allowed an attacker who convinced Use after free in IndexedDB in Google Chrome prior to 90.0.4430.72 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
nvd
CVE-2018-19966P3HIGHCVSS 8.8v9.02018-12-08
CVE-2018-19966 [HIGH] CVE-2018-19966: An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of se An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service (host OS crash) or possibly gain host OS privileges because of an interpretation conflict for a union data structure associated with shadow paging. NOTE: this issue exists because of an incorrect fix for CVE-2017-15595.
nvd
CVE-2020-15503P3HIGHCVSS 7.5v10.02020-07-02
CVE-2020-15503 [HIGH] CWE-20 CVE-2020-15503: LibRaw before 0.20-RC1 lacks a thumbnail size range check. This affects decoders/unpack_thumb.cpp, p LibRaw before 0.20-RC1 lacks a thumbnail size range check. This affects decoders/unpack_thumb.cpp, postprocessing/mem_image.cpp, and utils/thumb_utils.cpp. For example, malloc(sizeof(libraw_processed_image_t)+T.tlength) occurs without validating T.tlength.
nvd
CVE-2019-17533P3HIGHCVSS 8.2v8.02019-10-13
CVE-2019-17533 [HIGH] CWE-125 CVE-2019-17533: Mat_VarReadNextInfo4 in mat4.c in MATIO 1.5.17 omits a certain '\0' character, leading to a heap-bas Mat_VarReadNextInfo4 in mat4.c in MATIO 1.5.17 omits a certain '\0' character, leading to a heap-based buffer over-read in strdup_vprintf when uninitialized memory is accessed.
nvd
CVE-2019-17340P3HIGHCVSS 8.8v9.0v10.02019-10-08
CVE-2019-17340 [HIGH] CWE-401 CVE-2019-17340: An issue was discovered in Xen through 4.11.x allowing x86 guest OS users to cause a denial of servi An issue was discovered in Xen through 4.11.x allowing x86 guest OS users to cause a denial of service or gain privileges because grant-table transfer requests are mishandled.
nvd
CVE-2020-24489P3HIGHCVSS 8.8v9.0v10.02021-06-09
CVE-2020-24489 [HIGH] CWE-459 CVE-2020-24489: Incomplete cleanup in some Intel(R) VT-d products may allow an authenticated user to potentially ena Incomplete cleanup in some Intel(R) VT-d products may allow an authenticated user to potentially enable escalation of privilege via local access.
nvd
CVE-2019-17346P3HIGHCVSS 8.8v9.0v10.02019-10-08
CVE-2019-17346 [HIGH] CWE-20 CVE-2019-17346: An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of se An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges because of an incompatibility between Process Context Identifiers (PCID) and TLB flushes.
nvd
CVE-2016-4324P3HIGHCVSS 7.8v8.02016-07-08
CVE-2016-4324 [HIGH] CWE-20 CVE-2016-4324: Use-after-free vulnerability in LibreOffice before 5.1.4 allows remote attackers to execute arbitrar Use-after-free vulnerability in LibreOffice before 5.1.4 allows remote attackers to execute arbitrary code via a crafted RTF file, related to stylesheet and superscript tokens.
nvd
CVE-2017-0379P3HIGHCVSS 7.5v9.02017-08-29
CVE-2017-0379 [HIGH] CWE-200 CVE-2017-0379: Libgcrypt before 1.8.1 does not properly consider Curve25519 side-channel attacks, which makes it ea Libgcrypt before 1.8.1 does not properly consider Curve25519 side-channel attacks, which makes it easier for attackers to discover a secret key, related to cipher/ecc.c and mpi/ec.c.
nvd
CVE-2021-25214P3MEDIUMCVSS 6.5v9.0v10.02021-04-29
CVE-2021-25214 [MEDIUM] CWE-617 CVE-2021-25214: In BIND 9.8.5 -> 9.8.8, 9.9.3 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S In BIND 9.8.5 -> 9.8.8, 9.9.3 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND 9 Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.11 of the BIND 9.17 development branch, when a vulnerable version of named receives a malformed IXFR triggering the flaw described above, the
nvd
CVE-2021-36048P3HIGHCVSS 7.8v10.02021-09-01
CVE-2021-36048 [HIGH] CWE-20 CVE-2021-36048: XMP Toolkit SDK version 2020.1 (and earlier) is affected by an Improper Input Validation vulnerabili XMP Toolkit SDK version 2020.1 (and earlier) is affected by an Improper Input Validation vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file.
nvd
Debian Linux vulnerabilities | cvebase