cbcvebase.

Debian Linux vulnerabilities

9,953 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358

Vulnerabilities

Page 184 of 498
CVE-2021-36047P3HIGHCVSS 7.8v10.02021-09-01
CVE-2021-36047 [HIGH] CWE-20 CVE-2021-36047: XMP Toolkit SDK version 2020.1 (and earlier) is affected by an Improper Input Validation vulnerabili XMP Toolkit SDK version 2020.1 (and earlier) is affected by an Improper Input Validation vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file.
nvd
CVE-2021-33196P3HIGHCVSS 7.5v9.02021-08-02
CVE-2021-33196 [HIGH] CWE-20 CVE-2021-33196: In archive/zip in Go before 1.15.13 and 1.16.x before 1.16.5, a crafted file count (in an archive's In archive/zip in Go before 1.15.13 and 1.16.x before 1.16.5, a crafted file count (in an archive's header) can cause a NewReader or OpenReader panic.
nvd
CVE-2021-43618P3HIGHCVSS 7.5v9.02021-11-15
CVE-2021-43618 [HIGH] CWE-190 CVE-2021-43618: GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input, leading to a segmentation fault on 32-bit platforms.
nvd
CVE-2018-1000098P3HIGHCVSS 7.5v9.02018-03-13
CVE-2018-1000098 [HIGH] CWE-190 CVE-2018-1000098: Teluu PJSIP version 2.7.1 and earlier contains a Integer Overflow vulnerability in pjmedia SDP parsi Teluu PJSIP version 2.7.1 and earlier contains a Integer Overflow vulnerability in pjmedia SDP parsing that can result in Crash. This attack appear to be exploitable via Sending a specially crafted message. This vulnerability appears to have been fixed in 2.7.2.
nvd
CVE-2019-8325P3HIGHCVSS 7.5v9.02019-06-17
CVE-2019-8325 [HIGH] CWE-74 CVE-2019-8325: An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::CommandManager#run calls An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::CommandManager#run calls alert_error without escaping, escape sequence injection is possible. (There are many ways to cause an error.)
nvd
CVE-2019-8321P3HIGHCVSS 7.5v9.02019-06-17
CVE-2019-8321 [HIGH] CWE-88 CVE-2019-8321: An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::UserInteraction#verbose An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::UserInteraction#verbose calls say without escaping, escape sequence injection is possible.
nvd
CVE-2020-6554P3HIGHCVSS 8.6v10.02020-09-21
CVE-2020-6554 [HIGH] CWE-416 CVE-2020-6554: Use after free in extensions in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to po Use after free in extensions in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially perform a sandbox escape via a crafted Chrome Extension.
nvd
CVE-2017-2870P3HIGHCVSS 7.8v8.02017-09-05
CVE-2017-2870 [HIGH] CWE-190 CVE-2017-2870: An exploitable integer overflow vulnerability exists in the tiff_image_parse functionality of Gdk-Pi An exploitable integer overflow vulnerability exists in the tiff_image_parse functionality of Gdk-Pixbuf 2.36.6 when compiled with Clang. A specially crafted tiff file can cause a heap-overflow resulting in remote code execution. An attacker can send a file or a URL to trigger this vulnerability.
nvd
CVE-2014-5439P3HIGHCVSS 7.8v8.0v9.0+1 more2019-11-19
CVE-2014-5439 [HIGH] CWE-787 CVE-2014-5439: Multiple Stack-based Buffer Overflow vulnerabilities exists in Sniffit prior to 0.3.7 via a crafted Multiple Stack-based Buffer Overflow vulnerabilities exists in Sniffit prior to 0.3.7 via a crafted configuration file that will bypass Non-eXecutable bit NX, stack smashing protector SSP, and address space layout randomization ASLR protection mechanisms, which could let a malicious user execute arbitrary code.
nvd
CVE-2021-21381P3HIGHCVSS 8.2v10.02021-03-11
CVE-2021-21381 [HIGH] CWE-74 CVE-2021-21381: Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In Flatpack since version 0.9.4 and before version 1.10.2 has a vulnerability in the "file forwarding" feature which can be used by an attacker to gain access to files that would not ordinarily be allowed by the app's permissions. By putting the special
nvd
CVE-2008-5023P3HIGHCVSS 7.5v4.02008-11-13
CVE-2008-5023 [HIGH] CWE-20 CVE-2008-5023: Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to bypass the protection mechanism for codebase principals and execute arbitrary script via the -moz-binding CSS property in a signed JAR file.
nvd
CVE-2014-1518P3HIGHCVSS 8.8v7.0v8.02014-04-30
CVE-2014-1518 [HIGH] CVE-2014-1518: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 29.0, Firefox E Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2021-36046P3HIGHCVSS 7.8v10.02021-09-01
CVE-2021-36046 [HIGH] CWE-788 CVE-2021-36046: XMP Toolkit version 2020.1 (and earlier) is affected by a memory corruption vulnerability, potential XMP Toolkit version 2020.1 (and earlier) is affected by a memory corruption vulnerability, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.
nvd
CVE-2017-12902P3CRITICALCVSS 9.8v9.0v10.02017-09-14
CVE-2017-12902 [CRITICAL] CWE-125 CVE-2017-12902: The Zephyr parser in tcpdump before 4.9.2 has a buffer over-read in print-zephyr.c, several function The Zephyr parser in tcpdump before 4.9.2 has a buffer over-read in print-zephyr.c, several functions.
nvd
CVE-2017-13024P3CRITICALCVSS 9.8v8.0v9.0+1 more2017-09-14
CVE-2017-13024 [CRITICAL] CWE-125 CVE-2017-13024: The IPv6 mobility parser in tcpdump before 4.9.2 has a buffer over-read in print-mobility.c:mobility The IPv6 mobility parser in tcpdump before 4.9.2 has a buffer over-read in print-mobility.c:mobility_opt_print().
nvd
CVE-2017-2825P3HIGHCVSS 7.0v8.0v9.02018-04-20
CVE-2017-2825 [HIGH] CVE-2017-2825: In the trapper functionality of Zabbix Server 2.4.x, specifically crafted trapper packets can pass d In the trapper functionality of Zabbix Server 2.4.x, specifically crafted trapper packets can pass database logic checks, resulting in database writes. An attacker can set up a Man-in-the-Middle server to alter trapper requests made between an active Zabbix proxy and Server to trigger this vulnerability.
nvd
CVE-2017-8073P3HIGHCVSS 7.5v8.02017-04-23
CVE-2017-8073 [HIGH] CWE-119 CVE-2017-8073: WeeChat before 1.7.1 allows a remote crash by sending a filename via DCC to the IRC plugin. This occ WeeChat before 1.7.1 allows a remote crash by sending a filename via DCC to the IRC plugin. This occurs in the irc_ctcp_dcc_filename_without_quotes function during quote removal, with a buffer overflow.
nvd
CVE-2004-0522P3CRITICALCVSS 10.0v3.02004-08-06
CVE-2004-0522 [CRITICAL] CVE-2004-0522: Gallery 1.4.3 and earlier allows remote attackers to bypass authentication and obtain Gallery admini Gallery 1.4.3 and earlier allows remote attackers to bypass authentication and obtain Gallery administrator privileges.
nvd
CVE-2019-19246P3HIGHCVSS 7.5v8.02019-11-25
CVE-2019-19246 [HIGH] CWE-125 CVE-2019-19246: Oniguruma through 6.9.3, as used in PHP 7.3.x and other products, has a heap-based buffer over-read Oniguruma through 6.9.3, as used in PHP 7.3.x and other products, has a heap-based buffer over-read in str_lower_case_match in regexec.c.
nvd
CVE-2017-13725P3CRITICALCVSS 9.8v8.0v9.0+1 more2017-09-14
CVE-2017-13725 [CRITICAL] CWE-125 CVE-2017-13725: The IPv6 routing header parser in tcpdump before 4.9.2 has a buffer over-read in print-rt6.c:rt6_pri The IPv6 routing header parser in tcpdump before 4.9.2 has a buffer over-read in print-rt6.c:rt6_print().
nvd
Debian Linux vulnerabilities | cvebase