cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4153MEDIUM4310LOW358

Vulnerabilities

Page 195 of 498
CVE-2009-3095P3MEDIUMCVSS 5.0v4.02009-09-08
CVE-2009-3095 [MEDIUM] CVE-2009-3095: The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access restrictions and send arbitrary commands to an FTP server via vectors related to the embedding of these commands in the Authorization HTTP header, as demonstrated by a certain module in VulnDisco Pack Professional 8.11.
nvd
CVE-2020-1711P3MEDIUMCVSS 6.0v8.0v9.02020-02-11
CVE-2020-1711 [MEDIUM] CWE-122 CVE-2020-1711: An out-of-bounds heap buffer access flaw was found in the way the iSCSI Block driver in QEMU version An out-of-bounds heap buffer access flaw was found in the way the iSCSI Block driver in QEMU versions 2.12.0 before 4.2.1 handled a response coming from an iSCSI server while checking the status of a Logical Address Block (LBA) in an iscsi_co_block_status() routine. A remote user could use this flaw to crash the QEMU process, resulting in a denial of
nvd
CVE-2018-10811P3HIGHCVSS 7.5v8.0v9.02018-06-19
CVE-2018-10811 [HIGH] CWE-909 CVE-2018-10811: strongSwan 5.6.0 and older allows Remote Denial of Service because of Missing Initialization of a Va strongSwan 5.6.0 and older allows Remote Denial of Service because of Missing Initialization of a Variable.
nvd
CVE-2024-33602P3HIGHCVSS 7.4v10.02024-05-06
CVE-2024-33602 [HIGH] CWE-466 CVE-2024-33602: nscd: netgroup cache assumes NSS callback uses in-buffer strings The Name Service Cache Daemon's (n nscd: netgroup cache assumes NSS callback uses in-buffer strings The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory when the NSS callback does not store all strings in the provided buffer. The flaw was introduced in glibc 2.15 when the cache was added to nscd. This vulnerability is only present in the nscd binary.
nvd
CVE-2018-12265P3HIGHCVSS 8.8v8.0v9.02018-06-13
CVE-2018-12265 [HIGH] CWE-125 CVE-2018-12265: Exiv2 0.26 has an integer overflow in the LoaderExifJpeg class in preview.cpp, leading to an out-of- Exiv2 0.26 has an integer overflow in the LoaderExifJpeg class in preview.cpp, leading to an out-of-bounds read in Exiv2::MemIo::read in basicio.cpp.
nvd
CVE-2016-1649P3HIGHCVSS 8.8v8.02016-03-29
CVE-2016-1649 [HIGH] CWE-119 CVE-2016-1649: The Program::getUniformInternal function in Program.cpp in libANGLE, as used in Google Chrome before The Program::getUniformInternal function in Program.cpp in libANGLE, as used in Google Chrome before 49.0.2623.108, does not properly handle a certain data-type mismatch, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via crafted shader stages.
nvd
CVE-2008-5014P3CRITICALCVSS 10.0v4.02008-11-13
CVE-2008-5014 [CRITICAL] CWE-20 CVE-2008-5014: jslock.cpp in Mozilla Firefox 3.x before 3.0.2, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before jslock.cpp in Mozilla Firefox 3.x before 3.0.2, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by modifying the window.__proto__.__proto__ object in a way that causes a lock on a non-native object, which trigg
nvd
CVE-2019-10241P3MEDIUMCVSS 6.1v9.0v10.02019-04-22
CVE-2019-10241 [MEDIUM] CWE-79 CVE-2019-10241: In Eclipse Jetty version 9.2.26 and older, 9.3.25 and older, and 9.4.15 and older, the server is vul In Eclipse Jetty version 9.2.26 and older, 9.3.25 and older, and 9.4.15 and older, the server is vulnerable to XSS conditions if a remote client USES a specially formatted URL against the DefaultServlet or ResourceHandler that is configured for showing a Listing of directory contents.
nvd
CVE-2017-9992P3HIGHCVSS 8.8v8.02017-06-28
CVE-2017-9992 [HIGH] CWE-119 CVE-2017-9992: Heap-based buffer overflow in the decode_dds1 function in libavcodec/dfa.c in FFmpeg before 2.8.12, Heap-based buffer overflow in the decode_dds1 function in libavcodec/dfa.c in FFmpeg before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.3.1 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file.
nvd
CVE-2017-7650P3MEDIUMCVSS 6.5v8.02017-09-11
CVE-2017-7650 [MEDIUM] CWE-287 CVE-2017-7650: In Mosquitto before 1.4.12, pattern based ACLs can be bypassed by clients that set their username/cl In Mosquitto before 1.4.12, pattern based ACLs can be bypassed by clients that set their username/client id to '#' or '+'. This allows locally or remotely connected clients to access MQTT topics that they do have the rights to. The same issue may be present in third party authentication/access control plugins for Mosquitto.
nvd
CVE-2018-16335P3HIGHCVSS 8.8v9.02018-09-02
CVE-2018-16335 [HIGH] CVE-2018-16335: newoffsets handling in ChopUpSingleUncompressedStrip in tif_dirread.c in LibTIFF 4.0.9 allows remote newoffsets handling in ChopUpSingleUncompressedStrip in tif_dirread.c in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted TIFF file, as demonstrated by tiff2pdf. This is a different vulnerability than CVE-2018-15209.
nvd
CVE-2017-17500P3HIGHCVSS 8.8v7.0v8.0+1 more2017-12-11
CVE-2017-17500 [HIGH] CWE-125 CVE-2017-17500: ReadRGBImage in coders/rgb.c in GraphicsMagick 1.3.26 has a magick/import.c ImportRGBQuantumType hea ReadRGBImage in coders/rgb.c in GraphicsMagick 1.3.26 has a magick/import.c ImportRGBQuantumType heap-based buffer over-read via a crafted file.
nvd
CVE-2017-14990P3MEDIUMCVSS 6.5v8.0v9.02017-10-03
CVE-2017-14990 [MEDIUM] CWE-312 CVE-2017-14990: WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which might make it easier for remote attackers to hijack unactivated user accounts by leveraging database read access (such as access gained through an unspecified SQL injection vulnerability).
nvd
CVE-2018-5125P3HIGHCVSS 8.8v8.0v9.02018-06-11
CVE-2018-5125 [HIGH] CWE-119 CVE-2018-5125: Memory safety bugs were reported in Firefox 58 and Firefox ESR 52.6. Some of these bugs showed evide Memory safety bugs were reported in Firefox 58 and Firefox ESR 52.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 52.7, Firefox ESR < 52.7, and Firefox < 59.
nvd
CVE-2018-19870P3HIGHCVSS 8.8v8.0v9.02018-12-26
CVE-2018-19870 [HIGH] CWE-476 CVE-2018-19870: An issue was discovered in Qt before 5.11.3. A malformed GIF image causes a NULL pointer dereference An issue was discovered in Qt before 5.11.3. A malformed GIF image causes a NULL pointer dereference in QGifHandler resulting in a segmentation fault.
nvd
CVE-2013-6393P3MEDIUMCVSS 6.8v6.0v7.02014-02-06
CVE-2013-6393 [MEDIUM] CWE-119 CVE-2013-6393: The yaml_parser_scan_tag_uri function in scanner.c in LibYAML before 0.1.5 performs an incorrect cas The yaml_parser_scan_tag_uri function in scanner.c in LibYAML before 0.1.5 performs an incorrect cast, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted tags in a YAML document, which triggers a heap-based buffer overflow.
nvd
CVE-2019-11338P3HIGHCVSS 8.8v8.0v9.02019-04-19
CVE-2019-11338 [HIGH] CWE-476 CVE-2019-11338: libavcodec/hevcdec.c in FFmpeg 3.4 and 4.1.2 mishandles detection of duplicate first slices, which a libavcodec/hevcdec.c in FFmpeg 3.4 and 4.1.2 mishandles detection of duplicate first slices, which allows remote attackers to cause a denial of service (NULL pointer dereference and out-of-array access) or possibly have unspecified other impact via crafted HEVC data.
nvd
CVE-2019-10903P3HIGHCVSS 7.5v8.0v9.02019-04-09
CVE-2019-10903 [HIGH] CWE-125 CVE-2019-10903: In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the DCERPC SPOOLSS dissector could crash. T In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the DCERPC SPOOLSS dissector could crash. This was addressed in epan/dissectors/packet-dcerpc-spoolss.c by adding a boundary check.
nvd
CVE-2019-10901P3HIGHCVSS 7.5v8.0v9.02019-04-09
CVE-2019-10901 [HIGH] CWE-476 CVE-2019-10901: In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the LDSS dissector could crash. This was ad In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the LDSS dissector could crash. This was addressed in epan/dissectors/packet-ldss.c by handling file digests properly.
nvd
CVE-2023-3338P3MEDIUMCVSS 6.5v10.0v11.02023-06-30
CVE-2023-3338 [MEDIUM] CWE-476 CVE-2023-3338: A null pointer dereference flaw was found in the Linux kernel's DECnet networking protocol. This iss A null pointer dereference flaw was found in the Linux kernel's DECnet networking protocol. This issue could allow a remote user to crash the system.
nvd
Debian Linux vulnerabilities | cvebase