Debian Linux vulnerabilities
9,954 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4153MEDIUM4310LOW358
Vulnerabilities
Page 196 of 498
CVE-2020-15472P3CRITICALCVSS 9.1v10.02020-07-01
CVE-2020-15472 [CRITICAL] CWE-125 CVE-2020-15472: In nDPI through 3.2, the H.323 dissector is vulnerable to a heap-based buffer over-read in ndpi_sear
In nDPI through 3.2, the H.323 dissector is vulnerable to a heap-based buffer over-read in ndpi_search_h323 in lib/protocols/h323.c, as demonstrated by a payload packet length that is too short.
nvd
CVE-2017-17670P3HIGHCVSS 8.8v9.02017-12-15
CVE-2017-17670 [HIGH] CWE-416 CVE-2017-17670: In VideoLAN VLC media player through 2.2.8, there is a type conversion vulnerability in modules/demu
In VideoLAN VLC media player through 2.2.8, there is a type conversion vulnerability in modules/demux/mp4/libmp4.c in the MP4 demux module leading to a invalid free, because the type of a box may be changed between a read operation and a free operation.
nvd
CVE-2019-9656P3HIGHCVSS 8.8v8.02019-03-11
CVE-2019-9656 [HIGH] CWE-476 CVE-2019-9656: An issue was discovered in LibOFX 0.9.14. There is a NULL pointer dereference in the function OFXApp
An issue was discovered in LibOFX 0.9.14. There is a NULL pointer dereference in the function OFXApplication::startElement in the file lib/ofx_sgml.cpp, as demonstrated by ofxdump.
nvd
CVE-2018-8789P3HIGHCVSS 7.5v8.02018-11-29
CVE-2018-8789 [HIGH] CWE-126 CVE-2018-8789: FreeRDP prior to version 2.0.0-rc4 contains several Out-Of-Bounds Reads in the NTLM Authentication m
FreeRDP prior to version 2.0.0-rc4 contains several Out-Of-Bounds Reads in the NTLM Authentication module that results in a Denial of Service (segfault).
nvd
CVE-2020-12100P3HIGHCVSS 7.5v9.0v10.02020-08-12
CVE-2020-12100 [HIGH] CWE-674 CVE-2020-12100: In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda allows remote attack
In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda allows remote attackers to cause a denial of service (resource consumption) via a crafted e-mail message with deeply nested MIME parts.
nvd
CVE-2022-21682P3MEDIUMCVSS 6.5v9.0v10.0+1 more2022-01-13
CVE-2022-21682 [MEDIUM] CWE-22 CVE-2022-21682: Flatpak is a Linux application sandboxing and distribution framework. A path traversal vulnerability
Flatpak is a Linux application sandboxing and distribution framework. A path traversal vulnerability affects versions of Flatpak prior to 1.12.3 and 1.10.6. flatpak-builder applies `finish-args` last in the build. At this point the build directory will have the full access that is specified in the manifest, so running `flatpak build` against it will
nvd
CVE-2016-3981P3HIGHCVSS 7.8v7.0v8.02016-04-13
CVE-2016-3981 [HIGH] CWE-119 CVE-2016-3981: Heap-based buffer overflow in the bmp_read_rows function in pngxrbmp.c in OptiPNG before 0.7.6 allow
Heap-based buffer overflow in the bmp_read_rows function in pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (out-of-bounds read or write access and crash) or possibly execute arbitrary code via a crafted image file.
nvd
CVE-2017-17502P3HIGHCVSS 8.8v7.0v8.0+1 more2017-12-11
CVE-2017-17502 [HIGH] CWE-125 CVE-2017-17502: ReadCMYKImage in coders/cmyk.c in GraphicsMagick 1.3.26 has a magick/import.c ImportCMYKQuantumType
ReadCMYKImage in coders/cmyk.c in GraphicsMagick 1.3.26 has a magick/import.c ImportCMYKQuantumType heap-based buffer over-read via a crafted file.
nvd
CVE-2017-17503P3HIGHCVSS 8.8v7.0v8.0+1 more2017-12-11
CVE-2017-17503 [HIGH] CWE-125 CVE-2017-17503: ReadGRAYImage in coders/gray.c in GraphicsMagick 1.3.26 has a magick/import.c ImportGrayQuantumType
ReadGRAYImage in coders/gray.c in GraphicsMagick 1.3.26 has a magick/import.c ImportGrayQuantumType heap-based buffer over-read via a crafted file.
nvd
CVE-2014-9087P3HIGHCVSS 7.5v7.0v8.02014-12-01
CVE-2014-9087 [HIGH] CWE-191 CVE-2014-9087: Integer underflow in the ksba_oid_to_str function in Libksba before 1.3.2, as used in GnuPG, allows
Integer underflow in the ksba_oid_to_str function in Libksba before 1.3.2, as used in GnuPG, allows remote attackers to cause a denial of service (crash) via a crafted OID in a (1) S/MIME message or (2) ECC based OpenPGP data, which triggers a buffer overflow.
nvd
CVE-2019-16201P3HIGHCVSS 7.5v8.02019-11-26
CVE-2019-16201 [HIGH] CWE-287 CVE-2019-16201: WEBrick::HTTPAuth::DigestAuth in Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 ha
WEBrick::HTTPAuth::DigestAuth in Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 has a regular expression Denial of Service cause by looping/backtracking. A victim must expose a WEBrick server that uses DigestAuth to the Internet or a untrusted network.
nvd
CVE-2005-2498P3HIGHCVSS 7.5v3.12005-08-15
CVE-2005-2498 [HIGH] CVE-2005-2498: Eval injection vulnerability in PHPXMLRPC 1.1.1 and earlier (PEAR XML-RPC for PHP), as used in multi
Eval injection vulnerability in PHPXMLRPC 1.1.1 and earlier (PEAR XML-RPC for PHP), as used in multiple products including (1) Drupal, (2) phpAdsNew, (3) phpPgAds, and (4) phpgroupware, allows remote attackers to execute arbitrary PHP code via certain nested XML tags in a PHP document that should not be nested, which are injected into an eval function call, a d
nvd
CVE-2017-9064P3HIGHCVSS 8.8v8.0v9.02017-05-18
CVE-2017-9064 [HIGH] CWE-352 CVE-2017-9064: In WordPress before 4.7.5, a Cross Site Request Forgery (CSRF) vulnerability exists in the filesyste
In WordPress before 4.7.5, a Cross Site Request Forgery (CSRF) vulnerability exists in the filesystem credentials dialog because a nonce is not required for updating credentials.
nvd
CVE-2003-0358P4MEDIUMCVSS 4.6PoCv2.2v3.02003-06-09
CVE-2003-0358 [MEDIUM] CWE-120 CVE-2003-0358: Buffer overflow in (1) nethack 3.4.0 and earlier, and (2) falconseye 1.9.3 and earlier, which is bas
Buffer overflow in (1) nethack 3.4.0 and earlier, and (2) falconseye 1.9.3 and earlier, which is based on nethack, allows local users to gain privileges via a long -s command line option.
nvd
CVE-2021-39924P3HIGHCVSS 7.5v9.02021-11-19
CVE-2021-39924 [HIGH] CWE-834 CVE-2021-39924: Large loop in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows den
Large loop in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
nvd
CVE-2014-4049P3MEDIUMCVSS 5.1v7.0v8.02014-06-18
CVE-2014-4049 [MEDIUM] CWE-119 CVE-2014-4049: Heap-based buffer overflow in the php_parserr function in ext/standard/dns.c in PHP 5.6.0beta4 and e
Heap-based buffer overflow in the php_parserr function in ext/standard/dns.c in PHP 5.6.0beta4 and earlier allows remote servers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted DNS TXT record, related to the dns_get_record function.
nvd
CVE-2023-45866P3MEDIUMCVSS 6.3v10.02023-12-08
CVE-2023-45866 [MEDIUM] CVE-2023-45866: Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate an
Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example affected package is bluez 5.64-0ubuntu1 in Ub
nvd
CVE-2007-6353P3HIGHCVSS 7.5v3.1v4.02007-12-20
CVE-2007-6353 [HIGH] CWE-190 CVE-2007-6353: Integer overflow in exif.cpp in exiv2 library allows context-dependent attackers to execute arbitrar
Integer overflow in exif.cpp in exiv2 library allows context-dependent attackers to execute arbitrary code via a crafted EXIF file that triggers a heap-based buffer overflow.
nvd
CVE-2021-38504P3HIGHCVSS 8.8v9.0v10.0+1 more2021-12-08
CVE-2021-38504 [HIGH] CWE-416 CVE-2021-38504: When interacting with an HTML input element's file picker dialog with webkitdirectory set, a use-aft
When interacting with an HTML input element's file picker dialog with webkitdirectory set, a use-after-free could have resulted, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
nvd
CVE-2015-6525P3HIGHCVSS 7.5v7.12015-08-24
CVE-2015-6525 [HIGH] CVE-2015-6525: Multiple integer overflows in the evbuffer API in Libevent 2.0.x before 2.0.22 and 2.1.x before 2.1.
Multiple integer overflows in the evbuffer API in Libevent 2.0.x before 2.0.22 and 2.1.x before 2.1.5-beta allow context-dependent attackers to cause a denial of service or possibly have other unspecified impact via "insanely large inputs" to the (1) evbuffer_add, (2) evbuffer_prepend, (3) evbuffer_expand, (4) exbuffer_reserve_space, or (5) evbuffer_read functi
nvd