cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 197 of 498
CVE-2015-6525P3HIGHCVSS 7.5v7.12015-08-24
CVE-2015-6525 [HIGH] CVE-2015-6525: Multiple integer overflows in the evbuffer API in Libevent 2.0.x before 2.0.22 and 2.1.x before 2.1. Multiple integer overflows in the evbuffer API in Libevent 2.0.x before 2.0.22 and 2.1.x before 2.1.5-beta allow context-dependent attackers to cause a denial of service or possibly have other unspecified impact via "insanely large inputs" to the (1) evbuffer_add, (2) evbuffer_prepend, (3) evbuffer_expand, (4) exbuffer_reserve_space, or (5) evbuffer_read functi
nvd
CVE-2019-7635P3HIGHCVSS 8.1v8.0v9.02019-02-08
CVE-2019-7635 [HIGH] CWE-125 CVE-2019-7635: SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-rea SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in Blit1to4 in video/SDL_blit_1.c.
nvd
CVE-2007-1887P3HIGHCVSS 7.5v4.02007-04-06
CVE-2007-1887 [HIGH] CWE-120 CVE-2007-1887: Buffer overflow in the sqlite_decode_binary function in the bundled sqlite library in PHP 4 before 4 Buffer overflow in the sqlite_decode_binary function in the bundled sqlite library in PHP 4 before 4.4.5 and PHP 5 before 5.2.1 allows context-dependent attackers to execute arbitrary code via an empty value of the in parameter, as demonstrated by calling the sqlite_udf_decode_binary function with a 0x01 character.
nvd
CVE-2018-6071P3HIGHCVSS 8.8v9.02018-11-14
CVE-2018-6071 [HIGH] CWE-125 CVE-2018-6071: An integer overflow in Skia in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to per An integer overflow in Skia in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
nvd
CVE-2017-13748P3HIGHCVSS 7.5v8.02017-08-29
CVE-2017-13748 [HIGH] CWE-772 CVE-2017-13748: There are lots of memory leaks in JasPer 2.0.12, triggered in the function jas_strdup() in base/jas_ There are lots of memory leaks in JasPer 2.0.12, triggered in the function jas_strdup() in base/jas_string.c, that will lead to a remote denial of service attack.
nvd
CVE-2014-9653P3HIGHCVSS 7.5v7.02015-03-30
CVE-2014-9653 [HIGH] CWE-20 CVE-2014-9653: readelf.c in file before 5.22, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before readelf.c in file before 5.22, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not consider that pread calls sometimes read only a subset of the available data, which allows remote attackers to cause a denial of service (uninitialized memory access) or possibly have unspecified other impact via a c
nvd
CVE-2018-8764P3HIGHCVSS 8.8v8.0v9.02018-03-27
CVE-2018-8764 [HIGH] CWE-352 CVE-2018-8764: Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 places a CSRF token in the sec_tok Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 places a CSRF token in the sec_token parameter of a URI, which makes it easier for remote attackers to defeat a CSRF protection mechanism by leveraging logging.
nvd
CVE-2018-17963P3CRITICALCVSS 9.8v8.0v9.02018-10-09
CVE-2018-17963 [CRITICAL] CWE-190 CVE-2018-17963: qemu_deliver_packet_iov in net/net.c in Qemu accepts packet sizes greater than INT_MAX, which allows qemu_deliver_packet_iov in net/net.c in Qemu accepts packet sizes greater than INT_MAX, which allows attackers to cause a denial of service or possibly have unspecified other impact.
nvd
CVE-2017-5100P3HIGHCVSS 8.8v9.02017-10-27
CVE-2017-5100 [HIGH] CWE-416 CVE-2017-5100: A use after free in Apps in Google Chrome prior to 60.0.3112.78 for Windows allowed a remote attacke A use after free in Apps in Google Chrome prior to 60.0.3112.78 for Windows allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
nvd
CVE-2022-24807P3MEDIUMCVSS 6.5v10.0v11.02024-04-16
CVE-2022-24807 [MEDIUM] CWE-120 CVE-2022-24807: net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a malformed OID in a SET request to `SNMP-VIEW-BASED-ACM-MIB::vacmAccessTable` can cause an out-of-bounds memory access. A user with read-write credentials can exploit the issue. Version 5.9.2 contains a patch. Users should use strong SNMPv3 c
nvd
CVE-2022-47950P3MEDIUMCVSS 6.5v10.02023-01-18
CVE-2022-47950 [MEDIUM] CWE-552 CVE-2022-47950: An issue was discovered in OpenStack Swift before 2.28.1, 2.29.x before 2.29.2, and 2.30.0. By suppl An issue was discovered in OpenStack Swift before 2.28.1, 2.29.x before 2.29.2, and 2.30.0. By supplying crafted XML files, an authenticated user may coerce the S3 API into returning arbitrary file contents from the host server, resulting in unauthorized read access to potentially sensitive data. This impacts both s3api deployments (Rocky or later),
nvd
CVE-2020-13871P3HIGHCVSS 7.5v9.02020-06-06
CVE-2020-13871 [HIGH] CWE-416 CVE-2020-13871: SQLite 3.32.2 has a use-after-free in resetAccumulator in select.c because the parse tree rewrite fo SQLite 3.32.2 has a use-after-free in resetAccumulator in select.c because the parse tree rewrite for window functions is too late.
nvd
CVE-2020-12243P3HIGHCVSS 7.5v8.0v9.0+1 more2020-04-28
CVE-2020-12243 [HIGH] CWE-674 CVE-2020-12243: In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean expressions In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean expressions can result in denial of service (daemon crash).
nvd
CVE-2020-7663P3HIGHCVSS 7.5v9.02020-06-02
CVE-2020-7663 [HIGH] CVE-2020-7663: websocket-extensions ruby module prior to 0.1.5 allows Denial of Service (DoS) via Regex Backtrackin websocket-extensions ruby module prior to 0.1.5 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take quadratic time when parsing a header containing an unclosed string parameter value whose content is a repeating two-byte sequence of a backslash and some other character. This could be abused by an attacker to conduct Regex Denial
nvd
CVE-2008-4360P3HIGHCVSS 7.5v4.02008-10-03
CVE-2008-4360 [HIGH] CWE-200 CVE-2008-4360: mod_userdir in lighttpd before 1.4.20, when a case-insensitive operating system or filesystem is use mod_userdir in lighttpd before 1.4.20, when a case-insensitive operating system or filesystem is used, performs case-sensitive comparisons on filename components in configuration options, which might allow remote attackers to bypass intended access restrictions, as demonstrated by a request for a .PHP file when there is a configuration rule for .php fil
nvd
CVE-2018-16451P3HIGHCVSS 7.5v8.0v9.0+1 more2019-10-03
CVE-2018-16451 [HIGH] CWE-125 CVE-2018-16451: The SMB parser in tcpdump before 4.9.3 has buffer over-reads in print-smb.c:print_trans() for \MAILS The SMB parser in tcpdump before 4.9.3 has buffer over-reads in print-smb.c:print_trans() for \MAILSLOT\BROWSE and \PIPE\LANMAN.
nvd
CVE-2009-1891P3HIGHCVSS 7.1v4.0v5.0+1 more2009-07-10
CVE-2009-1891 [HIGH] CWE-400 CVE-2009-1891: The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion ev The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion even after the associated network connection is closed, which allows remote attackers to cause a denial of service (CPU consumption).
nvd
CVE-2017-9524P3HIGHCVSS 7.5v9.02017-07-06
CVE-2017-9524 [HIGH] CWE-20 CVE-2017-9524: The qemu-nbd server in QEMU (aka Quick Emulator), when built with the Network Block Device (NBD) Ser The qemu-nbd server in QEMU (aka Quick Emulator), when built with the Network Block Device (NBD) Server support, allows remote attackers to cause a denial of service (segmentation fault and server crash) by leveraging failure to ensure that all initialization occurs before talking to a client in the nbd_negotiate function.
nvd
CVE-2008-2108P3CRITICALCVSS 9.8v4.02008-05-07
CVE-2008-2108 [CRITICAL] CWE-331 CVE-2008-2108: The GENERATE_SEED macro in PHP 4.x before 4.4.8 and 5.x before 5.2.5, when running on 64-bit systems The GENERATE_SEED macro in PHP 4.x before 4.4.8 and 5.x before 5.2.5, when running on 64-bit systems, performs a multiplication that generates a portion of zero bits during conversion due to insufficient precision, which produces 24 bits of entropy and simplifies brute force attacks against protection mechanisms that use the rand and mt_rand functio
nvd
CVE-2021-44227P3HIGHCVSS 8.8v9.02021-12-02
CVE-2021-44227 [HIGH] CWE-352 CVE-2021-44227: In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin req In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin request (using that token) to set a new admin password or make other changes.
nvd
Debian Linux vulnerabilities | cvebase