cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 198 of 498
CVE-2021-27291P3HIGHCVSS 7.5v9.0v10.02021-03-17
CVE-2021-27291 [HIGH] CWE-1333 CVE-2021-27291: In pygments 1.1+, fixed in 2.7.4, the lexers used to parse programming languages rely heavily on reg In pygments 1.1+, fixed in 2.7.4, the lexers used to parse programming languages rely heavily on regular expressions. Some of the regular expressions have exponential or cubic worst-case complexity and are vulnerable to ReDoS. By crafting malicious input, an attacker can cause a denial of service.
nvd
CVE-2014-1481P3HIGHCVSS 7.5v7.02014-02-06
CVE-2014-1481 [HIGH] CVE-2014-1481: Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey be Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allow remote attackers to bypass intended restrictions on window objects by leveraging inconsistency in native getter methods across different JavaScript engines.
nvd
CVE-2018-14622P3HIGHCVSS 7.5v8.02018-08-30
CVE-2018-14622 [HIGH] CWE-252 CVE-2018-14622: A null-pointer dereference vulnerability was found in libtirpc before version 0.3.3-rc3. The return A null-pointer dereference vulnerability was found in libtirpc before version 0.3.3-rc3. The return value of makefd_xprt() was not checked in all instances, which could lead to a crash when the server exhausted the maximum number of available file descriptors. A remote attacker could cause an rpc-based application to crash by flooding it with new conne
nvd
CVE-2017-9766P3HIGHCVSS 7.5v8.02017-06-21
CVE-2017-9766 [HIGH] CWE-674 CVE-2017-9766: In Wireshark 2.2.7, PROFINET IO data with a high recursion depth allows remote attackers to cause a In Wireshark 2.2.7, PROFINET IO data with a high recursion depth allows remote attackers to cause a denial of service (stack exhaustion) in the dissect_IODWriteReq function in plugins/profinet/packet-dcerpc-pn-io.c.
nvd
CVE-2014-0021P3HIGHCVSS 7.5v8.0v9.0+1 more2019-11-15
CVE-2014-0021 [HIGH] CVE-2014-0021: Chrony before 1.29.1 has traffic amplification in cmdmon protocol Chrony before 1.29.1 has traffic amplification in cmdmon protocol
nvd
CVE-2014-3468P3HIGHCVSS 7.5v7.02014-06-05
CVE-2014-3468 [HIGH] CWE-131 CVE-2014-3468: The asn1_get_bit_der function in GNU Libtasn1 before 3.6 does not properly report an error when a ne The asn1_get_bit_der function in GNU Libtasn1 before 3.6 does not properly report an error when a negative bit length is identified, which allows context-dependent attackers to cause out-of-bounds access via crafted ASN.1 data.
nvd
CVE-2018-14368P3HIGHCVSS 7.5v8.02018-07-19
CVE-2018-14368 [HIGH] CWE-835 CVE-2018-14368: In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the Bazaar protocol dissector coul In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the Bazaar protocol dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-bzr.c by properly handling items that are too long.
nvd
CVE-2018-15909P3HIGHCVSS 7.8v8.02018-08-27
CVE-2018-15909 [HIGH] CWE-704 CVE-2018-15909: In Artifex Ghostscript 9.23 before 2018-08-24, a type confusion using the .shfill operator could be In Artifex Ghostscript 9.23 before 2018-08-24, a type confusion using the .shfill operator could be used by attackers able to supply crafted PostScript files to crash the interpreter or potentially execute code.
nvd
CVE-2018-7541P3HIGHCVSS 8.8v9.02018-02-27
CVE-2018-7541 [HIGH] CVE-2018-7541: An issue was discovered in Xen through 4.10.x allowing guest OS users to cause a denial of service ( An issue was discovered in Xen through 4.10.x allowing guest OS users to cause a denial of service (hypervisor crash) or gain privileges by triggering a grant-table transition from v2 to v1.
nvd
CVE-2018-14341P3HIGHCVSS 7.5v8.02018-07-19
CVE-2018-14341 [HIGH] CWE-190 CVE-2018-14341: In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the DICOM dissector could go into In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the DICOM dissector could go into a large or infinite loop. This was addressed in epan/dissectors/packet-dcm.c by preventing an offset overflow.
nvd
CVE-2020-13113P3HIGHCVSS 8.2v8.02020-05-21
CVE-2020-13113 [HIGH] CWE-908 CVE-2020-13113: An issue was discovered in libexif before 0.6.22. Use of uninitialized memory in EXIF Makernote hand An issue was discovered in libexif before 0.6.22. Use of uninitialized memory in EXIF Makernote handling could lead to crashes and potential use-after-free conditions.
nvd
CVE-2018-5996P3HIGHCVSS 7.8v7.0v8.0+1 more2018-01-31
CVE-2018-5996 [HIGH] CWE-119 CVE-2018-5996: Insufficient exception handling in the method NCompress::NRar3::CDecoder::Code of 7-Zip before 18.00 Insufficient exception handling in the method NCompress::NRar3::CDecoder::Code of 7-Zip before 18.00 and p7zip can lead to multiple memory corruptions within the PPMd code, allows remote attackers to cause a denial of service (segmentation fault) or execute arbitrary code via a crafted RAR archive.
nvd
CVE-2016-5424P3HIGHCVSS 7.1v8.02016-12-09
CVE-2016-5424 [HIGH] CWE-94 CVE-2016-5424: PostgreSQL before 9.1.23, 9.2.x before 9.2.18, 9.3.x before 9.3.14, 9.4.x before 9.4.9, and 9.5.x be PostgreSQL before 9.1.23, 9.2.x before 9.2.18, 9.3.x before 9.3.14, 9.4.x before 9.4.9, and 9.5.x before 9.5.4 might allow remote authenticated users with the CREATEDB or CREATEROLE role to gain superuser privileges via a (1) " (double quote), (2) \ (backslash), (3) carriage return, or (4) newline character in a (a) database or (b) role name that is mish
nvd
CVE-2019-20839P3HIGHCVSS 7.5v8.0v9.02020-06-17
CVE-2019-20839 [HIGH] CWE-120 CVE-2019-20839: libvncclient/sockets.c in LibVNCServer before 0.9.13 has a buffer overflow via a long socket filenam libvncclient/sockets.c in LibVNCServer before 0.9.13 has a buffer overflow via a long socket filename.
nvd
CVE-2020-12663P3HIGHCVSS 7.5v9.0v10.02020-05-19
CVE-2020-12663 [HIGH] CWE-835 CVE-2020-12663: Unbound before 1.10.1 has an infinite loop via malformed DNS answers received from upstream servers. Unbound before 1.10.1 has an infinite loop via malformed DNS answers received from upstream servers.
nvd
CVE-2020-14147P3HIGHCVSS 7.7v10.02020-06-15
CVE-2020-14147 [HIGH] CVE-2020-14147: An integer overflow in the getnum function in lua_struct.c in Redis before 6.0.3 allows context-depe An integer overflow in the getnum function in lua_struct.c in Redis before 6.0.3 allows context-dependent attackers with permission to run Lua code in a Redis session to cause a denial of service (memory corruption and application crash) or possibly bypass intended sandbox restrictions via a large number, which triggers a stack-based buffer overflow. NOTE: th
nvd
CVE-2017-13139P3CRITICALCVSS 9.8v8.0v9.02017-08-23
CVE-2017-13139 [CRITICAL] CWE-125 CVE-2017-13139: In ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1, the ReadOneMNGImage function in coders/png.c h In ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1, the ReadOneMNGImage function in coders/png.c has an out-of-bounds read with the MNG CLIP chunk.
nvd
CVE-2021-39929P3HIGHCVSS 7.5v9.0v10.0+1 more2021-11-19
CVE-2021-39929 [HIGH] CWE-674 CVE-2021-39929: Uncontrolled Recursion in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.1 Uncontrolled Recursion in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
nvd
CVE-2022-42309P3HIGHCVSS 8.8v11.02022-11-01
CVE-2022-42309 [HIGH] CWE-763 CVE-2022-42309: Xenstore: Guests can crash xenstored Due to a bug in the fix of XSA-115 a malicious guest can cause Xenstore: Guests can crash xenstored Due to a bug in the fix of XSA-115 a malicious guest can cause xenstored to use a wrong pointer during node creation in an error path, resulting in a crash of xenstored or a memory corruption in xenstored causing further damage. Entering the error path can be controlled by the guest e.g. by exceeding the quota value
nvd
CVE-2018-1000099P3HIGHCVSS 7.5v9.02018-03-13
CVE-2018-1000099 [HIGH] CWE-824 CVE-2018-1000099: Teluu PJSIP version 2.7.1 and earlier contains a Access of Null/Uninitialized Pointer vulnerability Teluu PJSIP version 2.7.1 and earlier contains a Access of Null/Uninitialized Pointer vulnerability in pjmedia SDP parsing that can result in Crash. This attack appear to be exploitable via Sending a specially crafted message. This vulnerability appears to have been fixed in 2.7.2.
nvd
Debian Linux vulnerabilities | cvebase