cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 200 of 498
CVE-2017-8823P3HIGHCVSS 8.1v8.0v9.02017-12-03
CVE-2017-8823 [HIGH] CWE-416 CVE-2017-8823: In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3 In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, there is a use-after-free in onion service v2 during intro-point expiration because the expiring list is mismanaged in certain error cases, aka TROVE-2017-013.
nvd
CVE-2017-12896P3CRITICALCVSS 9.8v9.0v10.02017-09-14
CVE-2017-12896 [CRITICAL] CWE-125 CVE-2017-12896: The ISAKMP parser in tcpdump before 4.9.2 has a buffer over-read in print-isakmp.c:isakmp_rfc3948_pr The ISAKMP parser in tcpdump before 4.9.2 has a buffer over-read in print-isakmp.c:isakmp_rfc3948_print().
nvd
CVE-2017-12899P3CRITICALCVSS 9.8v9.0v10.02017-09-14
CVE-2017-12899 [CRITICAL] CWE-125 CVE-2017-12899: The DECnet parser in tcpdump before 4.9.2 has a buffer over-read in print-decnet.c:decnet_print(). The DECnet parser in tcpdump before 4.9.2 has a buffer over-read in print-decnet.c:decnet_print().
nvd
CVE-2017-13020P3CRITICALCVSS 9.8v8.0v9.0+1 more2017-09-14
CVE-2017-13020 [CRITICAL] CWE-125 CVE-2017-13020: The VTP parser in tcpdump before 4.9.2 has a buffer over-read in print-vtp.c:vtp_print(). The VTP parser in tcpdump before 4.9.2 has a buffer over-read in print-vtp.c:vtp_print().
nvd
CVE-2020-6079P3HIGHCVSS 7.5v9.0v10.02020-03-24
CVE-2020-6079 [HIGH] CWE-401 CVE-2020-6079: An exploitable denial-of-service vulnerability exists in the resource allocation handling of Videola An exploitable denial-of-service vulnerability exists in the resource allocation handling of Videolabs libmicrodns 0.1.0. When encountering errors while parsing mDNS messages, some allocated data is not freed, possibly leading to a denial-of-service condition via resource exhaustion. An attacker can send one mDNS message repeatedly to trigger this vulne
nvd
CVE-2021-27219P3HIGHCVSS 7.5v9.02021-02-15
CVE-2021-27219 [HIGH] CWE-681 CVE-2021-27219: An issue was discovered in GNOME GLib before 2.66.6 and 2.67.x before 2.67.3. The function g_bytes_n An issue was discovered in GNOME GLib before 2.66.6 and 2.67.x before 2.67.3. The function g_bytes_new has an integer overflow on 64-bit platforms due to an implicit cast from 64 bits to 32 bits. The overflow could potentially lead to memory corruption.
nvd
CVE-2023-36053P3HIGHCVSS 7.5v10.0v11.0+1 more2023-07-03
CVE-2023-36053 [HIGH] CWE-1333 CVE-2023-36053: In Django 3.2 before 3.2.20, 4 before 4.1.10, and 4.2 before 4.2.3, EmailValidator and URLValidator In Django 3.2 before 3.2.20, 4 before 4.1.10, and 4.2 before 4.2.3, EmailValidator and URLValidator are subject to a potential ReDoS (regular expression denial of service) attack via a very large number of domain name labels of emails and URLs.
nvd
CVE-2018-16802P3HIGHCVSS 7.8v8.0v9.02018-09-10
CVE-2018-16802 [HIGH] CVE-2018-16802: An issue was discovered in Artifex Ghostscript before 9.25. Incorrect "restoration of privilege" che An issue was discovered in Artifex Ghostscript before 9.25. Incorrect "restoration of privilege" checking when running out of stack during exception handling could be used by attackers able to supply crafted PostScript to execute code using the "pipe" instruction. This is due to an incomplete fix for CVE-2018-16509.
nvd
CVE-2017-16853P3HIGHCVSS 8.1v8.0v9.02017-11-16
CVE-2017-16853 [HIGH] CWE-347 CVE-2017-16853: The DynamicMetadataProvider class in saml/saml2/metadata/impl/DynamicMetadataProvider.cpp in OpenSAM The DynamicMetadataProvider class in saml/saml2/metadata/impl/DynamicMetadataProvider.cpp in OpenSAML-C in OpenSAML before 2.6.1 fails to properly configure itself with the MetadataFilter plugins and does not perform critical security checks such as signature verification, enforcement of validity periods, and other checks specific to deployments, aka
nvd
CVE-2019-19448P3HIGHCVSS 7.8v9.02019-12-08
CVE-2019-19448 [HIGH] CWE-416 CVE-2019-19448: In the Linux kernel 5.0.21 and 5.3.11, mounting a crafted btrfs filesystem image, performing some op In the Linux kernel 5.0.21 and 5.3.11, mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in try_merge_free_space in fs/btrfs/free-space-cache.c because the pointer to a left data structure can be the same as the pointer to a right data structure.
nvd
CVE-2017-6470P3HIGHCVSS 7.5v8.02017-03-04
CVE-2017-6470 [HIGH] CWE-835 CVE-2017-6470: In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is an IAX2 infinite loop, triggered by packet In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is an IAX2 infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-iax2.c by constraining packet lateness.
nvd
CVE-2019-1010006P3HIGHCVSS 7.8v8.0v9.0+1 more2019-07-15
CVE-2019-1010006 [HIGH] CWE-190 CVE-2019-1010006: Evince 3.26.0 is affected by buffer overflow. The impact is: DOS / Possible code execution. The comp Evince 3.26.0 is affected by buffer overflow. The impact is: DOS / Possible code execution. The component is: backend/tiff/tiff-document.c. The attack vector is: Victim must open a crafted PDF file. The issue occurs because of an incorrect integer overflow protection mechanism in tiff_document_render and tiff_document_get_thumbnail.
nvd
CVE-2020-14400P3HIGHCVSS 7.5v8.0v9.02020-06-17
CVE-2020-14400 [HIGH] CVE-2020-14400: An issue was discovered in LibVNCServer before 0.9.13. Byte-aligned data is accessed through uint16_ An issue was discovered in LibVNCServer before 0.9.13. Byte-aligned data is accessed through uint16_t pointers in libvncserver/translate.c. NOTE: Third parties do not consider this to be a vulnerability as there is no known path of exploitation or cross of a trust boundary
nvd
CVE-2022-23772P3HIGHCVSS 7.5v9.02022-02-11
CVE-2022-23772 [HIGH] CWE-190 CVE-2022-23772: Rat.SetString in math/big in Go before 1.16.14 and 1.17.x before 1.17.7 has an overflow that can lea Rat.SetString in math/big in Go before 1.16.14 and 1.17.x before 1.17.7 has an overflow that can lead to Uncontrolled Memory Consumption.
nvd
CVE-2020-14399P3HIGHCVSS 7.5v8.0v9.02020-06-17
CVE-2020-14399 [HIGH] CVE-2020-14399: An issue was discovered in LibVNCServer before 0.9.13. Byte-aligned data is accessed through uint32_ An issue was discovered in LibVNCServer before 0.9.13. Byte-aligned data is accessed through uint32_t pointers in libvncclient/rfbproto.c. NOTE: there is reportedly "no trust boundary crossed.
nvd
CVE-2018-2634P3MEDIUMCVSS 6.8v7.0v8.0+1 more2018-01-18
CVE-2018-2634 [MEDIUM] CVE-2018-2634: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JGSS). Sup Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JGSS). Supported versions that are affected are Java SE: 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. While the vuln
nvd
CVE-2022-26353P3HIGHCVSS 7.5v11.02022-03-16
CVE-2022-26353 [HIGH] CVE-2022-26353: A flaw was found in the virtio-net device of QEMU. This flaw was inadvertently introduced with the f A flaw was found in the virtio-net device of QEMU. This flaw was inadvertently introduced with the fix for CVE-2021-3748, which forgot to unmap the cached virtqueue elements on error, leading to memory leakage and other unexpected results. Affected QEMU version: 6.2.0.
nvd
CVE-2021-3580P3HIGHCVSS 7.5v9.02021-08-05
CVE-2021-3580 [HIGH] CWE-20 CVE-2021-3580: A flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext. A flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext. An attacker could use this flaw to provide a manipulated ciphertext leading to application crash and denial of service.
nvd
CVE-2018-15908P3HIGHCVSS 7.8v8.0v9.02018-08-27
CVE-2018-15908 [HIGH] CVE-2018-15908: In Artifex Ghostscript 9.23 before 2018-08-23, attackers are able to supply malicious PostScript fil In Artifex Ghostscript 9.23 before 2018-08-23, attackers are able to supply malicious PostScript files to bypass .tempfile restrictions and write files.
nvd
CVE-2022-38177P3HIGHCVSS 7.5v10.0v11.02022-09-21
CVE-2022-38177 [HIGH] CWE-401 CVE-2022-38177: By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker ca By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.
nvd
Debian Linux vulnerabilities | cvebase