cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 201 of 498
CVE-2019-8075P3HIGHCVSS 7.5v10.02019-09-27
CVE-2019-8075 [HIGH] CVE-2019-8075: Adobe Flash Player version 32.0.0.192 and earlier versions have a Same Origin Policy Bypass vulnerab Adobe Flash Player version 32.0.0.192 and earlier versions have a Same Origin Policy Bypass vulnerability. Successful exploitation could lead to Information Disclosure in the context of the current user.
nvd
CVE-2022-0629P3HIGHCVSS 7.8v10.02022-02-17
CVE-2022-0629 [HIGH] CWE-121 CVE-2022-0629: Stack-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. Stack-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
nvd
CVE-2021-3498P3HIGHCVSS 7.8v10.02021-04-19
CVE-2021-3498 [HIGH] CWE-119 CVE-2021-3498: GStreamer before 1.18.4 might cause heap corruption when parsing certain malformed Matroska files. GStreamer before 1.18.4 might cause heap corruption when parsing certain malformed Matroska files.
nvd
CVE-2022-38178P3HIGHCVSS 7.5v11.02022-09-21
CVE-2022-38178 [HIGH] CWE-401 CVE-2022-38178: By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker ca By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.
nvd
CVE-2022-23098P3HIGHCVSS 7.5v9.0v11.02022-01-28
CVE-2022-23098 [HIGH] CWE-835 CVE-2022-23098: An issue was discovered in the DNS proxy in Connman through 1.40. The TCP server reply implementatio An issue was discovered in the DNS proxy in Connman through 1.40. The TCP server reply implementation has an infinite loop if no data is received.
nvd
CVE-2005-3912P3HIGHCVSS 7.5v3.12005-11-30
CVE-2005-3912 [HIGH] CVE-2005-3912: Format string vulnerability in miniserv.pl Perl web server in Webmin before 1.250 and Usermin before Format string vulnerability in miniserv.pl Perl web server in Webmin before 1.250 and Usermin before 1.180, with syslog logging enabled, allows remote attackers to cause a denial of service (crash or memory consumption) and possibly execute arbitrary code via format string specifiers in the username parameter to the login form, which is ultimately used in a sys
nvd
CVE-2018-7051P3HIGHCVSS 7.5v7.0v9.02018-02-15
CVE-2018-7051 [HIGH] CWE-125 CVE-2018-7051: An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. Certain nick names could resul An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. Certain nick names could result in out-of-bounds access when printing theme strings.
nvd
CVE-2018-1000051P3HIGHCVSS 7.8v8.0v9.02018-02-09
CVE-2018-1000051 [HIGH] CWE-416 CVE-2018-1000051: Artifex Mupdf version 1.12.0 contains a Use After Free vulnerability in fz_keep_key_storable that ca Artifex Mupdf version 1.12.0 contains a Use After Free vulnerability in fz_keep_key_storable that can result in DOS / Possible code execution. This attack appear to be exploitable via Victim opens a specially crafted PDF.
nvd
CVE-2017-7757P3CRITICALCVSS 9.8v8.0v9.02018-06-11
CVE-2017-7757 [CRITICAL] CWE-416 CVE-2017-7757: A use-after-free vulnerability in IndexedDB when one of its objects is destroyed in memory while a m A use-after-free vulnerability in IndexedDB when one of its objects is destroyed in memory while a method on it is still being executed. This results in a potentially exploitable crash. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
nvd
CVE-2017-15572P3HIGHCVSS 7.5v9.02017-10-18
CVE-2017-15572 [HIGH] CWE-532 CVE-2017-15572: In Redmine before 3.2.6 and 3.3.x before 3.3.3, remote attackers can obtain sensitive information (p In Redmine before 3.2.6 and 3.3.x before 3.3.3, remote attackers can obtain sensitive information (password reset tokens) by reading a Referer log, because account/lost_password does not use a redirect.
nvd
CVE-2020-6097P3HIGHCVSS 7.5v9.02020-09-10
CVE-2020-6097 [HIGH] CWE-617 CVE-2020-6097: An exploitable denial of service vulnerability exists in the atftpd daemon functionality of atftp 0. An exploitable denial of service vulnerability exists in the atftpd daemon functionality of atftp 0.7.git20120829-3.1+b1. A specially crafted sequence of RRQ-Multicast requests trigger an assert() call resulting in denial-of-service. An attacker can send a sequence of malicious packets to trigger this vulnerability.
nvd
CVE-2020-6077P3HIGHCVSS 7.5v9.02020-03-24
CVE-2020-6077 [HIGH] CWE-125 CVE-2020-6077: An exploitable denial-of-service vulnerability exists in the message-parsing functionality of Videol An exploitable denial-of-service vulnerability exists in the message-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing mDNS messages, the implementation does not properly keep track of the available data in the message, possibly leading to an out-of-bounds read that would result in a denial of service. An attacker can send an mDNS messa
nvd
CVE-2018-2562P3HIGHCVSS 7.1v7.0v8.0+1 more2018-01-18
CVE-2018-2562 [HIGH] CVE-2018-2562: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server : Partition). Supp Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server : Partition). Supported versions that are affected are 5.5.58 and prior, 5.6.38 and prior and 5.7.19 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnera
nvd
CVE-2020-6080P3HIGHCVSS 7.5v9.0v10.02020-03-24
CVE-2020-6080 [HIGH] CWE-401 CVE-2020-6080: An exploitable denial-of-service vulnerability exists in the resource allocation handling of Videola An exploitable denial-of-service vulnerability exists in the resource allocation handling of Videolabs libmicrodns 0.1.0. When encountering errors while parsing mDNS messages, some allocated data is not freed, possibly leading to a denial-of-service condition via resource exhaustion. An attacker can send one mDNS message repeatedly to trigger this vulne
nvd
CVE-2013-2600P3HIGHCVSS 7.5v8.0v9.0+1 more2019-11-01
CVE-2013-2600 [HIGH] CWE-200 CVE-2013-2600: MiniUPnPd has information disclosure use of snprintf() MiniUPnPd has information disclosure use of snprintf()
nvd
CVE-2017-5470P3CRITICALCVSS 9.8v8.0v9.02018-06-11
CVE-2017-5470 [CRITICAL] CWE-119 CVE-2017-5470: Memory safety bugs were reported in Firefox 53 and Firefox ESR 52.1. Some of these bugs showed evide Memory safety bugs were reported in Firefox 53 and Firefox ESR 52.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
nvd
CVE-2022-2000P3HIGHCVSS 7.8v10.02022-06-09
CVE-2022-2000 [HIGH] CWE-787 CVE-2022-2000: Out-of-bounds Write in GitHub repository vim/vim prior to 8.2. Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.
nvd
CVE-2020-35965P3HIGHCVSS 7.5v9.0v10.02021-01-04
CVE-2020-35965 [HIGH] CWE-787 CVE-2020-35965: decode_frame in libavcodec/exr.c in FFmpeg 4.3.1 has an out-of-bounds write because of errors in cal decode_frame in libavcodec/exr.c in FFmpeg 4.3.1 has an out-of-bounds write because of errors in calculations of when to perform memset zero operations.
nvd
CVE-2021-32920P3HIGHCVSS 7.5v10.02021-05-13
CVE-2021-32920 [HIGH] CVE-2021-32920: Prosody before 0.11.9 allows Uncontrolled CPU Consumption via a flood of SSL/TLS renegotiation reque Prosody before 0.11.9 allows Uncontrolled CPU Consumption via a flood of SSL/TLS renegotiation requests.
nvd
CVE-2021-3546P3HIGHCVSS 8.2v11.02021-06-02
CVE-2021-3546 [HIGH] CWE-787 CVE-2021-3546: An out-of-bounds write vulnerability was found in the virtio vhost-user GPU device (vhost-user-gpu) An out-of-bounds write vulnerability was found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including 6.0. The flaw occurs while processing the 'VIRTIO_GPU_CMD_GET_CAPSET' command from the guest. It could allow a privileged guest user to crash the QEMU process on the host, resulting in a denial of service condition,
nvd
Debian Linux vulnerabilities | cvebase