cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 210 of 498
CVE-2019-8907P3HIGHCVSS 8.8v8.02019-02-18
CVE-2019-8907 [HIGH] CWE-787 CVE-2019-8907: do_core_note in readelf.c in libmagic.a in file 5.35 allows remote attackers to cause a denial of se do_core_note in readelf.c in libmagic.a in file 5.35 allows remote attackers to cause a denial of service (stack corruption and application crash) or possibly have unspecified other impact.
nvd
CVE-2024-1546P3HIGHCVSS 7.5v10.02024-02-20
CVE-2024-1546 [HIGH] CWE-125 CVE-2024-1546: When storing and re-accessing data on a networking channel, the length of buffers may have been conf When storing and re-accessing data on a networking channel, the length of buffers may have been confused, resulting in an out-of-bounds memory read. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.
nvd
CVE-2017-2834P3HIGHCVSS 7.0v8.0v9.02018-04-24
CVE-2017-2834 [HIGH] CWE-787 CVE-2017-2834: An exploitable code execution vulnerability exists in the authentication functionality of FreeRDP 2. An exploitable code execution vulnerability exists in the authentication functionality of FreeRDP 2.0.0-beta1+android11. A specially crafted server response can cause an out-of-bounds write resulting in an exploitable condition. An attacker can compromise the server or use a man in the middle attack to trigger this vulnerability.
nvd
CVE-2025-43965P3HIGHCVSS 7.5v11.02025-04-23
CVE-2025-43965 [HIGH] CWE-131 CVE-2025-43965: In MIFF image processing in ImageMagick before 7.1.1-44, image depth is mishandled after SetQuantumF In MIFF image processing in ImageMagick before 7.1.1-44, image depth is mishandled after SetQuantumFormat is used.
nvd
CVE-2020-14355P3MEDIUMCVSS 6.6v9.02020-10-07
CVE-2020-14355 [MEDIUM] CWE-120 CVE-2020-14355: Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws. These flaws allow a malicious client or server to send specially crafted messages that, when processed by the QUIC image compression
nvd
CVE-2018-17101P3HIGHCVSS 8.8v8.0v9.02018-09-16
CVE-2018-17101 [HIGH] CWE-787 CVE-2018-17101: An issue was discovered in LibTIFF 4.0.9. There are two out-of-bounds writes in cpTags in tools/tiff An issue was discovered in LibTIFF 4.0.9. There are two out-of-bounds writes in cpTags in tools/tiff2bw.c and tools/pal2rgb.c, which can cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image file.
nvd
CVE-2021-3713P3HIGHCVSS 7.4v9.0v10.0+1 more2021-08-25
CVE-2021-3713 [HIGH] CWE-787 CVE-2021-3713: An out-of-bounds write flaw was found in the UAS (USB Attached SCSI) device emulation of QEMU in ver An out-of-bounds write flaw was found in the UAS (USB Attached SCSI) device emulation of QEMU in versions prior to 6.2.0-rc0. The device uses the guest supplied stream number unchecked, which can lead to out-of-bounds access to the UASDevice->data3 and UASDevice->status3 fields. A malicious guest user could use this flaw to crash QEMU or potentially ach
nvd
CVE-2015-5177P3HIGHCVSS 7.5v7.0v8.02017-10-22
CVE-2015-5177 [HIGH] CWE-415 CVE-2015-5177: Double free vulnerability in the SLPDKnownDAAdd function in slpd/slpd_knownda.c in OpenSLP 1.2.1 all Double free vulnerability in the SLPDKnownDAAdd function in slpd/slpd_knownda.c in OpenSLP 1.2.1 allows remote attackers to cause a denial of service (crash) via a crafted package.
nvd
CVE-2010-3432P3HIGHCVSS 7.8v5.02010-11-22
CVE-2010-3432 [HIGH] CWE-20 CVE-2010-3432: The sctp_packet_config function in net/sctp/output.c in the Linux kernel before 2.6.35.6 performs ex The sctp_packet_config function in net/sctp/output.c in the Linux kernel before 2.6.35.6 performs extraneous initializations of packet data structures, which allows remote attackers to cause a denial of service (panic) via a certain sequence of SCTP traffic.
nvd
CVE-2018-10871P3HIGHCVSS 7.2v8.02018-07-18
CVE-2018-10871 [HIGH] CWE-312 CVE-2018-10871: 389-ds-base before versions 1.3.8.5, 1.4.0.12 is vulnerable to a Cleartext Storage of Sensitive Info 389-ds-base before versions 1.3.8.5, 1.4.0.12 is vulnerable to a Cleartext Storage of Sensitive Information. By default, when the Replica and/or retroChangeLog plugins are enabled, 389-ds-base stores passwords in plaintext format in their respective changelog files. An attacker with sufficiently high privileges, such as root or Directory Manager, can
nvd
CVE-2026-1940P3HIGHCVSS 7.5v11.0v12.02026-03-23
CVE-2026-1940 [HIGH] CVE-2026-1940: An incomplete fix for CVE-2024-47778 allows an out-of-bounds read in gst_wavparse_adtl_chunk() funct An incomplete fix for CVE-2024-47778 allows an out-of-bounds read in gst_wavparse_adtl_chunk() function. The patch added a size validation check lsize + 8 > size, but it does not account for the GST_ROUND_UP_2(lsize) used in the actual offset calculation. When lsize is an odd number, the parser advances more bytes than validated, causing OOB read.
nvd
CVE-2017-3735P3MEDIUMCVSS 5.3v8.0v9.02017-08-28
CVE-2017-3735 [MEDIUM] CWE-119 CVE-2017-3735: While parsing an IPAddressFamily extension in an X.509 certificate, it is possible to do a one-byte While parsing an IPAddressFamily extension in an X.509 certificate, it is possible to do a one-byte overread. This would result in an incorrect text display of the certificate. This bug has been present since 2006 and is present in all versions of OpenSSL before 1.0.2m and 1.1.0g.
nvd
CVE-2009-2625P4MEDIUMCVSS 5.0v4.0v5.02009-08-06
CVE-2009-2625 [MEDIUM] CVE-2009-2625: XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.
nvd
CVE-2022-34903P3MEDIUMCVSS 6.5v10.0v11.02022-07-01
CVE-2022-34903 [MEDIUM] CWE-74 CVE-2022-34903: GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information fr GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim's keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery via injection into the status line.
nvd
CVE-2018-16430P3HIGHCVSS 8.8v8.0v9.02018-09-04
CVE-2018-16430 [HIGH] CWE-125 CVE-2018-16430: GNU Libextractor through 1.7 has an out-of-bounds read vulnerability in EXTRACTOR_zip_extract_method GNU Libextractor through 1.7 has an out-of-bounds read vulnerability in EXTRACTOR_zip_extract_method() in zip_extractor.c.
nvd
CVE-2014-0198P4MEDIUMCVSS 4.3v6.0v7.0+1 more2014-05-06
CVE-2014-0198 [MEDIUM] CWE-476 CVE-2014-0198: The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, does not properly manage a buffer pointer during certain recursive calls, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors that trigger an alert condition.
nvd
CVE-2017-15930P3HIGHCVSS 8.8v8.0v9.02017-10-27
CVE-2017-15930 [HIGH] CWE-476 CVE-2017-15930: In ReadOneJNGImage in coders/png.c in GraphicsMagick 1.3.26, a Null Pointer Dereference occurs while In ReadOneJNGImage in coders/png.c in GraphicsMagick 1.3.26, a Null Pointer Dereference occurs while transferring JPEG scanlines, related to a PixelPacket pointer.
nvd
CVE-2017-5193P3HIGHCVSS 7.5v7.02017-03-03
CVE-2017-5193 [HIGH] CWE-476 CVE-2017-5193: The nickcmp function in Irssi before 0.8.21 allows remote attackers to cause a denial of service (NU The nickcmp function in Irssi before 0.8.21 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a message without a nick.
nvd
CVE-2019-10650P3HIGHCVSS 8.1v9.02019-03-30
CVE-2019-10650 [HIGH] CWE-125 CVE-2019-10650: In ImageMagick 7.0.8-36 Q16, there is a heap-based buffer over-read in the function WriteTIFFImage o In ImageMagick 7.0.8-36 Q16, there is a heap-based buffer over-read in the function WriteTIFFImage of coders/tiff.c, which allows an attacker to cause a denial of service or information disclosure via a crafted image file.
nvd
CVE-2007-2443P3HIGHCVSS 8.3v3.1v4.02007-06-26
CVE-2007-2443 [HIGH] CVE-2007-2443: Integer signedness error in the gssrpc__svcauth_unix function in svc_auth_unix.c in the RPC library Integer signedness error in the gssrpc__svcauth_unix function in svc_auth_unix.c in the RPC library in MIT Kerberos 5 (krb5) 1.6.1 and earlier might allow remote attackers to execute arbitrary code via a negative length value.
nvd
Debian Linux vulnerabilities | cvebase