cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 211 of 498
CVE-2017-16546P3HIGHCVSS 8.8v8.0v9.02017-11-05
CVE-2017-16546 [HIGH] CWE-119 CVE-2017-16546: The ReadWPGImage function in coders/wpg.c in ImageMagick 7.0.7-9 does not properly validate the colo The ReadWPGImage function in coders/wpg.c in ImageMagick 7.0.7-9 does not properly validate the colormap index in a WPG palette, which allows remote attackers to cause a denial of service (use of uninitialized data or invalid memory allocation) or possibly have unspecified other impact via a malformed WPG file.
nvd
CVE-2018-7436P3HIGHCVSS 8.8v7.0v8.0+1 more2018-02-23
CVE-2018-7436 [HIGH] CWE-125 CVE-2018-7436: An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in a pointer An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in a pointer dereference of the parse_SST function.
nvd
CVE-2016-1655P3HIGHCVSS 8.8v8.02016-04-18
CVE-2016-1655 [HIGH] CVE-2016-1655: Google Chrome before 50.0.2661.75 does not properly consider that frame removal may occur during cal Google Chrome before 50.0.2661.75 does not properly consider that frame removal may occur during callback execution, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted extension.
nvd
CVE-2018-14469P3HIGHCVSS 7.5v8.0v9.0+1 more2019-10-03
CVE-2018-14469 [HIGH] CWE-125 CVE-2018-14469: The IKEv1 parser in tcpdump before 4.9.3 has a buffer over-read in print-isakmp.c:ikev1_n_print(). The IKEv1 parser in tcpdump before 4.9.3 has a buffer over-read in print-isakmp.c:ikev1_n_print().
nvd
CVE-2018-14880P3HIGHCVSS 7.5v8.0v9.0+1 more2019-10-03
CVE-2018-14880 [HIGH] CWE-125 CVE-2018-14880: The OSPFv3 parser in tcpdump before 4.9.3 has a buffer over-read in print-ospf6.c:ospf6_print_lshdr( The OSPFv3 parser in tcpdump before 4.9.3 has a buffer over-read in print-ospf6.c:ospf6_print_lshdr().
nvd
CVE-2017-15565P3HIGHCVSS 8.8v7.0v8.0+1 more2017-10-17
CVE-2017-15565 [HIGH] CWE-476 CVE-2017-15565: In Poppler 0.59.0, a NULL Pointer Dereference exists in the GfxImageColorMap::getGrayLine() function In Poppler 0.59.0, a NULL Pointer Dereference exists in the GfxImageColorMap::getGrayLine() function in GfxState.cc via a crafted PDF document.
nvd
CVE-2017-15672P3HIGHCVSS 8.8v8.0v9.02017-11-06
CVE-2017-15672 [HIGH] CWE-125 CVE-2017-15672: The read_header function in libavcodec/ffv1dec.c in FFmpeg 2.4 and 3.3.4 and possibly earlier allows The read_header function in libavcodec/ffv1dec.c in FFmpeg 2.4 and 3.3.4 and possibly earlier allows remote attackers to have unspecified impact via a crafted MP4 file, which triggers an out-of-bounds read.
nvd
CVE-2017-12598P3HIGHCVSS 8.8v8.0v9.02017-08-07
CVE-2017-12598 [HIGH] CWE-125 CVE-2017-12598: OpenCV (Open Source Computer Vision Library) through 3.3 has an out-of-bounds read error in the cv:: OpenCV (Open Source Computer Vision Library) through 3.3 has an out-of-bounds read error in the cv::RBaseStream::readBlock function in modules/imgcodecs/src/bitstrm.cpp when reading an image file by using cv::imread, as demonstrated by the 8-opencv-invalid-read-fread test case.
nvd
CVE-2016-10196P3HIGHCVSS 7.5v8.02017-03-15
CVE-2016-10196 [HIGH] CWE-787 CVE-2016-10196: Stack-based buffer overflow in the evutil_parse_sockaddr_port function in evutil.c in libevent befor Stack-based buffer overflow in the evutil_parse_sockaddr_port function in evutil.c in libevent before 2.1.6-beta allows attackers to cause a denial of service (segmentation fault) via vectors involving a long string in brackets in the ip_as_string argument.
nvd
CVE-2015-9381P3HIGHCVSS 8.8v8.02019-09-03
CVE-2015-9381 [HIGH] CWE-125 CVE-2015-9381: FreeType before 2.6.1 has a heap-based buffer over-read in T1_Get_Private_Dict in type1/t1parse.c. FreeType before 2.6.1 has a heap-based buffer over-read in T1_Get_Private_Dict in type1/t1parse.c.
nvd
CVE-2019-11050P3MEDIUMCVSS 6.5v8.0v9.0+1 more2019-12-23
CVE-2019-11050 [MEDIUM] CWE-125 CVE-2019-11050: When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() functio When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.
nvd
CVE-2015-5213P3MEDIUMCVSS 6.8v7.0v8.02015-11-10
CVE-2015-5213 [MEDIUM] CWE-189 CVE-2015-5213: Integer overflow in LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2 allows remote attack Integer overflow in LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a long DOC file, which triggers a buffer overflow.
nvd
CVE-2017-6362P3HIGHCVSS 7.5v8.0v9.02017-09-07
CVE-2017-6362 [HIGH] CWE-415 CVE-2017-6362: Double free vulnerability in the gdImagePngPtr function in libgd2 before 2.2.5 allows remote attacke Double free vulnerability in the gdImagePngPtr function in libgd2 before 2.2.5 allows remote attackers to cause a denial of service via vectors related to a palette with no colors.
nvd
CVE-2017-17915P3HIGHCVSS 8.8v7.0v8.0+1 more2017-12-27
CVE-2017-17915 [HIGH] CWE-125 CVE-2017-17915: In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a heap-based buffer over-read in ReadMNGImage i In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a heap-based buffer over-read in ReadMNGImage in coders/png.c, related to accessing one byte before testing whether a limit has been reached.
nvd
CVE-2018-12364P3HIGHCVSS 8.8v8.0v9.02018-10-18
CVE-2018-12364 [HIGH] CWE-352 CVE-2018-12364: NPAPI plugins, such as Adobe Flash, can send non-simple cross-origin requests, bypassing CORS by mak NPAPI plugins, such as Adobe Flash, can send non-simple cross-origin requests, bypassing CORS by making a same-origin POST that does a 307 redirect to the target site. This allows for a malicious site to engage in cross-site request forgery (CSRF) attacks. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR
nvd
CVE-2017-17912P3HIGHCVSS 8.8v7.0v8.0+1 more2017-12-27
CVE-2017-17912 [HIGH] CWE-125 CVE-2017-17912: In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a heap-based buffer over-read in ReadNewsProfil In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a heap-based buffer over-read in ReadNewsProfile in coders/tiff.c, in which LocaleNCompare reads heap data beyond the allocated region.
nvd
CVE-2017-18189P3HIGHCVSS 7.5v8.02018-02-15
CVE-2017-18189 [HIGH] CWE-476 CVE-2017-18189: In the startread function in xa.c in Sound eXchange (SoX) through 14.4.2, a corrupt header specifyin In the startread function in xa.c in Sound eXchange (SoX) through 14.4.2, a corrupt header specifying zero channels triggers an infinite loop with a resultant NULL pointer dereference, which may allow a remote attacker to cause a denial-of-service.
nvd
CVE-2010-0159P3CRITICALCVSS 10.0v5.02010-02-22
CVE-2010-0159 [CRITICAL] CVE-2010-0159: The browser engine in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, Thunderbird before The browser engine in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, Thunderbird before 3.0.2, and SeaMonkey before 2.0.3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the nsBlockFrame::StealFrame function in layout/generic/nsBlockFrame.cp
nvd
CVE-2004-0398P3HIGHCVSS 7.5v3.02004-07-07
CVE-2004-0398 [HIGH] CWE-787 CVE-2004-0398: Heap-based buffer overflow in the ne_rfc1036_parse date parsing function for the neon library (libne Heap-based buffer overflow in the ne_rfc1036_parse date parsing function for the neon library (libneon) 0.24.5 and earlier, as used by cadaver before 0.22, allows remote WebDAV servers to execute arbitrary code on the client.
nvd
CVE-2019-11047P3MEDIUMCVSS 6.5v8.0v9.0+1 more2019-12-23
CVE-2019-11047 [MEDIUM] CWE-125 CVE-2019-11047: When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() functio When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.
nvd
Debian Linux vulnerabilities | cvebase