cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 212 of 498
CVE-2018-7871P3HIGHCVSS 8.8v7.02018-03-08
CVE-2018-7871 [HIGH] CWE-125 CVE-2018-7871: There is a heap-based buffer over-read in the getName function of util/decompile.c in libming 0.4.8 There is a heap-based buffer over-read in the getName function of util/decompile.c in libming 0.4.8 for CONSTANT16 data. A crafted input will lead to a denial of service or possibly unspecified other impact.
nvd
CVE-2016-1678P3HIGHCVSS 8.8v8.02016-06-05
CVE-2016-1678 [HIGH] CWE-119 CVE-2016-1678: objects.cc in Google V8 before 5.0.71.32, as used in Google Chrome before 51.0.2704.63, does not pro objects.cc in Google V8 before 5.0.71.32, as used in Google Chrome before 51.0.2704.63, does not properly restrict lazy deoptimization, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted JavaScript code.
nvd
CVE-2021-44532P3MEDIUMCVSS 5.3v11.02022-02-24
CVE-2021-44532 [MEDIUM] CWE-296 CVE-2021-44532: Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 converts SANs (Subject Alternative Names) to a Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 converts SANs (Subject Alternative Names) to a string format. It uses this string to check peer certificates against hostnames when validating connections. The string format was subject to an injection vulnerability when name constraints were used within a certificate chain, allowing the bypass o
nvd
CVE-2020-7039P3MEDIUMCVSS 5.6v8.0v9.02020-01-16
CVE-2020-7039 [MEDIUM] CWE-787 CVE-2020-7039: tcp_emu in tcp_subr.c in libslirp 4.1.0, as used in QEMU 4.2.0, mismanages memory, as demonstrated b tcp_emu in tcp_subr.c in libslirp 4.1.0, as used in QEMU 4.2.0, mismanages memory, as demonstrated by IRC DCC commands in EMU_IRC. This can cause a heap-based buffer overflow or other out-of-bounds access which can lead to a DoS or potential execute arbitrary code.
nvd
CVE-2016-1681P3HIGHCVSS 8.8v8.02016-06-05
CVE-2016-1681 [HIGH] CWE-119 CVE-2016-1681: Heap-based buffer overflow in the opj_j2k_read_SPCod_SPCoc function in j2k.c in OpenJPEG, as used in Heap-based buffer overflow in the opj_j2k_read_SPCod_SPCoc function in j2k.c in OpenJPEG, as used in PDFium in Google Chrome before 51.0.2704.63, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted PDF document.
nvd
CVE-2024-37891P3MEDIUMCVSS 6.5v11.02024-06-17
CVE-2024-37891 [MEDIUM] CWE-669 CVE-2024-37891: urllib3 is a user-friendly HTTP client library for Python. When using urllib3's proxy support with urllib3 is a user-friendly HTTP client library for Python. When using urllib3's proxy support with `ProxyManager`, the `Proxy-Authorization` header is only sent to the configured proxy, as expected. However, when sending HTTP requests *without* using urllib3's proxy support, it's possible to accidentally configure the `Proxy-Authorization` header even
nvd
CVE-2009-1961P4MEDIUMCVSS 4.7PoCv4.02009-06-08
CVE-2009-1961 [MEDIUM] CWE-667 CVE-2009-1961: The inode double locking code in fs/ocfs2/file.c in the Linux kernel 2.6.30 before 2.6.30-rc3, 2.6.2 The inode double locking code in fs/ocfs2/file.c in the Linux kernel 2.6.30 before 2.6.30-rc3, 2.6.27 before 2.6.27.24, 2.6.29 before 2.6.29.4, and possibly other versions down to 2.6.19 allows local users to cause a denial of service (prevention of file creation and removal) via a series of splice system calls that trigger a deadlock between the gene
nvd
CVE-2015-8080P3HIGHCVSS 7.5v8.0v9.02016-04-13
CVE-2015-8080 [HIGH] CWE-190 CVE-2015-8080: Integer overflow in the getnum function in lua_struct.c in Redis 2.8.x before 2.8.24 and 3.0.x befor Integer overflow in the getnum function in lua_struct.c in Redis 2.8.x before 2.8.24 and 3.0.x before 3.0.6 allows context-dependent attackers with permission to run Lua code in a Redis session to cause a denial of service (memory corruption and application crash) or possibly bypass intended sandbox restrictions via a large number, which triggers a stac
nvd
CVE-2019-9811P3HIGHCVSS 8.3v8.02019-07-23
CVE-2019-9811 [HIGH] CWE-74 CVE-2019-9811: As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malic As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
nvd
CVE-2016-1668P3HIGHCVSS 8.8v8.02016-05-14
CVE-2016-1668 [HIGH] CWE-284 CVE-2016-1668: The forEachForBinding function in WebKit/Source/bindings/core/v8/Iterable.h in the V8 bindings in Bl The forEachForBinding function in WebKit/Source/bindings/core/v8/Iterable.h in the V8 bindings in Blink, as used in Google Chrome before 50.0.2661.102, uses an improper creation context, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.
nvd
CVE-2018-6151P3HIGHCVSS 8.8v9.02019-01-09
CVE-2018-6151 [HIGH] CWE-125 CVE-2018-6151: Bad cast in DevTools in Google Chrome on Win, Linux, Mac, Chrome OS prior to 66.0.3359.117 allowed a Bad cast in DevTools in Google Chrome on Win, Linux, Mac, Chrome OS prior to 66.0.3359.117 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory read via a crafted Chrome Extension.
nvd
CVE-2016-1623P3HIGHCVSS 8.8v8.02016-02-14
CVE-2016-1623 [HIGH] CWE-264 CVE-2016-1623: The DOM implementation in Google Chrome before 48.0.2564.109 does not properly restrict frame-attach The DOM implementation in Google Chrome before 48.0.2564.109 does not properly restrict frame-attach operations from occurring during or after frame-detach operations, which allows remote attackers to bypass the Same Origin Policy via a crafted web site, related to FrameLoader.cpp, HTMLFrameOwnerElement.h, LocalFrame.cpp, and WebLocalFrameImpl.cpp.
nvd
CVE-2019-7578P3HIGHCVSS 8.1v8.0v9.02019-02-07
CVE-2019-7578 [HIGH] CWE-125 CVE-2019-7578: SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-rea SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in InitIMA_ADPCM in audio/SDL_wave.c.
nvd
CVE-2014-1532P3CRITICALCVSS 9.8v7.0v8.02014-04-30
CVE-2014-1532 [CRITICAL] CWE-416 CVE-2014-1532: Use-after-free vulnerability in the nsHostResolver::ConditionallyRefreshRecord function in libxul.so Use-after-free vulnerability in the nsHostResolver::ConditionallyRefreshRecord function in libxul.so in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors related to host resol
nvd
CVE-1999-0804P4MEDIUMCVSS 5.0PoCv2.11999-06-01
CVE-1999-0804 [MEDIUM] CVE-1999-0804: Denial of service in Linux 2.2.x kernels via malformed ICMP packets containing unusual types, codes, Denial of service in Linux 2.2.x kernels via malformed ICMP packets containing unusual types, codes, and IP header lengths.
nvd
CVE-2019-7636P3HIGHCVSS 8.1v8.0v9.02019-02-08
CVE-2019-7636 [HIGH] CWE-125 CVE-2019-7636: SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-rea SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in SDL_GetRGB in video/SDL_pixels.c.
nvd
CVE-2021-43535P3HIGHCVSS 8.8v9.0v10.0+1 more2021-12-08
CVE-2021-43535 [HIGH] CWE-416 CVE-2021-43535: A use-after-free could have occured when an HTTP2 session object was released on a different thread, A use-after-free could have occured when an HTTP2 session object was released on a different thread, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 93, Thunderbird < 91.3, and Firefox ESR < 91.3.
nvd
CVE-2018-20178P3HIGHCVSS 7.5v8.0v9.02019-03-15
CVE-2018-20178 [HIGH] CWE-125 CVE-2018-20178: rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in the function process_d rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in the function process_demand_active() that results in a Denial of Service (segfault).
nvd
CVE-2012-0449P3CRITICALCVSS 9.3v5.0v6.02012-02-01
CVE-2012-0449 [CRITICAL] CWE-119 CVE-2012-0449: Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, an Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a malformed XSLT stylesheet that is embedded in a document.
nvd
CVE-2018-20175P3HIGHCVSS 7.5v8.0v9.02019-03-15
CVE-2018-20175 [HIGH] CWE-125 CVE-2018-20175: rdesktop versions up to and including v1.8.3 contains several Integer Signedness errors that lead to rdesktop versions up to and including v1.8.3 contains several Integer Signedness errors that lead to Out-Of-Bounds Reads in the file mcs.c and result in a Denial of Service (segfault).
nvd
Debian Linux vulnerabilities | cvebase