cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 214 of 498
CVE-2017-2670P3HIGHCVSS 7.5v9.02018-07-27
CVE-2017-2670 [HIGH] CWE-835 CVE-2017-2670: It was found in Undertow before 1.3.28 that with non-clean TCP close, the Websocket server gets into It was found in Undertow before 1.3.28 that with non-clean TCP close, the Websocket server gets into infinite loop on every IO thread, effectively causing DoS.
nvd
CVE-2008-5024P3HIGHCVSS 7.5v4.02008-11-13
CVE-2008-5024 [HIGH] CWE-91 CVE-2008-5024: Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 do not properly escape quote characters used for XML processing, which allows remote attackers to conduct XML injection attacks via the default namespace in an E4X document.
nvd
CVE-2019-20218P3HIGHCVSS 7.5v9.02020-01-02
CVE-2019-20218 [HIGH] CWE-755 CVE-2019-20218: selectExpander in select.c in SQLite 3.30.1 proceeds with WITH stack unwinding even after a parsing selectExpander in select.c in SQLite 3.30.1 proceeds with WITH stack unwinding even after a parsing error.
nvd
CVE-2022-24836P3HIGHCVSS 7.5v9.0v10.02022-04-11
CVE-2022-24836 [HIGH] CWE-400 CVE-2022-24836: Nokogiri is an open source XML and HTML library for Ruby. Nokogiri `< v1.13.4` contains an inefficie Nokogiri is an open source XML and HTML library for Ruby. Nokogiri `= 1.13.4`. There are no known workarounds for this issue.
nvd
CVE-2018-14339P3HIGHCVSS 7.5v8.02018-07-19
CVE-2018-14339 [HIGH] CWE-20 CVE-2018-14339: In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the MMSE dissector could go into a In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the MMSE dissector could go into an infinite loop. This was addressed in epan/proto.c by adding offset and length validation.
nvd
CVE-2015-6855P3HIGHCVSS 7.5v7.0v8.0+1 more2015-11-06
CVE-2015-6855 [HIGH] CWE-369 CVE-2015-6855: hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which all hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which allows guest users to cause a denial of service or possibly have unspecified other impact via certain IDE commands, as demonstrated by a WIN_READ_NATIVE_MAX command to an empty drive, which triggers a divide-by-zero error and instance crash.
nvd
CVE-2021-23841P3MEDIUMCVSS 5.9v10.02021-02-16
CVE-2021-23841 [MEDIUM] CWE-476 CVE-2021-23841: The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value based on the issuer and serial number data contained within an X509 certificate. However it fails to correctly handle any errors that may occur while parsing the issuer field (which might occur if the issuer field is maliciously constructed). This ma
nvd
CVE-2018-16058P3HIGHCVSS 7.5v8.0v9.02018-08-30
CVE-2018-16058 [HIGH] CWE-665 CVE-2018-16058: In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16, the Bluetooth AVDTP dissector coul In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16, the Bluetooth AVDTP dissector could crash. This was addressed in epan/dissectors/packet-btavdtp.c by properly initializing a data structure.
nvd
CVE-2017-2918P3HIGHCVSS 7.8v8.0v9.02018-04-24
CVE-2017-2918 [HIGH] CWE-190 CVE-2017-2918: An exploitable integer overflow exists in the Image loading functionality of the Blender open-source An exploitable integer overflow exists in the Image loading functionality of the Blender open-source 3d creation suite v2.78c. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to open the file or use it as
nvd
CVE-2018-16056P3HIGHCVSS 7.5v9.02018-08-30
CVE-2018-16056 [HIGH] CVE-2018-16056: In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16, the Bluetooth Attribute Protocol d In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16, the Bluetooth Attribute Protocol dissector could crash. This was addressed in epan/dissectors/packet-btatt.c by verifying that a dissector for a specific UUID exists.
nvd
CVE-2020-18771P3HIGHCVSS 8.1v10.02021-08-23
CVE-2020-18771 [HIGH] CWE-125 CVE-2020-18771: Exiv2 0.27.99.0 has a global buffer over-read in Exiv2::Internal::Nikon1MakerNote::print0x0088 in ni Exiv2 0.27.99.0 has a global buffer over-read in Exiv2::Internal::Nikon1MakerNote::print0x0088 in nikonmn_int.cpp which can result in an information leak.
nvd
CVE-2021-35559P3MEDIUMCVSS 5.3v9.0v10.0+1 more2021-10-20
CVE-2021-35559 [MEDIUM] CWE-400 CVE-2021-35559: Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to
nvd
CVE-2021-42260P3HIGHCVSS 7.5v9.0v10.02021-10-11
CVE-2021-42260 [HIGH] CWE-835 CVE-2021-42260: TinyXML through 2.6.2 has an infinite loop in TiXmlParsingData::Stamp in tinyxmlparser.cpp via the T TinyXML through 2.6.2 has an infinite loop in TiXmlParsingData::Stamp in tinyxmlparser.cpp via the TIXML_UTF_LEAD_0 case. It can be triggered by a crafted XML message and leads to a denial of service.
nvd
CVE-2017-7703P3HIGHCVSS 7.5v8.02017-04-12
CVE-2017-7703 [HIGH] CWE-74 CVE-2017-7703: In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the IMAP dissector could crash, triggered by packet In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the IMAP dissector could crash, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-imap.c by calculating a line's end correctly.
nvd
CVE-2018-15822P3HIGHCVSS 7.5v8.0v9.02018-08-23
CVE-2018-15822 [HIGH] CWE-617 CVE-2018-15822: The flv_write_packet function in libavformat/flvenc.c in FFmpeg through 2.8 does not check for an em The flv_write_packet function in libavformat/flvenc.c in FFmpeg through 2.8 does not check for an empty audio packet, leading to an assertion failure.
nvd
CVE-2015-1781P3MEDIUMCVSS 6.8v7.02015-09-28
CVE-2015-1781 [MEDIUM] CWE-119 CVE-2015-1781: Buffer overflow in the gethostbyname_r and other unspecified NSS functions in the GNU C Library (aka Buffer overflow in the gethostbyname_r and other unspecified NSS functions in the GNU C Library (aka glibc or libc6) before 2.22 allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response, which triggers a call with a misaligned buffer.
nvd
CVE-2018-20024P3HIGHCVSS 7.5v8.0v9.02018-12-19
CVE-2018-20024 [HIGH] CWE-476 CVE-2018-20024: LibVNC before commit 4a21bbd097ef7c44bb000c3bd0907f96a10e4ce7 contains null pointer dereference in V LibVNC before commit 4a21bbd097ef7c44bb000c3bd0907f96a10e4ce7 contains null pointer dereference in VNC client code that can result DoS.
nvd
CVE-2021-39921P3HIGHCVSS 7.5v9.02021-11-19
CVE-2021-39921 [HIGH] CWE-476 CVE-2021-39921: NULL pointer exception in the Modbus dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allow NULL pointer exception in the Modbus dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
nvd
CVE-2017-1000256P3HIGHCVSS 8.1v9.02017-10-31
CVE-2017-1000256 [HIGH] CWE-295 CVE-2017-1000256: libvirt version 2.3.0 and later is vulnerable to a bad default configuration of "verify-peer=no" pas libvirt version 2.3.0 and later is vulnerable to a bad default configuration of "verify-peer=no" passed to QEMU by libvirt resulting in a failure to validate SSL/TLS certificates by default.
nvd
CVE-2017-5410P3CRITICALCVSS 9.8v8.02018-06-11
CVE-2017-5410 [CRITICAL] CWE-119 CVE-2017-5410: Memory corruption resulting in a potentially exploitable crash during garbage collection of JavaScri Memory corruption resulting in a potentially exploitable crash during garbage collection of JavaScript due errors in how incremental sweeping is managed for memory cleanup. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
nvd
Debian Linux vulnerabilities | cvebase