Debian Linux vulnerabilities
9,954 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358
Vulnerabilities
Page 215 of 498
CVE-2017-7805P3HIGHCVSS 7.5v7.0v8.0+1 more2018-06-11
CVE-2017-7805 [HIGH] CWE-416 CVE-2017-7805: During TLS 1.2 exchanges, handshake hashes are generated which point to a message buffer. This saved
During TLS 1.2 exchanges, handshake hashes are generated which point to a message buffer. This saved data is used for later messages but in some cases, the handshake transcript can exceed the space available in the current buffer, causing the allocation of a new buffer. This leaves a pointer pointing to the old, freed buffer, resulting in a use-after-fr
nvd
CVE-2020-8037P3HIGHCVSS 7.5v9.02020-11-04
CVE-2020-8037 [HIGH] CWE-770 CVE-2020-8037: The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory.
The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory.
nvd
CVE-2014-8182P3HIGHCVSS 7.5v8.0v9.0+1 more2020-01-02
CVE-2014-8182 [HIGH] CWE-193 CVE-2014-8182: An off-by-one error leading to a crash was discovered in openldap 2.4 when processing DNS SRV messag
An off-by-one error leading to a crash was discovered in openldap 2.4 when processing DNS SRV messages. If slapd was configured to use the dnssrv backend, an attacker could crash the service with crafted DNS responses.
nvd
CVE-2021-3326P3HIGHCVSS 7.5v10.02021-01-27
CVE-2021-3326 [HIGH] CWE-617 CVE-2021-3326: The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing inval
The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid input sequences in the ISO-2022-JP-3 encoding, fails an assertion in the code path and aborts the program, potentially resulting in a denial of service.
nvd
CVE-2017-11406P3HIGHCVSS 7.5v8.02017-07-18
CVE-2017-11406 [HIGH] CWE-835 CVE-2017-11406: In Wireshark 2.2.0 to 2.2.7 and 2.0.0 to 2.0.13, the DOCSIS dissector could go into an infinite loop
In Wireshark 2.2.0 to 2.2.7 and 2.0.0 to 2.0.13, the DOCSIS dissector could go into an infinite loop. This was addressed in plugins/docsis/packet-docsis.c by rejecting invalid Frame Control parameter values.
nvd
CVE-2017-5510P3HIGHCVSS 7.8v8.0v9.0+1 more2017-03-24
CVE-2017-5510 [HIGH] CWE-787 CVE-2017-5510: coders/psd.c in ImageMagick allows remote attackers to have unspecified impact via a crafted PSD fil
coders/psd.c in ImageMagick allows remote attackers to have unspecified impact via a crafted PSD file, which triggers an out-of-bounds write.
nvd
CVE-2020-6078P3HIGHCVSS 7.5v9.0v10.02020-03-24
CVE-2020-6078 [HIGH] CWE-252 CVE-2020-6078: An exploitable denial-of-service vulnerability exists in the message-parsing functionality of Videol
An exploitable denial-of-service vulnerability exists in the message-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing mDNS messages in mdns_recv, the return value of the mdns_read_header function is not checked, leading to an uninitialized variable usage that eventually results in a null pointer dereference, leading to service crash. A
nvd
CVE-2021-31808P3MEDIUMCVSS 6.5v9.0v10.02021-05-27
CVE-2021-31808 [MEDIUM] CWE-190 CVE-2021-31808: An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to an input-validation bug, i
An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to an input-validation bug, it is vulnerable to a Denial of Service attack (against all clients using the proxy). A client sends an HTTP Range request to trigger this.
nvd
CVE-2017-6469P3HIGHCVSS 7.5v8.02017-03-04
CVE-2017-6469 [HIGH] CWE-20 CVE-2017-6469: In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is an LDSS dissector crash, triggered by pack
In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is an LDSS dissector crash, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-ldss.c by ensuring that memory is allocated for a certain data structure.
nvd
CVE-2017-6014P3HIGHCVSS 7.5v8.02017-02-17
CVE-2017-6014 [HIGH] CWE-835 CVE-2017-6014: In Wireshark 2.2.4 and earlier, a crafted or malformed STANAG 4607 capture file will cause an infini
In Wireshark 2.2.4 and earlier, a crafted or malformed STANAG 4607 capture file will cause an infinite loop and memory exhaustion. If the packet size field in a packet header is null, the offset to read from will not advance, causing continuous attempts to read the same zero length packet. This will quickly exhaust all system memory.
nvd
CVE-2019-18397P3HIGHCVSS 7.8v10.0v8.0+1 more2019-11-13
CVE-2019-18397 [HIGH] CWE-120 CVE-2019-18397: A buffer overflow in the fribidi_get_par_embedding_levels_ex() function in lib/fribidi-bidi.c of GNU
A buffer overflow in the fribidi_get_par_embedding_levels_ex() function in lib/fribidi-bidi.c of GNU FriBidi through 1.0.7 allows an attacker to cause a denial of service or possibly execute arbitrary code by delivering crafted text content to a user, when this content is then rendered by an application that uses FriBidi for text layout calculations.
nvd
CVE-2020-36278P3HIGHCVSS 7.5v9.02021-03-12
CVE-2020-36278 [HIGH] CWE-125 CVE-2020-36278: Leptonica before 1.80.0 allows a heap-based buffer over-read in findNextBorderPixel in ccbord.c.
Leptonica before 1.80.0 allows a heap-based buffer over-read in findNextBorderPixel in ccbord.c.
nvd
CVE-2020-36281P3HIGHCVSS 7.5v9.02021-03-12
CVE-2020-36281 [HIGH] CWE-125 CVE-2020-36281: Leptonica before 1.80.0 allows a heap-based buffer over-read in pixFewColorsOctcubeQuantMixed in col
Leptonica before 1.80.0 allows a heap-based buffer over-read in pixFewColorsOctcubeQuantMixed in colorquant1.c.
nvd
CVE-2010-5312P3MEDIUMCVSS 6.1v7.0v9.02014-11-24
CVE-2010-5312 [MEDIUM] CWE-79 CVE-2010-5312: Cross-site scripting (XSS) vulnerability in jquery.ui.dialog.js in the Dialog widget in jQuery UI be
Cross-site scripting (XSS) vulnerability in jquery.ui.dialog.js in the Dialog widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title option.
nvd
CVE-2019-13307P3HIGHCVSS 7.8v9.0v10.02019-07-05
CVE-2019-13307 [HIGH] CWE-787 CVE-2019-13307: ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/statistic.c in EvaluateImage
ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/statistic.c in EvaluateImages because of mishandling rows.
nvd
CVE-2018-5819P3HIGHCVSS 7.5v8.02019-02-20
CVE-2018-5819 [HIGH] CWE-400 CVE-2018-5819: An error within the "parse_sinar_ia()" function (internal/dcraw_common.cpp) within LibRaw versions p
An error within the "parse_sinar_ia()" function (internal/dcraw_common.cpp) within LibRaw versions prior to 0.19.1 can be exploited to exhaust available CPU resources.
nvd
CVE-2022-32208P3MEDIUMCVSS 5.9v10.0v11.02022-07-07
CVE-2022-32208 [MEDIUM] CWE-840 CVE-2022-32208: When curl < 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wron
When curl < 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed and even allows it to inject data to the client.
nvd
CVE-2019-1551P3MEDIUMCVSS 5.3v9.0v10.02019-12-06
CVE-2019-1551 [MEDIUM] CWE-190 CVE-2019-1551: There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512
There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against 2-prime RSA1024, 3-prime RSA1536, and DSA1024 as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH512 are conside
nvd
CVE-2014-9751P3MEDIUMCVSS 6.8v7.0v8.0+1 more2015-10-06
CVE-2014-9751 [MEDIUM] CWE-20 CVE-2014-9751: The read_network_packet function in ntp_io.c in ntpd in NTP 4.x before 4.2.8p1 on Linux and OS X doe
The read_network_packet function in ntp_io.c in ntpd in NTP 4.x before 4.2.8p1 on Linux and OS X does not properly determine whether a source IP address is an IPv6 loopback address, which makes it easier for remote attackers to spoof restricted packets, and read or write to the runtime state, by leveraging the ability to reach the ntpd machine's networ
nvd
CVE-2017-12086P3HIGHCVSS 7.8v8.0v9.02018-04-24
CVE-2017-12086 [HIGH] CWE-190 CVE-2017-12086: An exploitable integer overflow exists in the 'BKE_mesh_calc_normals_tessface' functionality of the
An exploitable integer overflow exists in the 'BKE_mesh_calc_normals_tessface' functionality of the Blender open-source 3d creation suite. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to open a .blend
nvd