Debian Linux vulnerabilities
9,954 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358
Vulnerabilities
Page 216 of 498
CVE-2020-27814P3HIGHCVSS 7.8v9.0v10.02021-01-26
CVE-2020-27814 [HIGH] CWE-122 CVE-2020-27814: A heap-buffer overflow was found in the way openjpeg2 handled certain PNG format files. An attacker
A heap-buffer overflow was found in the way openjpeg2 handled certain PNG format files. An attacker could use this flaw to cause an application crash or in some cases execute arbitrary code with the permission of the user running such an application.
nvd
CVE-2020-14398P3HIGHCVSS 7.5v8.0v9.02020-06-17
CVE-2020-14398 [HIGH] CWE-835 CVE-2020-14398: An issue was discovered in LibVNCServer before 0.9.13. An improperly closed TCP connection causes an
An issue was discovered in LibVNCServer before 0.9.13. An improperly closed TCP connection causes an infinite loop in libvncclient/sockets.c.
nvd
CVE-2018-1000097P3HIGHCVSS 7.8v8.0v9.02018-03-13
CVE-2018-1000097 [HIGH] CWE-119 CVE-2018-1000097: Sharutils sharutils (unshar command) version 4.15.2 contains a Buffer Overflow vulnerability in Affe
Sharutils sharutils (unshar command) version 4.15.2 contains a Buffer Overflow vulnerability in Affected component on the file unshar.c at line 75, function looks_like_c_code. Failure to perform checking of the buffer containing input line. that can result in Could lead to code execution. This attack appear to be exploitable via Victim have to run
nvd
CVE-2017-17083P3HIGHCVSS 7.5v8.0v9.02017-12-01
CVE-2017-17083 [HIGH] CWE-754 CVE-2017-17083: In Wireshark 2.4.0 to 2.4.2 and 2.2.0 to 2.2.10, the NetBIOS dissector could crash. This was address
In Wireshark 2.4.0 to 2.4.2 and 2.2.0 to 2.2.10, the NetBIOS dissector could crash. This was addressed in epan/dissectors/packet-netbios.c by ensuring that write operations are bounded by the beginning of a buffer.
nvd
CVE-2021-28831P3HIGHCVSS 7.5v9.02021-03-19
CVE-2021-28831 [HIGH] CWE-755 CVE-2021-28831: decompress_gunzip.c in BusyBox through 1.32.1 mishandles the error bit on the huft_build result poin
decompress_gunzip.c in BusyBox through 1.32.1 mishandles the error bit on the huft_build result pointer, with a resultant invalid free or segmentation fault, via malformed gzip data.
nvd
CVE-2018-7417P3HIGHCVSS 7.5v7.0v8.02018-02-23
CVE-2018-7417 [HIGH] CVE-2018-7417: In Wireshark 2.2.0 to 2.2.12 and 2.4.0 to 2.4.4, the IPMI dissector could crash. This was addressed
In Wireshark 2.2.0 to 2.2.12 and 2.4.0 to 2.4.4, the IPMI dissector could crash. This was addressed in epan/dissectors/packet-ipmi-picmg.c by adding support for crafted packets that lack an IPMI header.
nvd
CVE-2019-14970P3HIGHCVSS 7.8v9.0v10.02019-08-29
CVE-2019-14970 [HIGH] CWE-787 CVE-2019-14970: A vulnerability in mkv::event_thread_t in VideoLAN VLC media player 3.0.7.1 allows remote attackers
A vulnerability in mkv::event_thread_t in VideoLAN VLC media player 3.0.7.1 allows remote attackers to trigger a heap-based buffer overflow via a crafted .mkv file.
nvd
CVE-2021-38291P3HIGHCVSS 7.5v9.0v10.0+1 more2021-08-12
CVE-2021-38291 [HIGH] CWE-617 CVE-2021-38291: FFmpeg version (git commit de8e6e67e7523e48bb27ac224a0b446df05e1640) suffers from a an assertion fai
FFmpeg version (git commit de8e6e67e7523e48bb27ac224a0b446df05e1640) suffers from a an assertion failure at src/libavutil/mathematics.c.
nvd
CVE-2018-16511P3HIGHCVSS 7.8v8.0v9.02018-09-05
CVE-2018-16511 [HIGH] CWE-704 CVE-2018-16511: An issue was discovered in Artifex Ghostscript before 9.24. A type confusion in "ztype" could be use
An issue was discovered in Artifex Ghostscript before 9.24. A type confusion in "ztype" could be used by remote attackers able to supply crafted PostScript to crash the interpreter or possibly have unspecified other impact.
nvd
CVE-2020-12762P3HIGHCVSS 7.8v8.0v9.0+1 more2020-05-09
CVE-2020-12762 [HIGH] CWE-190 CVE-2020-12762: json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demons
json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend.
nvd
CVE-2019-20840P3HIGHCVSS 7.5v8.0v9.02020-06-17
CVE-2019-20840 [HIGH] CWE-787 CVE-2019-20840: An issue was discovered in LibVNCServer before 0.9.13. libvncserver/ws_decode.c can lead to a crash
An issue was discovered in LibVNCServer before 0.9.13. libvncserver/ws_decode.c can lead to a crash because of unaligned accesses in hybiReadAndDecode.
nvd
CVE-2017-12101P3HIGHCVSS 7.8v8.0v9.02018-04-24
CVE-2017-12101 [HIGH] CWE-190 CVE-2017-12101: An exploitable integer overflow exists in the 'modifier_mdef_compact_influences' functionality of th
An exploitable integer overflow exists in the 'modifier_mdef_compact_influences' functionality of the Blender open-source 3d creation suite v2.78c. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to open
nvd
CVE-2017-12100P3HIGHCVSS 7.8v8.0v9.02018-04-24
CVE-2017-12100 [HIGH] CWE-190 CVE-2017-12100: An exploitable integer overflow exists in the 'multires_load_old_dm' functionality of the Blender op
An exploitable integer overflow exists in the 'multires_load_old_dm' functionality of the Blender open-source 3d creation suite v2.78c. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to open a .blend fi
nvd
CVE-2020-36279P3HIGHCVSS 7.5v9.02021-03-12
CVE-2020-36279 [HIGH] CWE-125 CVE-2020-36279: Leptonica before 1.80.0 allows a heap-based buffer over-read in rasteropGeneralLow, related to adapt
Leptonica before 1.80.0 allows a heap-based buffer over-read in rasteropGeneralLow, related to adaptmap_reg.c and adaptmap.c.
nvd
CVE-2018-11806P3HIGHCVSS 8.2v8.0v9.02018-06-13
CVE-2018-11806 [HIGH] CWE-787 CVE-2018-11806: m_cat in slirp/mbuf.c in Qemu has a heap-based buffer overflow via incoming fragmented datagrams.
m_cat in slirp/mbuf.c in Qemu has a heap-based buffer overflow via incoming fragmented datagrams.
nvd
CVE-2019-14438P3HIGHCVSS 7.8v9.0v10.02019-08-29
CVE-2019-14438 [HIGH] CWE-125 CVE-2019-14438: A heap-based buffer over-read in xiph_PackHeaders() in modules/demux/xiph.h in VideoLAN VLC media pl
A heap-based buffer over-read in xiph_PackHeaders() in modules/demux/xiph.h in VideoLAN VLC media player 3.0.7.1 allows remote attackers to trigger a heap-based buffer over-read via a crafted .ogg file.
nvd
CVE-2021-25219P3MEDIUMCVSS 5.3v9.0v10.0+1 more2021-10-27
CVE-2021-25219 [MEDIUM] CVE-2021-25219: In BIND 9.3.0 -> 9.11.35, 9.12.0 -> 9.16.21, and versions 9.9.3-S1 -> 9.11.35-S1 and 9.16.8-S1 -> 9.
In BIND 9.3.0 -> 9.11.35, 9.12.0 -> 9.16.21, and versions 9.9.3-S1 -> 9.11.35-S1 and 9.16.8-S1 -> 9.16.21-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.18 of the BIND 9.17 development branch, exploitation of broken authoritative servers using a flaw in response processing can cause degradation in BIND resolver performance.
nvd
CVE-2016-7143P3HIGHCVSS 8.1v8.02016-09-21
CVE-2016-7143 [HIGH] CWE-285 CVE-2016-7143: The m_authenticate function in modules/m_sasl.c in Charybdis before 3.5.3 allows remote attackers to
The m_authenticate function in modules/m_sasl.c in Charybdis before 3.5.3 allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a crafted AUTHENTICATE parameter.
nvd
CVE-2021-31292P3HIGHCVSS 7.5v9.0v10.02021-07-26
CVE-2021-31292 [HIGH] CWE-190 CVE-2021-31292: An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based
An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata.
nvd
CVE-2013-1817P3HIGHCVSS 7.5v9.0v10.02019-11-20
CVE-2013-1817 [HIGH] CWE-200 CVE-2013-1817: MediaWiki before 1.19.4 and 1.20.x before 1.20.3 contains an error in the api.php script which allow
MediaWiki before 1.19.4 and 1.20.x before 1.20.3 contains an error in the api.php script which allows remote attackers to obtain sensitive information.
nvd