cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 217 of 498
CVE-2018-5817P3HIGHCVSS 7.5v8.02019-02-20
CVE-2018-5817 [HIGH] CWE-704 CVE-2018-5817: A type confusion error within the "unpacked_load_raw()" function within LibRaw versions prior to 0.1 A type confusion error within the "unpacked_load_raw()" function within LibRaw versions prior to 0.19.1 (internal/dcraw_common.cpp) can be exploited to trigger an infinite loop.
nvd
CVE-2017-7747P3HIGHCVSS 7.5v8.02017-04-12
CVE-2017-7747 [HIGH] CWE-20 CVE-2017-7747: In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the PacketBB dissector could crash, triggered by pa In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the PacketBB dissector could crash, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-packetbb.c by restricting additions to the protocol tree.
nvd
CVE-2019-9894P3HIGHCVSS 7.5v8.0v9.02019-03-21
CVE-2019-9894 [HIGH] CWE-320 CVE-2019-9894: A remotely triggerable memory overwrite in RSA key exchange in PuTTY before 0.71 can occur before ho A remotely triggerable memory overwrite in RSA key exchange in PuTTY before 0.71 can occur before host key verification.
nvd
CVE-2022-0261P3HIGHCVSS 7.8v9.0v10.02022-01-18
CVE-2022-0261 [HIGH] CWE-122 CVE-2022-0261: Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
nvd
CVE-2020-6555P3HIGHCVSS 7.6v10.02020-09-21
CVE-2020-6555 [HIGH] CWE-125 CVE-2020-6555: Out of bounds read in WebGL in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to obt Out of bounds read in WebGL in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2020-6073P3HIGHCVSS 7.5v9.02020-03-24
CVE-2020-6073 [HIGH] CWE-190 CVE-2020-6073: An exploitable denial-of-service vulnerability exists in the TXT record-parsing functionality of Vid An exploitable denial-of-service vulnerability exists in the TXT record-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing the RDATA section in a TXT record in mDNS messages, multiple integer overflows can be triggered, leading to a denial of service. An attacker can send an mDNS message to trigger this vulnerability.
nvd
CVE-2017-7787P3HIGHCVSS 7.5v8.0v9.02018-06-11
CVE-2017-7787 [HIGH] CWE-200 CVE-2017-7787: Same-origin policy protections can be bypassed on pages with embedded iframes during page reloads, a Same-origin policy protections can be bypassed on pages with embedded iframes during page reloads, allowing the iframes to access content on the top level page, leading to information disclosure. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
nvd
CVE-2022-28463P3HIGHCVSS 7.8v9.0v10.02022-05-08
CVE-2022-28463 [HIGH] CWE-120 CVE-2022-28463: ImageMagick 7.1.0-27 is vulnerable to Buffer Overflow. ImageMagick 7.1.0-27 is vulnerable to Buffer Overflow.
nvd
CVE-2014-1487P3HIGHCVSS 7.5v7.02014-02-06
CVE-2014-1487 [HIGH] CWE-346 CVE-2014-1487: The Web workers implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunder The Web workers implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to bypass the Same Origin Policy and obtain sensitive authentication information via vectors involving error messages.
nvd
CVE-2018-5818P3HIGHCVSS 7.5v8.02019-02-20
CVE-2018-5818 [HIGH] CWE-835 CVE-2018-5818: An error within the "parse_rollei()" function (internal/dcraw_common.cpp) within LibRaw versions pri An error within the "parse_rollei()" function (internal/dcraw_common.cpp) within LibRaw versions prior to 0.19.1 can be exploited to trigger an infinite loop.
nvd
CVE-2022-1942P3HIGHCVSS 7.8v10.02022-05-31
CVE-2022-1942 [HIGH] CWE-122 CVE-2022-1942: Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
nvd
CVE-2016-9893P3CRITICALCVSS 9.8v9.02018-06-11
CVE-2016-9893 [CRITICAL] CWE-119 CVE-2016-9893: Memory safety bugs were reported in Thunderbird 45.5. Some of these bugs showed evidence of memory c Memory safety bugs were reported in Thunderbird 45.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
nvd
CVE-2017-5464P3CRITICALCVSS 9.8v8.02018-06-11
CVE-2017-5464 [CRITICAL] CWE-119 CVE-2017-5464: During DOM manipulations of the accessibility tree through script, the DOM tree can become out of sy During DOM manipulations of the accessibility tree through script, the DOM tree can become out of sync with the accessibility tree, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2019-12473P3HIGHCVSS 7.5v9.02019-07-10
CVE-2019-12473 [HIGH] CVE-2019-12473: Wikimedia MediaWiki 1.27.0 through 1.32.1 might allow DoS. Passing invalid titles to the API could c Wikimedia MediaWiki 1.27.0 through 1.32.1 might allow DoS. Passing invalid titles to the API could cause a DoS by querying the entire watchlist table. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
nvd
CVE-2009-5045P3HIGHCVSS 7.5v8.02019-11-06
CVE-2009-5045 [HIGH] CWE-200 CVE-2009-5045: Dump Servlet information leak in jetty before 6.1.22. Dump Servlet information leak in jetty before 6.1.22.
nvd
CVE-2018-1000127P3HIGHCVSS 7.5v7.0v8.0+1 more2018-03-13
CVE-2018-1000127 [HIGH] CWE-190 CVE-2018-1000127: memcached version prior to 1.4.37 contains an Integer Overflow vulnerability in items.c:item_free() memcached version prior to 1.4.37 contains an Integer Overflow vulnerability in items.c:item_free() that can result in data corruption and deadlocks due to items existing in hash table being reused from free list. This attack appear to be exploitable via network connectivity to the memcached service. This vulnerability appears to have been fixed in
nvd
CVE-2022-1897P3HIGHCVSS 7.8v10.02022-05-27
CVE-2022-1897 [HIGH] CWE-787 CVE-2022-1897: Out-of-bounds Write in GitHub repository vim/vim prior to 8.2. Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.
nvd
CVE-2018-2582P3MEDIUMCVSS 6.5v9.02018-01-18
CVE-2018-2582 [MEDIUM] CVE-2018-2582: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are affected are Java SE: 8u152 and 9.0.1; Java SE Embedded: 8u151. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks re
nvd
CVE-2017-7671P3HIGHCVSS 7.5v9.02018-02-27
CVE-2017-7671 [HIGH] CWE-20 CVE-2017-7671: There is a DOS attack vulnerability in Apache Traffic Server (ATS) 5.2.0 to 5.3.2, 6.0.0 to 6.2.0, a There is a DOS attack vulnerability in Apache Traffic Server (ATS) 5.2.0 to 5.3.2, 6.0.0 to 6.2.0, and 7.0.0 with the TLS handshake. This issue can cause the server to coredump.
nvd
CVE-2013-0800P3MEDIUMCVSS 6.8v7.02013-04-03
CVE-2013-0800 [MEDIUM] CVE-2013-0800: Integer signedness error in the pixman_fill_sse2 function in pixman-sse2.c in Pixman, as distributed Integer signedness error in the pixman_fill_sse2 function in pixman-sse2.c in Pixman, as distributed with Cairo and used in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, SeaMonkey before 2.17, and other products, allows remote attackers to execute arbitrary code via crafted values t
nvd
Debian Linux vulnerabilities | cvebase