cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 219 of 498
CVE-2022-0545P3HIGHCVSS 7.8v10.0v11.02022-02-24
CVE-2022-0545 [HIGH] CWE-190 CVE-2022-0545: An integer overflow in the processing of loaded 2D images leads to a write-what-where vulnerability An integer overflow in the processing of loaded 2D images leads to a write-what-where vulnerability and an out-of-bounds read vulnerability, allowing an attacker to leak sensitive information or achieve code execution in the context of the Blender process when a specially crafted image file is loaded. This flaw affects Blender versions prior to 2.83.19,
nvd
CVE-2016-4423P3HIGHCVSS 7.5v8.02016-06-01
CVE-2016-4423 [HIGH] CWE-399 CVE-2016-4423: The attemptAuthentication function in Component/Security/Http/Firewall/UsernamePasswordFormAuthentic The attemptAuthentication function in Component/Security/Http/Firewall/UsernamePasswordFormAuthenticationListener.php in Symfony before 2.3.41, 2.7.x before 2.7.13, 2.8.x before 2.8.6, and 3.0.x before 3.0.6 does not limit the length of a username stored in a session, which allows remote attackers to cause a denial of service (session storage consumptio
nvd
CVE-2013-0339P3MEDIUMCVSS 6.8v6.0v7.02014-01-21
CVE-2013-0339 [MEDIUM] CWE-264 CVE-2013-0339: libxml2 through 2.9.1 does not properly handle external entities expansion unless an application dev libxml2 through 2.9.1 does not properly handle external entities expansion unless an application developer uses the xmlSAX2ResolveEntity or xmlSetExternalEntityLoader function, which allows remote attackers to cause a denial of service (resource consumption), send HTTP requests to intranet servers, or read arbitrary files via a crafted XML document, a
nvd
CVE-2017-17848P3HIGHCVSS 7.5v7.0v8.0+1 more2017-12-27
CVE-2017-17848 [HIGH] CVE-2017-17848: An issue was discovered in Enigmail before 1.9.9. In a variant of CVE-2017-17847, signature spoofing An issue was discovered in Enigmail before 1.9.9. In a variant of CVE-2017-17847, signature spoofing is possible for multipart/related messages because a signed message part can be referenced with a cid: URI but not actually displayed. In other words, the entire containing message appears to be signed, but the recipient does not see any of the signed text.
nvd
CVE-2019-5815P3HIGHCVSS 7.5v10.02019-12-11
CVE-2019-5815 [HIGH] CWE-787 CVE-2019-5815: Type confusion in xsltNumberFormatGetMultipleLevel prior to libxslt 1.1.33 could allow attackers to Type confusion in xsltNumberFormatGetMultipleLevel prior to libxslt 1.1.33 could allow attackers to potentially exploit heap corruption via crafted XML data.
nvd
CVE-2022-32085P3HIGHCVSS 7.5v10.02022-07-01
CVE-2022-32085 [HIGH] CVE-2022-32085: MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Item_func_in MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Item_func_in::cleanup/Item::cleanup_processor.
nvd
CVE-2022-32088P3HIGHCVSS 7.5v10.02022-07-01
CVE-2022-32088 [HIGH] CVE-2022-32088: MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Exec_time_tr MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Exec_time_tracker::get_loops/Filesort_tracker::report_use/filesort.
nvd
CVE-2022-32083P3HIGHCVSS 7.5v10.02022-07-01
CVE-2022-32083 [HIGH] CVE-2022-32083: MariaDB v10.2 to v10.6.1 was discovered to contain a segmentation fault via the component Item_subse MariaDB v10.2 to v10.6.1 was discovered to contain a segmentation fault via the component Item_subselect::init_expr_cache_tracker.
nvd
CVE-2019-17539P3CRITICALCVSS 9.8v9.0v10.02019-10-14
CVE-2019-17539 [CRITICAL] CWE-476 CVE-2019-17539: In FFmpeg before 4.2, avcodec_open2 in libavcodec/utils.c allows a NULL pointer dereference and poss In FFmpeg before 4.2, avcodec_open2 in libavcodec/utils.c allows a NULL pointer dereference and possibly unspecified other impact when there is no valid close function pointer.
nvd
CVE-2018-11781P3HIGHCVSS 7.8v8.02018-09-17
CVE-2018-11781 [HIGH] CWE-94 CVE-2018-11781: Apache SpamAssassin 3.4.2 fixes a local user code injection in the meta rule syntax. Apache SpamAssassin 3.4.2 fixes a local user code injection in the meta rule syntax.
nvd
CVE-2022-40023P3HIGHCVSS 7.5v10.02022-09-07
CVE-2022-40023 [HIGH] CWE-1333 CVE-2022-40023: Sqlalchemy mako before 1.2.2 is vulnerable to Regular expression Denial of Service when using the Le Sqlalchemy mako before 1.2.2 is vulnerable to Regular expression Denial of Service when using the Lexer class to parse. This also affects babelplugin and linguaplugin.
nvd
CVE-2019-14816P3HIGHCVSS 7.8v8.02019-09-20
CVE-2019-14816 [HIGH] CWE-122 CVE-2019-14816: There is heap-based buffer overflow in kernel, all versions up to, excluding 5.3, in the marvell wif There is heap-based buffer overflow in kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local users to cause a denial of service(system crash) or possibly execute arbitrary code.
nvd
CVE-2018-5157P3HIGHCVSS 7.5v7.0v8.0+1 more2018-06-11
CVE-2018-5157 [HIGH] CWE-200 CVE-2018-5157: Same-origin protections for the PDF viewer can be bypassed, allowing a malicious site to intercept m Same-origin protections for the PDF viewer can be bypassed, allowing a malicious site to intercept messages meant for the viewer. This could allow the site to retrieve PDF files restricted to viewing by an authenticated user on a third-party website. This vulnerability affects Firefox ESR < 52.8 and Firefox < 60.
nvd
CVE-2019-14814P3HIGHCVSS 7.8v8.02019-09-20
CVE-2019-14814 [HIGH] CWE-122 CVE-2019-14814: There is heap-based buffer overflow in Linux kernel, all versions up to, excluding 5.3, in the marve There is heap-based buffer overflow in Linux kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local users to cause a denial of service(system crash) or possibly execute arbitrary code.
nvd
CVE-2021-45909P3HIGHCVSS 7.8v9.02021-12-28
CVE-2021-45909 [HIGH] CWE-787 CVE-2021-45909: An issue was discovered in gif2apng 1.9. There is a heap-based buffer overflow vulnerability in the An issue was discovered in gif2apng 1.9. There is a heap-based buffer overflow vulnerability in the DecodeLZW function. It allows an attacker to write a large amount of arbitrary data outside the boundaries of a buffer.
nvd
CVE-2018-10879P3HIGHCVSS 7.8v8.02018-07-26
CVE-2018-10879 [HIGH] CWE-416 CVE-2018-10879: A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause a use-after-free in e A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause a use-after-free in ext4_xattr_set_entry function and a denial of service or unspecified other impact may occur by renaming a file in a crafted ext4 filesystem image.
nvd
CVE-2015-0294P3HIGHCVSS 7.5v7.02020-01-27
CVE-2015-0294 [HIGH] CWE-295 CVE-2015-0294: GnuTLS before 3.3.13 does not validate that the signature algorithms match when importing a certific GnuTLS before 3.3.13 does not validate that the signature algorithms match when importing a certificate.
nvd
CVE-2018-10242P3HIGHCVSS 7.5v8.02019-04-04
CVE-2018-10242 [HIGH] CWE-125 CVE-2018-10242: Suricata version 4.0.4 incorrectly handles the parsing of the SSH banner. A malformed SSH banner can Suricata version 4.0.4 incorrectly handles the parsing of the SSH banner. A malformed SSH banner can cause the parsing code to read beyond the allocated data because SSHParseBanner in app-layer-ssh.c lacks a length check.
nvd
CVE-2023-37369P3HIGHCVSS 7.5v10.02023-08-20
CVE-2023-37369 [HIGH] CVE-2023-37369: In Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2, there can be an applic In Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2, there can be an application crash in QXmlStreamReader via a crafted XML string that triggers a situation in which a prefix is greater than a length.
nvd
CVE-2021-46829P3HIGHCVSS 7.8v11.02022-07-24
CVE-2021-46829 [HIGH] CWE-190 CVE-2021-46829: GNOME GdkPixbuf (aka GDK-PixBuf) before 2.42.8 allows a heap-based buffer overflow when compositing GNOME GdkPixbuf (aka GDK-PixBuf) before 2.42.8 allows a heap-based buffer overflow when compositing or clearing frames in GIF files, as demonstrated by io-gif-animation.c composite_frame. This overflow is controllable and could be abused for code execution, especially on 32-bit systems.
nvd
Debian Linux vulnerabilities | cvebase