Debian Linux vulnerabilities
9,954 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358
Vulnerabilities
Page 228 of 498
CVE-2005-1513P3CRITICALCVSS 9.8v8.0v9.0+1 more2005-05-11
CVE-2005-1513 [CRITICAL] CWE-190 CVE-2005-1513: Integer overflow in the stralloc_readyplus function in qmail, when running on 64 bit platforms with
Integer overflow in the stralloc_readyplus function in qmail, when running on 64 bit platforms with a large amount of virtual memory, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large SMTP request.
nvd
CVE-2016-5177P3HIGHCVSS 8.8v8.02017-05-23
CVE-2016-5177 [HIGH] CWE-416 CVE-2016-5177: Use-after-free vulnerability in V8 in Google Chrome before 53.0.2785.143 allows remote attackers to
Use-after-free vulnerability in V8 in Google Chrome before 53.0.2785.143 allows remote attackers to cause a denial of service (crash) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2018-1283P3MEDIUMCVSS 5.3v8.0v9.02018-03-26
CVE-2018-1283 [MEDIUM] CVE-2018-1283: In Apache httpd 2.4.0 to 2.4.29, when mod_session is configured to forward its session data to CGI a
In Apache httpd 2.4.0 to 2.4.29, when mod_session is configured to forward its session data to CGI applications (SessionEnv on, not the default), a remote user may influence their content by using a "Session" header. This comes from the "HTTP_SESSION" variable name used by mod_session to forward its data to CGIs, since the prefix "HTTP_" is also used by the A
nvd
CVE-2014-9661P3HIGHCVSS 7.5v7.02015-02-08
CVE-2014-9661 [HIGH] CVE-2014-9661: type42/t42parse.c in FreeType before 2.5.4 does not consider that scanning can be incomplete without
type42/t42parse.c in FreeType before 2.5.4 does not consider that scanning can be incomplete without triggering an error, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted Type42 font.
nvd
CVE-2009-1837P3HIGHCVSS 7.5v5.02009-06-12
CVE-2009-1837 [HIGH] CWE-362 CVE-2009-1837: Race condition in the NPObjWrapper_NewResolve function in modules/plugin/base/src/nsJSNPRuntime.cpp
Race condition in the NPObjWrapper_NewResolve function in modules/plugin/base/src/nsJSNPRuntime.cpp in xul.dll in Mozilla Firefox 3 before 3.0.11 might allow remote attackers to execute arbitrary code via a page transition during Java applet loading, related to a use-after-free vulnerability for memory associated with a destroyed Java object.
nvd
CVE-2019-20421P3HIGHCVSS 7.5v9.0v10.02020-01-27
CVE-2019-20421 [HIGH] CWE-835 CVE-2019-20421: In Jp2Image::readMetadata() in jp2image.cpp in Exiv2 0.27.2, an input file can result in an infinite
In Jp2Image::readMetadata() in jp2image.cpp in Exiv2 0.27.2, an input file can result in an infinite loop and hang, with high CPU consumption. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file.
nvd
CVE-2019-19553P3HIGHCVSS 7.5v9.02019-12-05
CVE-2019-19553 [HIGH] CWE-909 CVE-2019-19553: In Wireshark 3.0.0 to 3.0.6 and 2.6.0 to 2.6.12, the CMS dissector could crash. This was addressed i
In Wireshark 3.0.0 to 3.0.6 and 2.6.0 to 2.6.12, the CMS dissector could crash. This was addressed in epan/dissectors/asn1/cms/packet-cms-template.c by ensuring that an object identifier is set to NULL after a ContentInfo dissection.
nvd
CVE-2013-2487P3HIGHCVSS 7.8v7.02013-03-07
CVE-2013-2487 [HIGH] CVE-2013-2487: epan/dissectors/packet-reload.c in the REsource LOcation And Discovery (aka RELOAD) dissector in Wir
epan/dissectors/packet-reload.c in the REsource LOcation And Discovery (aka RELOAD) dissector in Wireshark 1.8.x before 1.8.6 uses incorrect integer data types, which allows remote attackers to cause a denial of service (infinite loop) via crafted integer values in a packet, related to the (1) dissect_icecandidates, (2) dissect_kinddata, (3) dissect_nodeid_list
nvd
CVE-2018-14465P3HIGHCVSS 7.5v8.0v9.0+1 more2019-10-03
CVE-2018-14465 [HIGH] CWE-125 CVE-2018-14465: The RSVP parser in tcpdump before 4.9.3 has a buffer over-read in print-rsvp.c:rsvp_obj_print().
The RSVP parser in tcpdump before 4.9.3 has a buffer over-read in print-rsvp.c:rsvp_obj_print().
nvd
CVE-2018-11406P3HIGHCVSS 8.8v9.02018-06-13
CVE-2018-11406 [HIGH] CWE-352 CVE-2018-11406: An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.4
An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. By default, a user's session is invalidated when the user is logged out. This behavior can be disabled through the invalidate_session option. In this case, CSRF tokens were not erased
nvd
CVE-2018-14467P3HIGHCVSS 7.5v8.0v9.0+1 more2019-10-03
CVE-2018-14467 [HIGH] CWE-125 CVE-2018-14467: The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_capabilities_print(
The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_capabilities_print() (BGP_CAPCODE_MP).
nvd
CVE-2018-14464P3HIGHCVSS 7.5v8.0v9.0+1 more2019-10-03
CVE-2018-14464 [HIGH] CWE-125 CVE-2018-14464: The LMP parser in tcpdump before 4.9.3 has a buffer over-read in print-lmp.c:lmp_print_data_link_sub
The LMP parser in tcpdump before 4.9.3 has a buffer over-read in print-lmp.c:lmp_print_data_link_subobjs().
nvd
CVE-2018-14470P3HIGHCVSS 7.5v8.0v9.0+1 more2019-10-03
CVE-2018-14470 [HIGH] CWE-125 CVE-2018-14470: The Babel parser in tcpdump before 4.9.3 has a buffer over-read in print-babel.c:babel_print_v2().
The Babel parser in tcpdump before 4.9.3 has a buffer over-read in print-babel.c:babel_print_v2().
nvd
CVE-2018-14461P3HIGHCVSS 7.5v8.0v9.0+1 more2019-10-03
CVE-2018-14461 [HIGH] CWE-125 CVE-2018-14461: The LDP parser in tcpdump before 4.9.3 has a buffer over-read in print-ldp.c:ldp_tlv_print().
The LDP parser in tcpdump before 4.9.3 has a buffer over-read in print-ldp.c:ldp_tlv_print().
nvd
CVE-2018-14466P3HIGHCVSS 7.5v8.0v9.0+1 more2019-10-03
CVE-2018-14466 [HIGH] CWE-125 CVE-2018-14466: The Rx parser in tcpdump before 4.9.3 has a buffer over-read in print-rx.c:rx_cache_find() and rx_ca
The Rx parser in tcpdump before 4.9.3 has a buffer over-read in print-rx.c:rx_cache_find() and rx_cache_insert().
nvd
CVE-2018-14462P3HIGHCVSS 7.5v8.0v9.0+1 more2019-10-03
CVE-2018-14462 [HIGH] CWE-125 CVE-2018-14462: The ICMP parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp.c:icmp_print().
The ICMP parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp.c:icmp_print().
nvd
CVE-2015-8619P3HIGHCVSS 7.5v8.02017-04-13
CVE-2015-8619 [HIGH] CWE-787 CVE-2015-8619: The Human Monitor Interface support in QEMU allows remote attackers to cause a denial of service (ou
The Human Monitor Interface support in QEMU allows remote attackers to cause a denial of service (out-of-bounds write and application crash).
nvd
CVE-2018-14882P3HIGHCVSS 7.5v8.0v9.0+1 more2019-10-03
CVE-2018-14882 [HIGH] CWE-125 CVE-2018-14882: The ICMPv6 parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp6.c.
The ICMPv6 parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp6.c.
nvd
CVE-2018-16230P3HIGHCVSS 7.5v8.0v9.0+1 more2019-10-03
CVE-2018-16230 [HIGH] CWE-125 CVE-2018-16230: The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_attr_print() (MP_RE
The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_attr_print() (MP_REACH_NLRI).
nvd
CVE-2018-17461P3HIGHCVSS 8.8v9.02019-01-09
CVE-2018-17461 [HIGH] CWE-125 CVE-2018-17461: An out of bounds read in PDFium in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to
An out of bounds read in PDFium in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to perform an out of bounds memory read via a crafted PDF file.
nvd