Debian Linux vulnerabilities
9,954 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358
Vulnerabilities
Page 229 of 498
CVE-2022-39177P3HIGHCVSS 8.8v10.02022-09-02
CVE-2022-39177 [HIGH] CVE-2022-39177: BlueZ before 5.59 allows physically proximate attackers to cause a denial of service because malform
BlueZ before 5.59 allows physically proximate attackers to cause a denial of service because malformed and invalid capabilities can be processed in profiles/audio/avdtp.c.
nvd
CVE-2016-7800P3HIGHCVSS 7.5v8.02017-02-06
CVE-2016-7800 [HIGH] CWE-119 CVE-2016-7800: Integer underflow in the parse8BIM function in coders/meta.c in GraphicsMagick 1.3.25 and earlier al
Integer underflow in the parse8BIM function in coders/meta.c in GraphicsMagick 1.3.25 and earlier allows remote attackers to cause a denial of service (application crash) via a crafted 8BIM chunk, which triggers a heap-based buffer overflow.
nvd
CVE-2017-13711P3HIGHCVSS 7.5v9.02017-09-01
CVE-2017-13711 [HIGH] CWE-416 CVE-2017-13711: Use-after-free vulnerability in the sofree function in slirp/socket.c in QEMU (aka Quick Emulator) a
Use-after-free vulnerability in the sofree function in slirp/socket.c in QEMU (aka Quick Emulator) allows attackers to cause a denial of service (QEMU instance crash) by leveraging failure to properly clear ifq_so from pending packets.
nvd
CVE-2016-2124P3MEDIUMCVSS 5.9v9.0v10.02022-02-18
CVE-2016-2124 [MEDIUM] CWE-287 CVE-2016-2124: A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw t
A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the wire even if Kerberos authentication was required.
nvd
CVE-2017-14246P3HIGHCVSS 8.1v8.02017-09-21
CVE-2017-14246 [HIGH] CWE-125 CVE-2017-14246: An out of bounds read in the function d2ulaw_array() in ulaw.c of libsndfile 1.0.28 may lead to a re
An out of bounds read in the function d2ulaw_array() in ulaw.c of libsndfile 1.0.28 may lead to a remote DoS attack or information disclosure, related to mishandling of the NAN and INFINITY floating-point values.
nvd
CVE-2018-14342P3HIGHCVSS 7.5v8.02018-07-19
CVE-2018-14342 [HIGH] CWE-834 CVE-2018-14342: In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the BGP protocol dissector could g
In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the BGP protocol dissector could go into a large loop. This was addressed in epan/dissectors/packet-bgp.c by validating Path Attribute lengths.
nvd
CVE-2019-18804P3HIGHCVSS 7.5v8.0v9.0+2 more2019-11-07
CVE-2019-18804 [HIGH] CWE-476 CVE-2019-18804: DjVuLibre 3.5.27 has a NULL pointer dereference in the function DJVU::filter_fv at IW44EncodeCodec.c
DjVuLibre 3.5.27 has a NULL pointer dereference in the function DJVU::filter_fv at IW44EncodeCodec.cpp.
nvd
CVE-2018-2799P3MEDIUMCVSS 5.3v8.0v9.02018-04-19
CVE-2018-2799 [MEDIUM] CVE-2018-2799: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: J
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JAXP). Supported versions that are affected are Java SE: 7u171, 8u162 and 10; Java SE Embedded: 8u161; JRockit: R28.3.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE E
nvd
CVE-2017-7807P3HIGHCVSS 8.1v8.0v9.02018-06-11
CVE-2017-7807 [HIGH] CWE-20 CVE-2017-7807: A mechanism that uses AppCache to hijack a URL in a domain using fallback by serving the files from
A mechanism that uses AppCache to hijack a URL in a domain using fallback by serving the files from a sub-path on the domain. This has been addressed by requiring fallback files be inside the manifest directory. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
nvd
CVE-2018-20743P3HIGHCVSS 7.5v8.0v9.02019-01-25
CVE-2018-20743 [HIGH] CWE-20 CVE-2018-20743: murmur in Mumble through 1.2.19 before 2018-08-31 mishandles multiple concurrent requests that are p
murmur in Mumble through 1.2.19 before 2018-08-31 mishandles multiple concurrent requests that are persisted in the database, which allows remote attackers to cause a denial of service (daemon hang or crash) via a message flood.
nvd
CVE-2004-0888P4CRITICALCVSS 10.0v3.02005-01-27
CVE-2004-0888 [CRITICAL] CVE-2004-0888: Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS,
Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0889.
nvd
CVE-2020-13848P3HIGHCVSS 7.5v8.02020-06-04
CVE-2020-13848 [HIGH] CWE-476 CVE-2020-13848: Portable UPnP SDK (aka libupnp) 1.12.1 and earlier allows remote attackers to cause a denial of serv
Portable UPnP SDK (aka libupnp) 1.12.1 and earlier allows remote attackers to cause a denial of service (crash) via a crafted SSDP message due to a NULL pointer dereference in the functions FindServiceControlURLPath and FindServiceEventURLPath in genlib/service_table/service_table.c.
nvd
CVE-2018-11360P3HIGHCVSS 7.5v8.0v9.02018-05-22
CVE-2018-11360 [HIGH] CWE-119 CVE-2018-11360: In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the GSM A DTAP dissector could crash. This
In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the GSM A DTAP dissector could crash. This was addressed in epan/dissectors/packet-gsm_a_dtap.c by fixing an off-by-one error that caused a buffer overflow.
nvd
CVE-2018-16057P3HIGHCVSS 7.5v8.0v9.02018-08-30
CVE-2018-16057 [HIGH] CVE-2018-16057: In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16, the Radiotap dissector could crash
In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16, the Radiotap dissector could crash. This was addressed in epan/dissectors/packet-ieee80211-radiotap-iter.c by validating iterator operations.
nvd
CVE-2017-9835P3HIGHCVSS 7.8v8.0v9.02017-07-26
CVE-2017-9835 [HIGH] CWE-190 CVE-2017-9835: The gs_alloc_ref_array function in psi/ialloc.c in Artifex Ghostscript 9.21 allows remote attackers
The gs_alloc_ref_array function in psi/ialloc.c in Artifex Ghostscript 9.21 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted PostScript document. This is related to a lack of an integer overflow check in base/gsalloc.c.
nvd
CVE-2020-14397P3HIGHCVSS 7.5v8.0v9.02020-06-17
CVE-2020-14397 [HIGH] CWE-476 CVE-2020-14397: An issue was discovered in LibVNCServer before 0.9.13. libvncserver/rfbregion.c has a NULL pointer d
An issue was discovered in LibVNCServer before 0.9.13. libvncserver/rfbregion.c has a NULL pointer dereference.
nvd
CVE-2020-18032P3HIGHCVSS 7.8v9.0v10.02021-04-29
CVE-2020-18032 [HIGH] CWE-120 CVE-2020-18032: Buffer Overflow in Graphviz Graph Visualization Tools from commit ID f8b9e035 and earlier allows rem
Buffer Overflow in Graphviz Graph Visualization Tools from commit ID f8b9e035 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by loading a crafted file into the "lib/common/shapes.c" component.
nvd
CVE-2020-11647P3HIGHCVSS 7.5v9.02020-04-10
CVE-2020-11647 [HIGH] CWE-674 CVE-2020-11647: In Wireshark 3.2.0 to 3.2.2, 3.0.0 to 3.0.9, and 2.6.0 to 2.6.15, the BACapp dissector could crash.
In Wireshark 3.2.0 to 3.2.2, 3.0.0 to 3.0.9, and 2.6.0 to 2.6.15, the BACapp dissector could crash. This was addressed in epan/dissectors/packet-bacapp.c by limiting the amount of recursion.
nvd
CVE-2021-22235P3HIGHCVSS 7.5v9.0v10.0+1 more2021-07-20
CVE-2021-22235 [HIGH] CWE-835 CVE-2021-22235: Crash in DNP dissector in Wireshark 3.4.0 to 3.4.6 and 3.2.0 to 3.2.14 allows denial of service via
Crash in DNP dissector in Wireshark 3.4.0 to 3.4.6 and 3.2.0 to 3.2.14 allows denial of service via packet injection or crafted capture file
nvd
CVE-2013-4232P3MEDIUMCVSS 6.8v6.0v7.02013-09-10
CVE-2013-4232 [MEDIUM] CWE-399 CVE-2013-4232: Use-after-free vulnerability in the t2p_readwrite_pdf_image function in tools/tiff2pdf.c in libtiff
Use-after-free vulnerability in the t2p_readwrite_pdf_image function in tools/tiff2pdf.c in libtiff 4.0.3 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted TIFF image.
nvd