cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 230 of 498
CVE-2019-5429P3HIGHCVSS 7.8v9.02019-04-29
CVE-2019-5429 [HIGH] CWE-426 CVE-2019-5429: Untrusted search path in FileZilla before 3.41.0-rc1 allows an attacker to gain privileges via a mal Untrusted search path in FileZilla before 3.41.0-rc1 allows an attacker to gain privileges via a malicious 'fzsftp' binary in the user's home directory.
nvd
CVE-2018-18226P3HIGHCVSS 7.5v9.02018-10-12
CVE-2018-18226 [HIGH] CWE-772 CVE-2018-18226: In Wireshark 2.6.0 to 2.6.3, the Steam IHS Discovery dissector could consume system memory. This was In Wireshark 2.6.0 to 2.6.3, the Steam IHS Discovery dissector could consume system memory. This was addressed in epan/dissectors/packet-steam-ihs-discovery.c by changing the memory-management approach.
nvd
CVE-2012-0442P3CRITICALCVSS 9.3v5.0v6.02012-02-01
CVE-2012-0442 [CRITICAL] CVE-2012-0442: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.6.26 and 4.x Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2021-33582P3HIGHCVSS 7.5v9.02021-09-01
CVE-2021-33582 [HIGH] CWE-407 CVE-2021-33582: Cyrus IMAP before 3.4.2 allows remote attackers to cause a denial of service (multiple-minute daemon Cyrus IMAP before 3.4.2 allows remote attackers to cause a denial of service (multiple-minute daemon hang) via input that is mishandled during hash-table interaction. Because there are many insertions into a single bucket, strcmp becomes slow. This is fixed in 3.4.2, 3.2.8, and 3.0.16.
nvd
CVE-2017-18359P3HIGHCVSS 7.5v8.0v9.02019-01-25
CVE-2017-18359 [HIGH] CWE-20 CVE-2017-18359: PostGIS 2.x before 2.3.3, as used with PostgreSQL, allows remote attackers to cause a denial of serv PostGIS 2.x before 2.3.3, as used with PostgreSQL, allows remote attackers to cause a denial of service via crafted ST_AsX3D function input, as demonstrated by an abnormal server termination for "SELECT ST_AsX3D('LINESTRING EMPTY');" because empty geometries are mishandled.
nvd
CVE-2019-9897P3HIGHCVSS 7.5v8.0v9.02019-03-21
CVE-2019-9897 [HIGH] CVE-2019-9897: Multiple denial-of-service attacks that can be triggered by writing to the terminal exist in PuTTY v Multiple denial-of-service attacks that can be triggered by writing to the terminal exist in PuTTY versions before 0.71.
nvd
CVE-2014-9747P3HIGHCVSS 7.5v7.0v8.02016-06-07
CVE-2014-9747 [HIGH] CWE-399 CVE-2014-9747: The t42_parse_encoding function in type42/t42parse.c in FreeType before 2.5.4 does not properly upda The t42_parse_encoding function in type42/t42parse.c in FreeType before 2.5.4 does not properly update the current position for immediates-only mode, which allows remote attackers to cause a denial of service (infinite loop) via a Type42 font.
nvd
CVE-2017-9349P3HIGHCVSS 7.5v8.02017-06-02
CVE-2017-9349 [HIGH] CWE-835 CVE-2017-9349: In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the DICOM dissector has an infinite loop. This was In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the DICOM dissector has an infinite loop. This was addressed in epan/dissectors/packet-dcm.c by validating a length value.
nvd
CVE-2019-7175P3HIGHCVSS 7.5v10.02019-03-07
CVE-2019-7175 [HIGH] CWE-401 CVE-2019-7175: In ImageMagick before 7.0.8-25, some memory leaks exist in DecodeImage in coders/pcd.c. In ImageMagick before 7.0.8-25, some memory leaks exist in DecodeImage in coders/pcd.c.
nvd
CVE-2013-4412P3HIGHCVSS 7.5v6.0v7.02019-11-04
CVE-2013-4412 [HIGH] CWE-476 CVE-2013-4412: slim has NULL pointer dereference when using crypt() method from glibc 2.17 slim has NULL pointer dereference when using crypt() method from glibc 2.17
nvd
CVE-2020-9369P3HIGHCVSS 7.5v10.02020-02-24
CVE-2020-9369 [HIGH] CWE-400 CVE-2020-9369: Sympa 6.2.38 through 6.2.52 allows remote attackers to cause a denial of service (disk consumption f Sympa 6.2.38 through 6.2.52 allows remote attackers to cause a denial of service (disk consumption from temporary files, and a flood of notifications to listmasters) via a series of requests with malformed parameters.
nvd
CVE-2018-1064P3HIGHCVSS 7.5v7.0v8.0+1 more2018-03-28
CVE-2018-1064 [HIGH] CWE-400 CVE-2018-1064: libvirt version before 4.2.0-rc1 is vulnerable to a resource exhaustion as a result of an incomplete libvirt version before 4.2.0-rc1 is vulnerable to a resource exhaustion as a result of an incomplete fix for CVE-2018-5748 that affects QEMU monitor but now also triggered via QEMU guest agent.
nvd
CVE-2018-10120P3HIGHCVSS 7.8v7.0v8.0+1 more2018-04-16
CVE-2018-10120 [HIGH] CWE-129 CVE-2018-10120: The SwCTBWrapper::Read function in sw/source/filter/ww8/ww8toolbar.cxx in LibreOffice before 5.4.6.1 The SwCTBWrapper::Read function in sw/source/filter/ww8/ww8toolbar.cxx in LibreOffice before 5.4.6.1 and 6.x before 6.0.2.1 does not validate a customizations index, which allows remote attackers to cause a denial of service (heap-based buffer overflow with write access) or possibly have unspecified other impact via a crafted document that contains a
nvd
CVE-2020-15890P3HIGHCVSS 7.5v9.02020-07-21
CVE-2020-15890 [HIGH] CWE-125 CVE-2020-15890: LuaJit through 2.1.0-beta3 has an out-of-bounds read because __gc handler frame traversal is mishand LuaJit through 2.1.0-beta3 has an out-of-bounds read because __gc handler frame traversal is mishandled.
nvd
CVE-2018-10537P3HIGHCVSS 7.8v8.0v9.02018-04-29
CVE-2018-10537 [HIGH] CWE-119 CVE-2018-10537: An issue was discovered in WavPack 5.1.0 and earlier. The W64 parser component contains a vulnerabil An issue was discovered in WavPack 5.1.0 and earlier. The W64 parser component contains a vulnerability that allows writing to memory because ParseWave64HeaderConfig in wave64.c does not reject multiple format chunks.
nvd
CVE-2017-12099P3HIGHCVSS 7.8v8.0v9.02018-04-24
CVE-2017-12099 [HIGH] CWE-190 CVE-2017-12099: An exploitable integer overflow exists in the upgrade of the legacy Mesh attribute 'tface' of the Bl An exploitable integer overflow exists in the upgrade of the legacy Mesh attribute 'tface' of the Blender open-source 3d creation suite v2.78c. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to open the
nvd
CVE-2017-5506P3HIGHCVSS 7.8v8.0v9.02017-03-24
CVE-2017-5506 [HIGH] CWE-415 CVE-2017-5506: Double free vulnerability in magick/profile.c in ImageMagick allows remote attackers to have unspeci Double free vulnerability in magick/profile.c in ImageMagick allows remote attackers to have unspecified impact via a crafted file.
nvd
CVE-2017-12082P3HIGHCVSS 7.8v8.0v9.02018-04-24
CVE-2017-12082 [HIGH] CWE-190 CVE-2017-12082: An exploitable integer overflow exists in the 'CustomData' Mesh loading functionality of the Blender An exploitable integer overflow exists in the 'CustomData' Mesh loading functionality of the Blender open-source 3d creation suite. A .blend file with a specially crafted external data file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a us
nvd
CVE-2017-12081P3HIGHCVSS 7.8v8.0v9.02018-04-24
CVE-2017-12081 [HIGH] CWE-190 CVE-2017-12081: An exploitable integer overflow exists in the upgrade of a legacy Mesh attribute of the Blender open An exploitable integer overflow exists in the upgrade of a legacy Mesh attribute of the Blender open-source 3d creation suite v2.78c. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to open the file or u
nvd
CVE-2021-20270P3HIGHCVSS 7.5v9.0v10.02021-03-23
CVE-2021-20270 [HIGH] CWE-835 CVE-2021-20270: An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when pe An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file, as demonstrated by input that only contains the "exception" keyword.
nvd
Debian Linux vulnerabilities | cvebase