cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 231 of 498
CVE-2016-9904P3HIGHCVSS 7.5v8.02018-06-11
CVE-2016-9904 [HIGH] CWE-200 CVE-2016-9904: An attacker could use a JavaScript Map/Set timing attack to determine whether an atom is used by ano An attacker could use a JavaScript Map/Set timing attack to determine whether an atom is used by another compartment/zone in specific contexts. This could be used to leak information, such as usernames embedded in JavaScript code, across websites. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
nvd
CVE-2017-2903P3HIGHCVSS 7.8v8.0v9.02018-04-24
CVE-2017-2903 [HIGH] CWE-190 CVE-2017-2903: An exploitable integer overflow exists in the DPX loading functionality of the Blender open-source 3 An exploitable integer overflow exists in the DPX loading functionality of the Blender open-source 3d creation suite version 2.78c. A specially crafted '.cin' file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to use the file as an ass
nvd
CVE-2019-14459P3HIGHCVSS 7.5v9.02019-07-31
CVE-2019-14459 [HIGH] CWE-190 CVE-2019-14459: nfdump 1.6.17 and earlier is affected by an integer overflow in the function Process_ipfix_template_ nfdump 1.6.17 and earlier is affected by an integer overflow in the function Process_ipfix_template_withdraw in ipfix.c that can be abused in order to crash the process remotely (denial of service).
nvd
CVE-2018-7334P3HIGHCVSS 7.5v7.0v8.0+1 more2018-02-23
CVE-2018-7334 [HIGH] CVE-2018-7334: In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, the UMTS MAC dissector could crash. This was addres In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, the UMTS MAC dissector could crash. This was addressed in epan/dissectors/packet-umts_mac.c by rejecting a certain reserved value.
nvd
CVE-2018-7418P3HIGHCVSS 7.5v7.0v8.02018-02-23
CVE-2018-7418 [HIGH] CVE-2018-7418: In Wireshark 2.2.0 to 2.2.12 and 2.4.0 to 2.4.4, the SIGCOMP dissector could crash. This was address In Wireshark 2.2.0 to 2.2.12 and 2.4.0 to 2.4.4, the SIGCOMP dissector could crash. This was addressed in epan/dissectors/packet-sigcomp.c by correcting the extraction of the length value.
nvd
CVE-2016-8654P3HIGHCVSS 7.8v8.02018-08-01
CVE-2016-8654 [HIGH] CWE-122 CVE-2016-8654: A heap-buffer overflow vulnerability was found in QMFB code in JPC codec caused by buffer being allo A heap-buffer overflow vulnerability was found in QMFB code in JPC codec caused by buffer being allocated with too small size. jasper versions before 2.0.0 are affected.
nvd
CVE-2017-6471P3HIGHCVSS 7.5v8.02017-03-04
CVE-2017-6471 [HIGH] CWE-20 CVE-2017-6471: In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a WSP infinite loop, triggered by packet i In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a WSP infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-wsp.c by validating the capability length.
nvd
CVE-2017-6472P3HIGHCVSS 7.5v8.02017-03-04
CVE-2017-6472 [HIGH] CWE-835 CVE-2017-6472: In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is an RTMPT dissector infinite loop, triggere In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is an RTMPT dissector infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-rtmpt.c by properly incrementing a certain sequence value.
nvd
CVE-2017-16852P3HIGHCVSS 8.1v8.0v9.02017-11-16
CVE-2017-16852 [HIGH] CWE-347 CVE-2017-16852: shibsp/metadata/DynamicMetadataProvider.cpp in the Dynamic MetadataProvider plugin in Shibboleth Ser shibsp/metadata/DynamicMetadataProvider.cpp in the Dynamic MetadataProvider plugin in Shibboleth Service Provider before 2.6.1 fails to properly configure itself with the MetadataFilter plugins and does not perform critical security checks such as signature verification, enforcement of validity periods, and other checks specific to deployments, aka SS
nvd
CVE-2013-4234P3MEDIUMCVSS 6.8v6.0v7.02013-09-16
CVE-2013-4234 [MEDIUM] CWE-119 CVE-2013-4234: Multiple heap-based buffer overflows in the (1) abc_MIDI_drum and (2) abc_MIDI_gchord functions in l Multiple heap-based buffer overflows in the (1) abc_MIDI_drum and (2) abc_MIDI_gchord functions in load_abc.cpp in libmodplug 0.8.8.4 and earlier allow remote attackers to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via a crafted ABC.
nvd
CVE-2017-2900P3HIGHCVSS 7.8v8.0v9.02018-04-24
CVE-2017-2900 [HIGH] CWE-190 CVE-2017-2900: An exploitable integer overflow exists in the PNG loading functionality of the Blender open-source 3 An exploitable integer overflow exists in the PNG loading functionality of the Blender open-source 3d creation suite version 2.78c. A specially crafted '.png' file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to use the file as an ass
nvd
CVE-2017-2905P3HIGHCVSS 7.8v8.0v9.02018-04-24
CVE-2017-2905 [HIGH] CWE-190 CVE-2017-2905: An exploitable integer overflow exists in the bmp loading functionality of the Blender open-source 3 An exploitable integer overflow exists in the bmp loading functionality of the Blender open-source 3d creation suite version 2.78c. A specially crafted '.bmp' file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to use the file as an ass
nvd
CVE-2017-2904P3HIGHCVSS 7.8v8.0v9.02018-04-24
CVE-2017-2904 [HIGH] CWE-190 CVE-2017-2904: An exploitable integer overflow exists in the RADIANCE loading functionality of the Blender open-sou An exploitable integer overflow exists in the RADIANCE loading functionality of the Blender open-source 3d creation suite version 2.78c. A specially crafted '.hdr' file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to use the file as a
nvd
CVE-2017-2902P3HIGHCVSS 7.8v8.0v9.02018-04-24
CVE-2017-2902 [HIGH] CWE-190 CVE-2017-2902: An exploitable integer overflow exists in the DPX loading functionality of the Blender open-source 3 An exploitable integer overflow exists in the DPX loading functionality of the Blender open-source 3d creation suite version 2.78c. A specially crafted '.cin' file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to use the file as an ass
nvd
CVE-2017-2907P3HIGHCVSS 7.8v8.0v9.02018-04-24
CVE-2017-2907 [HIGH] CWE-190 CVE-2017-2907: An exploitable integer overflow exists in the animation playing functionality of the Blender open-so An exploitable integer overflow exists in the animation playing functionality of the Blender open-source 3d creation suite version 2.78c. A specially created '.avi' file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to use the file as
nvd
CVE-2017-2901P3HIGHCVSS 7.8v8.0v9.02018-04-24
CVE-2017-2901 [HIGH] CWE-190 CVE-2017-2901: An exploitable integer overflow exists in the IRIS loading functionality of the Blender open-source An exploitable integer overflow exists in the IRIS loading functionality of the Blender open-source 3d creation suite version 2.78c. A specially crafted '.iris' file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to use the file as an as
nvd
CVE-2017-12104P3HIGHCVSS 7.8v8.0v9.02018-04-24
CVE-2017-12104 [HIGH] CWE-190 CVE-2017-12104: An exploitable integer overflow exists in the way that the Blender open-source 3d creation suite v2. An exploitable integer overflow exists in the way that the Blender open-source 3d creation suite v2.78c draws a Particle object. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to open the file or use th
nvd
CVE-2017-12103P3HIGHCVSS 7.8v8.0v9.02018-04-24
CVE-2017-12103 [HIGH] CWE-190 CVE-2017-12103: An exploitable integer overflow exists in the way that the Blender open-source 3d creation suite v2. An exploitable integer overflow exists in the way that the Blender open-source 3d creation suite v2.78c converts text rendered as a font into a curve. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to o
nvd
CVE-2017-14976P3HIGHCVSS 7.5v7.0v8.0+1 more2017-10-02
CVE-2017-14976 [HIGH] CWE-125 CVE-2017-14976: The FoFiType1C::convertToType0 function in FoFiType1C.cc in Poppler 0.59.0 has a heap-based buffer o The FoFiType1C::convertToType0 function in FoFiType1C.cc in Poppler 0.59.0 has a heap-based buffer over-read vulnerability if an out-of-bounds font dictionary index is encountered, which allows an attacker to launch a denial of service attack.
nvd
CVE-2018-17183P3HIGHCVSS 7.8v8.02018-09-19
CVE-2018-17183 [HIGH] CVE-2018-17183: Artifex Ghostscript before 9.25 allowed a user-writable error exception table, which could be used b Artifex Ghostscript before 9.25 allowed a user-writable error exception table, which could be used by remote attackers able to supply crafted PostScript to potentially overwrite or replace error handlers to inject code.
nvd
Debian Linux vulnerabilities | cvebase