cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 232 of 498
CVE-2017-2899P3HIGHCVSS 7.8v8.0v9.02018-04-24
CVE-2017-2899 [HIGH] CWE-190 CVE-2017-2899: An exploitable integer overflow exists in the TIFF loading functionality of the Blender open-source An exploitable integer overflow exists in the TIFF loading functionality of the Blender open-source 3d creation suite version 2.78c. A specially crafted '.tif' file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to use the file as an ass
nvd
CVE-2017-2906P3HIGHCVSS 7.8v8.0v9.02018-04-24
CVE-2017-2906 [HIGH] CWE-190 CVE-2017-2906: An exploitable integer overflow exists in the animation playing functionality of the Blender open-so An exploitable integer overflow exists in the animation playing functionality of the Blender open-source 3d creation suite version 2.78c. A specially created '.avi' file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to use the file as
nvd
CVE-2017-12102P3HIGHCVSS 7.8v8.0v9.02018-04-24
CVE-2017-12102 [HIGH] CWE-190 CVE-2017-12102: An exploitable integer overflow exists in the way that the Blender open-source 3d creation suite v2. An exploitable integer overflow exists in the way that the Blender open-source 3d creation suite v2.78c converts curves to polygons. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to open the file or us
nvd
CVE-2017-12105P3HIGHCVSS 7.8v8.0v9.02018-04-24
CVE-2017-12105 [HIGH] CWE-190 CVE-2017-12105: An exploitable integer overflow exists in the way that the Blender open-source 3d creation suite v2. An exploitable integer overflow exists in the way that the Blender open-source 3d creation suite v2.78c applies a particular object modifier to a Mesh. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to
nvd
CVE-2016-2194P3HIGHCVSS 7.5v8.02016-05-13
CVE-2016-2194 [HIGH] CWE-20 CVE-2016-2194: The ressol function in Botan before 1.10.11 and 1.11.x before 1.11.27 allows remote attackers to cau The ressol function in Botan before 1.10.11 and 1.11.x before 1.11.27 allows remote attackers to cause a denial of service (infinite loop) via unspecified input to the OS2ECP function, related to a composite modulus.
nvd
CVE-2017-7754P3HIGHCVSS 7.5v8.0v9.02018-06-11
CVE-2017-7754 [HIGH] CWE-125 CVE-2017-7754: An out-of-bounds read in WebGL with a maliciously crafted "ImageInfo" object during WebGL operations An out-of-bounds read in WebGL with a maliciously crafted "ImageInfo" object during WebGL operations. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
nvd
CVE-2014-3564P3MEDIUMCVSS 6.8v6.02014-10-20
CVE-2014-3564 [MEDIUM] CWE-119 CVE-2014-3564: Multiple heap-based buffer overflows in the status_handler function in (1) engine-gpgsm.c and (2) en Multiple heap-based buffer overflows in the status_handler function in (1) engine-gpgsm.c and (2) engine-uiserver.c in GPGME before 1.5.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to "different line lengths in a specific order."
nvd
CVE-2014-1490P3CRITICALCVSS 9.3v7.02014-02-06
CVE-2014-1490 [CRITICAL] CWE-362 CVE-2014-1490: Race condition in libssl in Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozill Race condition in libssl in Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via vectors involv
nvd
CVE-2023-41080P3MEDIUMCVSS 6.1v10.0v11.02023-08-25
CVE-2023-41080 [MEDIUM] CWE-601 CVE-2023-41080: URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apa URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0.0-M1 through 9.0.79 and from 8.5.0 through 8.5.92. Older, EOL versions may also be affected. The vulnerability is limited to the
nvd
CVE-2018-16585P3HIGHCVSS 7.8v8.0v9.02018-09-06
CVE-2018-16585 [HIGH] CVE-2018-16585: An issue was discovered in Artifex Ghostscript before 9.24. The .setdistillerkeys PostScript command An issue was discovered in Artifex Ghostscript before 9.24. The .setdistillerkeys PostScript command is accepted even though it is not intended for use during document processing (e.g., after the startup phase). This leads to memory corruption, allowing remote attackers able to supply crafted PostScript to crash the interpreter or possibly have unspecified ot
nvd
CVE-2017-7746P3HIGHCVSS 7.5v8.02017-04-12
CVE-2017-7746 [HIGH] CWE-835 CVE-2017-7746: In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the SLSK dissector could go into an infinite loop, In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the SLSK dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-slsk.c by adding checks for the remaining length.
nvd
CVE-2018-14624P3HIGHCVSS 7.5v8.02018-09-06
CVE-2018-14624 [HIGH] CWE-20 CVE-2018-14624: A vulnerability was discovered in 389-ds-base through versions 1.3.7.10, 1.3.8.8 and 1.4.0.16. The l A vulnerability was discovered in 389-ds-base through versions 1.3.7.10, 1.3.8.8 and 1.4.0.16. The lock controlling the error log was not correctly used when re-opening the log file in log__error_emergency(). An attacker could send a flood of modifications to a very large DN, which would cause slapd to crash.
nvd
CVE-2020-19131P3HIGHCVSS 7.5v9.02021-09-07
CVE-2020-19131 [HIGH] CWE-787 CVE-2020-19131: Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the "invertImag Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the "invertImage()" function in the component "tiffcrop".
nvd
CVE-2006-4245P3HIGHCVSS 8.1v8.0v9.0+1 more2019-11-06
CVE-2006-4245 [HIGH] CWE-362 CVE-2006-4245: archivemail 0.6.2 uses temporary files insecurely leading to a possible race condition. archivemail 0.6.2 uses temporary files insecurely leading to a possible race condition.
nvd
CVE-2018-7323P3HIGHCVSS 7.5v7.0v8.02018-02-23
CVE-2018-7323 [HIGH] CWE-834 CVE-2018-7323: In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-wccp.c had a large loop that In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-wccp.c had a large loop that was addressed by ensuring that a calculated length was monotonically increasing.
nvd
CVE-2019-1010057P3HIGHCVSS 7.8v9.02019-07-16
CVE-2019-1010057 [HIGH] CWE-787 CVE-2019-1010057: nfdump 1.6.16 and earlier is affected by: Buffer Overflow. The impact is: The impact could range fro nfdump 1.6.16 and earlier is affected by: Buffer Overflow. The impact is: The impact could range from a denial of service to local code execution. The component is: nfx.c:546, nffile_inline.c:83, minilzo.c (redistributed). The attack vector is: nfdump must read and process a specially crafted file. The fixed version is: after commit 9f0fe9563366f6
nvd
CVE-2018-10393P3HIGHCVSS 7.5v8.0v9.02018-04-26
CVE-2018-10393 [HIGH] CWE-125 CVE-2018-10393: bark_noise_hybridmp in psy.c in Xiph.Org libvorbis 1.3.6 has a stack-based buffer over-read. bark_noise_hybridmp in psy.c in Xiph.Org libvorbis 1.3.6 has a stack-based buffer over-read.
nvd
CVE-2020-6071P3HIGHCVSS 7.5v9.02020-03-24
CVE-2020-6071 [HIGH] CWE-674 CVE-2020-6071: An exploitable denial-of-service vulnerability exists in the resource record-parsing functionality o An exploitable denial-of-service vulnerability exists in the resource record-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing compressed labels in mDNS messages, the compression pointer is followed without checking for recursion, leading to a denial of service. An attacker can send an mDNS message to trigger this vulnerability.
nvd
CVE-2018-7324P3HIGHCVSS 7.5v7.0v8.02018-02-23
CVE-2018-7324 [HIGH] CWE-835 CVE-2018-7324: In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-sccp.c had an infinite loop In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-sccp.c had an infinite loop that was addressed by using a correct integer data type.
nvd
CVE-2020-9481P3HIGHCVSS 7.5v10.02020-04-27
CVE-2020-9481 [HIGH] CWE-400 CVE-2020-9481: Apache ATS 6.0.0 to 6.2.3, 7.0.0 to 7.1.9, and 8.0.0 to 8.0.6 is vulnerable to a HTTP/2 slow read at Apache ATS 6.0.0 to 6.2.3, 7.0.0 to 7.1.9, and 8.0.0 to 8.0.6 is vulnerable to a HTTP/2 slow read attack.
nvd
Debian Linux vulnerabilities | cvebase