Debian Linux vulnerabilities
9,954 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358
Vulnerabilities
Page 233 of 498
CVE-2021-35556P3MEDIUMCVSS 5.3v9.0v10.0+1 more2021-10-20
CVE-2021-35556 [MEDIUM] CWE-693 CVE-2021-35556: Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component
Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to
nvd
CVE-2020-27638P3HIGHCVSS 7.5v9.02020-10-22
CVE-2020-27638 [HIGH] CWE-617 CVE-2020-27638: receive.c in fastd before v21 allows denial of service (assertion failure) when receiving packets wi
receive.c in fastd before v21 allows denial of service (assertion failure) when receiving packets with an invalid type code.
nvd
CVE-2018-21247P3HIGHCVSS 7.5v8.0v9.02020-06-17
CVE-2018-21247 [HIGH] CWE-909 CVE-2018-21247: An issue was discovered in LibVNCServer before 0.9.13. There is an information leak (of uninitialize
An issue was discovered in LibVNCServer before 0.9.13. There is an information leak (of uninitialized memory contents) in the libvncclient/rfbproto.c ConnectToRFBRepeater function.
nvd
CVE-2018-7325P3HIGHCVSS 7.5v8.02018-02-23
CVE-2018-7325 [HIGH] CWE-835 CVE-2018-7325: In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-rpki-rtr.c had an infinite l
In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-rpki-rtr.c had an infinite loop that was addressed by validating a length field.
nvd
CVE-2018-7331P3HIGHCVSS 7.5v8.02018-02-23
CVE-2018-7331 [HIGH] CWE-835 CVE-2018-7331: In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-ber.c had an infinite loop t
In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-ber.c had an infinite loop that was addressed by validating a length.
nvd
CVE-2018-7332P3HIGHCVSS 7.5v7.02018-02-23
CVE-2018-7332 [HIGH] CWE-835 CVE-2018-7332: In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-reload.c had an infinite loo
In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-reload.c had an infinite loop that was addressed by validating a length.
nvd
CVE-2018-9256P3HIGHCVSS 7.5v8.02018-04-04
CVE-2018-9256 [HIGH] CWE-20 CVE-2018-9256: In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the LWAPP dissector could crash. This was addressed
In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the LWAPP dissector could crash. This was addressed in epan/dissectors/packet-lwapp.c by limiting the encapsulation levels to restrict the recursion depth.
nvd
CVE-2020-6510P3HIGHCVSS 7.8v10.02020-07-22
CVE-2020-6510 [HIGH] CWE-787 CVE-2020-6510: Heap buffer overflow in background fetch in Google Chrome prior to 84.0.4147.89 allowed a remote att
Heap buffer overflow in background fetch in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-0361P3HIGHCVSS 7.8v9.0v10.02022-01-26
CVE-2022-0361 [HIGH] CWE-122 CVE-2022-0361: Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
nvd
CVE-2022-0417P3HIGHCVSS 7.8v9.0v10.02022-02-01
CVE-2022-0417 [HIGH] CWE-122 CVE-2022-0417: Heap-based Buffer Overflow GitHub repository vim/vim prior to 8.2.
Heap-based Buffer Overflow GitHub repository vim/vim prior to 8.2.
nvd
CVE-2016-5285P3HIGHCVSS 7.5v8.0v9.0+1 more2019-11-15
CVE-2016-5285 [HIGH] CWE-476 CVE-2016-5285: A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missin
A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a Denial of Service.
nvd
CVE-2021-37789P3HIGHCVSS 8.1v10.02022-11-02
CVE-2021-37789 [HIGH] CWE-787 CVE-2021-37789: stb_image.h 2.27 has a heap-based buffer over in stbi__jpeg_load, leading to Information Disclosure
stb_image.h 2.27 has a heap-based buffer over in stbi__jpeg_load, leading to Information Disclosure or Denial of Service.
nvd
CVE-2016-4478P3HIGHCVSS 7.5v8.02016-06-13
CVE-2016-4478 [HIGH] CWE-119 CVE-2016-4478: Buffer overflow in the xmlrpc_char_encode function in modules/transport/xmlrpc/xmlrpclib.c in Atheme
Buffer overflow in the xmlrpc_char_encode function in modules/transport/xmlrpc/xmlrpclib.c in Atheme before 7.2.7 allows remote attackers to cause a denial of service via vectors related to XMLRPC response encoding.
nvd
CVE-2022-0392P3HIGHCVSS 7.8v10.02022-01-28
CVE-2022-0392 [HIGH] CWE-122 CVE-2022-0392: Heap-based Buffer Overflow in GitHub repository vim prior to 8.2.
Heap-based Buffer Overflow in GitHub repository vim prior to 8.2.
nvd
CVE-2004-0642P3HIGHCVSS 7.5v3.02004-09-28
CVE-2004-0642 [HIGH] CWE-415 CVE-2004-0642: Double free vulnerabilities in the error handling code for ASN.1 decoders in the (1) Key Distributio
Double free vulnerabilities in the error handling code for ASN.1 decoders in the (1) Key Distribution Center (KDC) library and (2) client library for MIT Kerberos 5 (krb5) 1.3.4 and earlier may allow remote attackers to execute arbitrary code.
nvd
CVE-2022-0408P3HIGHCVSS 7.8v9.0v10.02022-01-30
CVE-2022-0408 [HIGH] CWE-121 CVE-2022-0408: Stack-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
Stack-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
nvd
CVE-2019-14437P3HIGHCVSS 7.8v9.0v10.02019-08-29
CVE-2019-14437 [HIGH] CWE-125 CVE-2019-14437: The xiph_SplitHeaders function in modules/demux/xiph.h in VideoLAN VLC media player 3.0.7.1 does not
The xiph_SplitHeaders function in modules/demux/xiph.h in VideoLAN VLC media player 3.0.7.1 does not check array bounds properly. As a result, a heap-based buffer over-read can be triggered via a crafted .ogg file.
nvd
CVE-2021-43666P3HIGHCVSS 7.5v10.02022-03-24
CVE-2021-43666 [HIGH] CWE-130 CVE-2021-43666: A Denial of Service vulnerability exists in mbed TLS 3.0.0 and earlier in the mbedtls_pkcs12_derivat
A Denial of Service vulnerability exists in mbed TLS 3.0.0 and earlier in the mbedtls_pkcs12_derivation function when an input password's length is 0.
nvd
CVE-2022-25857P3HIGHCVSS 7.5v10.02022-08-30
CVE-2022-25857 [HIGH] CWE-776 CVE-2022-25857: The package org.yaml:snakeyaml from 0 and before 1.31 are vulnerable to Denial of Service (DoS) due
The package org.yaml:snakeyaml from 0 and before 1.31 are vulnerable to Denial of Service (DoS) due missing to nested depth limitation for collections.
nvd
CVE-2022-2304P3HIGHCVSS 7.8v10.02022-07-05
CVE-2022-2304 [HIGH] CWE-121 CVE-2022-2304: Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.
Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.
nvd