cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 234 of 498
CVE-2021-3803P3HIGHCVSS 7.5v10.02021-09-17
CVE-2021-3803 [HIGH] CWE-1333 CVE-2021-3803: nth-check is vulnerable to Inefficient Regular Expression Complexity nth-check is vulnerable to Inefficient Regular Expression Complexity
nvd
CVE-2022-27448P3HIGHCVSS 7.5v10.02022-04-14
CVE-2022-27448 [HIGH] CWE-617 CVE-2022-27448: There is an Assertion failure in MariaDB Server v10.9 and below via 'node->pcur->rel_pos == BTR_PCUR There is an Assertion failure in MariaDB Server v10.9 and below via 'node->pcur->rel_pos == BTR_PCUR_ON' at /row/row0mysql.cc.
nvd
CVE-2020-9549P3HIGHCVSS 7.8v8.02020-03-02
CVE-2020-9549 [HIGH] CWE-787 CVE-2020-9549: In PDFResurrect 0.12 through 0.19, get_type in pdf.c has an out-of-bounds write via a crafted PDF do In PDFResurrect 0.12 through 0.19, get_type in pdf.c has an out-of-bounds write via a crafted PDF document.
nvd
CVE-2017-18926P3HIGHCVSS 7.1v9.0v10.02020-11-06
CVE-2017-18926 [HIGH] CWE-787 CVE-2017-18926: raptor_xml_writer_start_element_common in raptor_xml_writer.c in Raptor RDF Syntax Library 2.0.15 mi raptor_xml_writer_start_element_common in raptor_xml_writer.c in Raptor RDF Syntax Library 2.0.15 miscalculates the maximum nspace declarations for the XML writer, leading to heap-based buffer overflows (sometimes seen in raptor_qname_format_as_xml).
nvd
CVE-2019-11222P3HIGHCVSS 7.8v8.02019-04-15
CVE-2019-11222 [HIGH] CWE-787 CVE-2019-11222: gf_bin128_parse in utils/os_divers.c in GPAC 0.7.1 has a buffer overflow issue for the crypt feature gf_bin128_parse in utils/os_divers.c in GPAC 0.7.1 has a buffer overflow issue for the crypt feature when encountering a crafted_drm_file.xml file.
nvd
CVE-2022-32091P3HIGHCVSS 7.5v10.02022-07-01
CVE-2022-32091 [HIGH] CWE-416 CVE-2022-32091: MariaDB v10.7 was discovered to contain an use-after-poison in in __interceptor_memset at /libsaniti MariaDB v10.7 was discovered to contain an use-after-poison in in __interceptor_memset at /libsanitizer/sanitizer_common/sanitizer_common_interceptors.inc.
nvd
CVE-2021-3805P3HIGHCVSS 7.5v10.02021-09-17
CVE-2021-3805 [HIGH] CWE-1321 CVE-2021-3805: object-path is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Pro object-path is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
nvd
CVE-2020-28030P3HIGHCVSS 7.5v9.02020-11-02
CVE-2020-28030 [HIGH] CWE-682 CVE-2020-28030: In Wireshark 3.2.0 to 3.2.7, the GQUIC dissector could crash. This was addressed in epan/dissectors/ In Wireshark 3.2.0 to 3.2.7, the GQUIC dissector could crash. This was addressed in epan/dissectors/packet-gquic.c by correcting the implementation of offset advancement.
nvd
CVE-2020-14409P3HIGHCVSS 7.8v9.02021-01-19
CVE-2020-14409 [HIGH] CWE-190 CVE-2020-14409: SDL (Simple DirectMedia Layer) through 2.0.12 has an Integer Overflow (and resultant SDL_memcpy heap SDL (Simple DirectMedia Layer) through 2.0.12 has an Integer Overflow (and resultant SDL_memcpy heap corruption) in SDL_BlitCopy in video/SDL_blit_copy.c via a crafted .BMP file.
nvd
CVE-2022-30122P3HIGHCVSS 7.5v11.02022-12-05
CVE-2022-30122 [HIGH] CWE-400 CVE-2022-30122: A possible denial of service vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 in the mul A possible denial of service vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 in the multipart parsing component of Rack.
nvd
CVE-2017-7803P3HIGHCVSS 7.5v8.0v9.02018-06-11
CVE-2017-7803 [HIGH] CWE-269 CVE-2017-7803: When a page's content security policy (CSP) header contains a "sandbox" directive, other directives When a page's content security policy (CSP) header contains a "sandbox" directive, other directives are ignored. This results in the incorrect enforcement of CSP. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
nvd
CVE-2015-5143P3HIGHCVSS 7.8v7.0v8.02015-07-14
CVE-2015-5143 [HIGH] CWE-399 CVE-2015-5143: The session backends in Django before 1.4.21, 1.5.x through 1.6.x, 1.7.x before 1.7.9, and 1.8.x bef The session backends in Django before 1.4.21, 1.5.x through 1.6.x, 1.7.x before 1.7.9, and 1.8.x before 1.8.3 allows remote attackers to cause a denial of service (session store consumption) via multiple requests with unique session keys.
nvd
CVE-2018-9258P3HIGHCVSS 7.5v7.02018-04-04
CVE-2018-9258 [HIGH] CWE-20 CVE-2018-9258: In Wireshark 2.4.0 to 2.4.5, the TCP dissector could crash. This was addressed in epan/dissectors/pa In Wireshark 2.4.0 to 2.4.5, the TCP dissector could crash. This was addressed in epan/dissectors/packet-tcp.c by preserving valid data sources.
nvd
CVE-2017-6302P3HIGHCVSS 7.8v8.0v9.02017-02-24
CVE-2017-6302 [HIGH] CWE-190 CVE-2017-6302: An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "5 of 9. Inte An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "5 of 9. Integer Overflow."
nvd
CVE-2018-7554P3CRITICALCVSS 9.8v7.02018-02-28
CVE-2018-7554 [CRITICAL] CWE-416 CVE-2018-7554: There is an invalid free in ReadImage in input-bmp.ci that leads to a Segmentation fault in sam2p 0. There is an invalid free in ReadImage in input-bmp.ci that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead to a denial of service or possibly unspecified other impact.
nvd
CVE-2017-8821P3HIGHCVSS 7.5v8.0v9.02017-12-03
CVE-2017-8821 [HIGH] CWE-119 CVE-2017-8821: In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3 In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, an attacker can cause a denial of service (application hang) via crafted PEM input that signifies a public key requiring a password, which triggers an attempt by the OpenSSL library to ask the user for the password, aka TR
nvd
CVE-2021-20275P3HIGHCVSS 7.5v9.02021-03-09
CVE-2021-20275 [HIGH] CWE-119 CVE-2021-20275: A flaw was found in privoxy before 3.0.32. A invalid read of size two may occur in chunked_body_is_c A flaw was found in privoxy before 3.0.32. A invalid read of size two may occur in chunked_body_is_complete() leading to denial of service.
nvd
CVE-2022-0546P3HIGHCVSS 7.8v9.0v10.0+1 more2022-02-24
CVE-2022-0546 [HIGH] CWE-190 CVE-2022-0546: A missing bounds check in the image loader used in Blender 3.x and 2.93.8 leads to out-of-bounds hea A missing bounds check in the image loader used in Blender 3.x and 2.93.8 leads to out-of-bounds heap access, allowing an attacker to cause denial of service, memory corruption or potentially code execution.
nvd
CVE-2020-8659P3HIGHCVSS 7.5v9.02020-03-04
CVE-2020-8659 [HIGH] CWE-770 CVE-2020-8659: CNCF Envoy through 1.13.0 may consume excessive amounts of memory when proxying HTTP/1.1 requests or CNCF Envoy through 1.13.0 may consume excessive amounts of memory when proxying HTTP/1.1 requests or responses with many small (i.e. 1 byte) chunks.
nvd
CVE-2015-1274P3MEDIUMCVSS 6.8v8.02015-07-23
CVE-2015-1274 [MEDIUM] CWE-254 CVE-2015-1274: Google Chrome before 44.0.2403.89 does not ensure that the auto-open list omits all dangerous file t Google Chrome before 44.0.2403.89 does not ensure that the auto-open list omits all dangerous file types, which makes it easier for remote attackers to execute arbitrary code by providing a crafted file and leveraging a user's previous "Always open files of this type" choice, related to download_commands.cc and download_prefs.cc.
nvd
Debian Linux vulnerabilities | cvebase