cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 241 of 498
CVE-2018-17100P3HIGHCVSS 8.8v8.02018-09-16
CVE-2018-17100 [HIGH] CWE-190 CVE-2018-17100: An issue was discovered in LibTIFF 4.0.9. There is a int32 overflow in multiply_ms in tools/ppm2tiff An issue was discovered in LibTIFF 4.0.9. There is a int32 overflow in multiply_ms in tools/ppm2tiff.c, which can cause a denial of service (crash) or possibly have unspecified other impact via a crafted image file.
nvd
CVE-2018-14659P3MEDIUMCVSS 6.5v8.0v9.02018-10-31
CVE-2018-14659 [MEDIUM] CWE-400 CVE-2018-14659: The Gluster file system through versions 4.1.4 and 3.1.2 is vulnerable to a denial of service attack The Gluster file system through versions 4.1.4 and 3.1.2 is vulnerable to a denial of service attack via use of the 'GF_XATTR_IOSTATS_DUMP_KEY' xattr. A remote, authenticated attacker could exploit this by mounting a Gluster volume and repeatedly calling 'setxattr(2)' to trigger a state dump and create an arbitrary number of files in the server's ru
nvd
CVE-2018-6359P3HIGHCVSS 8.8v7.02018-01-27
CVE-2018-6359 [HIGH] CWE-416 CVE-2018-6359: The decompileIF function (util/decompile.c) in libming through 0.4.8 is vulnerable to a use-after-fr The decompileIF function (util/decompile.c) in libming through 0.4.8 is vulnerable to a use-after-free, which may allow attackers to cause a denial of service or unspecified other impact via a crafted SWF file.
nvd
CVE-2017-11450P3HIGHCVSS 8.8v9.0v10.02017-07-19
CVE-2017-11450 [HIGH] CVE-2017-11450: coders/jpeg.c in ImageMagick before 7.0.6-1 allows remote attackers to cause a denial of service (ap coders/jpeg.c in ImageMagick before 7.0.6-1 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via JPEG data that is too short.
nvd
CVE-2015-5261P3HIGHCVSS 7.1v7.0v8.02016-06-07
CVE-2015-5261 [HIGH] CWE-119 CVE-2015-5261: Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to read and write to arbitra Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to read and write to arbitrary memory locations on the host via guest QXL commands related to surface creation.
nvd
CVE-2017-12678P3HIGHCVSS 8.8v9.02017-08-08
CVE-2017-12678 [HIGH] CWE-434 CVE-2017-12678: In TagLib 1.11.1, the rebuildAggregateFrames function in id3v2framefactory.cpp has a pointer to cast In TagLib 1.11.1, the rebuildAggregateFrames function in id3v2framefactory.cpp has a pointer to cast vulnerability, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted audio file.
nvd
CVE-2019-14433P3MEDIUMCVSS 6.5v10.02019-08-09
CVE-2019-14433 [MEDIUM] CWE-209 CVE-2019-14433: An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, and 19.x before 19.0.2 An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, and 19.x before 19.0.2. If an API request from an authenticated user ends in a fault condition due to an external exception, details of the underlying environment may be leaked in the response, and could include sensitive configuration or other data.
nvd
CVE-2003-0648P4CRITICALCVSS 10.0v3.02004-05-04
CVE-2003-0648 [CRITICAL] CVE-2003-0648: Multiple buffer overflows in vfte, based on FTE, before 0.50, allow local users to execute arbitrary Multiple buffer overflows in vfte, based on FTE, before 0.50, allow local users to execute arbitrary code.
nvd
CVE-2004-0994P3CRITICALCVSS 10.0v3.02005-01-10
CVE-2004-0994 [CRITICAL] CVE-2004-0994: Multiple integer overflows in xzgv 0.8 and earlier allow remote attackers to execute arbitrary code Multiple integer overflows in xzgv 0.8 and earlier allow remote attackers to execute arbitrary code via images with large width and height values, which trigger a heap-based buffer overflow, as demonstrated in the read_prf_file function in readprf.c. NOTE: CVE-2004-0994 and CVE-2004-1095 identify sets of bugs that only partially overlap, despite having the s
nvd
CVE-2019-14864P3MEDIUMCVSS 6.5v10.02020-01-02
CVE-2019-14864 [MEDIUM] CWE-117 CVE-2019-14864: Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, i Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results events to collectors. This would discloses and collects any sensitive data.
nvd
CVE-2021-46837P3MEDIUMCVSS 6.5v9.0v10.0+1 more2022-08-30
CVE-2021-46837 [MEDIUM] CVE-2021-46837: res_pjsip_t38 in Sangoma Asterisk 16.x before 16.16.2, 17.x before 17.9.3, and 18.x before 18.2.2, a res_pjsip_t38 in Sangoma Asterisk 16.x before 16.16.2, 17.x before 17.9.3, and 18.x before 18.2.2, and Certified Asterisk before 16.8-cert7, allows an attacker to trigger a crash by sending an m=image line and zero port in a response to a T.38 re-invite initiated by Asterisk. This is a re-occurrence of the CVE-2019-15297 symptoms but not for exactly the sam
nvd
CVE-2021-40085P3MEDIUMCVSS 6.5v9.0v10.0+1 more2021-08-31
CVE-2021-40085 [MEDIUM] CVE-2021-40085: An issue was discovered in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1 An issue was discovered in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. Authenticated attackers can reconfigure dnsmasq via a crafted extra_dhcp_opts value.
nvd
CVE-2016-1647P3HIGHCVSS 8.8v8.02016-03-29
CVE-2016-1647 [HIGH] CVE-2016-1647: Use-after-free vulnerability in the RenderWidgetHostImpl::Destroy function in content/browser/render Use-after-free vulnerability in the RenderWidgetHostImpl::Destroy function in content/browser/renderer_host/render_widget_host_impl.cc in the Navigation implementation in Google Chrome before 49.0.2623.108 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2018-16587P3MEDIUMCVSS 6.5v8.0v9.02018-09-28
CVE-2018-16587 [MEDIUM] CWE-20 CVE-2018-16587: In Open Ticket Request System (OTRS) 4.0.x before 4.0.32, 5.0.x before 5.0.30, and 6.0.x before 6.0. In Open Ticket Request System (OTRS) 4.0.x before 4.0.32, 5.0.x before 5.0.30, and 6.0.x before 6.0.11, an attacker could send a malicious email to an OTRS system. If a user with admin permissions opens it, it causes deletions of arbitrary files that the OTRS web server user has write access to.
nvd
CVE-2014-8160P3MEDIUMCVSS 5.0v7.0v8.02015-03-02
CVE-2014-8160 [MEDIUM] CWE-20 CVE-2014-8160: net/netfilter/nf_conntrack_proto_generic.c in the Linux kernel before 3.18 generates incorrect connt net/netfilter/nf_conntrack_proto_generic.c in the Linux kernel before 3.18 generates incorrect conntrack entries during handling of certain iptables rule sets for the SCTP, DCCP, GRE, and UDP-Lite protocols, which allows remote attackers to bypass intended access restrictions via packets with disallowed port numbers.
nvd
CVE-2008-4061P3CRITICALCVSS 10.0v4.02008-09-24
CVE-2008-4061 [CRITICAL] CWE-189 CVE-2008-4061: Integer overflow in the MathML component in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Th Integer overflow in the MathML component in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via an mtd element with a large integer value in the rowspan attri
nvd
CVE-2008-4062P3CRITICALCVSS 10.0v4.02008-09-24
CVE-2008-4062 [CRITICAL] CWE-399 CVE-2008-4062: Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunde Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the JavaScript engine and (1) misinterpretation
nvd
CVE-2021-23133P3HIGHCVSS 7.0v9.02021-04-22
CVE-2021-23133 [HIGH] CWE-362 CVE-2021-23133: A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from the context of a network service or an unprivileged process. If sctp_destroy_sock is called without sock_net(sk)->sctp.addr_wq_lock then an element is removed from the auto_asconf_splist list without any proper locking. This c
nvd
CVE-2019-13458P3MEDIUMCVSS 6.5v8.02019-08-21
CVE-2019-13458 [MEDIUM] CVE-2019-13458: An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.8, and Community Edit An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.8, and Community Edition 5.0.x through 5.0.36 and 6.0.x through 6.0.19. An attacker who is logged into OTRS as an agent user with appropriate permissions can leverage OTRS notification tags in templates in order to disclose hashed user passwords.
nvd
CVE-2016-1648P3HIGHCVSS 8.8v8.02016-03-29
CVE-2016-1648 [HIGH] CVE-2016-1648: Use-after-free vulnerability in the GetLoadTimes function in renderer/loadtimes_extension_bindings.c Use-after-free vulnerability in the GetLoadTimes function in renderer/loadtimes_extension_bindings.cc in the Extensions implementation in Google Chrome before 49.0.2623.108 allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code.
nvd
Debian Linux vulnerabilities | cvebase