cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 243 of 498
CVE-2016-9573P3HIGHCVSS 8.1v8.02018-08-01
CVE-2016-9573 [HIGH] CWE-125 CVE-2016-9573: An out-of-bounds read vulnerability was found in OpenJPEG 2.1.2, in the j2k_to_image tool. Convertin An out-of-bounds read vulnerability was found in OpenJPEG 2.1.2, in the j2k_to_image tool. Converting a specially crafted JPEG2000 file to another format could cause the application to crash or, potentially, disclose some data from the heap.
nvd
CVE-2016-10244P3HIGHCVSS 7.8v8.02017-03-06
CVE-2016-10244 [HIGH] CWE-125 CVE-2016-10244: The parse_charstrings function in type1/t1load.c in FreeType 2 before 2.7 does not ensure that a fon The parse_charstrings function in type1/t1load.c in FreeType 2 before 2.7 does not ensure that a font contains a glyph name, which allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a crafted file.
nvd
CVE-2012-5653P3MEDIUMCVSS 6.0v6.0v7.02013-01-03
CVE-2012-5653 [MEDIUM] CWE-20 CVE-2012-5653: The file upload feature in Drupal 6.x before 6.27 and 7.x before 7.18 allows remote authenticated us The file upload feature in Drupal 6.x before 6.27 and 7.x before 7.18 allows remote authenticated users to bypass the protection mechanism and execute arbitrary PHP code via a null byte in a file name.
nvd
CVE-2019-9208P3HIGHCVSS 7.5v9.02019-02-28
CVE-2019-9208 [HIGH] CWE-476 CVE-2019-9208: In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the TCAP dissector could crash. This was addressed In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the TCAP dissector could crash. This was addressed in epan/dissectors/asn1/tcap/tcap.cnf by avoiding NULL pointer dereferences.
nvd
CVE-2023-5115P3MEDIUMCVSS 6.3v10.02023-12-18
CVE-2023-5115 [MEDIUM] CWE-36 CVE-2023-5115: An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an att An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a malicious Ansible role and make the victim execute the role. A symlink can be used to overwrite a file outside of the extraction path.
nvd
CVE-2006-5170P3HIGHCVSS 7.5v3.12006-10-10
CVE-2006-5170 [HIGH] CWE-755 CVE-2006-5170: pam_ldap in nss_ldap on Red Hat Enterprise Linux 4, Fedora Core 3 and earlier, and possibly other di pam_ldap in nss_ldap on Red Hat Enterprise Linux 4, Fedora Core 3 and earlier, and possibly other distributions does not return an error condition when an LDAP directory server responds with a PasswordPolicyResponse control response, which causes the pam_authenticate function to return a success code even if authentication has failed, as originally repo
nvd
CVE-2018-13300P3HIGHCVSS 8.1v9.02018-07-05
CVE-2018-13300 [HIGH] CWE-125 CVE-2018-13300: In FFmpeg 3.2 and 4.0.1, an improper argument (AVCodecParameters) passed to the avpriv_request_sampl In FFmpeg 3.2 and 4.0.1, an improper argument (AVCodecParameters) passed to the avpriv_request_sample function in the handle_eac3 function in libavformat/movenc.c may trigger an out-of-array read while converting a crafted AVI file to MPEG4, leading to a denial of service and possibly an information disclosure.
nvd
CVE-2019-12295P3HIGHCVSS 7.5v9.02019-05-23
CVE-2019-12295 [HIGH] CWE-674 CVE-2019-12295: In Wireshark 3.0.0 to 3.0.1, 2.6.0 to 2.6.8, and 2.4.0 to 2.4.14, the dissection engine could crash. In Wireshark 3.0.0 to 3.0.1, 2.6.0 to 2.6.8, and 2.4.0 to 2.4.14, the dissection engine could crash. This was addressed in epan/packet.c by restricting the number of layers and consequently limiting recursion.
nvd
CVE-2018-16228P3HIGHCVSS 7.5v8.0v9.0+1 more2019-10-03
CVE-2018-16228 [HIGH] CWE-125 CVE-2018-16228: The HNCP parser in tcpdump before 4.9.3 has a buffer over-read in print-hncp.c:print_prefix(). The HNCP parser in tcpdump before 4.9.3 has a buffer over-read in print-hncp.c:print_prefix().
nvd
CVE-2017-5847P3HIGHCVSS 7.5v8.0v9.02017-02-09
CVE-2017-5847 [HIGH] CWE-125 CVE-2017-5847: The gst_asf_demux_process_ext_content_desc function in gst/asfdemux/gstasfdemux.c in gst-plugins-ugl The gst_asf_demux_process_ext_content_desc function in gst/asfdemux/gstasfdemux.c in gst-plugins-ugly in GStreamer allows remote attackers to cause a denial of service (out-of-bounds heap read) via vectors involving extended content descriptors.
nvd
CVE-2017-12135P3HIGHCVSS 8.8v8.0v9.02017-08-24
CVE-2017-12135 [HIGH] CWE-682 CVE-2017-12135: Xen allows local OS guest users to cause a denial of service (crash) or possibly obtain sensitive in Xen allows local OS guest users to cause a denial of service (crash) or possibly obtain sensitive information or gain privileges via vectors involving transitive grants.
nvd
CVE-2018-6767P3HIGHCVSS 7.8v9.02018-02-06
CVE-2018-6767 [HIGH] CWE-125 CVE-2018-6767: A stack-based buffer over-read in the ParseRiffHeaderConfig function of cli/riff.c file of WavPack 5 A stack-based buffer over-read in the ParseRiffHeaderConfig function of cli/riff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service attack or possibly have unspecified other impact via a maliciously crafted RF64 file.
nvd
CVE-2018-7253P3HIGHCVSS 7.8v9.02018-02-19
CVE-2018-7253 [HIGH] CWE-125 CVE-2018-7253: The ParseDsdiffHeaderConfig function of the cli/dsdiff.c file of WavPack 5.1.0 allows a remote attac The ParseDsdiffHeaderConfig function of the cli/dsdiff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service (heap-based buffer over-read) or possibly overwrite the heap via a maliciously crafted DSDIFF file.
nvd
CVE-2016-2518P4MEDIUMCVSS 5.3v8.0v9.0+1 more2017-01-30
CVE-2016-2518 [MEDIUM] CWE-125 CVE-2016-2518: The MATCH_ASSOC function in NTP before version 4.2.8p9 and 4.3.x before 4.3.92 allows remote attacke The MATCH_ASSOC function in NTP before version 4.2.8p9 and 4.3.x before 4.3.92 allows remote attackers to cause an out-of-bounds reference via an addpeer request with a large hmode value.
nvd
CVE-2018-10887P3HIGHCVSS 8.1v8.0v9.02018-07-10
CVE-2018-10887 [HIGH] CWE-194 CVE-2018-10887: A flaw was found in libgit2 before version 0.27.3. It has been discovered that an unexpected sign ex A flaw was found in libgit2 before version 0.27.3. It has been discovered that an unexpected sign extension in git_delta_apply function in delta.c file may lead to an integer overflow which in turn leads to an out of bound read, allowing to read before the base object. An attacker may use this flaw to leak memory addresses or cause a Denial of Service
nvd
CVE-2016-8682P3HIGHCVSS 7.5v8.02017-02-15
CVE-2016-8682 [HIGH] CWE-125 CVE-2016-8682: The ReadSCTImage function in coders/sct.c in GraphicsMagick 1.3.25 allows remote attackers to cause The ReadSCTImage function in coders/sct.c in GraphicsMagick 1.3.25 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted SCT header.
nvd
CVE-2017-14245P3HIGHCVSS 8.1v8.02017-09-21
CVE-2017-14245 [HIGH] CWE-125 CVE-2017-14245: An out of bounds read in the function d2alaw_array() in alaw.c of libsndfile 1.0.28 may lead to a re An out of bounds read in the function d2alaw_array() in alaw.c of libsndfile 1.0.28 may lead to a remote DoS attack or information disclosure, related to mishandling of the NAN and INFINITY floating-point values.
nvd
CVE-2015-8875P3HIGHCVSS 7.8v8.02016-06-01
CVE-2015-8875 [HIGH] CWE-189 CVE-2015-8875: Multiple integer overflows in the (1) pixops_composite_nearest, (2) pixops_composite_color_nearest, Multiple integer overflows in the (1) pixops_composite_nearest, (2) pixops_composite_color_nearest, and (3) pixops_process functions in pixops/pixops.c in gdk-pixbuf before 2.33.1 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted image, which triggers a heap-based buffer overflow.
nvd
CVE-2016-5296P3HIGHCVSS 7.5v8.02018-06-11
CVE-2016-5296 [HIGH] CWE-119 CVE-2016-5296: A heap-buffer-overflow in Cairo when processing SVG content caused by compiler optimization, resulti A heap-buffer-overflow in Cairo when processing SVG content caused by compiler optimization, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.
nvd
CVE-2018-14340P3HIGHCVSS 7.5v8.02018-07-19
CVE-2018-14340 [HIGH] CWE-125 CVE-2018-14340: In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, dissectors that support zlib decom In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, dissectors that support zlib decompression could crash. This was addressed in epan/tvbuff_zlib.c by rejecting negative lengths to avoid a buffer over-read.
nvd
Debian Linux vulnerabilities | cvebase