cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 244 of 498
CVE-2019-12111P3HIGHCVSS 7.5v8.02019-05-15
CVE-2019-12111 [HIGH] CWE-476 CVE-2019-12111: A Denial Of Service vulnerability in MiniUPnP MiniUPnPd through 2.1 exists due to a NULL pointer der A Denial Of Service vulnerability in MiniUPnP MiniUPnPd through 2.1 exists due to a NULL pointer dereference in copyIPv6IfDifferent in pcpserver.c.
nvd
CVE-2018-10756P3HIGHCVSS 7.8v8.0v9.02020-05-15
CVE-2018-10756 [HIGH] CWE-416 CVE-2018-10756: Use-after-free in libtransmission/variant.c in Transmission before 3.00 allows remote attackers to c Use-after-free in libtransmission/variant.c in Transmission before 3.00 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted torrent file.
nvd
CVE-2019-14493P3HIGHCVSS 7.5v9.02019-08-01
CVE-2019-14493 [HIGH] CWE-476 CVE-2019-14493: An issue was discovered in OpenCV before 4.1.1. There is a NULL pointer dereference in the function An issue was discovered in OpenCV before 4.1.1. There is a NULL pointer dereference in the function cv::XMLParser::parse at modules/core/src/persistence.cpp.
nvd
CVE-2018-14369P3HIGHCVSS 7.5v8.02018-07-19
CVE-2018-14369 [HIGH] CWE-20 CVE-2018-14369: In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the HTTP2 dissector could crash. T In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the HTTP2 dissector could crash. This was addressed in epan/dissectors/packet-http2.c by verifying that header data was found before proceeding to header decompression.
nvd
CVE-2018-14343P3HIGHCVSS 7.5v8.02018-07-19
CVE-2018-14343 [HIGH] CWE-190 CVE-2018-14343: In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the ASN.1 BER dissector could cras In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the ASN.1 BER dissector could crash. This was addressed in epan/dissectors/packet-ber.c by ensuring that length values do not exceed the maximum signed integer.
nvd
CVE-2015-0838P3HIGHCVSS 7.5v7.02015-03-31
CVE-2015-0838 [HIGH] CWE-119 CVE-2015-0838: Buffer overflow in the C implementation of the apply_delta function in _pack.c in Dulwich before 0.9 Buffer overflow in the C implementation of the apply_delta function in _pack.c in Dulwich before 0.9.9 allows remote attackers to execute arbitrary code via a crafted pack file.
nvd
CVE-2016-3521P3MEDIUMCVSS 6.5v8.02016-07-21
CVE-2016-3521 [MEDIUM] CVE-2016-3521: Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and ear Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and earlier and MariaDB before 5.5.50, 10.0.x before 10.0.26, and 10.1.x before 10.1.15 allows remote authenticated users to affect availability via vectors related to Server: Types.
nvd
CVE-2017-9468P3HIGHCVSS 7.5v8.0v9.02017-06-07
CVE-2017-9468 [HIGH] CWE-476 CVE-2017-9468: In Irssi before 1.0.3, when receiving a DCC message without source nick/host, it attempts to derefer In Irssi before 1.0.3, when receiving a DCC message without source nick/host, it attempts to dereference a NULL pointer. Thus, remote IRC servers can cause a crash.
nvd
CVE-2021-22939P4MEDIUMCVSS 5.3v10.02021-08-16
CVE-2021-22939 [MEDIUM] CWE-295 CVE-2021-22939: If the Node.js https API was used incorrectly and "undefined" was in passed for the "rejectUnauthori If the Node.js https API was used incorrectly and "undefined" was in passed for the "rejectUnauthorized" parameter, no error was returned and connections to servers with an expired certificate would have been accepted.
nvd
CVE-2013-0783P4CRITICALCVSS 9.3v7.02013-02-19
CVE-2013-0783 [CRITICAL] CVE-2013-0783: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 19.0, Firefox E Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vector
nvd
CVE-2020-13428P3HIGHCVSS 7.8v9.0v10.02020-06-08
CVE-2020-13428 [HIGH] CWE-787 CVE-2020-13428: A heap-based buffer overflow in the hxxx_AnnexB_to_xVC function in modules/packetizer/hxxx_nal.c in A heap-based buffer overflow in the hxxx_AnnexB_to_xVC function in modules/packetizer/hxxx_nal.c in VideoLAN VLC media player before 3.0.11 for macOS/iOS allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted H.264 Annex-B video (.avi for example) file.
nvd
CVE-2018-18227P3HIGHCVSS 7.5v9.02018-10-12
CVE-2018-18227 [HIGH] CWE-476 CVE-2018-18227: In Wireshark 2.6.0 to 2.6.3 and 2.4.0 to 2.4.9, the MS-WSP protocol dissector could crash. This was In Wireshark 2.6.0 to 2.6.3 and 2.4.0 to 2.4.9, the MS-WSP protocol dissector could crash. This was addressed in epan/dissectors/packet-mswsp.c by properly handling NULL return values.
nvd
CVE-2017-11591P3HIGHCVSS 7.5v10.02017-07-24
CVE-2017-11591 [HIGH] CVE-2017-11591: There is a Floating point exception in the Exiv2::ValueType function in Exiv2 0.26 that will lead to There is a Floating point exception in the Exiv2::ValueType function in Exiv2 0.26 that will lead to a remote denial of service attack via crafted input.
nvd
CVE-2018-11362P3HIGHCVSS 7.5v7.0v8.0+1 more2018-05-22
CVE-2018-11362 [HIGH] CWE-125 CVE-2018-11362: In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the LDSS dissector could crash. This was ad In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the LDSS dissector could crash. This was addressed in epan/dissectors/packet-ldss.c by avoiding a buffer over-read upon encountering a missing '\0' character.
nvd
CVE-2005-3323P3HIGHCVSS 7.5v3.0v3.12005-10-27
CVE-2005-3323 [HIGH] CVE-2005-3323: docutils in Zope 2.6, 2.7 before 2.7.8, and 2.8 before 2.8.2 allows remote attackers to include arbi docutils in Zope 2.6, 2.7 before 2.7.8, and 2.8 before 2.8.2 allows remote attackers to include arbitrary files via include directives in RestructuredText functionality.
nvd
CVE-2015-6031P3MEDIUMCVSS 6.8v7.0v8.02015-11-02
CVE-2015-6031 [MEDIUM] CWE-119 CVE-2015-6031: Buffer overflow in the IGDstartelt function in igd_desc_parse.c in the MiniUPnP client (aka MiniUPnP Buffer overflow in the IGDstartelt function in igd_desc_parse.c in the MiniUPnP client (aka MiniUPnPc) before 1.9.20150917 allows remote UPNP servers to cause a denial of service (application crash) and possibly execute arbitrary code via an "oversized" XML element name.
nvd
CVE-1999-0986P4MEDIUMCVSS 5.0PoCv2.11999-12-08
CVE-1999-0986 [MEDIUM] CVE-1999-0986: The ping command in Linux 2.0.3x allows local users to cause a denial of service by sending large pa The ping command in Linux 2.0.3x allows local users to cause a denial of service by sending large packets with the -R (record route) option.
nvd
CVE-2016-1254P3HIGHCVSS 7.5v8.0v9.02017-12-05
CVE-2016-1254 [HIGH] CWE-119 CVE-2016-1254: Tor before 0.2.8.12 might allow remote attackers to cause a denial of service (client crash) via a c Tor before 0.2.8.12 might allow remote attackers to cause a denial of service (client crash) via a crafted hidden service descriptor.
nvd
CVE-2016-8684P3HIGHCVSS 7.8v8.02017-02-15
CVE-2016-8684 [HIGH] CWE-119 CVE-2016-8684: The MagickMalloc function in magick/memory.c in GraphicsMagick 1.3.25 allows remote attackers to hav The MagickMalloc function in magick/memory.c in GraphicsMagick 1.3.25 allows remote attackers to have unspecified impact via a crafted image, which triggers a memory allocation failure and a "file truncation error for corrupt file."
nvd
CVE-2014-3480P4MEDIUMCVSS 6.5v7.0v8.02014-07-09
CVE-2014-3480 [MEDIUM] CWE-20 CVE-2014-3480: The cdf_count_chain function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP The cdf_count_chain function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, does not properly validate sector-count data, which allows remote attackers to cause a denial of service (application crash) via a crafted CDF file.
nvd
Debian Linux vulnerabilities | cvebase