Debian Linux vulnerabilities
9,954 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358
Vulnerabilities
Page 245 of 498
CVE-2020-1971P3MEDIUMCVSS 5.9v9.0v10.02020-12-08
CVE-2020-1971 [MEDIUM] CWE-476 CVE-2020-1971: The X.509 GeneralName type is a generic type for representing different types of names. One of those
The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both GENERAL_NAMEs contain an EDIPARTYNAME. A
nvd
CVE-2017-5333P3HIGHCVSS 7.8v8.0v9.0+1 more2019-11-04
CVE-2017-5333 [HIGH] CWE-190 CVE-2017-5333: Integer overflow in the extract_group_icon_cursor_resource function in b/wrestool/extract.c in icout
Integer overflow in the extract_group_icon_cursor_resource function in b/wrestool/extract.c in icoutils before 0.31.1 allows local users to cause a denial of service (process crash) or execute arbitrary code via a crafted executable file.
nvd
CVE-2017-6474P3HIGHCVSS 7.5v8.02017-03-04
CVE-2017-6474 [HIGH] CWE-835 CVE-2017-6474: In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a NetScaler file parser infinite loop, tri
In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a NetScaler file parser infinite loop, triggered by a malformed capture file. This was addressed in wiretap/netscaler.c by validating record sizes.
nvd
CVE-2016-0747P3MEDIUMCVSS 5.3v7.0v8.0+1 more2016-02-15
CVE-2016-0747 [MEDIUM] CWE-400 CVE-2016-0747: The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly limit CNAME resolution,
The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly limit CNAME resolution, which allows remote attackers to cause a denial of service (worker process resource consumption) via vectors related to arbitrary name resolution.
nvd
CVE-2021-33623P3HIGHCVSS 7.5v10.02021-05-28
CVE-2021-33623 [HIGH] CWE-400 CVE-2021-33623: The trim-newlines package before 3.0.1 and 4.x before 4.0.1 for Node.js has an issue related to regu
The trim-newlines package before 3.0.1 and 4.x before 4.0.1 for Node.js has an issue related to regular expression denial-of-service (ReDoS) for the .end() method.
nvd
CVE-2019-20326P3HIGHCVSS 7.8v9.02020-03-16
CVE-2019-20326 [HIGH] CWE-787 CVE-2019-20326: A heap-based buffer overflow in _cairo_image_surface_create_from_jpeg() in extensions/cairo_io/cairo
A heap-based buffer overflow in _cairo_image_surface_create_from_jpeg() in extensions/cairo_io/cairo-image-surface-jpeg.c in GNOME gThumb before 3.8.3 and Linux Mint Pix before 2.4.5 allows attackers to cause a crash and potentially execute arbitrary code via a crafted JPEG file.
nvd
CVE-2018-18225P3HIGHCVSS 7.5v9.02018-10-12
CVE-2018-18225 [HIGH] CWE-682 CVE-2018-18225: In Wireshark 2.6.0 to 2.6.3, the CoAP dissector could crash. This was addressed in epan/dissectors/p
In Wireshark 2.6.0 to 2.6.3, the CoAP dissector could crash. This was addressed in epan/dissectors/packet-coap.c by ensuring that the piv length is correctly computed.
nvd
CVE-2015-8931P3HIGHCVSS 7.8v7.0v8.02016-09-20
CVE-2015-8931 [HIGH] CWE-190 CVE-2015-8931: Multiple integer overflows in the (1) get_time_t_max and (2) get_time_t_min functions in archive_rea
Multiple integer overflows in the (1) get_time_t_max and (2) get_time_t_min functions in archive_read_support_format_mtree.c in libarchive before 3.2.0 allow remote attackers to have unspecified impact via a crafted mtree file, which triggers undefined behavior.
nvd
CVE-2017-5332P3HIGHCVSS 7.8v8.0v9.0+1 more2019-11-04
CVE-2017-5332 [HIGH] CWE-119 CVE-2017-5332: The extract_group_icon_cursor_resource in wrestool/extract.c in icoutils before 0.31.1 can access un
The extract_group_icon_cursor_resource in wrestool/extract.c in icoutils before 0.31.1 can access unallocated memory, which allows local users to cause a denial of service (process crash) and execute arbitrary code via a crafted executable.
nvd
CVE-2019-13602P3HIGHCVSS 7.8v9.0v10.02019-07-14
CVE-2019-13602 [HIGH] CWE-191 CVE-2019-13602: An Integer Underflow in MP4_EIA608_Convert() in modules/demux/mp4/mp4.c in VideoLAN VLC media player
An Integer Underflow in MP4_EIA608_Convert() in modules/demux/mp4/mp4.c in VideoLAN VLC media player through 3.0.7.1 allows remote attackers to cause a denial of service (heap-based buffer overflow and crash) or possibly have unspecified other impact via a crafted .mp4 file.
nvd
CVE-2022-21293P3MEDIUMCVSS 5.3v9.0v10.0+1 more2022-01-19
CVE-2022-21293 [MEDIUM] CWE-400 CVE-2022-21293: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (co
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via
nvd
CVE-2020-9430P3HIGHCVSS 7.5v9.02020-02-27
CVE-2020-9430 [HIGH] CWE-20 CVE-2020-9430: In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the WiMax DLMAP dissector could cr
In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the WiMax DLMAP dissector could crash. This was addressed in plugins/epan/wimax/msg_dlmap.c by validating a length field.
nvd
CVE-2018-10536P3HIGHCVSS 7.8v8.0v9.02018-04-29
CVE-2018-10536 [HIGH] CWE-787 CVE-2018-10536: An issue was discovered in WavPack 5.1.0 and earlier. The WAV parser component contains a vulnerabil
An issue was discovered in WavPack 5.1.0 and earlier. The WAV parser component contains a vulnerability that allows writing to memory because ParseRiffHeaderConfig in riff.c does not reject multiple format chunks.
nvd
CVE-2016-2821P3HIGHCVSS 7.5v8.02016-06-13
CVE-2016-2821 [HIGH] CVE-2016-2821: Use-after-free vulnerability in the mozilla::dom::Element class in Mozilla Firefox before 47.0 and F
Use-after-free vulnerability in the mozilla::dom::Element class in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2, when contenteditable mode is enabled, allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) by triggering deletion of DOM elements that were created in the editor.
nvd
CVE-2020-7105P3HIGHCVSS 7.5v8.02020-01-16
CVE-2020-7105 [HIGH] CWE-476 CVE-2020-7105: async.c and dict.c in libhiredis.a in hiredis through 0.14.0 allow a NULL pointer dereference becaus
async.c and dict.c in libhiredis.a in hiredis through 0.14.0 allow a NULL pointer dereference because malloc return values are unchecked.
nvd
CVE-2018-5144P3HIGHCVSS 7.3v7.0v8.0+1 more2018-06-11
CVE-2018-5144 [HIGH] CWE-190 CVE-2018-5144: An integer overflow can occur during conversion of text to some Unicode character sets due to an unc
An integer overflow can occur during conversion of text to some Unicode character sets due to an unchecked length parameter. This vulnerability affects Firefox ESR < 52.7 and Thunderbird < 52.7.
nvd
CVE-2017-17084P3HIGHCVSS 7.5v8.0v9.02017-12-01
CVE-2017-17084 [HIGH] CWE-754 CVE-2017-17084: In Wireshark 2.4.0 to 2.4.2 and 2.2.0 to 2.2.10, the IWARP_MPA dissector could crash. This was addre
In Wireshark 2.4.0 to 2.4.2 and 2.2.0 to 2.2.10, the IWARP_MPA dissector could crash. This was addressed in epan/dissectors/packet-iwarp-mpa.c by validating a ULPDU length.
nvd
CVE-2017-9344P3HIGHCVSS 7.5v8.02017-06-02
CVE-2017-9344 [HIGH] CWE-369 CVE-2017-9344: In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the Bluetooth L2CAP dissector could divide by zero.
In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the Bluetooth L2CAP dissector could divide by zero. This was addressed in epan/dissectors/packet-btl2cap.c by validating an interval value.
nvd
CVE-2017-1000229P3HIGHCVSS 7.8v7.0v8.0+1 more2017-11-17
CVE-2017-1000229 [HIGH] CWE-190 CVE-2017-1000229: Integer overflow bug in function minitiff_read_info() of optipng 0.7.6 allows an attacker to remotel
Integer overflow bug in function minitiff_read_info() of optipng 0.7.6 allows an attacker to remotely execute code or cause denial of service.
nvd
CVE-2020-9431P3HIGHCVSS 7.5v9.02020-02-27
CVE-2020-9431 [HIGH] CWE-401 CVE-2020-9431: In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the LTE RRC dissector could leak m
In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the LTE RRC dissector could leak memory. This was addressed in epan/dissectors/packet-lte-rrc.c by adjusting certain append operations.
nvd