cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 246 of 498
CVE-2017-17789P3HIGHCVSS 7.8v7.0v8.0+1 more2017-12-20
CVE-2017-17789 [HIGH] CWE-787 CVE-2017-17789: In GIMP 2.8.22, there is a heap-based buffer overflow in read_channel_data in plug-ins/common/file-p In GIMP 2.8.22, there is a heap-based buffer overflow in read_channel_data in plug-ins/common/file-psp.c.
nvd
CVE-2022-23094P3HIGHCVSS 7.5v10.02022-01-15
CVE-2022-23094 [HIGH] CWE-476 CVE-2022-23094: Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer derefer Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKEv1 packet because pluto/ikev1.c wrongly expects that a state object exists. This is fixed in 4.6.
nvd
CVE-2017-5445P3HIGHCVSS 7.5v9.02018-06-11
CVE-2017-5445 [HIGH] CWE-129 CVE-2017-5445: A vulnerability while parsing "application/http-index-format" format content where uninitialized val A vulnerability while parsing "application/http-index-format" format content where uninitialized values are used to create an array. This could allow the reading of uninitialized memory into the arrays affected. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2017-15191P3HIGHCVSS 7.5v8.02017-10-10
CVE-2017-15191 [HIGH] CWE-134 CVE-2017-15191: In Wireshark 2.4.0 to 2.4.1, 2.2.0 to 2.2.9, and 2.0.0 to 2.0.15, the DMP dissector could crash. Thi In Wireshark 2.4.0 to 2.4.1, 2.2.0 to 2.2.9, and 2.0.0 to 2.0.15, the DMP dissector could crash. This was addressed in epan/dissectors/packet-dmp.c by validating a string length.
nvd
CVE-2018-7335P3HIGHCVSS 7.5v7.0v8.0+1 more2018-02-23
CVE-2018-7335 [HIGH] CVE-2018-7335: In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, the IEEE 802.11 dissector could crash. This was add In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, the IEEE 802.11 dissector could crash. This was addressed in epan/crypt/airpdcap.c by rejecting lengths that are too small.
nvd
CVE-2018-5336P3HIGHCVSS 7.5v7.0v8.0+1 more2018-01-11
CVE-2018-5336 [HIGH] CWE-119 CVE-2018-5336: In Wireshark 2.4.0 to 2.4.3 and 2.2.0 to 2.2.11, the JSON, XML, NTP, XMPP, and GDB dissectors could In Wireshark 2.4.0 to 2.4.3 and 2.2.0 to 2.2.11, the JSON, XML, NTP, XMPP, and GDB dissectors could crash. This was addressed in epan/tvbparse.c by limiting the recursion depth.
nvd
CVE-2013-1816P3HIGHCVSS 7.5v9.0v10.02019-11-20
CVE-2013-1816 [HIGH] CWE-20 CVE-2013-1816: MediaWiki before 1.19.4 and 1.20.x before 1.20.3 allows remote attackers to cause a denial of servic MediaWiki before 1.19.4 and 1.20.x before 1.20.3 allows remote attackers to cause a denial of service (application crash) by sending a specially crafted request.
nvd
CVE-2018-7419P3HIGHCVSS 7.5v7.0v8.0+1 more2018-02-23
CVE-2018-7419 [HIGH] CWE-665 CVE-2018-7419: In Wireshark 2.2.0 to 2.2.12 and 2.4.0 to 2.4.4, the NBAP dissector could crash. This was addressed In Wireshark 2.2.0 to 2.2.12 and 2.4.0 to 2.4.4, the NBAP dissector could crash. This was addressed in epan/dissectors/asn1/nbap/nbap.cnf by ensuring DCH ID initialization.
nvd
CVE-2017-6473P3HIGHCVSS 7.5v8.02017-03-04
CVE-2017-6473 [HIGH] CWE-20 CVE-2017-6473: In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a K12 file parser crash, triggered by a ma In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a K12 file parser crash, triggered by a malformed capture file. This was addressed in wiretap/k12.c by validating the relationships between lengths and offsets.
nvd
CVE-2020-35573P3HIGHCVSS 7.5v9.02020-12-20
CVE-2020-35573 [HIGH] CWE-834 CVE-2020-35573: srs2.c in PostSRSd before 1.10 allows remote attackers to cause a denial of service (CPU consumption srs2.c in PostSRSd before 1.10 allows remote attackers to cause a denial of service (CPU consumption) via a long timestamp tag in an SRS address.
nvd
CVE-2018-7320P3HIGHCVSS 7.5v8.0v9.02018-02-23
CVE-2018-7320 [HIGH] CVE-2018-7320: In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, the SIGCOMP protocol dissector could crash. This wa In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, the SIGCOMP protocol dissector could crash. This was addressed in epan/dissectors/packet-sigcomp.c by validating operand offsets.
nvd
CVE-2018-7337P3HIGHCVSS 7.5v7.02018-02-23
CVE-2018-7337 [HIGH] CVE-2018-7337: In Wireshark 2.4.0 to 2.4.4, the DOCSIS protocol dissector could crash. This was addressed in plugin In Wireshark 2.4.0 to 2.4.4, the DOCSIS protocol dissector could crash. This was addressed in plugins/docsis/packet-docsis.c by removing the recursive algorithm that had been used for concatenated PDUs.
nvd
CVE-2017-9994P3HIGHCVSS 7.8v8.02017-06-28
CVE-2017-9994 [HIGH] CWE-119 CVE-2017-9994: libavcodec/webp.c in FFmpeg before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2. libavcodec/webp.c in FFmpeg before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.3.1 does not ensure that pix_fmt is set, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file, related to the vp8_d
nvd
CVE-2017-6467P3HIGHCVSS 7.5v8.02017-03-04
CVE-2017-6467 [HIGH] CWE-835 CVE-2017-6467: In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a Netscaler file parser infinite loop, tri In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a Netscaler file parser infinite loop, triggered by a malformed capture file. This was addressed in wiretap/netscaler.c by changing the restrictions on file size.
nvd
CVE-2016-8683P3HIGHCVSS 7.8v8.02017-02-15
CVE-2016-8683 [HIGH] CWE-119 CVE-2016-8683: The ReadPCXImage function in coders/pcx.c in GraphicsMagick 1.3.25 allows remote attackers to have u The ReadPCXImage function in coders/pcx.c in GraphicsMagick 1.3.25 allows remote attackers to have unspecified impact via a crafted image, which triggers a memory allocation failure and a "file truncation error for corrupt file."
nvd
CVE-2017-2908P3HIGHCVSS 7.8v8.0v9.02018-04-24
CVE-2017-2908 [HIGH] CWE-190 CVE-2017-2908: An exploitable integer overflow exists in the thumbnail functionality of the Blender open-source 3d An exploitable integer overflow exists in the thumbnail functionality of the Blender open-source 3d creation suite version 2.78c. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to render the thumbnail for
nvd
CVE-2020-14396P3HIGHCVSS 7.5v8.0v9.02020-06-17
CVE-2020-14396 [HIGH] CWE-476 CVE-2020-14396: An issue was discovered in LibVNCServer before 0.9.13. libvncclient/tls_openssl.c has a NULL pointer An issue was discovered in LibVNCServer before 0.9.13. libvncclient/tls_openssl.c has a NULL pointer dereference.
nvd
CVE-2018-19200P3HIGHCVSS 7.5fixed in 8.02018-11-12
CVE-2018-19200 [HIGH] CWE-476 CVE-2018-19200: An issue was discovered in uriparser before 0.9.0. UriCommon.c allows attempted operations on NULL i An issue was discovered in uriparser before 0.9.0. UriCommon.c allows attempted operations on NULL input via a uriResetUri* function.
nvd
CVE-2022-0685P3HIGHCVSS 7.8v9.0v10.02022-02-20
CVE-2022-0685 [HIGH] CWE-823 CVE-2022-0685: Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4418. Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4418.
nvd
CVE-2018-1000637P3HIGHCVSS 7.8v8.02018-08-20
CVE-2018-1000637 [HIGH] CWE-119 CVE-2018-1000637: zutils version prior to version 1.8-pre2 contains a Buffer Overflow vulnerability in zcat that can r zutils version prior to version 1.8-pre2 contains a Buffer Overflow vulnerability in zcat that can result in Potential denial of service or arbitrary code execution. This attack appear to be exploitable via the victim openning a crafted compressed file. This vulnerability appears to have been fixed in 1.8-pre2.
nvd
Debian Linux vulnerabilities | cvebase