cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 247 of 498
CVE-2011-3919P3HIGHCVSS 7.5v5.0v6.0+1 more2012-01-07
CVE-2011-3919 [HIGH] CWE-787 CVE-2011-3919: Heap-based buffer overflow in libxml2, as used in Google Chrome before 16.0.912.75, allows remote at Heap-based buffer overflow in libxml2, as used in Google Chrome before 16.0.912.75, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2018-7322P3HIGHCVSS 7.5v7.0v8.02018-02-23
CVE-2018-7322 [HIGH] CWE-835 CVE-2018-7322: In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-dcm.c had an infinite loop t In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-dcm.c had an infinite loop that was addressed by checking for integer wraparound.
nvd
CVE-2021-25290P3HIGHCVSS 7.5v9.02021-03-19
CVE-2021-25290 [HIGH] CWE-787 CVE-2021-25290: An issue was discovered in Pillow before 8.1.1. In TiffDecode.c, there is a negative-offset memcpy w An issue was discovered in Pillow before 8.1.1. In TiffDecode.c, there is a negative-offset memcpy with an invalid size.
nvd
CVE-2022-1851P3HIGHCVSS 7.8v9.0v10.02022-05-25
CVE-2022-1851 [HIGH] CWE-125 CVE-2022-1851: Out-of-bounds Read in GitHub repository vim/vim prior to 8.2. Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
nvd
CVE-2013-4233P3MEDIUMCVSS 6.8v6.0v7.02013-09-16
CVE-2013-4233 [MEDIUM] CWE-189 CVE-2013-4233: Integer overflow in the abc_set_parts function in load_abc.cpp in libmodplug 0.8.8.4 and earlier all Integer overflow in the abc_set_parts function in load_abc.cpp in libmodplug 0.8.8.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted P header in an ABC file, which triggers a heap-based buffer overflow.
nvd
CVE-2021-29376P3HIGHCVSS 7.5v9.02021-03-30
CVE-2021-29376 [HIGH] CVE-2021-29376: ircII before 20210314 allows remote attackers to cause a denial of service (segmentation fault and c ircII before 20210314 allows remote attackers to cause a denial of service (segmentation fault and client crash, disconnecting the victim from an IRC server) via a crafted CTCP UTC message.
nvd
CVE-2018-16540P3HIGHCVSS 7.8v8.0v9.02018-09-05
CVE-2018-16540 [HIGH] CWE-416 CVE-2018-16540: In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files to the builtin In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files to the builtin PDF14 converter could use a use-after-free in copydevice handling to crash the interpreter or possibly have unspecified other impact.
nvd
CVE-2019-13217P3HIGHCVSS 7.8v10.02019-08-15
CVE-2019-13217 [HIGH] CWE-787 CVE-2019-13217: A heap buffer overflow in the start_decoder function in stb_vorbis through 2019-03-04 allows an atta A heap buffer overflow in the start_decoder function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service or execute arbitrary code by opening a crafted Ogg Vorbis file.
nvd
CVE-2017-3238P3MEDIUMCVSS 6.5v8.02017-01-27
CVE-2017-3238 [MEDIUM] CVE-2017-3238: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Suppo Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.5.53 and earlier, 5.6.34 and earlier and 5.7.16 and earlier. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this
nvd
CVE-2018-7752P3HIGHCVSS 7.8v8.02018-03-07
CVE-2018-7752 [HIGH] CVE-2018-7752: GPAC through 0.7.1 has a Buffer Overflow in the gf_media_avc_read_sps function in media_tools/av_par GPAC through 0.7.1 has a Buffer Overflow in the gf_media_avc_read_sps function in media_tools/av_parsers.c, a different vulnerability than CVE-2018-1000100.
nvd
CVE-2019-14498P3HIGHCVSS 7.8v9.0v10.02019-08-29
CVE-2019-14498 [HIGH] CWE-369 CVE-2019-14498: A divide-by-zero error exists in the Control function of demux/caf.c in VideoLAN VLC media player 3. A divide-by-zero error exists in the Control function of demux/caf.c in VideoLAN VLC media player 3.0.7.1. As a result, an FPE can be triggered via a crafted CAF file.
nvd
CVE-2017-11409P3HIGHCVSS 7.5v8.02017-07-18
CVE-2017-11409 [HIGH] CWE-834 CVE-2017-11409: In Wireshark 2.0.0 to 2.0.13, the GPRS LLC dissector could go into a large loop. This was addressed In Wireshark 2.0.0 to 2.0.13, the GPRS LLC dissector could go into a large loop. This was addressed in epan/dissectors/packet-gprs-llc.c by using a different integer data type.
nvd
CVE-2022-2124P3HIGHCVSS 7.8v9.02022-06-19
CVE-2022-2124 [HIGH] CWE-126 CVE-2022-2124: Buffer Over-read in GitHub repository vim/vim prior to 8.2. Buffer Over-read in GitHub repository vim/vim prior to 8.2.
nvd
CVE-2022-2126P3HIGHCVSS 7.8v9.02022-06-19
CVE-2022-2126 [HIGH] CWE-125 CVE-2022-2126: Out-of-bounds Read in GitHub repository vim/vim prior to 8.2. Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
nvd
CVE-2018-16881P3HIGHCVSS 7.5v9.02019-01-25
CVE-2018-16881 [HIGH] CWE-190 CVE-2018-16881: A denial of service vulnerability was found in rsyslog in the imptcp module. An attacker could send A denial of service vulnerability was found in rsyslog in the imptcp module. An attacker could send a specially crafted message to the imptcp socket, which would cause rsyslog to crash. Versions before 8.27.0 are vulnerable.
nvd
CVE-2019-14776P3HIGHCVSS 7.8v9.0v10.02019-08-29
CVE-2019-14776 [HIGH] CWE-125 CVE-2019-14776: A heap-based buffer over-read exists in DemuxInit() in demux/asf/asf.c in VideoLAN VLC media player A heap-based buffer over-read exists in DemuxInit() in demux/asf/asf.c in VideoLAN VLC media player 3.0.7.1 via a crafted .mkv file.
nvd
CVE-2018-20762P3HIGHCVSS 7.8v8.02019-02-06
CVE-2018-20762 [HIGH] CWE-119 CVE-2018-20762: GPAC version 0.7.1 and earlier has a buffer overflow vulnerability in the cat_multiple_files functio GPAC version 0.7.1 and earlier has a buffer overflow vulnerability in the cat_multiple_files function in applications/mp4box/fileimport.c when MP4Box is used for a local directory containing crafted filenames.
nvd
CVE-2020-26664P3HIGHCVSS 7.8v9.0v10.02021-01-08
CVE-2020-26664 [HIGH] CWE-787 CVE-2020-26664: A vulnerability in EbmlTypeDispatcher::send in VideoLAN VLC media player 3.0.11 allows attackers to A vulnerability in EbmlTypeDispatcher::send in VideoLAN VLC media player 3.0.11 allows attackers to trigger a heap-based buffer overflow via a crafted .mkv file.
nvd
CVE-2019-13221P3HIGHCVSS 7.8v10.02019-08-15
CVE-2019-13221 [HIGH] CWE-787 CVE-2019-13221: A stack buffer overflow in the compute_codewords function in stb_vorbis through 2019-03-04 allows an A stack buffer overflow in the compute_codewords function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service or execute arbitrary code by opening a crafted Ogg Vorbis file.
nvd
CVE-2019-14533P3HIGHCVSS 7.8v9.0v10.02019-08-29
CVE-2019-14533 [HIGH] CWE-416 CVE-2019-14533: The Control function of demux/asf/asf.c in VideoLAN VLC media player 3.0.7.1 has a use-after-free. The Control function of demux/asf/asf.c in VideoLAN VLC media player 3.0.7.1 has a use-after-free.
nvd
Debian Linux vulnerabilities | cvebase