Debian Linux vulnerabilities
9,954 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358
Vulnerabilities
Page 248 of 498
CVE-2017-7654P3HIGHCVSS 7.5v8.0v9.02018-06-05
CVE-2017-7654 [HIGH] CWE-401 CVE-2017-7654: In Eclipse Mosquitto 1.4.15 and earlier, a Memory Leak vulnerability was found within the Mosquitto
In Eclipse Mosquitto 1.4.15 and earlier, a Memory Leak vulnerability was found within the Mosquitto Broker. Unauthenticated clients can send crafted CONNECT packets which could cause a denial of service in the Mosquitto Broker.
nvd
CVE-2022-1968P3HIGHCVSS 7.8v9.0v10.02022-06-02
CVE-2022-1968 [HIGH] CWE-416 CVE-2022-1968: Use After Free in GitHub repository vim/vim prior to 8.2.
Use After Free in GitHub repository vim/vim prior to 8.2.
nvd
CVE-2019-9210P3HIGHCVSS 7.8v8.0v9.02019-02-27
CVE-2019-9210 [HIGH] CWE-125 CVE-2019-9210: In AdvanceCOMP 2.1, png_compress in pngex.cc in advpng has an integer overflow upon encountering an
In AdvanceCOMP 2.1, png_compress in pngex.cc in advpng has an integer overflow upon encountering an invalid PNG size, which results in an attempted memcpy to write into a buffer that is too small. (There is also a heap-based buffer over-read.)
nvd
CVE-2022-1898P3HIGHCVSS 7.8v9.0v10.02022-05-27
CVE-2022-1898 [HIGH] CWE-416 CVE-2022-1898: Use After Free in GitHub repository vim/vim prior to 8.2.
Use After Free in GitHub repository vim/vim prior to 8.2.
nvd
CVE-2019-19331P3HIGHCVSS 7.5v10.02019-12-16
CVE-2019-19331 [HIGH] CWE-407 CVE-2019-19331: knot-resolver before version 4.3.0 is vulnerable to denial of service through high CPU utilization.
knot-resolver before version 4.3.0 is vulnerable to denial of service through high CPU utilization. DNS replies with very many resource records might be processed very inefficiently, in extreme cases taking even several CPU seconds for each such uncached message. For example, a few thousand A records can be squashed into one DNS message (limit is 64kB)
nvd
CVE-2018-20760P3HIGHCVSS 7.8v8.02019-02-06
CVE-2018-20760 [HIGH] CWE-787 CVE-2018-20760: In GPAC 0.7.1 and earlier, gf_text_get_utf8_line in media_tools/text_import.c in libgpac_static.a al
In GPAC 0.7.1 and earlier, gf_text_get_utf8_line in media_tools/text_import.c in libgpac_static.a allows an out-of-bounds write because a certain -1 return value is mishandled.
nvd
CVE-2017-6309P3HIGHCVSS 7.8v8.02017-02-24
CVE-2017-6309 [HIGH] CWE-125 CVE-2017-6309: An issue was discovered in tnef before 1.4.13. Two type confusions have been identified in the parse
An issue was discovered in tnef before 1.4.13. Two type confusions have been identified in the parse_file() function. These might lead to invalid read and write operations, controlled by an attacker.
nvd
CVE-2017-6310P3HIGHCVSS 7.8v8.02017-02-24
CVE-2017-6310 [HIGH] CWE-125 CVE-2017-6310: An issue was discovered in tnef before 1.4.13. Four type confusions have been identified in the file
An issue was discovered in tnef before 1.4.13. Four type confusions have been identified in the file_add_mapi_attrs() function. These might lead to invalid read and write operations, controlled by an attacker.
nvd
CVE-2017-6307P3HIGHCVSS 7.8v8.02017-02-24
CVE-2017-6307 [HIGH] CWE-787 CVE-2017-6307: An issue was discovered in tnef before 1.4.13. Two OOB Writes have been identified in src/mapi_attr.
An issue was discovered in tnef before 1.4.13. Two OOB Writes have been identified in src/mapi_attr.c:mapi_attr_read(). These might lead to invalid read and write operations, controlled by an attacker.
nvd
CVE-2015-1279P3HIGHCVSS 7.5v8.02015-07-23
CVE-2015-1279 [HIGH] CWE-189 CVE-2015-1279: Integer overflow in the CJBig2_Image::expand function in fxcodec/jbig2/JBig2_Image.cpp in PDFium, as
Integer overflow in the CJBig2_Image::expand function in fxcodec/jbig2/JBig2_Image.cpp in PDFium, as used in Google Chrome before 44.0.2403.89, allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via large height and stride values.
nvd
CVE-2016-1683P3HIGHCVSS 7.5v8.02016-06-05
CVE-2016-1683 [HIGH] CWE-119 CVE-2016-1683: numbers.c in libxslt before 1.1.29, as used in Google Chrome before 51.0.2704.63, mishandles namespa
numbers.c in libxslt before 1.1.29, as used in Google Chrome before 51.0.2704.63, mishandles namespace nodes, which allows remote attackers to cause a denial of service (out-of-bounds heap memory access) or possibly have unspecified other impact via a crafted document.
nvd
CVE-2019-14497P3HIGHCVSS 7.8v8.0v9.02019-08-01
CVE-2019-14497 [HIGH] CWE-787 CVE-2019-14497: ModuleEditor::convertInstrument in tracker/ModuleEditor.cpp in MilkyTracker 1.02.00 has a heap-based
ModuleEditor::convertInstrument in tracker/ModuleEditor.cpp in MilkyTracker 1.02.00 has a heap-based buffer overflow.
nvd
CVE-2017-7483P3HIGHCVSS 7.5v9.02017-05-02
CVE-2017-7483 [HIGH] CWE-125 CVE-2017-7483: Rxvt 2.7.10 is vulnerable to a denial of service attack by passing the value -2^31 inside a terminal
Rxvt 2.7.10 is vulnerable to a denial of service attack by passing the value -2^31 inside a terminal escape code, which results in a non-invertible integer that eventually leads to a segfault due to an out of bounds read.
nvd
CVE-2019-19911P3HIGHCVSS 7.5v9.0v10.02020-01-05
CVE-2019-19911 [HIGH] CWE-190 CVE-2019-19911: There is a DoS vulnerability in Pillow before 6.2.2 caused by FpxImagePlugin.py calling the range fu
There is a DoS vulnerability in Pillow before 6.2.2 caused by FpxImagePlugin.py calling the range function on an unvalidated 32-bit integer if the number of bands is large. On Windows running 32-bit Python, this results in an OverflowError or MemoryError due to the 2 GB limit. However, on Linux running 64-bit Python this results in the process being t
nvd
CVE-2020-15476P3HIGHCVSS 7.5v9.0v10.02020-07-01
CVE-2020-15476 [HIGH] CWE-125 CVE-2020-15476: In nDPI through 3.2, the Oracle protocol dissector has a heap-based buffer over-read in ndpi_search_
In nDPI through 3.2, the Oracle protocol dissector has a heap-based buffer over-read in ndpi_search_oracle in lib/protocols/oracle.c.
nvd
CVE-2019-2529P3MEDIUMCVSS 6.5v8.02019-01-16
CVE-2019-2529 [MEDIUM] CVE-2019-2529: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Suppo
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.6.42 and prior, 5.7.24 and prior and 8.0.13 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulner
nvd
CVE-2020-11653P3HIGHCVSS 7.5v10.02020-04-08
CVE-2020-11653 [HIGH] CWE-617 CVE-2020-11653: An issue was discovered in Varnish Cache before 6.0.6 LTS, 6.1.x and 6.2.x before 6.2.3, and 6.3.x b
An issue was discovered in Varnish Cache before 6.0.6 LTS, 6.1.x and 6.2.x before 6.2.3, and 6.3.x before 6.3.2. It occurs when communication with a TLS termination proxy uses PROXY version 2. There can be an assertion failure and daemon restart, which causes a performance loss.
nvd
CVE-2020-13254P3MEDIUMCVSS 5.9v8.0v9.0+1 more2020-06-03
CVE-2020-13254 [MEDIUM] CWE-295 CVE-2020-13254: An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. In cases where a memcached
An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. In cases where a memcached backend does not perform key validation, passing malformed cache keys could result in a key collision, and potential data leakage.
nvd
CVE-2022-0359P3HIGHCVSS 7.8v9.0v10.02022-01-26
CVE-2022-0359 [HIGH] CWE-122 CVE-2022-0359: Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
nvd
CVE-2014-6272P3HIGHCVSS 7.5v7.02015-08-24
CVE-2014-6272 [HIGH] CWE-189 CVE-2014-6272: Multiple integer overflows in the evbuffer API in Libevent 1.4.x before 1.4.15, 2.0.x before 2.0.22,
Multiple integer overflows in the evbuffer API in Libevent 1.4.x before 1.4.15, 2.0.x before 2.0.22, and 2.1.x before 2.1.5-beta allow context-dependent attackers to cause a denial of service or possibly have other unspecified impact via "insanely large inputs" to the (1) evbuffer_add, (2) evbuffer_expand, or (3) bufferevent_write function, which trigge
nvd