cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 249 of 498
CVE-2021-32278P3HIGHCVSS 7.8v9.0v10.02021-09-20
CVE-2021-32278 [HIGH] CWE-787 CVE-2021-32278: An issue was discovered in faad2 through 2.10.0. A heap-buffer-overflow exists in the function lt_pr An issue was discovered in faad2 through 2.10.0. A heap-buffer-overflow exists in the function lt_prediction located in lt_predict.c. It allows an attacker to cause code Execution.
nvd
CVE-2021-32274P3HIGHCVSS 7.8v9.0v10.02021-09-20
CVE-2021-32274 [HIGH] CWE-787 CVE-2021-32274: An issue was discovered in faad2 through 2.10.0. A heap-buffer-overflow exists in the function sbr_q An issue was discovered in faad2 through 2.10.0. A heap-buffer-overflow exists in the function sbr_qmf_synthesis_64 located in sbr_qmf.c. It allows an attacker to cause code Execution.
nvd
CVE-2021-32277P3HIGHCVSS 7.8v9.0v10.02021-09-20
CVE-2021-32277 [HIGH] CWE-787 CVE-2021-32277: An issue was discovered in faad2 through 2.10.0. A heap-buffer-overflow exists in the function sbr_q An issue was discovered in faad2 through 2.10.0. A heap-buffer-overflow exists in the function sbr_qmf_analysis_32 located in sbr_qmf.c. It allows an attacker to cause code Execution.
nvd
CVE-2021-32272P3HIGHCVSS 7.8v10.02021-09-20
CVE-2021-32272 [HIGH] CWE-787 CVE-2021-32272: An issue was discovered in faad2 before 2.10.0. A heap-buffer-overflow exists in the function stszin An issue was discovered in faad2 before 2.10.0. A heap-buffer-overflow exists in the function stszin located in mp4read.c. It allows an attacker to cause Code Execution.
nvd
CVE-2021-46784P3MEDIUMCVSS 6.5v10.0v11.0+1 more2022-07-17
CVE-2021-46784 [MEDIUM] CWE-617 CVE-2021-46784: In Squid 3.x through 3.5.28, 4.x through 4.17, and 5.x before 5.6, due to improper buffer management In Squid 3.x through 3.5.28, 4.x through 4.17, and 5.x before 5.6, due to improper buffer management, a Denial of Service can occur when processing long Gopher server responses.
nvd
CVE-2018-7551P4CRITICALCVSS 9.8v7.02018-02-28
CVE-2018-7551 [CRITICAL] CWE-416 CVE-2018-7551: There is an invalid free in MiniPS::delete0 in minips.cpp that leads to a Segmentation fault in sam2 There is an invalid free in MiniPS::delete0 in minips.cpp that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead to a denial of service or possibly unspecified other impact.
nvd
CVE-2018-7552P4CRITICALCVSS 9.8v7.02018-02-28
CVE-2018-7552 [CRITICAL] CWE-119 CVE-2018-7552: There is an invalid free in Mapping::DoubleHash::clear in mapping.cpp that leads to a Segmentation f There is an invalid free in Mapping::DoubleHash::clear in mapping.cpp that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead to a denial of service or possibly unspecified other impact.
nvd
CVE-2012-6700P3HIGHCVSS 7.5v7.02016-04-11
CVE-2012-6700 [HIGH] CWE-119 CVE-2012-6700: The decode_search function in dhcp.c in dhcpcd 3.x does not properly free allocated memory, which al The decode_search function in dhcp.c in dhcpcd 3.x does not properly free allocated memory, which allows remote DHCP servers to cause a denial of service via a crafted response.
nvd
CVE-2015-5291P3MEDIUMCVSS 6.8v7.0v8.02015-11-02
CVE-2015-5291 [MEDIUM] CWE-119 CVE-2015-5291: Heap-based buffer overflow in PolarSSL 1.x before 1.2.17 and ARM mbed TLS (formerly PolarSSL) 1.3.x Heap-based buffer overflow in PolarSSL 1.x before 1.2.17 and ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.x before 2.1.2 allows remote SSL servers to cause a denial of service (client crash) and possibly execute arbitrary code via a long hostname to the server name indication (SNI) extension, which is not properly handled when creating a
nvd
CVE-2012-6697P3HIGHCVSS 7.5v7.02017-04-13
CVE-2012-6697 [HIGH] CWE-399 CVE-2012-6697: InspIRCd before 2.0.7 allows remote attackers to cause a denial of service (infinite loop). InspIRCd before 2.0.7 allows remote attackers to cause a denial of service (infinite loop).
nvd
CVE-2014-8102P3MEDIUMCVSS 6.5v7.02014-12-10
CVE-2014-8102 [MEDIUM] CWE-119 CVE-2014-8102: The SProcXFixesSelectSelectionInput function in the XFixes extension in X.Org X Window System (aka X The SProcXFixesSelectSelectionInput function in the XFixes extension in X.Org X Window System (aka X11 or X) X11R6.8.0 and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or write) or possibly execute arbitrary code via a crafted length value.
nvd
CVE-2017-13194P3HIGHCVSS 7.5v7.0v8.0+1 more2018-01-12
CVE-2017-13194 [HIGH] CWE-20 CVE-2017-13194: A vulnerability in the Android media framework (libvpx) related to odd frame width. Product: Android A vulnerability in the Android media framework (libvpx) related to odd frame width. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-64710201.
nvd
CVE-2020-20740P3HIGHCVSS 7.8v9.02020-11-20
CVE-2020-20740 [HIGH] CWE-787 CVE-2020-20740: PDFResurrect before 0.20 lack of header validation checks causes heap-buffer-overflow in pdf_get_ver PDFResurrect before 0.20 lack of header validation checks causes heap-buffer-overflow in pdf_get_version().
nvd
CVE-2017-17997P3HIGHCVSS 7.5v8.02017-12-30
CVE-2017-17997 [HIGH] CWE-476 CVE-2017-17997: In Wireshark before 2.2.12, the MRDISC dissector misuses a NULL pointer and crashes. This was addres In Wireshark before 2.2.12, the MRDISC dissector misuses a NULL pointer and crashes. This was addressed in epan/dissectors/packet-mrdisc.c by validating an IPv4 address. This vulnerability is similar to CVE-2017-9343.
nvd
CVE-2017-7655P3HIGHCVSS 7.5v8.0v9.02019-03-27
CVE-2017-7655 [HIGH] CWE-476 CVE-2017-7655: In Eclipse Mosquitto version from 1.0 to 1.4.15, a Null Dereference vulnerability was found in the M In Eclipse Mosquitto version from 1.0 to 1.4.15, a Null Dereference vulnerability was found in the Mosquitto library which could lead to crashes for those applications using the library.
nvd
CVE-2017-6800P3HIGHCVSS 7.5v8.0v9.02017-03-10
CVE-2017-6800 [HIGH] CWE-125 CVE-2017-6800: An issue was discovered in ytnef before 1.9.2. An invalid memory access (heap-based buffer over-read An issue was discovered in ytnef before 1.9.2. An invalid memory access (heap-based buffer over-read) can occur during handling of LONG data types, related to MAPIPrint() in libytnef.
nvd
CVE-2022-1441P3HIGHCVSS 7.8v11.02022-04-25
CVE-2022-1441 [HIGH] CWE-119 CVE-2022-1441: MP4Box is a component of GPAC-2.0.0, which is a widely-used third-party package on RPM Fusion. When MP4Box is a component of GPAC-2.0.0, which is a widely-used third-party package on RPM Fusion. When MP4Box tries to parse a MP4 file, it calls the function `diST_box_read()` to read from video. In this function, it allocates a buffer `str` with fixed length. However, content read from `bs` is controllable by user, so is the length, which causes a buffer
nvd
CVE-2015-1252P3HIGHCVSS 7.5v8.02015-05-20
CVE-2015-1252 [HIGH] CWE-119 CVE-2015-1252: common/partial_circular_buffer.cc in Google Chrome before 43.0.2357.65 does not properly handle wrap common/partial_circular_buffer.cc in Google Chrome before 43.0.2357.65 does not properly handle wraps, which allows remote attackers to bypass a sandbox protection mechanism or cause a denial of service (out-of-bounds write) via vectors that trigger a write operation with a large amount of data, related to the PartialCircularBuffer::Write and PartialCir
nvd
CVE-2018-8040P3MEDIUMCVSS 5.3v9.02018-08-29
CVE-2018-8040 [MEDIUM] CWE-668 CVE-2018-8040: Pages that are rendered using the ESI plugin can have access to the cookie header when the plugin is Pages that are rendered using the ESI plugin can have access to the cookie header when the plugin is configured not to allow access. This affects Apache Traffic Server (ATS) versions 6.0.0 to 6.2.2 and 7.0.0 to 7.1.3. To resolve this issue users running 6.x should upgrade to 6.2.3 or later versions and 7.x users should upgrade to 7.1.4 or later versio
nvd
CVE-2021-32490P3HIGHCVSS 7.8v10.0v11.02021-06-24
CVE-2021-32490 [HIGH] CWE-119 CVE-2021-32490: A flaw was found in djvulibre-3.5.28 and earlier. An out of bounds write in function DJVU::filter_bv A flaw was found in djvulibre-3.5.28 and earlier. An out of bounds write in function DJVU::filter_bv() via crafted djvu file may lead to application crash and other consequences.
nvd
Debian Linux vulnerabilities | cvebase