Debian Linux vulnerabilities
9,954 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358
Vulnerabilities
Page 257 of 498
CVE-2015-5522P4MEDIUMCVSS 6.8v7.0v8.02015-08-11
CVE-2015-5522 [MEDIUM] CWE-119 CVE-2015-5522: Heap-based buffer overflow in the ParseValue function in lexer.c in tidy before 4.9.31 allows remote
Heap-based buffer overflow in the ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving a command character in an href.
nvd
CVE-2017-6306P4HIGHCVSS 7.8v8.0v9.02017-02-24
CVE-2017-6306 [HIGH] CWE-22 CVE-2017-6306: An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "9 of 9. Dire
An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "9 of 9. Directory Traversal using the filename; SanitizeFilename function in settings.c."
nvd
CVE-2018-11357P4HIGHCVSS 7.5v8.02018-05-22
CVE-2018-11357 [HIGH] CWE-20 CVE-2018-11357: In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the LTP dissector and other dissectors coul
In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the LTP dissector and other dissectors could consume excessive memory. This was addressed in epan/tvbuff.c by rejecting negative lengths.
nvd
CVE-2016-1651P3HIGHCVSS 8.1v8.02016-04-18
CVE-2016-1651 [HIGH] CWE-200 CVE-2016-1651: fxcodec/codec/fx_codec_jpx_opj.cpp in PDFium, as used in Google Chrome before 50.0.2661.75, does not
fxcodec/codec/fx_codec_jpx_opj.cpp in PDFium, as used in Google Chrome before 50.0.2661.75, does not properly implement the sycc420_to_rgb and sycc422_to_rgb functions, which allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via crafted JPEG 2000 data in a PDF document.
nvd
CVE-2017-11407P4HIGHCVSS 7.5v8.02017-07-18
CVE-2017-11407 [HIGH] CWE-20 CVE-2017-11407: In Wireshark 2.2.0 to 2.2.7 and 2.0.0 to 2.0.13, the MQ dissector could crash. This was addressed in
In Wireshark 2.2.0 to 2.2.7 and 2.0.0 to 2.0.13, the MQ dissector could crash. This was addressed in epan/dissectors/packet-mq.c by validating the fragment length before a reassembly attempt.
nvd
CVE-2018-10119P4HIGHCVSS 7.8v7.0v8.0+1 more2018-04-16
CVE-2018-10119 [HIGH] CWE-416 CVE-2018-10119: sot/source/sdstor/stgstrms.cxx in LibreOffice before 5.4.5.1 and 6.x before 6.0.1.1 uses an incorrec
sot/source/sdstor/stgstrms.cxx in LibreOffice before 5.4.5.1 and 6.x before 6.0.1.1 uses an incorrect integer data type in the StgSmallStrm class, which allows remote attackers to cause a denial of service (use-after-free with write access) or possibly have unspecified other impact via a crafted document that uses the structured storage ole2 wrapper f
nvd
CVE-2018-7420P4HIGHCVSS 7.5v7.0v8.02018-02-23
CVE-2018-7420 [HIGH] CVE-2018-7420: In Wireshark 2.2.0 to 2.2.12 and 2.4.0 to 2.4.4, the pcapng file parser could crash. This was addres
In Wireshark 2.2.0 to 2.2.12 and 2.4.0 to 2.4.4, the pcapng file parser could crash. This was addressed in wiretap/pcapng.c by adding a block-size check for sysdig event blocks.
nvd
CVE-2018-0490P4HIGHCVSS 7.5v9.02018-03-05
CVE-2018-0490 [HIGH] CWE-476 CVE-2018-0490: An issue was discovered in Tor before 0.2.9.15, 0.3.1.x before 0.3.1.10, and 0.3.2.x before 0.3.2.10
An issue was discovered in Tor before 0.2.9.15, 0.3.1.x before 0.3.1.10, and 0.3.2.x before 0.3.2.10. The directory-authority protocol-list subprotocol implementation allows remote attackers to cause a denial of service (NULL pointer dereference and directory-authority crash) via a misformatted relay descriptor that is mishandled during voting.
nvd
CVE-2019-14494P4HIGHCVSS 7.5v9.0v10.02019-08-01
CVE-2019-14494 [HIGH] CWE-369 CVE-2019-14494: An issue was discovered in Poppler through 0.78.0. There is a divide-by-zero error in the function S
An issue was discovered in Poppler through 0.78.0. There is a divide-by-zero error in the function SplashOutputDev::tilingPatternFill at SplashOutputDev.cc.
nvd
CVE-2018-7336P4HIGHCVSS 7.5v7.0v8.02018-02-23
CVE-2018-7336 [HIGH] CWE-476 CVE-2018-7336: In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, the FCP protocol dissector could crash. This was ad
In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, the FCP protocol dissector could crash. This was addressed in epan/dissectors/packet-fcp.c by checking for a NULL pointer.
nvd
CVE-2017-6468P4HIGHCVSS 7.5v8.02017-03-04
CVE-2017-6468 [HIGH] CWE-20 CVE-2017-6468: In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a NetScaler file parser crash, triggered b
In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a NetScaler file parser crash, triggered by a malformed capture file. This was addressed in wiretap/netscaler.c by validating the relationship between pages and records.
nvd
CVE-2018-9263P4HIGHCVSS 7.5v7.0v8.02018-04-04
CVE-2018-9263 [HIGH] CVE-2018-9263: In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the Kerberos dissector could crash. This was addres
In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the Kerberos dissector could crash. This was addressed in epan/dissectors/packet-kerberos.c by ensuring a nonzero key length.
nvd
CVE-2018-9260P4HIGHCVSS 7.5v7.0v8.02018-04-04
CVE-2018-9260 [HIGH] CWE-20 CVE-2018-9260: In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the IEEE 802.15.4 dissector could crash. This was a
In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the IEEE 802.15.4 dissector could crash. This was addressed in epan/dissectors/packet-ieee802154.c by ensuring that an allocation step occurs.
nvd
CVE-2014-0238P4MEDIUMCVSS 5.0v7.0v8.02014-06-01
CVE-2014-0238 [MEDIUM] CWE-119 CVE-2014-0238: The cdf_read_property_info function in cdf.c in the Fileinfo component in PHP before 5.4.29 and 5.5.
The cdf_read_property_info function in cdf.c in the Fileinfo component in PHP before 5.4.29 and 5.5.x before 5.5.13 allows remote attackers to cause a denial of service (infinite loop or out-of-bounds memory access) via a vector that (1) has zero length or (2) is too long.
nvd
CVE-2018-25033P4HIGHCVSS 8.1v9.02022-05-08
CVE-2018-25033 [HIGH] CWE-125 CVE-2018-25033: ADMesh through 0.98.4 has a heap-based buffer over-read in stl_update_connects_remove_1 (called from
ADMesh through 0.98.4 has a heap-based buffer over-read in stl_update_connects_remove_1 (called from stl_remove_degenerate) in connect.c in libadmesh.a.
nvd
CVE-2017-14975P4HIGHCVSS 7.5v7.0v8.0+1 more2017-10-02
CVE-2017-14975 [HIGH] CWE-476 CVE-2017-14975: The FoFiType1C::convertToType0 function in FoFiType1C.cc in Poppler 0.59.0 has a NULL pointer derefe
The FoFiType1C::convertToType0 function in FoFiType1C.cc in Poppler 0.59.0 has a NULL pointer dereference vulnerability because a data structure is not initialized, which allows an attacker to launch a denial of service attack.
nvd
CVE-2022-0554P3HIGHCVSS 7.8v9.0v10.02022-02-10
CVE-2022-0554 [HIGH] CWE-823 CVE-2022-0554: Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.
Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.
nvd
CVE-2020-26147P4MEDIUMCVSS 5.4v9.02021-05-11
CVE-2020-26147 [MEDIUM] CVE-2020-26147: An issue was discovered in the Linux kernel 5.8.9. The WEP, WPA, WPA2, and WPA3 implementations reas
An issue was discovered in the Linux kernel 5.8.9. The WEP, WPA, WPA2, and WPA3 implementations reassemble fragments even though some of them were sent in plaintext. This vulnerability can be abused to inject packets and/or exfiltrate selected fragments when another device sends fragmented frames and the WEP, CCMP, or GCMP data-confidentiality protocol is u
nvd
CVE-2019-20387P4HIGHCVSS 7.5v8.02020-01-21
CVE-2019-20387 [HIGH] CWE-125 CVE-2019-20387: repodata_schema2id in repodata.c in libsolv before 0.7.6 has a heap-based buffer over-read via a las
repodata_schema2id in repodata.c in libsolv before 0.7.6 has a heap-based buffer over-read via a last schema whose length is less than the length of the input schema.
nvd
CVE-2018-9262P4HIGHCVSS 7.5v8.02018-04-04
CVE-2018-9262 [HIGH] CWE-20 CVE-2018-9262: In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the VLAN dissector could crash. This was addressed
In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the VLAN dissector could crash. This was addressed in epan/dissectors/packet-vlan.c by limiting VLAN tag nesting to restrict the recursion depth.
nvd