cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 258 of 498
CVE-2014-0138P4MEDIUMCVSS 6.4v7.02014-04-15
CVE-2014-0138 [MEDIUM] CVE-2014-0138: The default configuration in cURL and libcurl 7.10.6 before 7.36.0 re-uses (1) SCP, (2) SFTP, (3) PO The default configuration in cURL and libcurl 7.10.6 before 7.36.0 re-uses (1) SCP, (2) SFTP, (3) POP3, (4) POP3S, (5) IMAP, (6) IMAPS, (7) SMTP, (8) SMTPS, (9) LDAP, and (10) LDAPS connections, which might allow context-dependent attackers to connect as other users via a request, a similar issue to CVE-2014-0015.
nvd
CVE-2017-15723P4HIGHCVSS 7.5v8.0v9.02017-10-22
CVE-2017-15723 [HIGH] CWE-476 CVE-2017-15723: In Irssi before 1.0.5, overlong nicks or targets may result in a NULL pointer dereference while spli In Irssi before 1.0.5, overlong nicks or targets may result in a NULL pointer dereference while splitting the message.
nvd
CVE-2017-6308P4HIGHCVSS 7.8v8.02017-02-24
CVE-2017-6308 [HIGH] CWE-190 CVE-2017-6308: An issue was discovered in tnef before 1.4.13. Several Integer Overflows, which can lead to Heap Ove An issue was discovered in tnef before 1.4.13. Several Integer Overflows, which can lead to Heap Overflows, have been identified in the functions that wrap memory allocation.
nvd
CVE-2022-0368P4HIGHCVSS 7.8v9.0v10.02022-01-26
CVE-2022-0368 [HIGH] CWE-125 CVE-2022-0368: Out-of-bounds Read in GitHub repository vim/vim prior to 8.2. Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
nvd
CVE-2018-13005P4CRITICALCVSS 9.8v8.02018-06-29
CVE-2018-13005 [CRITICAL] CWE-125 CVE-2018-13005: An issue was discovered in MP4Box in GPAC 0.7.1. The function urn_Read in isomedia/box_code_base.c h An issue was discovered in MP4Box in GPAC 0.7.1. The function urn_Read in isomedia/box_code_base.c has a heap-based buffer over-read.
nvd
CVE-2022-21340P4MEDIUMCVSS 5.3v9.0v10.0+1 more2022-01-19
CVE-2022-21340 [MEDIUM] CWE-400 CVE-2022-21340: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (co Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via
nvd
CVE-2017-5040P4MEDIUMCVSS 4.3v8.0v9.02017-04-24
CVE-2017-5040 [MEDIUM] CVE-2017-5040: V8 in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android V8 in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android was missing a neutering check, which allowed a remote attacker to read values in memory via a crafted HTML page.
nvd
CVE-2019-14535P4HIGHCVSS 7.8v9.0v10.02019-08-29
CVE-2019-14535 [HIGH] CWE-369 CVE-2019-14535: A divide-by-zero error exists in the SeekIndex function of demux/asf/asf.c in VideoLAN VLC media pla A divide-by-zero error exists in the SeekIndex function of demux/asf/asf.c in VideoLAN VLC media player 3.0.7.1. As a result, an FPE can be triggered via a crafted WMV file.
nvd
CVE-2022-1154P3HIGHCVSS 7.8v9.0v10.02022-03-30
CVE-2022-1154 [HIGH] CWE-416 CVE-2022-1154: Use after free in utf_ptr2char in GitHub repository vim/vim prior to 8.2.4646. Use after free in utf_ptr2char in GitHub repository vim/vim prior to 8.2.4646.
nvd
CVE-2019-14777P4HIGHCVSS 7.8v9.0v10.02019-08-29
CVE-2019-14777 [HIGH] CWE-416 CVE-2019-14777: The Control function of demux/mkv/mkv.cpp in VideoLAN VLC media player 3.0.7.1 has a use-after-free. The Control function of demux/mkv/mkv.cpp in VideoLAN VLC media player 3.0.7.1 has a use-after-free.
nvd
CVE-2018-9989P4HIGHCVSS 7.5v8.0v9.02018-04-10
CVE-2018-9989 [HIGH] CWE-125 CVE-2018-9989: ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_serve ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_server_psk_hint() that could cause a crash on invalid input.
nvd
CVE-2023-31490P3HIGHCVSS 7.5v10.0v11.0+1 more2023-05-09
CVE-2023-31490 [HIGH] CVE-2023-31490: An issue found in Frrouting bgpd v.8.4.2 allows a remote attacker to cause a denial of service via t An issue found in Frrouting bgpd v.8.4.2 allows a remote attacker to cause a denial of service via the bgp_attr_psid_sub() function.
nvd
CVE-2022-0443P4HIGHCVSS 7.8v9.0v10.02022-02-02
CVE-2022-0443 [HIGH] CWE-416 CVE-2022-0443: Use After Free in GitHub repository vim/vim prior to 8.2. Use After Free in GitHub repository vim/vim prior to 8.2.
nvd
CVE-2022-0413P4HIGHCVSS 7.8v9.0v10.02022-01-30
CVE-2022-0413 [HIGH] CWE-416 CVE-2022-0413: Use After Free in GitHub repository vim/vim prior to 8.2. Use After Free in GitHub repository vim/vim prior to 8.2.
nvd
CVE-2014-8096P4MEDIUMCVSS 6.5v7.1v8.02014-12-10
CVE-2014-8096 [MEDIUM] CWE-119 CVE-2014-8096: The SProcXCMiscGetXIDList function in the XC-MISC extension in X.Org X Window System (aka X11 or X) The SProcXCMiscGetXIDList function in the XC-MISC extension in X.Org X Window System (aka X11 or X) X11R6.0 and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or write) or possibly execute arbitrary code via a crafted length or index value.
nvd
CVE-2022-2285P4HIGHCVSS 7.8v10.02022-07-02
CVE-2022-2285 [HIGH] CWE-190 CVE-2022-2285: Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0. Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.
nvd
CVE-2021-28021P4HIGHCVSS 7.8v10.02021-10-15
CVE-2021-28021 [HIGH] CWE-787 CVE-2021-28021: Buffer overflow vulnerability in function stbi__extend_receive in stb_image.h in stb 2.26 via a craf Buffer overflow vulnerability in function stbi__extend_receive in stb_image.h in stb 2.26 via a crafted JPEG file.
nvd
CVE-2019-15296P4HIGHCVSS 7.8v8.02019-08-21
CVE-2019-15296 [HIGH] CWE-119 CVE-2019-15296: An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The faad_resetbits funct An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The faad_resetbits function in libfaad/bits.c is affected by a buffer overflow vulnerability. The number of bits to be read is determined by ld->buffer_size - words*4, cast to uint32. If ld->buffer_size - words*4 is negative, a buffer overflow is later performed via getdword_n
nvd
CVE-2021-45078P3HIGHCVSS 7.8v9.0v10.0+1 more2021-12-15
CVE-2021-45078 [HIGH] CVE-2021-45078: stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial o stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write. NOTE: this issue exists because of an incorrect fix for CVE-2018-12699.
nvd
CVE-2018-13006P4CRITICALCVSS 9.8v8.02018-06-29
CVE-2018-13006 [CRITICAL] CWE-125 CVE-2018-13006: An issue was discovered in MP4Box in GPAC 0.7.1. There is a heap-based buffer over-read in the isome An issue was discovered in MP4Box in GPAC 0.7.1. There is a heap-based buffer over-read in the isomedia/box_dump.c function hdlr_dump.
nvd
Debian Linux vulnerabilities | cvebase