cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 259 of 498
CVE-2018-19216P4HIGHCVSS 7.8v8.0v9.02018-11-12
CVE-2018-19216 [HIGH] CWE-416 CVE-2018-19216: Netwide Assembler (NASM) before 2.13.02 has a use-after-free in detoken at asm/preproc.c. Netwide Assembler (NASM) before 2.13.02 has a use-after-free in detoken at asm/preproc.c.
nvd
CVE-2017-14977P4HIGHCVSS 7.5v7.0v8.0+1 more2017-10-02
CVE-2017-14977 [HIGH] CWE-476 CVE-2017-14977: The FoFiTrueType::getCFFBlock function in FoFiTrueType.cc in Poppler 0.59.0 has a NULL pointer deref The FoFiTrueType::getCFFBlock function in FoFiTrueType.cc in Poppler 0.59.0 has a NULL pointer dereference vulnerability due to lack of validation of a table pointer, which allows an attacker to launch a denial of service attack.
nvd
CVE-2012-6699P4HIGHCVSS 7.5v7.02016-04-11
CVE-2012-6699 [HIGH] CWE-119 CVE-2012-6699: The decode_search function in dhcp.c in dhcpcd 3.x allows remote DHCP servers to cause a denial of s The decode_search function in dhcp.c in dhcpcd 3.x allows remote DHCP servers to cause a denial of service (out-of-bounds read) via a crafted response.
nvd
CVE-2013-7089P4HIGHCVSS 7.5v8.0v9.0+1 more2019-11-15
CVE-2013-7089 [HIGH] CWE-200 CVE-2013-7089: ClamAV before 0.97.7: dbg_printhex possible information leak ClamAV before 0.97.7: dbg_printhex possible information leak
nvd
CVE-2019-14934P4HIGHCVSS 7.8v9.02019-08-11
CVE-2019-14934 [HIGH] CWE-787 CVE-2019-14934: An issue was discovered in PDFResurrect before 0.18. pdf_load_pages_kids in pdf.c doesn't validate a An issue was discovered in PDFResurrect before 0.18. pdf_load_pages_kids in pdf.c doesn't validate a certain size value, which leads to a malloc failure and out-of-bounds write.
nvd
CVE-2014-8094P4MEDIUMCVSS 6.5v7.02014-12-10
CVE-2014-8094 [MEDIUM] CWE-190 CVE-2014-8094: Integer overflow in the ProcDRI2GetBuffers function in the DRI2 extension in X.Org Server (aka xserv Integer overflow in the ProcDRI2GetBuffers function in the DRI2 extension in X.Org Server (aka xserver and xorg-server) 1.7.0 through 1.16.x before 1.16.3 allows remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a crafted request, which triggers an out-of-bounds read or write.
nvd
CVE-2017-5039P4HIGHCVSS 7.8v8.0v9.02017-04-24
CVE-2017-5039 [HIGH] CWE-416 CVE-2017-5039: A use after free in PDFium in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57 A use after free in PDFium in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
nvd
CVE-2017-5617P3HIGHCVSS 7.4v8.02017-03-16
CVE-2017-5617 [HIGH] CWE-918 CVE-2017-5617: The SVG Salamander (aka svgSalamander) library, when used in a web application, allows remote attack The SVG Salamander (aka svgSalamander) library, when used in a web application, allows remote attackers to conduct server-side request forgery (SSRF) attacks via an xlink:href attribute in an SVG file.
nvd
CVE-2013-4852P4MEDIUMCVSS 6.8v6.0v7.0+1 more2013-08-19
CVE-2013-4852 [MEDIUM] CWE-189 CVE-2013-4852: Integer overflow in PuTTY 0.62 and earlier, WinSCP before 5.1.6, and other products that use PuTTY a Integer overflow in PuTTY 0.62 and earlier, WinSCP before 5.1.6, and other products that use PuTTY allows remote SSH servers to cause a denial of service (crash) and possibly execute arbitrary code in certain applications that use PuTTY via a negative size value in an RSA key signature during the SSH handshake, which triggers a heap-based buffer overf
nvd
CVE-2014-9673P4MEDIUMCVSS 6.8v7.02015-02-08
CVE-2014-9673 [MEDIUM] CWE-119 CVE-2014-9673: Integer signedness error in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before Integer signedness error in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.5.4 allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted Mac font.
nvd
CVE-2019-12482P4HIGHCVSS 7.5v8.02019-05-30
CVE-2019-12482 [HIGH] CWE-476 CVE-2019-12482: An issue was discovered in GPAC 0.7.1. There is a NULL pointer dereference in the function gf_isom_g An issue was discovered in GPAC 0.7.1. There is a NULL pointer dereference in the function gf_isom_get_original_format_type at isomedia/drm_sample.c in libgpac.a, as demonstrated by MP4Box.
nvd
CVE-2015-1253P4HIGHCVSS 7.5v8.02015-05-20
CVE-2015-1253 [HIGH] CWE-284 CVE-2015-1253: core/html/parser/HTMLConstructionSite.cpp in the DOM implementation in Blink, as used in Google Chro core/html/parser/HTMLConstructionSite.cpp in the DOM implementation in Blink, as used in Google Chrome before 43.0.2357.65, allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code that appends a child to a SCRIPT element, related to the insert and executeReparentTask functions.
nvd
CVE-2018-2641P4MEDIUMCVSS 6.1v7.0v8.0+1 more2018-01-18
CVE-2018-2641 [MEDIUM] CVE-2018-2641: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: AWT). Supp Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: AWT). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successf
nvd
CVE-2017-8815P4HIGHCVSS 7.5v9.02017-11-15
CVE-2017-8815 [HIGH] CWE-20 CVE-2017-8815: The language converter in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 al The language converter in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows attribute injection attacks via glossary rules.
nvd
CVE-2021-40516P4HIGHCVSS 7.5v10.02021-09-05
CVE-2021-40516 [HIGH] CWE-125 CVE-2021-40516: WeeChat before 3.2.1 allows remote attackers to cause a denial of service (crash) via a crafted WebS WeeChat before 3.2.1 allows remote attackers to cause a denial of service (crash) via a crafted WebSocket frame that trigger an out-of-bounds read in plugins/relay/relay-websocket.c in the Relay plugin.
nvd
CVE-2015-2754P4MEDIUMCVSS 6.8v7.02015-03-31
CVE-2015-2754 [MEDIUM] CWE-20 CVE-2015-2754: FreeXL before 1.0.0i allows remote attackers to cause a denial of service (stack corruption) and pos FreeXL before 1.0.0i allows remote attackers to cause a denial of service (stack corruption) and possibly execute arbitrary code via a crafted workbook, related to a "premature EOF."
nvd
CVE-2015-2753P4MEDIUMCVSS 6.8v7.02015-03-31
CVE-2015-2753 [MEDIUM] CWE-20 CVE-2015-2753: FreeXL before 1.0.0i allows remote attackers to cause a denial of service (stack corruption) or poss FreeXL before 1.0.0i allows remote attackers to cause a denial of service (stack corruption) or possibly execute arbitrary code via a crafted sector in a workbook.
nvd
CVE-2018-5388P4MEDIUMCVSS 6.5v8.0v9.02018-05-31
CVE-2018-5388 [MEDIUM] CWE-124 CVE-2018-5388: In stroke_socket.c in strongSwan before 5.6.3, a missing packet length check could allow a buffer un In stroke_socket.c in strongSwan before 5.6.3, a missing packet length check could allow a buffer underflow, which may lead to resource exhaustion and denial of service while reading from the socket.
nvd
CVE-2015-5727P4HIGHCVSS 7.5v8.02016-05-13
CVE-2015-5727 [HIGH] CWE-399 CVE-2015-5727: The BER decoder in Botan 1.10.x before 1.10.10 and 1.11.x before 1.11.19 allows remote attackers to The BER decoder in Botan 1.10.x before 1.10.10 and 1.11.x before 1.11.19 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors, related to a length field.
nvd
CVE-2021-3842P4HIGHCVSS 7.5v9.0v10.0+1 more2022-01-04
CVE-2021-3842 [HIGH] CWE-1333 CVE-2021-3842: nltk is vulnerable to Inefficient Regular Expression Complexity nltk is vulnerable to Inefficient Regular Expression Complexity
nvd
Debian Linux vulnerabilities | cvebase