Debian Linux vulnerabilities
9,954 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358
Vulnerabilities
Page 268 of 498
CVE-2014-9762P4HIGHCVSS 7.5v7.0v8.02016-05-13
CVE-2014-9762 [HIGH] CWE-20 CVE-2014-9762: imlib2 before 1.4.7 allows remote attackers to cause a denial of service (segmentation fault) via a
imlib2 before 1.4.7 allows remote attackers to cause a denial of service (segmentation fault) via a GIF image without a colormap.
nvd
CVE-2017-9611P4HIGHCVSS 7.8v8.0v9.02017-07-26
CVE-2017-9611 [HIGH] CWE-125 CVE-2017-9611: The Ins_MIRP function in base/ttinterp.c in Artifex Ghostscript GhostXPS 9.21 allows remote attacker
The Ins_MIRP function in base/ttinterp.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted document.
nvd
CVE-2018-10194P4HIGHCVSS 7.8v7.02018-04-18
CVE-2018-10194 [HIGH] CWE-119 CVE-2018-10194: The set_text_distance function in devices/vector/gdevpdts.c in the pdfwrite component in Artifex Gho
The set_text_distance function in devices/vector/gdevpdts.c in the pdfwrite component in Artifex Ghostscript through 9.22 does not prevent overflows in text-positioning calculation, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PDF document.
nvd
CVE-2010-2901P4CRITICALCVSS 10.0v6.0v7.02010-07-28
CVE-2010-2901 [CRITICAL] CWE-119 CVE-2010-2901: The rendering implementation in Google Chrome before 5.0.375.125 allows remote attackers to cause a
The rendering implementation in Google Chrome before 5.0.375.125 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2025-64098P4MEDIUMCVSS 5.9v11.0v12.0+1 more2026-02-03
CVE-2025-64098 [MEDIUM] CWE-125 CVE-2025-64098: Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object
Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group
). Prior to versions 3.4.1, 3.3.1, and 2.6.11, when the security mode is enabled, modifying the DATA Submessage within an
SPDP packet sent by a publisher causes an Out-Of-Memory (OOM) condition, resulting in remote termination of Fast-
nvd
CVE-2017-18234P4HIGHCVSS 7.8v7.02018-03-15
CVE-2017-18234 [HIGH] CWE-416 CVE-2017-18234: An issue was discovered in Exempi before 2.4.3. It allows remote attackers to cause a denial of serv
An issue was discovered in Exempi before 2.4.3. It allows remote attackers to cause a denial of service (invalid memcpy with resultant use-after-free) or possibly have unspecified other impact via a .pdf file containing JPEG data, related to XMPFiles/source/FormatSupport/ReconcileTIFF.cpp, XMPFiles/source/FormatSupport/TIFF_MemoryReader.cpp, and XMPFi
nvd
CVE-2015-1258P4HIGHCVSS 7.5v8.02015-05-20
CVE-2015-1258 [HIGH] CWE-189 CVE-2015-1258: Google Chrome before 43.0.2357.65 relies on libvpx code that was not built with an appropriate --siz
Google Chrome before 43.0.2357.65 relies on libvpx code that was not built with an appropriate --size-limit value, which allows remote attackers to trigger a negative value for a size field, and consequently cause a denial of service or possibly have unspecified other impact, via a crafted frame size in VP9 video data.
nvd
CVE-2017-15721P4HIGHCVSS 7.5v7.0v8.0+1 more2017-10-22
CVE-2017-15721 [HIGH] CWE-476 CVE-2017-15721: In Irssi before 1.0.5, certain incorrectly formatted DCC CTCP messages could cause a NULL pointer de
In Irssi before 1.0.5, certain incorrectly formatted DCC CTCP messages could cause a NULL pointer dereference. This is a separate, but similar, issue relative to CVE-2017-9468.
nvd
CVE-2018-1000179P4HIGHCVSS 7.5v8.0v9.02018-05-08
CVE-2018-1000179 [HIGH] CWE-476 CVE-2018-1000179: A NULL Pointer Dereference of CWE-476 exists in quassel version 0.12.4 in the quasselcore void CoreA
A NULL Pointer Dereference of CWE-476 exists in quassel version 0.12.4 in the quasselcore void CoreAuthHandler::handle(const Login &msg) coreauthhandler.cpp line 235 that allows an attacker to cause a denial of service.
nvd
CVE-2015-1243P4HIGHCVSS 7.5v8.02015-05-01
CVE-2015-1243 [HIGH] CVE-2015-1243: Use-after-free vulnerability in the MutationObserver::disconnect function in core/dom/MutationObserv
Use-after-free vulnerability in the MutationObserver::disconnect function in core/dom/MutationObserver.cpp in the DOM implementation in Blink, as used in Google Chrome before 42.0.2311.135, allows remote attackers to cause a denial of service or possibly have unspecified other impact by triggering an attempt to unregister a MutationObserver object that is not c
nvd
CVE-2018-9259P4HIGHCVSS 7.5v8.02018-04-04
CVE-2018-9259 [HIGH] CWE-20 CVE-2018-9259: In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the MP4 dissector could crash. This was addressed i
In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the MP4 dissector could crash. This was addressed in epan/dissectors/file-mp4.c by restricting the box recursion depth.
nvd
CVE-2018-7050P4HIGHCVSS 7.5v9.02018-02-15
CVE-2018-7050 [HIGH] CWE-476 CVE-2018-7050: An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. A NULL pointer dereference occ
An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. A NULL pointer dereference occurs for an "empty" nick.
nvd
CVE-2018-2795P4MEDIUMCVSS 5.3v8.0v9.02018-04-19
CVE-2018-2795 [MEDIUM] CVE-2018-2795: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: S
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u181, 7u171, 8u162 and 10; Java SE Embedded: 8u161; JRockit: R28.3.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE
nvd
CVE-2018-2797P4MEDIUMCVSS 5.3v8.0v9.02018-04-19
CVE-2018-2797 [MEDIUM] CVE-2018-2797: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: J
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JMX). Supported versions that are affected are Java SE: 6u181, 7u171, 8u162 and 10; Java SE Embedded: 8u161; JRockit: R28.3.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Jav
nvd
CVE-2018-2798P4MEDIUMCVSS 5.3v8.0v9.02018-04-19
CVE-2018-2798 [MEDIUM] CVE-2018-2798: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: A
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: AWT). Supported versions that are affected are Java SE: 6u181, 7u171, 8u162 and 10; Java SE Embedded: 8u161; JRockit: R28.3.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Jav
nvd
CVE-2015-5289P3MEDIUMCVSS 6.4v8.0v9.02015-10-26
CVE-2015-5289 [MEDIUM] CWE-119 CVE-2015-5289: Multiple stack-based buffer overflows in json parsing in PostgreSQL before 9.3.x before 9.3.10 and 9
Multiple stack-based buffer overflows in json parsing in PostgreSQL before 9.3.x before 9.3.10 and 9.4.x before 9.4.5 allow attackers to cause a denial of service (server crash) via unspecified vectors, which are not properly handled in (1) json or (2) jsonb values.
nvd
CVE-2015-7852P4MEDIUMCVSS 5.9v7.0v8.0+1 more2017-08-07
CVE-2015-7852 [MEDIUM] CWE-20 CVE-2015-7852: ntpq in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial
ntpq in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash) via crafted mode 6 response packets.
nvd
CVE-2017-5035P4HIGHCVSS 8.1v8.0v9.02017-04-24
CVE-2017-5035 [HIGH] CWE-362 CVE-2017-5035: Google Chrome prior to 57.0.2987.98 for Windows and Mac had a race condition, which could cause Chro
Google Chrome prior to 57.0.2987.98 for Windows and Mac had a race condition, which could cause Chrome to display incorrect certificate information for a site.
nvd
CVE-2018-16513P4HIGHCVSS 7.8v8.0v9.02018-09-05
CVE-2018-16513 [HIGH] CWE-704 CVE-2018-16513: In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use a ty
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use a type confusion in the setcolor function to crash the interpreter or possibly have unspecified other impact.
nvd
CVE-2019-8308P4HIGHCVSS 8.2v9.0v10.02019-02-12
CVE-2019-8308 [HIGH] CWE-668 CVE-2019-8308: Flatpak before 1.0.7, and 1.1.x and 1.2.x before 1.2.3, exposes /proc in the apply_extra script sand
Flatpak before 1.0.7, and 1.1.x and 1.2.x before 1.2.3, exposes /proc in the apply_extra script sandbox, which allows attackers to modify a host-side executable file.
nvd