cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 269 of 498
CVE-2017-17784P4HIGHCVSS 7.8v7.0v8.0+1 more2017-12-20
CVE-2017-17784 [HIGH] CWE-125 CVE-2017-17784: In GIMP 2.8.22, there is a heap-based buffer over-read in load_image in plug-ins/common/file-gbr.c i In GIMP 2.8.22, there is a heap-based buffer over-read in load_image in plug-ins/common/file-gbr.c in the gbr import parser, related to mishandling of UTF-8 data.
nvd
CVE-2017-17846P4HIGHCVSS 7.5v8.0v9.02017-12-27
CVE-2017-17846 [HIGH] CWE-20 CVE-2017-17846: An issue was discovered in Enigmail before 1.9.9. Regular expressions are exploitable for Denial of An issue was discovered in Enigmail before 1.9.9. Regular expressions are exploitable for Denial of Service, because of attempts to match arbitrarily long strings, aka TBE-01-003.
nvd
CVE-2017-0376P4HIGHCVSS 7.5v8.0v9.02017-06-09
CVE-2017-0376 [HIGH] CWE-617 CVE-2017-0376: The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (assertion failure and d The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (assertion failure and daemon exit) in the connection_edge_process_relay_cell function via a BEGIN_DIR cell on a rendezvous circuit.
nvd
CVE-2018-9988P4HIGHCVSS 7.5v8.0v9.02018-04-10
CVE-2018-9988 [HIGH] CWE-125 CVE-2018-9988: ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_serve ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_server_key_exchange() that could cause a crash on invalid input.
nvd
CVE-2017-8890P4HIGHCVSS 7.8v8.0v9.02017-05-10
CVE-2017-8890 [HIGH] CWE-415 CVE-2017-8890: The inet_csk_clone_lock function in net/ipv4/inet_connection_sock.c in the Linux kernel through 4.10 The inet_csk_clone_lock function in net/ipv4/inet_connection_sock.c in the Linux kernel through 4.10.15 allows attackers to cause a denial of service (double free) or possibly have unspecified other impact by leveraging use of the accept system call.
nvd
CVE-2018-12249P4HIGHCVSS 7.5v9.02018-06-12
CVE-2018-12249 [HIGH] CWE-476 CVE-2018-12249: An issue was discovered in mruby 1.4.1. There is a NULL pointer dereference in mrb_class_real becaus An issue was discovered in mruby 1.4.1. There is a NULL pointer dereference in mrb_class_real because "class BasicObject" is not properly supported in class.c.
nvd
CVE-2017-6300P4HIGHCVSS 7.8v8.0v9.02017-02-24
CVE-2017-6300 [HIGH] CWE-119 CVE-2017-6300: An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "3 of 9. Buff An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "3 of 9. Buffer Overflow in version field in lib/tnef-types.h."
nvd
CVE-2011-3895P4HIGHCVSS 7.5v6.02011-11-11
CVE-2011-3895 [HIGH] CWE-787 CVE-2011-3895: Heap-based buffer overflow in the Vorbis decoder in Google Chrome before 15.0.874.120 allows remote Heap-based buffer overflow in the Vorbis decoder in Google Chrome before 15.0.874.120 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted stream.
nvd
CVE-2017-17786P4HIGHCVSS 7.8v7.0v8.0+1 more2017-12-20
CVE-2017-17786 [HIGH] CWE-125 CVE-2017-17786: In GIMP 2.8.22, there is a heap-based buffer over-read in ReadImage in plug-ins/common/file-tga.c (r In GIMP 2.8.22, there is a heap-based buffer over-read in ReadImage in plug-ins/common/file-tga.c (related to bgr2rgb.part.1) via an unexpected bits-per-pixel value for an RGBA image.
nvd
CVE-2019-16394P3MEDIUMCVSS 5.3v8.0v9.0+1 more2019-09-17
CVE-2019-16394 [MEDIUM] CWE-203 CVE-2019-16394: SPIP before 3.1.11 and 3.2 before 3.2.5 provides different error messages from the password-reminder SPIP before 3.1.11 and 3.2 before 3.2.5 provides different error messages from the password-reminder page depending on whether an e-mail address exists, which might help attackers to enumerate subscribers.
nvd
CVE-2017-6303P4HIGHCVSS 7.8v8.0v9.02017-02-24
CVE-2017-6303 [HIGH] CWE-190 CVE-2017-6303: An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "6 of 9. Inva An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "6 of 9. Invalid Write and Integer Overflow."
nvd
CVE-2015-5296P4MEDIUMCVSS 5.4v7.0v8.02015-12-29
CVE-2015-5296 [MEDIUM] CWE-20 CVE-2015-5296: Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 supports connections tha Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 supports connections that are encrypted but unsigned, which allows man-in-the-middle attackers to conduct encrypted-to-unencrypted downgrade attacks by modifying the client-server data stream, related to clidfs.c, libsmb_server.c, and smbXcli_base.c.
nvd
CVE-2020-13143P4MEDIUMCVSS 6.5v8.0v9.0+1 more2020-05-18
CVE-2020-13143 [MEDIUM] CWE-125 CVE-2020-13143: gadget_dev_desc_UDC_store in drivers/usb/gadget/configfs.c in the Linux kernel 3.16 through 5.6.13 r gadget_dev_desc_UDC_store in drivers/usb/gadget/configfs.c in the Linux kernel 3.16 through 5.6.13 relies on kstrdup without considering the possibility of an internal '\0' value, which allows attackers to trigger an out-of-bounds read, aka CID-15753588bcd4.
nvd
CVE-2019-8383P4HIGHCVSS 7.8v9.02019-02-17
CVE-2019-8383 [HIGH] CWE-119 CVE-2019-8383: An issue was discovered in AdvanceCOMP through 2.1. An invalid memory address occurs in the function An issue was discovered in AdvanceCOMP through 2.1. An invalid memory address occurs in the function adv_png_unfilter_8 in lib/png.c. It can be triggered by sending a crafted file to a binary. It allows an attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact when a victim opens a specially crafted file.
nvd
CVE-2017-6305P4HIGHCVSS 7.8v8.0v9.02017-02-24
CVE-2017-6305 [HIGH] CWE-125 CVE-2017-6305: An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "8 of 9. Out An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "8 of 9. Out of Bounds read and write."
nvd
CVE-2017-6304P4HIGHCVSS 7.8v8.0v9.02017-02-24
CVE-2017-6304 [HIGH] CWE-125 CVE-2017-6304: An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "7 of 9. Out An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "7 of 9. Out of Bounds read."
nvd
CVE-2017-6301P4HIGHCVSS 7.8v8.0v9.02017-02-24
CVE-2017-6301 [HIGH] CWE-125 CVE-2017-6301: An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "4 of 9. Out An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "4 of 9. Out of Bounds Reads."
nvd
CVE-2021-32273P4HIGHCVSS 7.8v10.02021-09-20
CVE-2021-32273 [HIGH] CWE-787 CVE-2021-32273: An issue was discovered in faad2 through 2.10.0. A stack-buffer-overflow exists in the function ftyp An issue was discovered in faad2 through 2.10.0. A stack-buffer-overflow exists in the function ftypin located in mp4read.c. It allows an attacker to cause Code Execution.
nvd
CVE-2017-17785P4HIGHCVSS 7.8v7.0v8.0+1 more2017-12-20
CVE-2017-17785 [HIGH] CWE-787 CVE-2017-17785: In GIMP 2.8.22, there is a heap-based buffer overflow in the fli_read_brun function in plug-ins/file In GIMP 2.8.22, there is a heap-based buffer overflow in the fli_read_brun function in plug-ins/file-fli/fli.c.
nvd
CVE-2011-2902P4MEDIUMCVSS 5.3v7.0v8.0+1 more2018-01-30
CVE-2011-2902 [MEDIUM] CWE-20 CVE-2011-2902: zxpdf in xpdf before 3.02-19 as packaged in Debian unstable and 3.02-12+squeeze1 as packaged in Debi zxpdf in xpdf before 3.02-19 as packaged in Debian unstable and 3.02-12+squeeze1 as packaged in Debian squeeze deletes temporary files insecurely, which allows remote attackers to delete arbitrary files via a crafted .pdf.gz file name.
nvd
Debian Linux vulnerabilities | cvebase