cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 270 of 498
CVE-2019-19630P4HIGHCVSS 7.8v8.0v9.02019-12-08
CVE-2019-19630 [HIGH] CWE-787 CVE-2019-19630: HTMLDOC 1.9.7 allows a stack-based buffer overflow in the hd_strlcpy() function in string.c (when ca HTMLDOC 1.9.7 allows a stack-based buffer overflow in the hd_strlcpy() function in string.c (when called from render_contents in ps-pdf.cxx) via a crafted HTML document.
nvd
CVE-2018-9240P4HIGHCVSS 7.5v8.02018-04-03
CVE-2018-9240 [HIGH] CWE-476 CVE-2018-9240: ncmpc through 0.29 is prone to a NULL pointer dereference flaw. If a user uses the chat screen and a ncmpc through 0.29 is prone to a NULL pointer dereference flaw. If a user uses the chat screen and another client sends a long chat message, a crash and denial of service could occur.
nvd
CVE-2019-25059P4HIGHCVSS 7.8v9.02022-04-25
CVE-2019-25059 [HIGH] CVE-2019-25059: Artifex Ghostscript through 9.26 mishandles .completefont. NOTE: this issue exists because of an inc Artifex Ghostscript through 9.26 mishandles .completefont. NOTE: this issue exists because of an incomplete fix for CVE-2019-3839.
nvd
CVE-2018-7998P4HIGHCVSS 7.5v7.02018-03-09
CVE-2018-7998 [HIGH] CWE-362 CVE-2018-7998: In libvips before 8.6.3, a NULL function pointer dereference vulnerability was found in the vips_reg In libvips before 8.6.3, a NULL function pointer dereference vulnerability was found in the vips_region_generate function in region.c, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted image file. This occurs because of a race condition involving a failed delayed load and other worker thre
nvd
CVE-2017-6960P4HIGHCVSS 7.5v8.02017-03-17
CVE-2017-6960 [HIGH] CWE-190 CVE-2017-6960: An issue was discovered in apng2gif 1.7. There is an integer overflow resulting in a heap-based buff An issue was discovered in apng2gif 1.7. There is an integer overflow resulting in a heap-based buffer over-read, related to the load_apng function and the imagesize variable.
nvd
CVE-2019-12521P4MEDIUMCVSS 5.9v9.0v10.02020-04-15
CVE-2019-12521 [MEDIUM] CWE-193 CVE-2019-12521: An issue was discovered in Squid through 4.7. When Squid is parsing ESI, it keeps the ESI elements i An issue was discovered in Squid through 4.7. When Squid is parsing ESI, it keeps the ESI elements in ESIContext. ESIContext contains a buffer for holding a stack of ESIElements. When a new ESIElement is parsed, it is added via addStackElement. addStackElement has a check for the number of elements in this buffer, but it's off by 1, leading to a Hea
nvd
CVE-2017-5036P4HIGHCVSS 7.8v8.0v9.02017-04-24
CVE-2017-5036 [HIGH] CWE-416 CVE-2017-5036: A use after free in PDFium in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57 A use after free in PDFium in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to have an unspecified impact via a crafted PDF file.
nvd
CVE-2018-6519P4HIGHCVSS 7.5v8.0v9.02018-02-02
CVE-2018-6519 [HIGH] CWE-74 CVE-2018-6519: The SAML2 library before 1.10.4, 2.x before 2.3.5, and 3.x before 3.1.1 in SimpleSAMLphp has a Regul The SAML2 library before 1.10.4, 2.x before 2.3.5, and 3.x before 3.1.1 in SimpleSAMLphp has a Regular Expression Denial of Service vulnerability for fraction-of-seconds data in a timestamp.
nvd
CVE-2021-32491P4HIGHCVSS 7.8v10.0v11.02021-06-24
CVE-2021-32491 [HIGH] CWE-190 CVE-2021-32491: A flaw was found in djvulibre-3.5.28 and earlier. An integer overflow in function render() in tools/ A flaw was found in djvulibre-3.5.28 and earlier. An integer overflow in function render() in tools/ddjvu via crafted djvu file may lead to application crash and other consequences.
nvd
CVE-2017-8814P4HIGHCVSS 7.5v9.02017-11-15
CVE-2017-8814 [HIGH] CWE-20 CVE-2017-8814: The language converter in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 al The language converter in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows attackers to replace text inside tags via a rule definition followed by "a lot of junk."
nvd
CVE-2018-3214P4MEDIUMCVSS 5.3v8.0v9.02018-10-17
CVE-2018-3214 [MEDIUM] CVE-2018-3214: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: S Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Sound). Supported versions that are affected are Java SE: 6u201, 7u191 and 8u182; Java SE Embedded: 8u181; JRockit: R28.3.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java
nvd
CVE-2016-1691P4HIGHCVSS 7.5v8.02016-06-05
CVE-2016-1691 [HIGH] CWE-119 CVE-2016-1691: Skia, as used in Google Chrome before 51.0.2704.63, mishandles coincidence runs, which allows remote Skia, as used in Google Chrome before 51.0.2704.63, mishandles coincidence runs, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted curves, related to SkOpCoincidence.cpp and SkPathOpsCommon.cpp.
nvd
CVE-2017-6801P4HIGHCVSS 7.5v8.0v9.02017-03-10
CVE-2017-6801 [HIGH] CWE-125 CVE-2017-6801: An issue was discovered in ytnef before 1.9.2. There is a potential out-of-bounds access with fields An issue was discovered in ytnef before 1.9.2. There is a potential out-of-bounds access with fields of Size 0 in TNEFParse() in libytnef.
nvd
CVE-2023-20588P4MEDIUMCVSS 5.5v10.0v11.0+1 more2023-08-08
CVE-2023-20588 [MEDIUM] CWE-369 CVE-2023-20588: A division-by-zero error on some AMD processors can potentially return speculative data resulting i A division-by-zero error on some AMD processors can potentially return speculative data resulting in loss of confidentiality.
nvd
CVE-2018-2603P4MEDIUMCVSS 5.3v7.0v8.0+1 more2018-01-18
CVE-2018-2603 [MEDIUM] CVE-2018-2603: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: L Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Jav
nvd
CVE-2022-41325P4HIGHCVSS 7.8v11.02022-12-06
CVE-2022-41325 [HIGH] CWE-190 CVE-2022-41325: An integer overflow in the VNC module in VideoLAN VLC Media Player through 3.0.17.4 allows attackers An integer overflow in the VNC module in VideoLAN VLC Media Player through 3.0.17.4 allows attackers, by tricking a user into opening a crafted playlist or connecting to a rogue VNC server, to crash VLC or execute code under some conditions.
nvd
CVE-2018-2796P4MEDIUMCVSS 5.3v8.0v9.02018-04-19
CVE-2018-2796 [MEDIUM] CVE-2018-2796: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: C Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Concurrency). Supported versions that are affected are Java SE: 7u171, 8u162 and 10; Java SE Embedded: 8u161; JRockit: R28.3.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Ja
nvd
CVE-2018-6927P4HIGHCVSS 7.8v7.0v8.02018-02-12
CVE-2018-6927 [HIGH] CWE-190 CVE-2018-6927: The futex_requeue function in kernel/futex.c in the Linux kernel before 4.14.15 might allow attacker The futex_requeue function in kernel/futex.c in the Linux kernel before 4.14.15 might allow attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact by triggering a negative wake or requeue value.
nvd
CVE-2020-27218P4MEDIUMCVSS 4.8v10.02020-11-28
CVE-2020-27218 [MEDIUM] CWE-226 CVE-2020-27218: In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.al In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2, if GZIP request body inflation is enabled and requests from different clients are multiplexed onto a single connection, and if an attacker can send a request with a body that is received entirely but not consumed by the applicati
nvd
CVE-2015-5726P4HIGHCVSS 7.5v8.02016-05-13
CVE-2015-5726 [HIGH] CWE-20 CVE-2015-5726: The BER decoder in Botan 0.10.x before 1.10.10 and 1.11.x before 1.11.19 allows remote attackers to The BER decoder in Botan 0.10.x before 1.10.10 and 1.11.x before 1.11.19 allows remote attackers to cause a denial of service (application crash) via an empty BIT STRING in ASN.1 data.
nvd
Debian Linux vulnerabilities | cvebase