cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 271 of 498
CVE-2017-14497P4HIGHCVSS 7.8v8.0v9.02017-09-15
CVE-2017-14497 [HIGH] CWE-119 CVE-2017-14497: The tpacket_rcv function in net/packet/af_packet.c in the Linux kernel before 4.13 mishandles vnet h The tpacket_rcv function in net/packet/af_packet.c in the Linux kernel before 4.13 mishandles vnet headers, which might allow local users to cause a denial of service (buffer overflow, and disk and memory corruption) or possibly have unspecified other impact via crafted system calls.
nvd
CVE-2022-3134P4HIGHCVSS 7.8v10.02022-09-06
CVE-2022-3134 [HIGH] CWE-416 CVE-2022-3134: Use After Free in GitHub repository vim/vim prior to 9.0.0389. Use After Free in GitHub repository vim/vim prior to 9.0.0389.
nvd
CVE-2022-2946P4HIGHCVSS 7.8v10.02022-08-23
CVE-2022-2946 [HIGH] CWE-416 CVE-2022-2946: Use After Free in GitHub repository vim/vim prior to 9.0.0246. Use After Free in GitHub repository vim/vim prior to 9.0.0246.
nvd
CVE-2022-3234P4HIGHCVSS 7.8v10.02022-09-17
CVE-2022-3234 [HIGH] CWE-122 CVE-2022-3234: Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0483. Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0483.
nvd
CVE-2022-3352P4HIGHCVSS 7.8v10.02022-09-29
CVE-2022-3352 [HIGH] CWE-416 CVE-2022-3352: Use After Free in GitHub repository vim/vim prior to 9.0.0614. Use After Free in GitHub repository vim/vim prior to 9.0.0614.
nvd
CVE-2022-3235P4HIGHCVSS 7.8v10.02022-09-18
CVE-2022-3235 [HIGH] CWE-416 CVE-2022-3235: Use After Free in GitHub repository vim/vim prior to 9.0.0490. Use After Free in GitHub repository vim/vim prior to 9.0.0490.
nvd
CVE-2022-3256P4HIGHCVSS 7.8v10.02022-09-22
CVE-2022-3256 [HIGH] CWE-416 CVE-2022-3256: Use After Free in GitHub repository vim/vim prior to 9.0.0530. Use After Free in GitHub repository vim/vim prior to 9.0.0530.
nvd
CVE-2022-3099P4HIGHCVSS 7.8v10.02022-09-03
CVE-2022-3099 [HIGH] CWE-416 CVE-2022-3099: Use After Free in GitHub repository vim/vim prior to 9.0.0360. Use After Free in GitHub repository vim/vim prior to 9.0.0360.
nvd
CVE-2017-5331P4HIGHCVSS 7.8v8.0v9.02019-11-04
CVE-2017-5331 [HIGH] CWE-190 CVE-2017-5331: Integer overflow in the check_offset function in b/wrestool/fileread.c in icoutils before 0.31.1 all Integer overflow in the check_offset function in b/wrestool/fileread.c in icoutils before 0.31.1 allows local users to cause a denial of service (process crash) and execute arbitrary code via a crafted executable.
nvd
CVE-2016-5829P4HIGHCVSS 7.8v8.02016-06-27
CVE-2016-5829 [HIGH] CWE-119 CVE-2016-5829: Multiple heap-based buffer overflows in the hiddev_ioctl_usage function in drivers/hid/usbhid/hiddev Multiple heap-based buffer overflows in the hiddev_ioctl_usage function in drivers/hid/usbhid/hiddev.c in the Linux kernel through 4.6.3 allow local users to cause a denial of service or possibly have unspecified other impact via a crafted (1) HIDIOCGUSAGES or (2) HIDIOCSUSAGES ioctl call.
nvd
CVE-2022-1270P4HIGHCVSS 7.8v10.0v11.02022-09-28
CVE-2022-1270 [HIGH] CWE-119 CVE-2022-1270: In GraphicsMagick, a heap buffer overflow was found when parsing MIFF. In GraphicsMagick, a heap buffer overflow was found when parsing MIFF.
nvd
CVE-2013-6643P4HIGHCVSS 7.5v7.0v8.02014-01-16
CVE-2013-6643 [HIGH] CWE-287 CVE-2013-6643: The OneClickSigninBubbleView::WindowClosing function in browser/ui/views/sync/one_click_signin_bubbl The OneClickSigninBubbleView::WindowClosing function in browser/ui/views/sync/one_click_signin_bubble_view.cc in Google Chrome before 32.0.1700.76 on Windows and before 32.0.1700.77 on Mac OS X and Linux allows attackers to trigger a sync with an arbitrary Google account by leveraging improper handling of the closing of an untrusted signin confirm dialo
nvd
CVE-2017-16541P3MEDIUMCVSS 6.5v8.0v9.02017-11-04
CVE-2017-16541 [MEDIUM] CWE-200 CVE-2017-16541: Tor Browser before 7.0.9 on macOS and Linux allows remote attackers to bypass the intended anonymity Tor Browser before 7.0.9 on macOS and Linux allows remote attackers to bypass the intended anonymity feature and discover a client IP address via vectors involving a crafted web site that leverages file:// mishandling in Firefox, aka TorMoil. NOTE: Tails is unaffected.
nvd
CVE-2023-46849P4HIGHCVSS 7.5v12.02023-11-11
CVE-2023-46849 [HIGH] CWE-369 CVE-2023-46849: Using the --fragment option in certain configuration setups OpenVPN version 2.6.0 to 2.6.6 allows an Using the --fragment option in certain configuration setups OpenVPN version 2.6.0 to 2.6.6 allows an attacker to trigger a divide by zero behaviour which could cause an application crash, leading to a denial of service.
nvd
CVE-2023-0770P4HIGHCVSS 7.8v11.02023-02-09
CVE-2023-0770 [HIGH] CWE-121 CVE-2023-0770: Stack-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.2. Stack-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.2.
nvd
CVE-2017-7487P4HIGHCVSS 7.8v8.0v9.02017-05-14
CVE-2017-7487 [HIGH] CWE-416 CVE-2017-7487: The ipxitf_ioctl function in net/ipx/af_ipx.c in the Linux kernel through 4.11.1 mishandles referenc The ipxitf_ioctl function in net/ipx/af_ipx.c in the Linux kernel through 4.11.1 mishandles reference counts, which allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via a failed SIOCGIFADDR ioctl call for an IPX interface.
nvd
CVE-2008-2931P4HIGHCVSS 7.8v4.02008-07-09
CVE-2008-2931 [HIGH] CWE-269 CVE-2008-2931: The do_change_type function in fs/namespace.c in the Linux kernel before 2.6.22 does not verify that The do_change_type function in fs/namespace.c in the Linux kernel before 2.6.22 does not verify that the caller has the CAP_SYS_ADMIN capability, which allows local users to gain privileges or cause a denial of service by modifying the properties of a mountpoint.
nvd
CVE-2017-8064P4HIGHCVSS 7.8v8.0v9.02017-04-23
CVE-2017-8064 [HIGH] CWE-119 CVE-2017-8064: drivers/media/usb/dvb-usb-v2/dvb_usb_core.c in the Linux kernel 4.9.x and 4.10.x before 4.10.12 inte drivers/media/usb/dvb-usb-v2/dvb_usb_core.c in the Linux kernel 4.9.x and 4.10.x before 4.10.12 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memory corruption) or possibly have unspecified other impact by leveraging use of more than one virtual page for a DMA scatterlist.
nvd
CVE-2020-20450P4HIGHCVSS 7.5v11.02021-05-25
CVE-2020-20450 [HIGH] CWE-476 CVE-2020-20450: FFmpeg 4.2 is affected by null pointer dereference passed as argument to libavformat/aviobuf.c, whic FFmpeg 4.2 is affected by null pointer dereference passed as argument to libavformat/aviobuf.c, which could cause a Denial of Service.
nvd
CVE-2023-41358P4HIGHCVSS 7.5v10.0v11.0+1 more2023-08-29
CVE-2023-41358 [HIGH] CWE-476 CVE-2023-41358: An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c processes NLRIs if the attri An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c processes NLRIs if the attribute length is zero.
nvd
Debian Linux vulnerabilities | cvebase