Debian Linux vulnerabilities
9,954 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358
Vulnerabilities
Page 277 of 498
CVE-2019-11042P4HIGHCVSS 7.1v8.0v9.0+1 more2019-08-09
CVE-2019-11042 [HIGH] CWE-125 CVE-2019-11042: When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() functio
When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x below 7.2.21 and 7.3.x below 7.3.8 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.
nvd
CVE-2018-14879P4HIGHCVSS 7.0v8.0v9.0+1 more2019-10-03
CVE-2018-14879 [HIGH] CWE-120 CVE-2018-14879: The command-line argument parser in tcpdump before 4.9.3 has a buffer overflow in tcpdump.c:get_next
The command-line argument parser in tcpdump before 4.9.3 has a buffer overflow in tcpdump.c:get_next_file().
nvd
CVE-2017-12607P4HIGHCVSS 7.8v7.0v8.02017-11-20
CVE-2017-12607 [HIGH] CWE-787 CVE-2017-12607: A vulnerability in OpenOffice's PPT file parser before 4.1.4, and specifically in PPTStyleSheet, all
A vulnerability in OpenOffice's PPT file parser before 4.1.4, and specifically in PPTStyleSheet, allows attackers to craft malicious documents that cause denial of service (memory corruption and application crash) potentially resulting in arbitrary code execution.
nvd
CVE-2010-2500P4MEDIUMCVSS 6.8v5.02010-08-19
CVE-2010-2500 [MEDIUM] CWE-190 CVE-2010-2500: Integer overflow in the gray_render_span function in smooth/ftgrays.c in FreeType before 2.4.0 allow
Integer overflow in the gray_render_span function in smooth/ftgrays.c in FreeType before 2.4.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.
nvd
CVE-2020-25672P4HIGHCVSS 7.5v9.02021-05-25
CVE-2020-25672 [HIGH] CWE-401 CVE-2020-25672: A memory leak vulnerability was found in Linux kernel in llcp_sock_connect
A memory leak vulnerability was found in Linux kernel in llcp_sock_connect
nvd
CVE-2011-0474P4CRITICALCVSS 10.0v6.0v7.02011-01-14
CVE-2011-0474 [CRITICAL] CVE-2011-0474: Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle Cascading S
Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle Cascading Style Sheets (CSS) token sequences in conjunction with cursors, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2016-2037P4MEDIUMCVSS 6.5v7.0v8.02016-02-22
CVE-2016-2037 [MEDIUM] CWE-119 CVE-2016-2037: The cpio_safer_name_suffix function in util.c in cpio 2.11 allows remote attackers to cause a denial
The cpio_safer_name_suffix function in util.c in cpio 2.11 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted cpio file.
nvd
CVE-2015-2739P4CRITICALCVSS 10.0v7.0v8.02015-07-06
CVE-2015-2739 [CRITICAL] CWE-119 CVE-2015-2739: The ArrayBufferBuilder::append function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8
The ArrayBufferBuilder::append function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 accesses unintended memory locations, which has unspecified impact and attack vectors.
nvd
CVE-2016-3993P4HIGHCVSS 7.5v7.0v8.02016-05-13
CVE-2016-3993 [HIGH] CWE-119 CVE-2016-3993: Off-by-one error in the __imlib_MergeUpdate function in lib/updates.c in imlib2 before 1.4.9 allows
Off-by-one error in the __imlib_MergeUpdate function in lib/updates.c in imlib2 before 1.4.9 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via crafted coordinates.
nvd
CVE-2015-2737P4CRITICALCVSS 10.0v7.0v8.02015-07-06
CVE-2015-2737 [CRITICAL] CWE-17 CVE-2015-2737: The rx::d3d11::SetBufferData function in the Direct3D 11 implementation in Mozilla Firefox before 39
The rx::d3d11::SetBufferData function in the Direct3D 11 implementation in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 reads data from uninitialized memory locations, which has unspecified impact and attack vectors.
nvd
CVE-2018-11356P4HIGHCVSS 7.5v8.02018-05-22
CVE-2018-11356 [HIGH] CWE-476 CVE-2018-11356: In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the DNS dissector could crash. This was add
In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the DNS dissector could crash. This was addressed in epan/dissectors/packet-dns.c by avoiding a NULL pointer dereference for an empty name in an SRV record.
nvd
CVE-2013-4133P4HIGHCVSS 7.5v8.02019-12-10
CVE-2013-4133 [HIGH] CWE-404 CVE-2013-4133: kde-workspace before 4.10.5 has a memory leak in plasma desktop
kde-workspace before 4.10.5 has a memory leak in plasma desktop
nvd
CVE-2014-9764P4HIGHCVSS 7.5v7.0v8.02016-05-13
CVE-2014-9764 [HIGH] CWE-20 CVE-2014-9764: imlib2 before 1.4.7 allows remote attackers to cause a denial of service (segmentation fault) via a
imlib2 before 1.4.7 allows remote attackers to cause a denial of service (segmentation fault) via a crafted GIF file.
nvd
CVE-2014-9771P4HIGHCVSS 7.5v7.0v8.02016-05-13
CVE-2014-9771 [HIGH] CVE-2014-9771: Integer overflow in imlib2 before 1.4.7 allows remote attackers to cause a denial of service (memory
Integer overflow in imlib2 before 1.4.7 allows remote attackers to cause a denial of service (memory consumption or application crash) via a crafted image, which triggers an invalid read operation.
nvd
CVE-2018-14629P4MEDIUMCVSS 6.5v8.0v9.02018-11-28
CVE-2018-14629 [MEDIUM] CWE-400 CVE-2018-14629: A denial of service vulnerability was discovered in Samba's LDAP server before versions 4.7.12, 4.8.
A denial of service vulnerability was discovered in Samba's LDAP server before versions 4.7.12, 4.8.7, and 4.9.3. A CNAME loop could lead to infinite recursion in the server. An unprivileged local attacker could create such an entry, leading to denial of service.
nvd
CVE-2014-3169P4HIGHCVSS 7.5v7.02014-08-27
CVE-2014-3169 [HIGH] CVE-2014-3169: Use-after-free vulnerability in core/dom/ContainerNode.cpp in the DOM implementation in Blink, as us
Use-after-free vulnerability in core/dom/ContainerNode.cpp in the DOM implementation in Blink, as used in Google Chrome before 37.0.2062.94, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging script execution that occurs before notification of node removal.
nvd
CVE-2015-7558P4HIGHCVSS 7.5v8.02016-05-20
CVE-2015-7558 [HIGH] CWE-20 CVE-2015-7558: librsvg before 2.40.12 allows context-dependent attackers to cause a denial of service (infinite loo
librsvg before 2.40.12 allows context-dependent attackers to cause a denial of service (infinite loop, stack consumption, and application crash) via cyclic references in an SVG document.
nvd
CVE-2017-8844P4HIGHCVSS 7.8v9.02017-05-08
CVE-2017-8844 [HIGH] CWE-119 CVE-2017-8844: The read_1g function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a de
The read_1g function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted archive.
nvd
CVE-2018-7052P4HIGHCVSS 7.5v9.02018-02-15
CVE-2018-7052 [HIGH] CWE-476 CVE-2018-7052: An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. When the number of windows exc
An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. When the number of windows exceeds the available space, a crash due to a NULL pointer dereference would occur.
nvd
CVE-2015-9268P4HIGHCVSS 7.8v8.02018-10-01
CVE-2015-9268 [HIGH] CWE-20 CVE-2015-9268: Nullsoft Scriptable Install System (NSIS) before 2.49 has unsafe implicit linking against Version.dl
Nullsoft Scriptable Install System (NSIS) before 2.49 has unsafe implicit linking against Version.dll. In other words, there is no protection mechanism in which a wrapper function resolves the dependency at an appropriate time during runtime.
nvd