cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 278 of 498
CVE-2019-14778P4HIGHCVSS 7.8v9.0v10.02019-08-29
CVE-2019-14778 [HIGH] CWE-416 CVE-2019-14778: The mkv::virtual_segment_c::seek method of demux/mkv/virtual_segment.cpp in VideoLAN VLC media playe The mkv::virtual_segment_c::seek method of demux/mkv/virtual_segment.cpp in VideoLAN VLC media player 3.0.7.1 has a use-after-free.
nvd
CVE-2018-5711P4MEDIUMCVSS 5.5v7.0v8.02018-01-16
CVE-2018-5711 [MEDIUM] CWE-681 CVE-2018-5711: gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.33, 7.0.x before 7.0.2 gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1, has an integer signedness error that leads to an infinite loop via a crafted GIF file, as demonstrated by a call to the imagecreatefromgif or imagecreatefromstring PHP function. This is related to GetCode_
nvd
CVE-2018-20196P4HIGHCVSS 7.8v8.0v10.02018-12-18
CVE-2018-20196 [HIGH] CWE-787 CVE-2018-20196: There is a stack-based buffer overflow in the third instance of the calculate_gain function in libfa There is a stack-based buffer overflow in the third instance of the calculate_gain function in libfaad/sbr_hfadj.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. A crafted input will lead to a denial of service or possibly unspecified other impact because the S_M array is mishandled.
nvd
CVE-2018-16543P4HIGHCVSS 7.8v8.0v9.02018-09-05
CVE-2018-16543 [HIGH] CVE-2018-16543: In Artifex Ghostscript before 9.24, gssetresolution and gsgetresolution allow attackers to have an u In Artifex Ghostscript before 9.24, gssetresolution and gsgetresolution allow attackers to have an unspecified impact.
nvd
CVE-2019-8379P4HIGHCVSS 7.8v9.02019-02-17
CVE-2019-8379 [HIGH] CWE-476 CVE-2019-8379: An issue was discovered in AdvanceCOMP through 2.1. A NULL pointer dereference exists in the functio An issue was discovered in AdvanceCOMP through 2.1. A NULL pointer dereference exists in the function be_uint32_read() located in endianrw.h. It can be triggered by sending a crafted file to a binary. It allows an attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact when a victim opens a specially crafted
nvd
CVE-2018-7487P4HIGHCVSS 7.8v7.02018-02-26
CVE-2018-7487 [HIGH] CWE-787 CVE-2018-7487: There is a heap-based buffer overflow in the LoadPCX function of in_pcx.cpp in sam2p 0.49.4. A Craft There is a heap-based buffer overflow in the LoadPCX function of in_pcx.cpp in sam2p 0.49.4. A Crafted input will lead to a denial of service or possibly unspecified other impact.
nvd
CVE-2017-7814P4HIGHCVSS 7.8v7.0v8.0+1 more2018-06-11
CVE-2017-7814 [HIGH] CWE-20 CVE-2017-7814: File downloads encoded with "blob:" and "data:" URL elements bypassed normal file download checks th File downloads encoded with "blob:" and "data:" URL elements bypassed normal file download checks though the Phishing and Malware Protection feature and its block lists of suspicious sites and files. This would allow malicious sites to lure users into downloading executables that would otherwise be detected as suspicious. This vulnerability affects Firef
nvd
CVE-2011-1293P4HIGHCVSS 7.5v6.0v7.02011-03-25
CVE-2011-1293 [HIGH] CWE-416 CVE-2011-1293: Use-after-free vulnerability in the HTMLCollection implementation in Google Chrome before 10.0.648.2 Use-after-free vulnerability in the HTMLCollection implementation in Google Chrome before 10.0.648.204 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2018-11743P4CRITICALCVSS 9.8v9.02018-06-05
CVE-2018-11743 [CRITICAL] CWE-824 CVE-2018-11743: The init_copy function in kernel.c in mruby 1.4.1 makes initialize_copy calls for TT_ICLASS objects, The init_copy function in kernel.c in mruby 1.4.1 makes initialize_copy calls for TT_ICLASS objects, which allows attackers to cause a denial of service (mrb_hash_keys uninitialized pointer and application crash) or possibly have unspecified other impact.
nvd
CVE-2014-1716P4HIGHCVSS 7.5v7.0v8.02014-04-09
CVE-2014-1716 [HIGH] CWE-94 CVE-2014-1716: Cross-site scripting (XSS) vulnerability in the Runtime_SetPrototype function in runtime.cc in Googl Cross-site scripting (XSS) vulnerability in the Runtime_SetPrototype function in runtime.cc in Google V8, as used in Google Chrome before 34.0.1847.116, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Universal XSS (UXSS)."
nvd
CVE-2019-12483P4HIGHCVSS 7.8v8.02019-05-30
CVE-2019-12483 [HIGH] CWE-787 CVE-2019-12483: An issue was discovered in GPAC 0.7.1. There is a heap-based buffer overflow in the function ReadGF_ An issue was discovered in GPAC 0.7.1. There is a heap-based buffer overflow in the function ReadGF_IPMPX_RemoveToolNotificationListener in odf/ipmpx_code.c in libgpac.a, as demonstrated by MP4Box.
nvd
CVE-2019-11221P4HIGHCVSS 7.8v8.02019-04-15
CVE-2019-11221 [HIGH] CWE-787 CVE-2019-11221: GPAC 0.7.1 has a buffer overflow issue in gf_import_message() in media_import.c. GPAC 0.7.1 has a buffer overflow issue in gf_import_message() in media_import.c.
nvd
CVE-2013-6644P4HIGHCVSS 7.5v7.0v8.02014-01-16
CVE-2013-6644 [HIGH] CWE-416 CVE-2013-6644: Multiple unspecified vulnerabilities in Google Chrome before 32.0.1700.76 on Windows and before 32.0 Multiple unspecified vulnerabilities in Google Chrome before 32.0.1700.76 on Windows and before 32.0.1700.77 on Mac OS X and Linux allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2017-5037P4HIGHCVSS 7.8v8.0v9.02017-04-24
CVE-2017-5037 [HIGH] CWE-190 CVE-2017-5037: An integer overflow in FFmpeg in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and An integer overflow in FFmpeg in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to perform an out of bounds memory write via a crafted video file, related to ChunkDemuxer.
nvd
CVE-2020-5313P4HIGHCVSS 7.1v9.0v10.02020-01-03
CVE-2020-5313 [HIGH] CWE-125 CVE-2020-5313: libImaging/FliDecode.c in Pillow before 6.2.2 has an FLI buffer overflow. libImaging/FliDecode.c in Pillow before 6.2.2 has an FLI buffer overflow.
nvd
CVE-2021-32493P4HIGHCVSS 7.8v10.0v11.02021-06-24
CVE-2021-32493 [HIGH] CWE-119 CVE-2021-32493: A flaw was found in djvulibre-3.5.28 and earlier. A heap buffer overflow in function DJVU::GBitmap:: A flaw was found in djvulibre-3.5.28 and earlier. A heap buffer overflow in function DJVU::GBitmap::decode() via crafted djvu file may lead to application crash and other consequences.
nvd
CVE-2017-18265P4HIGHCVSS 7.5v9.02018-05-09
CVE-2017-18265 [HIGH] CVE-2017-18265: Prosody before 0.10.0 allows remote attackers to cause a denial of service (application crash), rela Prosody before 0.10.0 allows remote attackers to cause a denial of service (application crash), related to an incompatibility with certain versions of the LuaSocket library, such as the lua-socket package from Debian stretch. The attacker needs to trigger a stream error. A crash can be observed in, for example, the c2s module.
nvd
CVE-2017-8820P4HIGHCVSS 7.5v8.0v9.02017-12-03
CVE-2017-8820 [HIGH] CWE-476 CVE-2017-8820: In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3 In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, remote attackers can cause a denial of service (NULL pointer dereference and application crash) against directory authorities via a malformed descriptor, aka TROVE-2017-010.
nvd
CVE-2021-3500P4HIGHCVSS 7.8v10.0v11.02021-06-24
CVE-2021-3500 [HIGH] CWE-787 CVE-2021-3500: A flaw was found in djvulibre-3.5.28 and earlier. A Stack overflow in function DJVU::DjVuDocument::g A flaw was found in djvulibre-3.5.28 and earlier. A Stack overflow in function DJVU::DjVuDocument::get_djvu_file() via crafted djvu file may lead to application crash and other consequences.
nvd
CVE-2015-1237P4HIGHCVSS 7.5v8.02015-04-19
CVE-2015-1237 [HIGH] CVE-2015-1237: Use-after-free vulnerability in the RenderFrameImpl::OnMessageReceived function in content/renderer/ Use-after-free vulnerability in the RenderFrameImpl::OnMessageReceived function in content/renderer/render_frame_impl.cc in Google Chrome before 42.0.2311.90 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger renderer IPC messages during a detach operation.
nvd
Debian Linux vulnerabilities | cvebase