cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 285 of 498
CVE-2017-11714P4HIGHCVSS 7.8v8.0v9.02017-07-28
CVE-2017-11714 [HIGH] CWE-125 CVE-2017-11714: psi/ztoken.c in Artifex Ghostscript 9.21 mishandles references to the scanner state structure, which psi/ztoken.c in Artifex Ghostscript 9.21 mishandles references to the scanner state structure, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PostScript document, related to an out-of-bounds read in the igc_reloc_struct_ptr function in psi/igc.c.
nvd
CVE-2024-20926P4MEDIUMCVSS 5.9v10.02024-01-16
CVE-2024-20926 [MEDIUM] CWE-284 CVE-2024-20926: Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition produ Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Scripting). Supported versions that are affected are Oracle Java SE: 8u391, 8u391-perf, 11.0.21; Oracle GraalVM for JDK: 17.0.9; Oracle GraalVM Enterprise Edition: 20.3.12, 21.3.8 and 22.3.4. Difficult to exploit vulne
nvd
CVE-2015-7942P4MEDIUMCVSS 6.8v7.0v8.02015-11-18
CVE-2015-7942 [MEDIUM] CVE-2015-7942: The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary entities when it stops parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via crafted XML data, a different vulnerability than CVE-2015-7941.
nvd
CVE-2005-0102P4CRITICALCVSS 9.8v3.02005-01-24
CVE-2005-0102 [CRITICAL] CWE-190 CVE-2005-0102: Integer overflow in camel-lock-helper in Evolution 2.0.2 and earlier allows local users or remote ma Integer overflow in camel-lock-helper in Evolution 2.0.2 and earlier allows local users or remote malicious POP3 servers to execute arbitrary code via a length value of -1, which leads to a zero byte memory allocation and a buffer overflow.
nvd
CVE-2007-1864P4HIGHCVSS 7.5v3.1v4.02007-05-09
CVE-2007-1864 [HIGH] CWE-119 CVE-2007-1864: Buffer overflow in the bundled libxmlrpc library in PHP before 4.4.7, and 5.x before 5.2.2, has unkn Buffer overflow in the bundled libxmlrpc library in PHP before 4.4.7, and 5.x before 5.2.2, has unknown impact and remote attack vectors.
nvd
CVE-2018-11359P4HIGHCVSS 7.5v8.02018-05-22
CVE-2018-11359 [HIGH] CWE-476 CVE-2018-11359: In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the RRC dissector and other dissectors coul In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the RRC dissector and other dissectors could crash. This was addressed in epan/proto.c by avoiding a NULL pointer dereference.
nvd
CVE-2010-3702P4HIGHCVSS 7.5v5.0v6.02010-11-05
CVE-2010-3702 [HIGH] CWE-476 CVE-2010-3702: The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of service (crash) via unknown vectors that trigger an uninitialized pointer dereference.
nvd
CVE-2017-9776P4HIGHCVSS 7.8v8.0v9.02017-06-22
CVE-2017-9776 [HIGH] CWE-190 CVE-2017-9776: Integer overflow leading to Heap buffer overflow in JBIG2Stream.cc in pdftocairo in Poppler before 0 Integer overflow leading to Heap buffer overflow in JBIG2Stream.cc in pdftocairo in Poppler before 0.56 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PDF document.
nvd
CVE-2019-13057P4MEDIUMCVSS 4.9v8.02019-07-26
CVE-2019-13057 [MEDIUM] CVE-2019-13057: An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator deleg An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from another database during a SASL bind or
nvd
CVE-2015-1242P4HIGHCVSS 7.5v8.02015-04-19
CVE-2015-1242 [HIGH] CVE-2015-1242: The ReduceTransitionElementsKind function in hydrogen-check-elimination.cc in Google V8 before 4.2.7 The ReduceTransitionElementsKind function in hydrogen-check-elimination.cc in Google V8 before 4.2.77.8, as used in Google Chrome before 42.0.2311.90, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that leverages "type confusion" in the check-elimination optimization.
nvd
CVE-2017-16927P4HIGHCVSS 8.4v7.02017-11-23
CVE-2017-16927 [HIGH] CWE-119 CVE-2017-16927: The scp_v0s_accept function in sesman/libscp/libscp_v0.c in the session manager in xrdp through 0.9. The scp_v0s_accept function in sesman/libscp/libscp_v0.c in the session manager in xrdp through 0.9.4 uses an untrusted integer as a write length, which allows local users to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted input stream.
nvd
CVE-2013-2882P4HIGHCVSS 7.5v7.02013-07-31
CVE-2013-2882 [HIGH] CWE-843 CVE-2013-2882: Google V8, as used in Google Chrome before 28.0.1500.95, allows remote attackers to cause a denial o Google V8, as used in Google Chrome before 28.0.1500.95, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that leverage "type confusion."
nvd
CVE-2014-8542P4HIGHCVSS 7.5v8.02014-11-05
CVE-2014-8542 [HIGH] CWE-119 CVE-2014-8542: libavcodec/utils.c in FFmpeg before 2.4.2 omits a certain codec ID during enforcement of alignment, libavcodec/utils.c in FFmpeg before 2.4.2 omits a certain codec ID during enforcement of alignment, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted JV data.
nvd
CVE-2015-2927P4MEDIUMCVSS 6.5v8.0v9.02017-09-20
CVE-2015-2927 [MEDIUM] CWE-399 CVE-2015-2927: node 0.3.2 and URONode before 1.0.5r3 allows remote attackers to cause a denial of service (bandwidt node 0.3.2 and URONode before 1.0.5r3 allows remote attackers to cause a denial of service (bandwidth consumption).
nvd
CVE-2021-39200P4MEDIUMCVSS 5.3v10.0v11.02021-09-09
CVE-2021-39200 [MEDIUM] CWE-200 CVE-2021-39200: WordPress is a free and open-source content management system written in PHP and paired with a MySQL WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions output data of the function wp_die() can be leaked under certain conditions, which can include data like nonces. It can then be used to perform actions on your behalf. This has been patched in WordPress 5.8.1
nvd
CVE-2020-36277P4HIGHCVSS 7.5v9.02021-03-11
CVE-2020-36277 [HIGH] CWE-670 CVE-2020-36277: Leptonica before 1.80.0 allows a denial of service (application crash) via an incorrect left shift i Leptonica before 1.80.0 allows a denial of service (application crash) via an incorrect left shift in pixConvert2To8 in pixconv.c.
nvd
CVE-2016-4348P4HIGHCVSS 7.5v8.02016-05-20
CVE-2016-4348 [HIGH] CWE-20 CVE-2016-4348: The _rsvg_css_normalize_font_size function in librsvg 2.40.2 allows context-dependent attackers to c The _rsvg_css_normalize_font_size function in librsvg 2.40.2 allows context-dependent attackers to cause a denial of service (stack consumption and application crash) via circular definitions in an SVG document.
nvd
CVE-2018-9268P4HIGHCVSS 7.5v7.0v8.02018-04-04
CVE-2018-9268 [HIGH] CWE-772 CVE-2018-9268: In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-smb2.c has a memory leak. In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-smb2.c has a memory leak.
nvd
CVE-2018-9269P4HIGHCVSS 7.5v7.0v8.02018-04-04
CVE-2018-9269 [HIGH] CWE-772 CVE-2018-9269: In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-giop.c has a memory leak. In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-giop.c has a memory leak.
nvd
CVE-2015-7977P4MEDIUMCVSS 5.9v8.0v9.02017-01-30
CVE-2015-7977 [MEDIUM] CWE-476 CVE-2015-7977: ntpd in NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of serv ntpd in NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (NULL pointer dereference) via a ntpdc reslist command.
nvd
Debian Linux vulnerabilities | cvebase