cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 286 of 498
CVE-2017-17866P4HIGHCVSS 7.8v9.02017-12-27
CVE-2017-17866 [HIGH] CWE-119 CVE-2017-17866: pdf/pdf-write.c in Artifex MuPDF before 1.12.0 mishandles certain length changes when a repair opera pdf/pdf-write.c in Artifex MuPDF before 1.12.0 mishandles certain length changes when a repair operation occurs during a clean operation, which allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted PDF document.
nvd
CVE-2015-8837P4HIGHCVSS 7.3v7.0v8.02016-03-30
CVE-2015-8837 [HIGH] CWE-119 CVE-2015-8837: Stack-based buffer overflow in the isofs_real_readdir function in isofs.c in FuseISO 20070708 allows Stack-based buffer overflow in the isofs_real_readdir function in isofs.c in FuseISO 20070708 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long pathname in an ISO file.
nvd
CVE-2018-19543P4HIGHCVSS 7.8v8.02018-11-26
CVE-2018-19543 [HIGH] CWE-125 CVE-2018-19543: An issue was discovered in JasPer 2.0.14. There is a heap-based buffer over-read of size 8 in the fu An issue was discovered in JasPer 2.0.14. There is a heap-based buffer over-read of size 8 in the function jp2_decode in libjasper/jp2/jp2_dec.c.
nvd
CVE-2018-20761P4HIGHCVSS 7.8v8.02019-02-06
CVE-2018-20761 [HIGH] CWE-119 CVE-2018-20761: GPAC version 0.7.1 and earlier has a Buffer Overflow vulnerability in the gf_sm_load_init function i GPAC version 0.7.1 and earlier has a Buffer Overflow vulnerability in the gf_sm_load_init function in scene_manager.c in libgpac_static.a.
nvd
CVE-2017-6298P4HIGHCVSS 7.8v8.0v9.02017-02-24
CVE-2017-6298 [HIGH] CWE-476 CVE-2017-6298: An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "1 of 9. Null An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "1 of 9. Null Pointer Deref / calloc return value not checked."
nvd
CVE-2013-6650P4HIGHCVSS 7.5v7.0v8.02014-01-28
CVE-2013-6650 [HIGH] CWE-20 CVE-2013-6650: The StoreBuffer::ExemptPopularPages function in store-buffer.cc in Google V8 before 3.22.24.16, as u The StoreBuffer::ExemptPopularPages function in store-buffer.cc in Google V8 before 3.22.24.16, as used in Google Chrome before 32.0.1700.102, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via vectors that trigger incorrect handling of "popular pages."
nvd
CVE-2011-1588P4HIGHCVSS 7.8v8.0v9.0+1 more2019-11-14
CVE-2011-1588 [HIGH] CWE-134 CVE-2011-1588: Thunar before 1.3.1 could crash when copy and pasting a file name with % format characters due to a Thunar before 1.3.1 could crash when copy and pasting a file name with % format characters due to a format string error.
nvd
CVE-2017-17787P4HIGHCVSS 7.8v7.0v8.0+1 more2017-12-20
CVE-2017-17787 [HIGH] CWE-125 CVE-2017-17787: In GIMP 2.8.22, there is a heap-based buffer over-read in read_creator_block in plug-ins/common/file In GIMP 2.8.22, there is a heap-based buffer over-read in read_creator_block in plug-ins/common/file-psp.c.
nvd
CVE-2013-6621P4HIGHCVSS 7.5v7.0v8.02013-11-13
CVE-2013-6621 [HIGH] CWE-399 CVE-2013-6621: Use-after-free vulnerability in Google Chrome before 31.0.1650.48 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 31.0.1650.48 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the x-webkit-speech attribute in a text INPUT element.
nvd
CVE-2011-1292P4HIGHCVSS 7.5v6.0v7.02011-03-25
CVE-2011-1292 [HIGH] CWE-416 CVE-2011-1292: Use-after-free vulnerability in the frame-loader implementation in Google Chrome before 10.0.648.204 Use-after-free vulnerability in the frame-loader implementation in Google Chrome before 10.0.648.204 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2014-3168P4HIGHCVSS 7.5v7.02014-08-27
CVE-2014-3168 [HIGH] CVE-2014-3168: Use-after-free vulnerability in the SVG implementation in Blink, as used in Google Chrome before 37. Use-after-free vulnerability in the SVG implementation in Blink, as used in Google Chrome before 37.0.2062.94, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging improper caching associated with animation.
nvd
CVE-2019-16168P4MEDIUMCVSS 6.5v9.02019-09-09
CVE-2019-16168 [MEDIUM] CWE-369 CVE-2019-16168: In SQLite through 3.29.0, whereLoopAddBtreeIndex in sqlite3.c can crash a browser or other applicati In SQLite through 3.29.0, whereLoopAddBtreeIndex in sqlite3.c can crash a browser or other application because of missing validation of a sqlite_stat1 sz field, aka a "severe division by zero in the query planner."
nvd
CVE-2017-9461P4MEDIUMCVSS 6.5v8.02017-06-06
CVE-2017-9461 [MEDIUM] CWE-835 CVE-2017-9461: smbd in Samba before 4.4.10 and 4.5.x before 4.5.6 has a denial of service vulnerability (fd_open_at smbd in Samba before 4.4.10 and 4.5.x before 4.5.6 has a denial of service vulnerability (fd_open_atomic infinite loop with high CPU usage and memory consumption) due to wrongly handling dangling symlinks.
nvd
CVE-2021-32492P4HIGHCVSS 7.8v10.0v11.02021-06-24
CVE-2021-32492 [HIGH] CWE-119 CVE-2021-32492: A flaw was found in djvulibre-3.5.28 and earlier. An out of bounds read in function DJVU::DataPool:: A flaw was found in djvulibre-3.5.28 and earlier. An out of bounds read in function DJVU::DataPool::has_data() via crafted djvu file may lead to application crash and other consequences.
nvd
CVE-2013-2904P4HIGHCVSS 7.5v7.02013-08-21
CVE-2013-2904 [HIGH] CWE-399 CVE-2013-2904: Use-after-free vulnerability in the Document::finishedParsing function in core/dom/Document.cpp in B Use-after-free vulnerability in the Document::finishedParsing function in core/dom/Document.cpp in Blink, as used in Google Chrome before 29.0.1547.57, allows remote attackers to cause a denial of service or possibly have unspecified other impact via an onload event that changes an IFRAME element so that its src attribute is no longer an XML document, l
nvd
CVE-2015-1257P4HIGHCVSS 7.5v8.02015-05-20
CVE-2015-1257 [HIGH] CWE-119 CVE-2015-1257: platform/graphics/filters/FEColorMatrix.cpp in the SVG implementation in Blink, as used in Google Ch platform/graphics/filters/FEColorMatrix.cpp in the SVG implementation in Blink, as used in Google Chrome before 43.0.2357.65, does not properly handle an insufficient number of values in an feColorMatrix filter, which allows remote attackers to cause a denial of service (container overflow) or possibly have unspecified other impact via a crafted documen
nvd
CVE-2015-1277P4HIGHCVSS 7.5v8.02015-07-23
CVE-2015-1277 [HIGH] CVE-2015-1277: Use-after-free vulnerability in the accessibility implementation in Google Chrome before 44.0.2403.8 Use-after-free vulnerability in the accessibility implementation in Google Chrome before 44.0.2403.89 allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging lack of certain validity checks for accessibility-tree data structures.
nvd
CVE-2015-1262P4HIGHCVSS 7.5v8.02015-05-20
CVE-2015-1262 [HIGH] CWE-17 CVE-2015-1262: platform/fonts/shaping/HarfBuzzShaper.cpp in Blink, as used in Google Chrome before 43.0.2357.65, do platform/fonts/shaping/HarfBuzzShaper.cpp in Blink, as used in Google Chrome before 43.0.2357.65, does not initialize a certain width field, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted Unicode text.
nvd
CVE-2015-1280P4HIGHCVSS 7.5v8.02015-07-23
CVE-2015-1280 [HIGH] CWE-119 CVE-2015-1280: SkPictureShader.cpp in Skia, as used in Google Chrome before 44.0.2403.89, allows remote attackers t SkPictureShader.cpp in Skia, as used in Google Chrome before 44.0.2403.89, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging access to a renderer process and providing crafted serialized data.
nvd
CVE-2018-7869P4HIGHCVSS 7.5v7.02018-03-08
CVE-2018-7869 [HIGH] CWE-772 CVE-2018-7869: There is a memory leak triggered in the function dcinit of util/decompile.c in libming 0.4.8, which There is a memory leak triggered in the function dcinit of util/decompile.c in libming 0.4.8, which will lead to a denial of service attack.
nvd
Debian Linux vulnerabilities | cvebase