Debian Linux vulnerabilities
9,954 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358
Vulnerabilities
Page 287 of 498
CVE-2017-17783P4HIGHCVSS 7.5v9.02017-12-20
CVE-2017-17783 [HIGH] CWE-125 CVE-2017-17783: In GraphicsMagick 1.3.27a, there is a buffer over-read in ReadPALMImage in coders/palm.c when Quantu
In GraphicsMagick 1.3.27a, there is a buffer over-read in ReadPALMImage in coders/palm.c when QuantumDepth is 8.
nvd
CVE-2016-2143P4HIGHCVSS 7.8v6.0v7.0+1 more2016-04-27
CVE-2016-2143 [HIGH] CWE-20 CVE-2016-2143: The fork implementation in the Linux kernel before 4.5 on s390 platforms mishandles the case of four
The fork implementation in the Linux kernel before 4.5 on s390 platforms mishandles the case of four page-table levels, which allows local users to cause a denial of service (system crash) or possibly have unspecified other impact via a crafted application, related to arch/s390/include/asm/mmu_context.h and arch/s390/include/asm/pgalloc.h.
nvd
CVE-2022-0714P4MEDIUMCVSS 5.5v9.0v10.02022-02-22
CVE-2022-0714 [MEDIUM] CWE-122 CVE-2022-0714: Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.4436.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.4436.
nvd
CVE-2013-2903P4HIGHCVSS 7.5v7.02013-08-21
CVE-2013-2903 [HIGH] CWE-399 CVE-2013-2903: Use-after-free vulnerability in the HTMLMediaElement::didMoveToNewDocument function in core/html/HTM
Use-after-free vulnerability in the HTMLMediaElement::didMoveToNewDocument function in core/html/HTMLMediaElement.cpp in Blink, as used in Google Chrome before 29.0.1547.57, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving moving a (1) AUDIO or (2) VIDEO element between documents.
nvd
CVE-2018-14680P4MEDIUMCVSS 6.5v8.0v9.02018-07-28
CVE-2018-14680 [MEDIUM] CWE-20 CVE-2018-14680: An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. It does not reject blank CHM
An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. It does not reject blank CHM filenames.
nvd
CVE-2019-16935P4MEDIUMCVSS 6.1v9.02019-09-28
CVE-2019-16935 [MEDIUM] CWE-79 CVE-2019-16935: The documentation XML-RPC server in Python through 2.7.16, 3.x through 3.6.9, and 3.7.x through 3.7.
The documentation XML-RPC server in Python through 2.7.16, 3.x through 3.6.9, and 3.7.x through 3.7.4 has XSS via the server_title field. This occurs in Lib/DocXMLRPCServer.py in Python 2.x, and in Lib/xmlrpc/server.py in Python 3.x. If set_server_title is called with untrusted input, arbitrary JavaScript can be delivered to clients that visit the ht
nvd
CVE-2018-16644P4MEDIUMCVSS 6.5v8.0v9.02018-09-06
CVE-2018-16644 [MEDIUM] CWE-119 CVE-2018-16644: There is a missing check for length in the functions ReadDCMImage of coders/dcm.c and ReadPICTImage
There is a missing check for length in the functions ReadDCMImage of coders/dcm.c and ReadPICTImage of coders/pict.c in ImageMagick 7.0.8-11, which allows remote attackers to cause a denial of service via a crafted image.
nvd
CVE-2017-17854P4HIGHCVSS 7.8v9.02017-12-27
CVE-2017-17854 [HIGH] CWE-190 CVE-2017-17854: kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of ser
kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (integer overflow and memory corruption) or possibly have unspecified other impact by leveraging unrestricted integer values for pointer arithmetic.
nvd
CVE-2017-17852P4HIGHCVSS 7.8v9.02017-12-27
CVE-2017-17852 [HIGH] CWE-119 CVE-2017-17852: kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of ser
kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging mishandling of 32-bit ALU ops.
nvd
CVE-2018-7480P4HIGHCVSS 7.8v9.02018-02-25
CVE-2018-7480 [HIGH] CWE-415 CVE-2018-7480: The blkcg_init_queue function in block/blk-cgroup.c in the Linux kernel before 4.11 allows local use
The blkcg_init_queue function in block/blk-cgroup.c in the Linux kernel before 4.11 allows local users to cause a denial of service (double free) or possibly have unspecified other impact by triggering a creation failure.
nvd
CVE-2020-35511P4HIGHCVSS 7.8v10.0v11.02022-08-23
CVE-2020-35511 [HIGH] CWE-126 CVE-2020-35511: A global buffer overflow was discovered in pngcheck function in pngcheck-2.4.0(5 patches applied) vi
A global buffer overflow was discovered in pngcheck function in pngcheck-2.4.0(5 patches applied) via a crafted png file.
nvd
CVE-2017-16526P4HIGHCVSS 7.8v8.02017-11-04
CVE-2017-16526 [HIGH] CWE-119 CVE-2017-16526: drivers/uwb/uwbd.c in the Linux kernel before 4.13.6 allows local users to cause a denial of service
drivers/uwb/uwbd.c in the Linux kernel before 4.13.6 allows local users to cause a denial of service (general protection fault and system crash) or possibly have unspecified other impact via a crafted USB device.
nvd
CVE-2014-4258P4MEDIUMCVSS 6.5v7.02014-07-17
CVE-2014-4258 [MEDIUM] CVE-2014-4258: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier and 5.6.1
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier and 5.6.17 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to SRINFOSC.
nvd
CVE-2014-9037P4MEDIUMCVSS 6.8v7.0v8.02014-11-25
CVE-2014-9037 [MEDIUM] CWE-310 CVE-2014-9037: WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow rem
WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to obtain access to an account idle since 2008 by leveraging an improper PHP dynamic type comparison for an MD5 hash.
nvd
CVE-2021-1056P4HIGHCVSS 7.1v9.02021-01-08
CVE-2021-1056 [HIGH] CWE-276 CVE-2021-1056: NVIDIA GPU Display Driver for Linux, all versions, contains a vulnerability in the kernel mode layer
NVIDIA GPU Display Driver for Linux, all versions, contains a vulnerability in the kernel mode layer (nvidia.ko) in which it does not completely honor operating system file system permissions to provide GPU device-level isolation, which may lead to denial of service or information disclosure.
nvd
CVE-2015-7498P4MEDIUMCVSS 5.0v7.0v8.02015-12-15
CVE-2015-7498 [MEDIUM] CWE-119 CVE-2015-7498: Heap-based buffer overflow in the xmlParseXmlDecl function in parser.c in libxml2 before 2.9.3 allow
Heap-based buffer overflow in the xmlParseXmlDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service via unspecified vectors related to extracting errors after an encoding conversion failure.
nvd
CVE-2017-12613P4HIGHCVSS 7.1v7.0v9.02017-10-24
CVE-2017-12613 [HIGH] CWE-125 CVE-2017-12613: When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value i
When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache Portable Runtime APR 1.6.2 and prior, out of bounds memory may be accessed in converting this value to an apr_time_exp_t value, potentially revealing the contents of a different static heap value or resulting in program termination, and may rep
nvd
CVE-2013-2064P4MEDIUMCVSS 6.8v6.0v7.02013-06-15
CVE-2013-2064 [MEDIUM] CWE-189 CVE-2013-2064: Integer overflow in X.org libxcb 1.9 and earlier allows X servers to trigger allocation of insuffici
Integer overflow in X.org libxcb 1.9 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the read_packet function.
nvd
CVE-2019-1000020P4MEDIUMCVSS 6.5v8.02019-02-04
CVE-2019-1000020 [MEDIUM] CWE-835 CVE-2019-1000020: libarchive version commit 5a98dcf8a86364b3c2c469c85b93647dfb139961 onwards (version v2.8.0 onwards)
libarchive version commit 5a98dcf8a86364b3c2c469c85b93647dfb139961 onwards (version v2.8.0 onwards) contains a CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in ISO9660 parser, archive_read_support_format_iso9660.c, read_CE()/parse_rockridge() that can result in DoS by infinite loop. This attack appears to be exploi
nvd
CVE-2016-4449P4HIGHCVSS 7.1v8.02016-06-09
CVE-2016-4449 [HIGH] CWE-20 CVE-2016-4449: XML external entity (XXE) vulnerability in the xmlStringLenDecodeEntities function in parser.c in li
XML external entity (XXE) vulnerability in the xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.4, when not in validating mode, allows context-dependent attackers to read arbitrary files or cause a denial of service (resource consumption) via unspecified vectors.
nvd