Debian Linux vulnerabilities
9,954 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358
Vulnerabilities
Page 288 of 498
CVE-2016-1677P4MEDIUMCVSS 6.5v8.02016-06-05
CVE-2016-1677 [MEDIUM] CWE-200 CVE-2016-1677: uri.js in Google V8 before 5.1.281.26, as used in Google Chrome before 51.0.2704.63, uses an incorre
uri.js in Google V8 before 5.1.281.26, as used in Google Chrome before 51.0.2704.63, uses an incorrect array type, which allows remote attackers to obtain sensitive information by calling the decodeURI function and leveraging "type confusion."
nvd
CVE-2017-14450P4HIGHCVSS 7.1v7.0v8.0+1 more2018-04-24
CVE-2017-14450 [HIGH] CWE-119 CVE-2017-14450: A buffer overflow vulnerability exists in the GIF image parsing functionality of SDL2_image-2.0.2. A
A buffer overflow vulnerability exists in the GIF image parsing functionality of SDL2_image-2.0.2. A specially crafted GIF image can lead to a buffer overflow on a global section. An attacker can display an image to trigger this vulnerability.
nvd
CVE-2014-2327P4MEDIUMCVSS 6.8v7.0v8.02014-04-23
CVE-2014-2327 [MEDIUM] CWE-352 CVE-2014-2327: Cross-site request forgery (CSRF) vulnerability in Cacti 0.8.7g, 0.8.8b, and earlier allows remote a
Cross-site request forgery (CSRF) vulnerability in Cacti 0.8.7g, 0.8.8b, and earlier allows remote attackers to hijack the authentication of users for unspecified commands, as demonstrated by requests that (1) modify binary files, (2) modify configurations, or (3) add arbitrary users.
nvd
CVE-2022-0891P4HIGHCVSS 7.1v10.0v11.02022-03-10
CVE-2022-0891 [HIGH] CWE-787 CVE-2022-0891: A heap buffer overflow in ExtractImageSection function in tiffcrop.c in libtiff library Version 4.3.
A heap buffer overflow in ExtractImageSection function in tiffcrop.c in libtiff library Version 4.3.0 allows attacker to trigger unsafe or out of bounds memory access via crafted TIFF image file which could result into application crash, potential information disclosure or any other context-dependent impact
nvd
CVE-2009-1888P4MEDIUMCVSS 5.8v4.0v5.02009-06-25
CVE-2009-1888 [MEDIUM] CWE-264 CVE-2009-1888: The acl_group_override function in smbd/posix_acls.c in smbd in Samba 3.0.x before 3.0.35, 3.1.x and
The acl_group_override function in smbd/posix_acls.c in smbd in Samba 3.0.x before 3.0.35, 3.1.x and 3.2.x before 3.2.13, and 3.3.x before 3.3.6, when dos filemode is enabled, allows remote attackers to modify access control lists for files via vectors related to read access to uninitialized memory.
nvd
CVE-2018-11439P4MEDIUMCVSS 6.5v8.0v9.02018-05-30
CVE-2018-11439 [MEDIUM] CWE-125 CVE-2018-11439: The TagLib::Ogg::FLAC::File::scan function in oggflacfile.cpp in TagLib 1.11.1 allows remote attacke
The TagLib::Ogg::FLAC::File::scan function in oggflacfile.cpp in TagLib 1.11.1 allows remote attackers to cause information disclosure (heap-based buffer over-read) via a crafted audio file.
nvd
CVE-2022-3564P4HIGHCVSS 7.1v10.02022-10-17
CVE-2022-3564 [HIGH] CWE-119 CVE-2022-3564: A vulnerability classified as critical was found in Linux Kernel. Affected by this vulnerability is
A vulnerability classified as critical was found in Linux Kernel. Affected by this vulnerability is the function l2cap_reassemble_sdu of the file net/bluetooth/l2cap_core.c of the component Bluetooth. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-2110
nvd
CVE-2018-0504P4MEDIUMCVSS 6.5v9.02018-10-04
CVE-2018-0504 [MEDIUM] CWE-532 CVE-2018-0504: Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains an information disclosure flaw in t
Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains an information disclosure flaw in the Special:Redirect/logid
nvd
CVE-2013-4475P4MEDIUMCVSS 4.0v6.0v7.02013-11-13
CVE-2013-4475 [MEDIUM] CWE-264 CVE-2013-4475: Samba 3.2.x through 3.6.x before 3.6.20, 4.0.x before 4.0.11, and 4.1.x before 4.1.1, when vfs_strea
Samba 3.2.x through 3.6.x before 3.6.20, 4.0.x before 4.0.11, and 4.1.x before 4.1.1, when vfs_streams_depot or vfs_streams_xattr is enabled, allows remote attackers to bypass intended file restrictions by leveraging ACL differences between a file and an associated alternate data stream (ADS).
nvd
CVE-2018-14652P4MEDIUMCVSS 6.5v8.0v9.02018-10-31
CVE-2018-14652 [MEDIUM] CWE-120 CVE-2018-14652: The Gluster file system through versions 3.12 and 4.1.4 is vulnerable to a buffer overflow in the 'f
The Gluster file system through versions 3.12 and 4.1.4 is vulnerable to a buffer overflow in the 'features/index' translator via the code handling the 'GF_XATTR_CLRLK_CMD' xattr in the 'pl_getxattr' function. A remote authenticated attacker could exploit this on a mounted volume to cause a denial of service.
nvd
CVE-2022-41742P4HIGHCVSS 7.1v10.0v11.02022-10-19
CVE-2022-41742 [HIGH] CWE-787 CVE-2022-41742: NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions
NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local attacker to cause a worker process crash, or might result in worker process memory disclosure by using a spe
nvd
CVE-2021-4204P4HIGHCVSS 7.1v11.02022-08-24
CVE-2021-4204 [HIGH] CWE-20 CVE-2021-4204: An out-of-bounds (OOB) memory access flaw was found in the Linux kernel's eBPF due to an Improper In
An out-of-bounds (OOB) memory access flaw was found in the Linux kernel's eBPF due to an Improper Input Validation. This flaw allows a local attacker with a special privilege to crash the system or leak internal information.
nvd
CVE-2021-45972P4HIGHCVSS 7.1v9.0v10.0+1 more2022-01-01
CVE-2021-45972 [HIGH] CWE-1284 CVE-2021-45972: The giftrans function in giftrans 1.12.2 contains a stack-based buffer overflow because a value insi
The giftrans function in giftrans 1.12.2 contains a stack-based buffer overflow because a value inside the input file determines the amount of data to write. This allows an attacker to overwrite up to 250 bytes outside of the allocated buffer with arbitrary data.
nvd
CVE-2020-14401P4MEDIUMCVSS 6.5v8.0v9.02020-06-17
CVE-2020-14401 [MEDIUM] CWE-190 CVE-2020-14401: An issue was discovered in LibVNCServer before 0.9.13. libvncserver/scale.c has a pixel_value intege
An issue was discovered in LibVNCServer before 0.9.13. libvncserver/scale.c has a pixel_value integer overflow.
nvd
CVE-2019-17637P4HIGHCVSS 7.1v9.02020-07-15
CVE-2019-17637 [HIGH] CWE-611 CVE-2019-17637: In all versions of Eclipse Web Tools Platform through release 3.18 (2020-06), XML and DTD files refe
In all versions of Eclipse Web Tools Platform through release 3.18 (2020-06), XML and DTD files referring to external entities could be exploited to send the contents of local files to a remote server when edited or validated, even when external entity resolution is disabled in the user preferences.
nvd
CVE-2016-0740P4MEDIUMCVSS 6.5v7.0v8.02016-04-13
CVE-2016-0740 [MEDIUM] CWE-119 CVE-2016-0740: Buffer overflow in the ImagingLibTiffDecode function in libImaging/TiffDecode.c in Pillow before 3.1
Buffer overflow in the ImagingLibTiffDecode function in libImaging/TiffDecode.c in Pillow before 3.1.1 allows remote attackers to overwrite memory via a crafted TIFF file.
nvd
CVE-2007-5729P4HIGHCVSS 7.2v3.1v4.02007-10-30
CVE-2007-5729 [HIGH] CVE-2007-5729: The NE2000 emulator in QEMU 0.8.2 allows local users to execute arbitrary code by writing Ethernet f
The NE2000 emulator in QEMU 0.8.2 allows local users to execute arbitrary code by writing Ethernet frames with a size larger than the MTU to the EN0_TCNT register, which triggers a heap-based buffer overflow in the slirp library, aka NE2000 "mtu" heap overflow. NOTE: some sources have used CVE-2007-1321 to refer to this issue as part of "NE2000 network driver a
nvd
CVE-2018-12396P4MEDIUMCVSS 6.5v8.0v9.02019-02-28
CVE-2018-12396 [MEDIUM] CWE-732 CVE-2018-12396: A vulnerability where a WebExtension can run content scripts in disallowed contexts following naviga
A vulnerability where a WebExtension can run content scripts in disallowed contexts following navigation or other events. This allows for potential privilege escalation by the WebExtension on sites where content scripts should not be run. This vulnerability affects Firefox ESR < 60.3 and Firefox < 63.
nvd
CVE-2020-11523P4MEDIUMCVSS 6.6v9.02020-05-15
CVE-2020-11523 [MEDIUM] CWE-190 CVE-2020-11523: libfreerdp/gdi/region.c in FreeRDP versions > 1.0 through 2.0.0-rc4 has an Integer Overflow.
libfreerdp/gdi/region.c in FreeRDP versions > 1.0 through 2.0.0-rc4 has an Integer Overflow.
nvd
CVE-2020-9383P4HIGHCVSS 7.1v8.0v9.02020-02-25
CVE-2020-9383 [HIGH] CWE-125 CVE-2020-9383: An issue was discovered in the Linux kernel 3.16 through 5.5.6. set_fdc in drivers/block/floppy.c le
An issue was discovered in the Linux kernel 3.16 through 5.5.6. set_fdc in drivers/block/floppy.c leads to a wait_til_ready out-of-bounds read because the FDC index is not checked for errors before assigning it, aka CID-2e90ca68b0d2.
nvd