cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 298 of 498
CVE-2013-2901P4HIGHCVSS 7.5v7.02013-08-21
CVE-2013-2901 [HIGH] CWE-189 CVE-2013-2901: Multiple integer overflows in (1) libGLESv2/renderer/Renderer9.cpp and (2) libGLESv2/renderer/Render Multiple integer overflows in (1) libGLESv2/renderer/Renderer9.cpp and (2) libGLESv2/renderer/Renderer11.cpp in Almost Native Graphics Layer Engine (ANGLE), as used in Google Chrome before 29.0.1547.57, allow remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2013-2902P4HIGHCVSS 7.5v7.02013-08-21
CVE-2013-2902 [HIGH] CWE-399 CVE-2013-2902: Use-after-free vulnerability in the XSLT ProcessingInstruction implementation in Blink, as used in G Use-after-free vulnerability in the XSLT ProcessingInstruction implementation in Blink, as used in Google Chrome before 29.0.1547.57, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to an applyXSLTransform call involving (1) an HTML document or (2) an xsl:processing-instruction element t
nvd
CVE-2013-2884P4HIGHCVSS 7.5v7.02013-07-31
CVE-2013-2884 [HIGH] CWE-399 CVE-2013-2884: Use-after-free vulnerability in the DOM implementation in Google Chrome before 28.0.1500.95 allows r Use-after-free vulnerability in the DOM implementation in Google Chrome before 28.0.1500.95 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to improper tracking of which document owns an Attr object.
nvd
CVE-2013-2873P4HIGHCVSS 7.5v7.02013-07-10
CVE-2013-2873 [HIGH] CWE-399 CVE-2013-2873: Use-after-free vulnerability in Google Chrome before 28.0.1500.71 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 28.0.1500.71 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a 404 HTTP status code during the loading of resources.
nvd
CVE-2016-3070P4HIGHCVSS 7.8v8.02016-08-06
CVE-2016-3070 [HIGH] CWE-476 CVE-2016-3070: The trace_writeback_dirty_page implementation in include/trace/events/writeback.h in the Linux kerne The trace_writeback_dirty_page implementation in include/trace/events/writeback.h in the Linux kernel before 4.4 improperly interacts with mm/migrate.c, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by triggering a certain page move.
nvd
CVE-2010-2798P4HIGHCVSS 7.8v5.02010-09-08
CVE-2010-2798 [HIGH] CWE-476 CVE-2010-2798: The gfs2_dirent_find_space function in fs/gfs2/dir.c in the Linux kernel before 2.6.35 uses an incor The gfs2_dirent_find_space function in fs/gfs2/dir.c in the Linux kernel before 2.6.35 uses an incorrect size value in calculations associated with sentinel directory entries, which allows local users to cause a denial of service (NULL pointer dereference and panic) and possibly have unspecified other impact by renaming a file in a GFS2 filesystem, rela
nvd
CVE-2006-5868P4CRITICALCVSS 9.3v3.1v4.02006-11-22
CVE-2006-5868 [CRITICAL] CVE-2006-5868: Multiple buffer overflows in Imagemagick 6.0 before 6.0.6.2, and 6.2 before 6.2.4.5, has unknown imp Multiple buffer overflows in Imagemagick 6.0 before 6.0.6.2, and 6.2 before 6.2.4.5, has unknown impact and user-assisted attack vectors via a crafted SGI image.
nvd
CVE-2015-8312P4HIGHCVSS 7.8v8.0v9.02016-05-13
CVE-2015-8312 [HIGH] CWE-189 CVE-2015-8312: Off-by-one error in afs_pioctl.c in OpenAFS before 1.6.16 might allow local users to cause a denial Off-by-one error in afs_pioctl.c in OpenAFS before 1.6.16 might allow local users to cause a denial of service (memory overwrite and system crash) via a pioctl with an input buffer size of 4096 bytes.
nvd
CVE-2013-2857P4HIGHCVSS 7.5v7.0v8.02013-06-05
CVE-2013-2857 [HIGH] CWE-416 CVE-2013-2857: Use-after-free vulnerability in Google Chrome before 27.0.1453.110 allows remote attackers to cause Use-after-free vulnerability in Google Chrome before 27.0.1453.110 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of images.
nvd
CVE-2014-6053P4MEDIUMCVSS 5.0v7.02014-12-15
CVE-2014-6053 [MEDIUM] CWE-19 CVE-2014-6053: The rfbProcessClientNormalMessage function in libvncserver/rfbserver.c in LibVNCServer 0.9.9 and ear The rfbProcessClientNormalMessage function in libvncserver/rfbserver.c in LibVNCServer 0.9.9 and earlier does not properly handle attempts to send a large amount of ClientCutText data, which allows remote attackers to cause a denial of service (memory consumption or daemon crash) via a crafted message that is processed by using a single unchecked mallo
nvd
CVE-2020-26139P4MEDIUMCVSS 5.3v9.02021-05-11
CVE-2020-26139 [MEDIUM] CWE-287 CVE-2020-26139: An issue was discovered in the kernel in NetBSD 7.1. An Access Point (AP) forwards EAPOL frames to o An issue was discovered in the kernel in NetBSD 7.1. An Access Point (AP) forwards EAPOL frames to other clients even though the sender has not yet successfully authenticated to the AP. This might be abused in projected Wi-Fi networks to launch denial-of-service attacks against connected clients and makes it easier to exploit other vulnerabilities i
nvd
CVE-2017-1000407P4HIGHCVSS 7.4v7.0v8.0+1 more2017-12-11
CVE-2017-1000407 [HIGH] CWE-754 CVE-2017-1000407: The Linux Kernel 2.6.32 and later are affected by a denial of service, by flooding the diagnostic po The Linux Kernel 2.6.32 and later are affected by a denial of service, by flooding the diagnostic port 0x80 an exception can be triggered leading to a kernel panic.
nvd
CVE-2015-7497P4MEDIUMCVSS 5.0v7.0v8.02015-12-15
CVE-2015-7497 [MEDIUM] CWE-119 CVE-2015-7497: Heap-based buffer overflow in the xmlDictComputeFastQKey function in dict.c in libxml2 before 2.9.3 Heap-based buffer overflow in the xmlDictComputeFastQKey function in dict.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service via unspecified vectors.
nvd
CVE-2026-56968P4MEDIUMCVSS 5.3v13.02026-06-23
CVE-2026-56968 [MEDIUM] CWE-839 CVE-2026-56968: GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a crafted server.
nvd
CVE-2019-20503P4MEDIUMCVSS 6.5v8.0v9.0+1 more2020-03-06
CVE-2019-20503 [MEDIUM] CWE-125 CVE-2019-20503: usrsctp before 2019-12-20 has out-of-bounds reads in sctp_load_addresses_from_init. usrsctp before 2019-12-20 has out-of-bounds reads in sctp_load_addresses_from_init.
nvd
CVE-2018-13988P4MEDIUMCVSS 6.5v8.02018-07-25
CVE-2018-13988 [MEDIUM] CWE-125 CVE-2018-13988: Poppler through 0.62 contains an out of bounds read vulnerability due to an incorrect memory access Poppler through 0.62 contains an out of bounds read vulnerability due to an incorrect memory access that is not mapped in its memory space, as demonstrated by pdfunite. This can result in memory corruption and denial of service. This may be exploitable when a victim opens a specially crafted PDF file.
nvd
CVE-2018-18584P4MEDIUMCVSS 6.5v8.02018-10-23
CVE-2018-18584 [MEDIUM] CWE-787 CVE-2018-18584: In mspack/cab.h in libmspack before 0.8alpha and cabextract before 1.8, the CAB block input buffer i In mspack/cab.h in libmspack before 0.8alpha and cabextract before 1.8, the CAB block input buffer is one byte too small for the maximal Quantum block, leading to an out-of-bounds write.
nvd
CVE-2018-16642P4MEDIUMCVSS 6.5v8.0v9.02018-09-06
CVE-2018-16642 [MEDIUM] CWE-787 CVE-2018-16642: The function InsertRow in coders/cut.c in ImageMagick 7.0.7-37 allows remote attackers to cause a de The function InsertRow in coders/cut.c in ImageMagick 7.0.7-37 allows remote attackers to cause a denial of service via a crafted image file due to an out-of-bounds write.
nvd
CVE-2022-40982P4MEDIUMCVSS 6.5v10.0v11.0+1 more2023-08-11
CVE-2022-40982 [MEDIUM] CWE-1342 CVE-2022-40982: Information exposure through microarchitectural state after transient execution in certain vector ex Information exposure through microarchitectural state after transient execution in certain vector execution units for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
nvd
CVE-2018-7456P4MEDIUMCVSS 6.5v7.0v8.0+1 more2018-02-24
CVE-2018-7456 [MEDIUM] CVE-2018-7456: A NULL Pointer Dereference occurs in the function TIFFPrintDirectory in tif_print.c in LibTIFF 3.9.3 A NULL Pointer Dereference occurs in the function TIFFPrintDirectory in tif_print.c in LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.0.6, 4.0.7, 4.0.8 and 4.0.9 when using the tiffinfo tool to print crafted TIFF information, a different vulnerability than CV
nvd
Debian Linux vulnerabilities | cvebase