cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 299 of 498
CVE-2020-35653P4HIGHCVSS 7.1v9.02021-01-12
CVE-2020-35653 [HIGH] CWE-125 CVE-2020-35653: In Pillow before 8.1.0, PcxDecode has a buffer over-read when decoding a crafted PCX file because th In Pillow before 8.1.0, PcxDecode has a buffer over-read when decoding a crafted PCX file because the user-supplied stride value is trusted for buffer calculations.
nvd
CVE-2020-27783P4MEDIUMCVSS 6.1v9.0v10.02020-12-03
CVE-2020-27783 [MEDIUM] CWE-79 CVE-2020-27783: A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properl A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A remote attacker could exploit this flaw to run arbitrary HTML/JS code.
nvd
CVE-2019-3824P4MEDIUMCVSS 6.5v8.02019-03-06
CVE-2019-3824 [MEDIUM] CWE-125 CVE-2019-3824: A flaw was found in the way an LDAP search expression could crash the shared LDAP server process of A flaw was found in the way an LDAP search expression could crash the shared LDAP server process of a samba AD DC in samba before version 4.10. An authenticated user, having read permissions on the LDAP server, could use this flaw to cause denial of service.
nvd
CVE-2017-5407P4MEDIUMCVSS 6.5v8.02018-06-11
CVE-2017-5407 [MEDIUM] CWE-200 CVE-2017-5407: Using SVG filters that don't use the fixed point math implementation on a target iframe, a malicious Using SVG filters that don't use the fixed point math implementation on a target iframe, a malicious page can extract pixel values from a targeted user. This can be used to extract history information and read text values across domains. This violates same-origin policy and leads to information disclosure. This vulnerability affects Firefox < 52, Fire
nvd
CVE-2018-6066P4MEDIUMCVSS 6.5v9.02018-11-14
CVE-2018-6066 [MEDIUM] CWE-200 CVE-2018-6066: Lack of CORS checking by ResourceFetcher/ResourceLoader in Blink in Google Chrome prior to 65.0.3325 Lack of CORS checking by ResourceFetcher/ResourceLoader in Blink in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2023-20593P4MEDIUMCVSS 5.5v10.0v11.0+1 more2023-07-24
CVE-2023-20593 [MEDIUM] CWE-209 CVE-2023-20593: An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may allow an attacker to An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may allow an attacker to potentially access sensitive information.
nvd
CVE-2016-3615P4MEDIUMCVSS 5.3v8.02016-07-21
CVE-2016-3615 [MEDIUM] CVE-2016-3615: Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and ear Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and earlier and MariaDB before 5.5.50, 10.0.x before 10.0.26, and 10.1.x before 10.1.15 allows remote authenticated users to affect availability via vectors related to Server: DML.
nvd
CVE-2020-11522P4MEDIUMCVSS 6.5v9.02020-05-15
CVE-2020-11522 [MEDIUM] CWE-125 CVE-2020-11522: libfreerdp/gdi/gdi.c in FreeRDP > 1.0 through 2.0.0-rc4 has an Out-of-bounds Read. libfreerdp/gdi/gdi.c in FreeRDP > 1.0 through 2.0.0-rc4 has an Out-of-bounds Read.
nvd
CVE-2015-1271P4MEDIUMCVSS 6.8v8.02015-07-23
CVE-2015-1271 [MEDIUM] CWE-119 CVE-2015-1271: PDFium, as used in Google Chrome before 44.0.2403.89, does not properly handle certain out-of-memory PDFium, as used in Google Chrome before 44.0.2403.89, does not properly handle certain out-of-memory conditions, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted PDF document that triggers a large memory allocation.
nvd
CVE-2022-22815P4MEDIUMCVSS 6.5v9.0v10.0+1 more2022-01-10
CVE-2022-22815 [MEDIUM] CWE-665 CVE-2022-22815: path_getbbox in path.c in Pillow before 9.0.0 improperly initializes ImagePath.Path. path_getbbox in path.c in Pillow before 9.0.0 improperly initializes ImagePath.Path.
nvd
CVE-2018-5800P4MEDIUMCVSS 6.5v8.02018-12-07
CVE-2018-5800 [MEDIUM] CWE-193 CVE-2018-5800: An off-by-one error within the "LibRaw::kodak_ycbcr_load_raw()" function (internal/dcraw_common.cpp) An off-by-one error within the "LibRaw::kodak_ycbcr_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.7 can be exploited to cause a heap-based buffer overflow and subsequently cause a crash.
nvd
CVE-2021-27364P4HIGHCVSS 7.1v9.02021-03-07
CVE-2021-27364 [HIGH] CWE-125 CVE-2021-27364: An issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/scsi_transport_iscsi.c is a An issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/scsi_transport_iscsi.c is adversely affected by the ability of an unprivileged user to craft Netlink messages.
nvd
CVE-2001-0456P4HIGHCVSS 7.5v2.22001-06-27
CVE-2001-0456 [HIGH] CVE-2001-0456: postinst installation script for Proftpd in Debian 2.2 does not properly change the "run as uid/gid postinst installation script for Proftpd in Debian 2.2 does not properly change the "run as uid/gid root" configuration when the user enables anonymous access, which causes the server to run at a higher privilege than intended.
nvd
CVE-2017-4965P4MEDIUMCVSS 6.1v9.02017-06-13
CVE-2017-4965 [MEDIUM] CWE-79 CVE-2017-4965: An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these RabbitMQ for PCF versions: all 1.5.x versions, 1.6.x versions prior to 1.6.18, and 1.7.x versions prior to 1.7.15. Several forms in the RabbitMQ management UI are vulnerable to XSS attacks.
nvd
CVE-2016-0546P4HIGHCVSS 7.2v8.02016-01-21
CVE-2016-0546 [HIGH] CVE-2016-0546: Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and Mari Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Client. NOTE: the previous information is from the January 2016 CPU. Oracle has not commen
nvd
CVE-2022-44729P4HIGHCVSS 7.1v10.02023-08-22
CVE-2022-44729 [HIGH] CWE-918 CVE-2022-44729: Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics B Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16. On version 1.16, a malicious SVG could trigger loading external resources by default, causing resource consumption or in some cases even information disclosure. Users are recommended to upgrade t
nvd
CVE-2015-1273P4MEDIUMCVSS 6.8v8.02015-07-23
CVE-2015-1273 [MEDIUM] CWE-119 CVE-2015-1273: Heap-based buffer overflow in j2k.c in OpenJPEG before r3002, as used in PDFium in Google Chrome bef Heap-based buffer overflow in j2k.c in OpenJPEG before r3002, as used in PDFium in Google Chrome before 44.0.2403.89, allows remote attackers to cause a denial of service or possibly have unspecified other impact via invalid JPEG2000 data in a PDF document.
nvd
CVE-2012-3515P4HIGHCVSS 7.2v6.0v7.02012-11-23
CVE-2012-3515 [HIGH] CWE-20 CVE-2012-3515: Qemu, as used in Xen 4.0, 4.1 and possibly other products, when emulating certain devices with a vir Qemu, as used in Xen 4.0, 4.1 and possibly other products, when emulating certain devices with a virtual console backend, allows local OS guest users to gain privileges via a crafted escape VT100 sequence that triggers the overwrite of a "device model's address space."
nvd
CVE-2017-13064P4MEDIUMCVSS 6.5v8.0v9.02017-08-22
CVE-2017-13064 [MEDIUM] CWE-119 CVE-2017-13064: GraphicsMagick 1.3.26 has a heap-based buffer overflow vulnerability in the function GetStyleTokens GraphicsMagick 1.3.26 has a heap-based buffer overflow vulnerability in the function GetStyleTokens in coders/svg.c:311:12.
nvd
CVE-2024-36916P4HIGHCVSS 7.1v10.02024-05-30
CVE-2024-36916 [HIGH] CWE-125 CVE-2024-36916: In the Linux kernel, the following vulnerability has been resolved: blk-iocost: avoid out of bounds In the Linux kernel, the following vulnerability has been resolved: blk-iocost: avoid out of bounds shift UBSAN catches undefined behavior in blk-iocost, where sometimes iocg->delay is shifted right by a number that is too large, resulting in undefined behavior on some architectures. [ 186.556576] ------------[ cut here ]------------ UBSAN: shift-ou
nvd
Debian Linux vulnerabilities | cvebase