cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 300 of 498
CVE-2019-12216P4MEDIUMCVSS 6.5v8.02019-05-20
CVE-2019-12216 [MEDIUM] CWE-787 CVE-2019-12216: An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunctio An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image.a in SDL2_image 2.0.4. There is a heap-based buffer overflow in the SDL2_image function IMG_LoadPCX_RW at IMG_pcx.c.
nvd
CVE-2017-15396P4MEDIUMCVSS 6.5v8.0v9.0+1 more2018-08-28
CVE-2017-15396 [MEDIUM] CWE-119 CVE-2017-15396: A stack buffer overflow in NumberingSystem in International Components for Unicode (ICU) for C/C++ b A stack buffer overflow in NumberingSystem in International Components for Unicode (ICU) for C/C++ before 60.2, as used in V8 in Google Chrome prior to 62.0.3202.75 and other products, allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2025-37879P4HIGHCVSS 7.1v11.02025-05-09
CVE-2025-37879 [HIGH] CWE-125 CVE-2025-37879: In the Linux kernel, the following vulnerability has been resolved: 9p/net: fix improper handling o In the Linux kernel, the following vulnerability has been resolved: 9p/net: fix improper handling of bogus negative read/write replies In p9_client_write() and p9_client_read_once(), if the server incorrectly replies with success but a negative write/read count then we would consider written (negative) 3)
nvd
CVE-2020-14393P4HIGHCVSS 7.1v9.02020-09-16
CVE-2020-14393 [HIGH] CWE-121 CVE-2020-14393: A buffer overflow was found in perl-DBI < 1.643 in DBI.xs. A local attacker who is able to supply a A buffer overflow was found in perl-DBI < 1.643 in DBI.xs. A local attacker who is able to supply a string longer than 300 characters could cause an out-of-bounds write, affecting the availability of the service or integrity of data.
nvd
CVE-2021-21375P4MEDIUMCVSS 6.5v9.02021-03-10
CVE-2021-21375 [MEDIUM] CWE-400 CVE-2021-21375: PJSIP is a free and open source multimedia communication library written in C language implementing PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In PJSIP version 2.10 and earlier, after an initial INVITE has been sent, when two 183 responses are received, with the first one causing negotiation failure, a crash will occur. This
nvd
CVE-2014-3538P4MEDIUMCVSS 5.0v7.0v8.02014-07-03
CVE-2014-3538 [MEDIUM] CVE-2014-3538: file before 5.19 does not properly restrict the amount of data read during a regex search, which all file before 5.19 does not properly restrict the amount of data read during a regex search, which allows remote attackers to cause a denial of service (CPU consumption) via a crafted file that triggers backtracking during processing of an awk rule. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7345.
nvd
CVE-2019-13751P4MEDIUMCVSS 6.5v9.0v10.02019-12-10
CVE-2019-13751 [MEDIUM] CWE-908 CVE-2019-13751: Uninitialized data in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obt Uninitialized data in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2021-3537P4MEDIUMCVSS 5.9v9.02021-05-14
CVE-2021-3537 [MEDIUM] CWE-476 CVE-2021-3537: A vulnerability found in libxml2 in versions before 2.9.11 shows that it did not propagate errors wh A vulnerability found in libxml2 in versions before 2.9.11 shows that it did not propagate errors while parsing XML mixed content, causing a NULL dereference. If an untrusted XML document was parsed in recovery mode and post-validated, the flaw could be used to crash the application. The highest threat from this vulnerability is to system availability
nvd
CVE-2015-8743P4HIGHCVSS 7.1v7.0v8.02016-12-29
CVE-2015-8743 [HIGH] CWE-125 CVE-2015-8743: QEMU (aka Quick Emulator) built with the NE2000 device emulation support is vulnerable to an OOB r/w QEMU (aka Quick Emulator) built with the NE2000 device emulation support is vulnerable to an OOB r/w access issue. It could occur while performing 'ioport' r/w operations. A privileged (CAP_SYS_RAWIO) user/process could use this flaw to leak or corrupt QEMU memory bytes.
nvd
CVE-2020-6397P4MEDIUMCVSS 6.5v9.0v10.02020-02-11
CVE-2020-6397 [MEDIUM] CVE-2020-6397: Inappropriate implementation in sharing in Google Chrome prior to 80.0.3987.87 allowed a remote atta Inappropriate implementation in sharing in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof security UI via a crafted HTML page.
nvd
CVE-2023-4504P4HIGHCVSS 7.0v10.02023-09-21
CVE-2023-4504 [HIGH] CWE-122 CVE-2023-4504: Due to failure in validating the length provided by an attacker-crafted PPD PostScript document, CUP Due to failure in validating the length provided by an attacker-crafted PPD PostScript document, CUPS and libppd are susceptible to a heap-based buffer overflow and possibly code execution. This issue has been fixed in CUPS version 2.4.7, released in September of 2023.
nvd
CVE-2019-9959P4MEDIUMCVSS 6.5v8.0v9.0+1 more2019-07-22
CVE-2019-9959 [MEDIUM] CWE-190 CVE-2019-9959: The JPXStream::init function in Poppler 0.78.0 and earlier doesn't check for negative values of stre The JPXStream::init function in Poppler 0.78.0 and earlier doesn't check for negative values of stream length, leading to an Integer Overflow, thereby making it possible to allocate a large memory chunk on the heap, with a size controlled by an attacker, as demonstrated by pdftocairo.
nvd
CVE-2020-19189P4MEDIUMCVSS 6.5v10.02023-08-22
CVE-2020-19189 [MEDIUM] CWE-787 CVE-2020-19189: Buffer Overflow vulnerability in postprocess_terminfo function in tinfo/parse_entry.c:997 in ncurses Buffer Overflow vulnerability in postprocess_terminfo function in tinfo/parse_entry.c:997 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.
nvd
CVE-2021-3596P4MEDIUMCVSS 6.5v9.02022-02-24
CVE-2021-3596 [MEDIUM] CWE-476 CVE-2021-3596: A NULL pointer dereference flaw was found in ImageMagick in versions prior to 7.0.10-31 in ReadSVGIm A NULL pointer dereference flaw was found in ImageMagick in versions prior to 7.0.10-31 in ReadSVGImage() in coders/svg.c. This issue is due to not checking the return value from libxml2's xmlCreatePushParserCtxt() and uses the value directly, which leads to a crash and segmentation fault.
nvd
CVE-2018-6123P4MEDIUMCVSS 6.5v9.02019-01-09
CVE-2018-6123 [MEDIUM] CWE-416 CVE-2018-6123: A use after free in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potent A use after free in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2018-12397P4HIGHCVSS 7.1v8.0v9.02019-02-28
CVE-2018-12397 [HIGH] CWE-200 CVE-2018-12397: A WebExtension can request access to local files without the warning prompt stating that the extensi A WebExtension can request access to local files without the warning prompt stating that the extension will "Access your data for all websites" being displayed to the user. This allows extensions to run content scripts in local pages without permission warnings when a local file is opened. This vulnerability affects Firefox ESR < 60.3 and Firefox < 63
nvd
CVE-2016-5172P4MEDIUMCVSS 6.5v8.0v9.02016-09-25
CVE-2016-5172 [MEDIUM] CWE-200 CVE-2016-5172: The parser in Google V8, as used in Google Chrome before 53.0.2785.113, mishandles scopes, which all The parser in Google V8, as used in Google Chrome before 53.0.2785.113, mishandles scopes, which allows remote attackers to obtain sensitive information from arbitrary memory locations via crafted JavaScript code.
nvd
CVE-2020-11096P4MEDIUMCVSS 6.5v10.02020-06-22
CVE-2020-11096 [MEDIUM] CWE-125 CVE-2020-11096: In FreeRDP before version 2.1.2, there is a global OOB read in update_read_cache_bitmap_v3_order. As In FreeRDP before version 2.1.2, there is a global OOB read in update_read_cache_bitmap_v3_order. As a workaround, one can disable bitmap cache with -bitmap-cache (default). This is fixed in version 2.1.2.
nvd
CVE-2019-3460P4MEDIUMCVSS 6.5v8.02019-04-11
CVE-2019-3460 [MEDIUM] CWE-20 CVE-2019-3460: A heap data infoleak in multiple locations including L2CAP_PARSE_CONF_RSP was found in the Linux ker A heap data infoleak in multiple locations including L2CAP_PARSE_CONF_RSP was found in the Linux kernel before 5.1-rc1.
nvd
CVE-2018-2815P4MEDIUMCVSS 5.3v8.0v9.02018-04-19
CVE-2018-2815 [MEDIUM] CVE-2018-2815: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: S Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affected are Java SE: 6u181, 7u171, 8u162 and 10; Java SE Embedded: 8u161; JRockit: R28.3.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Ja
nvd
Debian Linux vulnerabilities | cvebase