cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 312 of 498
CVE-2018-5380P4MEDIUMCVSS 4.3v7.0v8.0+1 more2018-02-19
CVE-2018-5380 [MEDIUM] CWE-125 CVE-2018-5380: The Quagga BGP daemon (bgpd) prior to version 1.2.3 can overrun internal BGP code-to-string conversi The Quagga BGP daemon (bgpd) prior to version 1.2.3 can overrun internal BGP code-to-string conversion tables used for debug by 1 pointer value, based on input.
nvd
CVE-2013-2072P4HIGHCVSS 7.4v7.02013-08-28
CVE-2013-2072 [HIGH] CWE-119 CVE-2013-2072: Buffer overflow in the Python bindings for the xc_vcpu_setaffinity call in Xen 4.0.x, 4.1.x, and 4.2 Buffer overflow in the Python bindings for the xc_vcpu_setaffinity call in Xen 4.0.x, 4.1.x, and 4.2.x allows local administrators with permissions to configure VCPU affinity to cause a denial of service (memory corruption and xend toolstack crash) and possibly gain privileges via a crafted cpumap.
nvd
CVE-2026-14355P4MEDIUMCVSS 5.3v12.02026-07-03
CVE-2026-14355 [MEDIUM] CWE-122 CVE-2026-14355: In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, t In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause
nvd
CVE-2022-21166P4MEDIUMCVSS 5.5v9.0v10.0+1 more2022-06-15
CVE-2022-21166 [MEDIUM] CWE-459 CVE-2022-21166: Incomplete cleanup in specific special register write operations for some Intel(R) Processors may al Incomplete cleanup in specific special register write operations for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
nvd
CVE-2018-20150P4MEDIUMCVSS 6.1v8.0v9.02018-12-14
CVE-2018-20150 [MEDIUM] CWE-79 CVE-2018-20150: In WordPress before 4.9.9 and 5.x before 5.0.1, crafted URLs could trigger XSS for certain use cases In WordPress before 4.9.9 and 5.x before 5.0.1, crafted URLs could trigger XSS for certain use cases involving plugins.
nvd
CVE-2018-7443P4MEDIUMCVSS 6.5v7.02018-02-23
CVE-2018-7443 [MEDIUM] CWE-770 CVE-2018-7443: The ReadTIFFImage function in coders/tiff.c in ImageMagick 7.0.7-23 Q16 does not properly validate t The ReadTIFFImage function in coders/tiff.c in ImageMagick 7.0.7-23 Q16 does not properly validate the amount of image data in a file, which allows remote attackers to cause a denial of service (memory allocation failure in the AcquireMagickMemory function in MagickCore/memory.c).
nvd
CVE-2018-12366P4MEDIUMCVSS 6.5v8.0v9.02018-10-18
CVE-2018-12366 [MEDIUM] CWE-125 CVE-2018-12366: An invalid grid size during QCMS (color profile) transformations can result in the out-of-bounds rea An invalid grid size during QCMS (color profile) transformations can result in the out-of-bounds read interpreted as a float value. This could leak private data into the output. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.
nvd
CVE-2021-3181P4MEDIUMCVSS 6.5v9.0v10.02021-01-19
CVE-2021-3181 [MEDIUM] CWE-401 CVE-2021-3181: rfc822.c in Mutt through 2.0.4 allows remote attackers to cause a denial of service (mailbox unavail rfc822.c in Mutt through 2.0.4 allows remote attackers to cause a denial of service (mailbox unavailability) by sending email messages with sequences of semicolon characters in RFC822 address fields (aka terminators of empty groups). A small email message from the attacker can cause large memory consumption, and the victim may then be unable to see em
nvd
CVE-2017-7943P4MEDIUMCVSS 6.5v8.0v9.02017-04-18
CVE-2017-7943 [MEDIUM] CWE-772 CVE-2017-7943: The ReadSVGImage function in svg.c in ImageMagick 7.0.5-4 allows remote attackers to consume an amou The ReadSVGImage function in svg.c in ImageMagick 7.0.5-4 allows remote attackers to consume an amount of available memory via a crafted file.
nvd
CVE-2015-7499P4MEDIUMCVSS 5.0v7.0v8.02015-12-15
CVE-2015-7499 [MEDIUM] CWE-119 CVE-2015-7499: Heap-based buffer overflow in the xmlGROW function in parser.c in libxml2 before 2.9.3 allows contex Heap-based buffer overflow in the xmlGROW function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive process memory information via unspecified vectors.
nvd
CVE-2019-14981P4MEDIUMCVSS 6.5v8.0v9.0+1 more2019-08-12
CVE-2019-14981 [MEDIUM] CWE-369 CVE-2019-14981: In ImageMagick 7.x before 7.0.8-41 and 6.x before 6.9.10-41, there is a divide-by-zero vulnerability In ImageMagick 7.x before 7.0.8-41 and 6.x before 6.9.10-41, there is a divide-by-zero vulnerability in the MeanShiftImage function. It allows an attacker to cause a denial of service by sending a crafted file.
nvd
CVE-2018-10547P4MEDIUMCVSS 6.1v7.0v8.0+1 more2018-04-29
CVE-2018-10547 [MEDIUM] CWE-79 CVE-2018-10547: An issue was discovered in ext/phar/phar_object.c in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x b An issue was discovered in ext/phar/phar_object.c in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. There is Reflected XSS on the PHAR 403 and 404 error pages via request data of a request for a .phar file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2018-5712.
nvd
CVE-2015-7981P4MEDIUMCVSS 5.0v7.0v8.02015-11-24
CVE-2015-7981 [MEDIUM] CWE-200 CVE-2015-7981: The png_convert_to_rfc1123 function in png.c in libpng 1.0.x before 1.0.64, 1.2.x before 1.2.54, and The png_convert_to_rfc1123 function in png.c in libpng 1.0.x before 1.0.64, 1.2.x before 1.2.54, and 1.4.x before 1.4.17 allows remote attackers to obtain sensitive process memory information via crafted tIME chunk data in an image file, which triggers an out-of-bounds read.
nvd
CVE-2014-5204P4MEDIUMCVSS 6.8v7.02014-08-18
CVE-2014-5204 [MEDIUM] CWE-352 CVE-2014-5204: wp-includes/pluggable.php in WordPress before 3.9.2 rejects invalid CSRF nonces with a different tim wp-includes/pluggable.php in WordPress before 3.9.2 rejects invalid CSRF nonces with a different timing depending on which characters in the nonce are incorrect, which makes it easier for remote attackers to bypass a CSRF protection mechanism via a brute-force attack.
nvd
CVE-2015-1819P4MEDIUMCVSS 5.0v7.0v8.02015-08-14
CVE-2015-1819 [MEDIUM] CWE-399 CVE-2015-1819: The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) vi The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expansion (XEE) attack.
nvd
CVE-2020-11019P4MEDIUMCVSS 6.5v10.02020-05-29
CVE-2020-11019 [MEDIUM] CWE-125 CVE-2020-11019: In FreeRDP less than or equal to 2.0.0, when running with logger set to "WLOG_TRACE", a possible cra In FreeRDP less than or equal to 2.0.0, when running with logger set to "WLOG_TRACE", a possible crash of application could occur due to a read of an invalid array index. Data could be printed as string to local terminal. This has been fixed in 2.1.0.
nvd
CVE-2017-7941P4MEDIUMCVSS 6.5v8.0v9.02017-04-18
CVE-2017-7941 [MEDIUM] CWE-772 CVE-2017-7941: The ReadSGIImage function in sgi.c in ImageMagick 7.0.5-4 allows remote attackers to consume an amou The ReadSGIImage function in sgi.c in ImageMagick 7.0.5-4 allows remote attackers to consume an amount of available memory via a crafted file.
nvd
CVE-2017-7830P4MEDIUMCVSS 6.5v7.0v8.0+1 more2018-06-11
CVE-2017-7830 [MEDIUM] CVE-2017-7830: The Resource Timing API incorrectly revealed navigations in cross-origin iframes. This is a same-ori The Resource Timing API incorrectly revealed navigations in cross-origin iframes. This is a same-origin policy violation and could allow for data theft of URLs loaded by users. This vulnerability affects Firefox < 57, Firefox ESR < 52.5, and Thunderbird < 52.5.
nvd
CVE-2017-15422P4MEDIUMCVSS 6.5v8.0v9.02018-08-28
CVE-2017-15422 [MEDIUM] CWE-190 CVE-2017-15422: Integer overflow in international date handling in International Components for Unicode (ICU) for C/ Integer overflow in international date handling in International Components for Unicode (ICU) for C/C++ before 60.1, as used in V8 in Google Chrome prior to 63.0.3239.84 and other products, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
nvd
CVE-2018-12372P4MEDIUMCVSS 6.5v8.0v9.02018-10-18
CVE-2018-12372 [MEDIUM] CWE-200 CVE-2018-12372: Decrypted S/MIME parts, when included in HTML crafted for an attack, can leak plaintext when include Decrypted S/MIME parts, when included in HTML crafted for an attack, can leak plaintext when included in a a HTML reply/forward. This vulnerability affects Thunderbird < 52.9.
nvd
Debian Linux vulnerabilities | cvebase