cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 313 of 498
CVE-2022-0585P4MEDIUMCVSS 6.5v9.02022-02-18
CVE-2022-0585 [MEDIUM] CWE-834 CVE-2022-0585: Large loops in multiple protocol dissectors in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allow de Large loops in multiple protocol dissectors in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allow denial of service via packet injection or crafted capture file
nvd
CVE-2015-2151P4HIGHCVSS 7.2v7.02015-03-12
CVE-2015-2151 [HIGH] CWE-264 CVE-2015-2151: The x86 emulator in Xen 3.2.x through 4.5.x does not properly ignore segment overrides for instructi The x86 emulator in Xen 3.2.x through 4.5.x does not properly ignore segment overrides for instructions with register operands, which allows local guest users to obtain sensitive information, cause a denial of service (memory corruption), or possibly execute arbitrary code via unspecified vectors.
nvd
CVE-2009-1270P4HIGHCVSS 7.8v4.0v5.02009-04-08
CVE-2009-1270 [HIGH] CWE-835 CVE-2009-1270: libclamav/untar.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (infini libclamav/untar.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (infinite loop) via a crafted TAR file that causes (1) clamd and (2) clamscan to hang.
nvd
CVE-2018-20184P4MEDIUMCVSS 6.5v8.02018-12-17
CVE-2018-20184 [MEDIUM] CWE-787 CVE-2018-20184: In GraphicsMagick 1.4 snapshot-20181209 Q8, there is a heap-based buffer overflow in the WriteTGAIma In GraphicsMagick 1.4 snapshot-20181209 Q8, there is a heap-based buffer overflow in the WriteTGAImage function of tga.c, which allows attackers to cause a denial of service via a crafted image file, because the number of rows or columns can exceed the pixel-dimension restrictions of the TGA specification.
nvd
CVE-2008-4539P4HIGHCVSS 7.2v4.0v5.02008-12-29
CVE-2008-4539 [HIGH] CVE-2008-4539: Heap-based buffer overflow in the Cirrus VGA implementation in (1) KVM before kvm-82 and (2) QEMU on Heap-based buffer overflow in the Cirrus VGA implementation in (1) KVM before kvm-82 and (2) QEMU on Debian GNU/Linux and Ubuntu might allow local users to gain privileges by using the VNC console for a connection, aka the LGD-54XX "bitblt" heap overflow. NOTE: this issue exists because of an incorrect fix for CVE-2007-1320.
nvd
CVE-2020-13630P4HIGHCVSS 7.0v9.02020-05-27
CVE-2020-13630 [HIGH] CWE-416 CVE-2020-13630: ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snip ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snippet feature.
nvd
CVE-2010-2520P4MEDIUMCVSS 5.1v5.02010-08-19
CVE-2010-2520 [MEDIUM] CWE-787 CVE-2010-2520: Heap-based buffer overflow in the Ins_IUP function in truetype/ttinterp.c in FreeType before 2.4.0, Heap-based buffer overflow in the Ins_IUP function in truetype/ttinterp.c in FreeType before 2.4.0, when TrueType bytecode support is enabled, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.
nvd
CVE-2014-4667P4MEDIUMCVSS 5.0v7.02014-07-03
CVE-2014-4667 [MEDIUM] CVE-2014-4667: The sctp_association_free function in net/sctp/associola.c in the Linux kernel before 3.15.2 does no The sctp_association_free function in net/sctp/associola.c in the Linux kernel before 3.15.2 does not properly manage a certain backlog value, which allows remote attackers to cause a denial of service (socket outage) via a crafted SCTP packet.
nvd
CVE-2017-9141P4MEDIUMCVSS 6.5v8.0v9.02017-05-22
CVE-2017-9141 [MEDIUM] CWE-20 CVE-2017-9141: In ImageMagick 7.0.5-7 Q16, a crafted file could trigger an assertion failure in the ResetImageProfi In ImageMagick 7.0.5-7 Q16, a crafted file could trigger an assertion failure in the ResetImageProfileIterator function in MagickCore/profile.c because of missing checks in the ReadDDSImage function in coders/dds.c.
nvd
CVE-2017-9142P4MEDIUMCVSS 6.5v8.0v9.02017-05-22
CVE-2017-9142 [MEDIUM] CWE-20 CVE-2017-9142: In ImageMagick 7.0.5-7 Q16, a crafted file could trigger an assertion failure in the WriteBlob funct In ImageMagick 7.0.5-7 Q16, a crafted file could trigger an assertion failure in the WriteBlob function in MagickCore/blob.c because of missing checks in the ReadOneJNGImage function in coders/png.c.
nvd
CVE-2014-8561P4MEDIUMCVSS 6.5v8.0v9.0+1 more2019-12-15
CVE-2014-8561 [MEDIUM] CWE-835 CVE-2014-8561: imagemagick 6.8.9.6 has remote DOS via infinite loop imagemagick 6.8.9.6 has remote DOS via infinite loop
nvd
CVE-2023-1161P4HIGHCVSS 7.1v10.0v12.02023-03-06
CVE-2023-1161 [HIGH] CWE-120 CVE-2023-1161: ISO 15765 and ISO 10681 dissector crash in Wireshark 4.0.0 to 4.0.3 and 3.6.0 to 3.6.11 allows denia ISO 15765 and ISO 10681 dissector crash in Wireshark 4.0.0 to 4.0.3 and 3.6.0 to 3.6.11 allows denial of service via packet injection or crafted capture file
nvd
CVE-2018-16846P4MEDIUMCVSS 6.5v8.0v9.02019-01-15
CVE-2018-16846 [MEDIUM] CWE-770 CVE-2018-16846: It was found in Ceph versions before 13.2.4 that authenticated ceph RGW users can cause a denial of It was found in Ceph versions before 13.2.4 that authenticated ceph RGW users can cause a denial of service against OMAPs holding bucket indices.
nvd
CVE-2014-3694P4MEDIUMCVSS 6.4v7.02014-10-29
CVE-2014-3694 [MEDIUM] CWE-310 CVE-2014-3694: The (1) bundled GnuTLS SSL/TLS plugin and the (2) bundled OpenSSL SSL/TLS plugin in libpurple in Pid The (1) bundled GnuTLS SSL/TLS plugin and the (2) bundled OpenSSL SSL/TLS plugin in libpurple in Pidgin before 2.10.10 do not properly consider the Basic Constraints extension during verification of X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
nvd
CVE-2014-3160P4MEDIUMCVSS 6.8v7.0v8.02014-07-20
CVE-2014-3160 [MEDIUM] CWE-264 CVE-2014-3160: The ResourceFetcher::canRequest function in core/fetch/ResourceFetcher.cpp in Blink, as used in Goog The ResourceFetcher::canRequest function in core/fetch/ResourceFetcher.cpp in Blink, as used in Google Chrome before 36.0.1985.125, does not properly restrict subresource requests associated with SVG files, which allows remote attackers to bypass the Same Origin Policy via a crafted file.
nvd
CVE-2018-18021P4HIGHCVSS 7.1v9.02018-10-07
CVE-2018-18021 [HIGH] CWE-20 CVE-2018-18021: arch/arm64/kvm/guest.c in KVM in the Linux kernel before 4.18.12 on the arm64 platform mishandles th arch/arm64/kvm/guest.c in KVM in the Linux kernel before 4.18.12 on the arm64 platform mishandles the KVM_SET_ON_REG ioctl. This is exploitable by attackers who can create virtual machines. An attacker can arbitrarily redirect the hypervisor flow of control (with full register control). An attacker can also cause a denial of service (hypervisor panic)
nvd
CVE-2014-9636P4MEDIUMCVSS 5.0v7.02015-02-06
CVE-2014-9636 [MEDIUM] CWE-119 CVE-2014-9636: unzip 6.0 allows remote attackers to cause a denial of service (out-of-bounds read or write and cras unzip 6.0 allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) via an extra field with an uncompressed size smaller than the compressed field size in a zip archive that advertises STORED method compression.
nvd
CVE-2019-25013P4MEDIUMCVSS 5.9v10.02021-01-04
CVE-2019-25013 [MEDIUM] CWE-125 CVE-2019-25013: The iconv feature in the GNU C Library (aka glibc or libc6) through 2.32, when processing invalid mu The iconv feature in the GNU C Library (aka glibc or libc6) through 2.32, when processing invalid multi-byte input sequences in the EUC-KR encoding, may have a buffer over-read.
nvd
CVE-2002-0401P4HIGHCVSS 7.5v2.22002-06-18
CVE-2002-0401 [HIGH] CWE-476 CVE-2002-0401: SMB dissector in Ethereal 0.9.3 and earlier allows remote attackers to cause a denial of service (cr SMB dissector in Ethereal 0.9.3 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via malformed packets that cause Ethereal to dereference a NULL pointer.
nvd
CVE-2018-6117P4MEDIUMCVSS 6.5v9.02019-01-09
CVE-2018-6117 [MEDIUM] CWE-200 CVE-2018-6117: Confusing settings in Autofill in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to Confusing settings in Autofill in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
Debian Linux vulnerabilities | cvebase