cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 324 of 498
CVE-2006-6501P4MEDIUMCVSS 6.8v3.1v4.02006-12-20
CVE-2006-6501 [MEDIUM] CWE-264 CVE-2006-6501: Unspecified vulnerability in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird b Unspecified vulnerability in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to gain privileges and install malicious code via the watch Javascript function.
nvd
CVE-2025-48432P4MEDIUMCVSS 5.3v11.02025-06-05
CVE-2025-48432 [MEDIUM] CWE-117 CVE-2025-48432: An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Intern An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead to log injection or forgery when logs are viewed in terminals or processed by external systems.
nvd
CVE-2018-19210P4MEDIUMCVSS 6.5v8.02018-11-12
CVE-2018-19210 [MEDIUM] CWE-476 CVE-2018-19210: In LibTIFF 4.0.9, there is a NULL pointer dereference in the TIFFWriteDirectorySec function in tif_d In LibTIFF 4.0.9, there is a NULL pointer dereference in the TIFFWriteDirectorySec function in tif_dirwrite.c that will lead to a denial of service attack, as demonstrated by tiffset.
nvd
CVE-2013-2856P4HIGHCVSS 7.5v7.0v8.02013-06-05
CVE-2013-2856 [HIGH] CWE-416 CVE-2013-2856: Use-after-free vulnerability in Google Chrome before 27.0.1453.110 allows remote attackers to cause Use-after-free vulnerability in Google Chrome before 27.0.1453.110 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of input.
nvd
CVE-2015-3153P4MEDIUMCVSS 5.0v8.02015-05-01
CVE-2015-3153 [MEDIUM] CWE-200 CVE-2015-3153: The default configuration for cURL and libcurl before 7.42.1 sends custom HTTP headers to both the p The default configuration for cURL and libcurl before 7.42.1 sends custom HTTP headers to both the proxy and destination server, which might allow remote proxy servers to obtain sensitive information by reading the header contents.
nvd
CVE-2017-9216P4MEDIUMCVSS 6.5v9.02017-05-24
CVE-2017-9216 [MEDIUM] CWE-476 CVE-2017-9216: libjbig2dec.a in Artifex jbig2dec 0.13, as used in MuPDF and Ghostscript, has a NULL pointer derefer libjbig2dec.a in Artifex jbig2dec 0.13, as used in MuPDF and Ghostscript, has a NULL pointer dereference in the jbig2_huffman_get function in jbig2_huffman.c. For example, the jbig2dec utility will crash (segmentation fault) when parsing an invalid file.
nvd
CVE-2017-18219P4MEDIUMCVSS 6.5v7.0v8.0+1 more2018-03-05
CVE-2017-18219 [MEDIUM] CWE-770 CVE-2017-18219: An issue was discovered in GraphicsMagick 1.3.26. An allocation failure vulnerability was found in t An issue was discovered in GraphicsMagick 1.3.26. An allocation failure vulnerability was found in the function ReadOnePNGImage in coders/png.c, which allows attackers to cause a denial of service via a crafted file that triggers an attempt at a large png_pixels array allocation.
nvd
CVE-2017-14997P4MEDIUMCVSS 6.5v8.0v9.02017-10-04
CVE-2017-14997 [MEDIUM] CWE-191 CVE-2017-14997: GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (excessive memory allocat GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (excessive memory allocation) because of an integer underflow in ReadPICTImage in coders/pict.c.
nvd
CVE-2012-3527P4MEDIUMCVSS 4.6v6.0v7.02012-09-05
CVE-2012-3527 [MEDIUM] CWE-502 CVE-2012-3527: view_help.php in the backend help system in TYPO3 4.5.x before 4.5.19, 4.6.x before 4.6.12 and 4.7.x view_help.php in the backend help system in TYPO3 4.5.x before 4.5.19, 4.6.x before 4.6.12 and 4.7.x before 4.7.4 allows remote authenticated backend users to unserialize arbitrary objects and possibly execute arbitrary PHP code via an unspecified parameter, related to a "missing signature (HMAC)."
nvd
CVE-2013-2867P4HIGHCVSS 7.5v7.02013-07-10
CVE-2013-2867 [HIGH] CVE-2013-2867: Google Chrome before 28.0.1500.71 does not properly prevent pop-under windows, which allows remote a Google Chrome before 28.0.1500.71 does not properly prevent pop-under windows, which allows remote attackers to have an unspecified impact via a crafted web site.
nvd
CVE-2015-1547P4MEDIUMCVSS 6.5v7.0v8.02016-04-13
CVE-2015-1547 [MEDIUM] CWE-119 CVE-2015-1547: The NeXTDecode function in tif_next.c in LibTIFF allows remote attackers to cause a denial of servic The NeXTDecode function in tif_next.c in LibTIFF allows remote attackers to cause a denial of service (uninitialized memory access) via a crafted TIFF image, as demonstrated by libtiff5.tif.
nvd
CVE-2015-3417P4MEDIUMCVSS 6.8v8.02015-04-24
CVE-2015-3417 [MEDIUM] CVE-2015-3417: Use-after-free vulnerability in the ff_h264_free_tables function in libavcodec/h264.c in FFmpeg befo Use-after-free vulnerability in the ff_h264_free_tables function in libavcodec/h264.c in FFmpeg before 2.3.6 allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted H.264 data in an MP4 file, as demonstrated by an HTML VIDEO element that references H.264 data.
nvd
CVE-2018-17000P4MEDIUMCVSS 6.5v8.02018-09-13
CVE-2018-17000 [MEDIUM] CWE-476 CVE-2018-17000: A NULL pointer dereference in the function _TIFFmemcmp at tif_unix.c (called from TIFFWriteDirectory A NULL pointer dereference in the function _TIFFmemcmp at tif_unix.c (called from TIFFWriteDirectoryTagTransferfunction) in LibTIFF 4.0.9 allows an attacker to cause a denial-of-service through a crafted tiff file. This vulnerability can be triggered by the executable tiffcp.
nvd
CVE-2011-1176P4MEDIUMCVSS 4.3v5.0v6.0+1 more2011-03-29
CVE-2011-1176 [MEDIUM] CVE-2011-1176: The configuration merger in itk.c in the Steinar H. Gunderson mpm-itk Multi-Processing Module 2.2.11 The configuration merger in itk.c in the Steinar H. Gunderson mpm-itk Multi-Processing Module 2.2.11-01 and 2.2.11-02 for the Apache HTTP Server does not properly handle certain configuration sections that specify NiceValue but not AssignUserID, which might allow remote attackers to gain privileges by leveraging the root uid and root gid of an mpm-itk process
nvd
CVE-2018-14040P4MEDIUMCVSS 6.1v8.02018-07-13
CVE-2018-14040 [MEDIUM] CWE-79 CVE-2018-14040: In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute. In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute.
nvd
CVE-2019-11135P4MEDIUMCVSS 6.5v8.0v9.0+1 more2019-11-14
CVE-2019-11135 [MEDIUM] CWE-385 CVE-2019-11135: TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authentic TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access.
nvd
CVE-2018-5784P4MEDIUMCVSS 6.5v7.0v8.0+1 more2018-01-19
CVE-2018-5784 [MEDIUM] CWE-400 CVE-2018-5784: In LibTIFF 4.0.9, there is an uncontrolled resource consumption in the TIFFSetDirectory function of In LibTIFF 4.0.9, there is an uncontrolled resource consumption in the TIFFSetDirectory function of tif_dir.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted tif file. This occurs because the declared number of directory entries is not validated against the actual number of directory entries.
nvd
CVE-2018-16646P4MEDIUMCVSS 6.5v8.02018-09-06
CVE-2018-16646 [MEDIUM] CWE-835 CVE-2018-16646: In Poppler 0.68.0, the Parser::getObj() function in Parser.cc may cause infinite recursion via a cra In Poppler 0.68.0, the Parser::getObj() function in Parser.cc may cause infinite recursion via a crafted file. A remote attacker can leverage this for a DoS attack.
nvd
CVE-2019-10131P4HIGHCVSS 7.1v9.02019-04-30
CVE-2019-10131 [HIGH] CWE-193 CVE-2019-10131: An off-by-one read vulnerability was discovered in ImageMagick before version 7.0.7-28 in the format An off-by-one read vulnerability was discovered in ImageMagick before version 7.0.7-28 in the formatIPTCfromBuffer function in coders/meta.c. A local attacker may use this flaw to read beyond the end of the buffer or to crash the program.
nvd
CVE-2018-16336P4MEDIUMCVSS 6.5v8.02018-09-02
CVE-2018-16336 [MEDIUM] CVE-2018-16336: Exiv2::Internal::PngChunk::parseTXTChunk in Exiv2 v0.26 allows remote attackers to cause a denial of Exiv2::Internal::PngChunk::parseTXTChunk in Exiv2 v0.26 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted image file, a different vulnerability than CVE-2018-10999.
nvd
Debian Linux vulnerabilities | cvebase