cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 325 of 498
CVE-2002-2443P4MEDIUMCVSS 5.0v6.0v7.0+1 more2013-05-29
CVE-2002-2443 [MEDIUM] CVE-2002-2443: schpw.c in the kpasswd service in kadmind in MIT Kerberos 5 (aka krb5) before 1.11.3 does not proper schpw.c in the kpasswd service in kadmind in MIT Kerberos 5 (aka krb5) before 1.11.3 does not properly validate UDP packets before sending responses, which allows remote attackers to cause a denial of service (CPU and bandwidth consumption) via a forged packet that triggers a communication loop, as demonstrated by krb_pingpong.nasl, a related issue to CVE-199
nvd
CVE-2017-13737P4MEDIUMCVSS 6.5v8.0v9.02017-08-29
CVE-2017-13737 [MEDIUM] CWE-416 CVE-2017-13737: There is an invalid free in the MagickFree function in magick/memory.c in GraphicsMagick 1.3.26 that There is an invalid free in the MagickFree function in magick/memory.c in GraphicsMagick 1.3.26 that will lead to a remote denial of service attack.
nvd
CVE-2021-3561P4HIGHCVSS 7.1v9.02021-05-26
CVE-2021-3561 [HIGH] CWE-119 CVE-2021-3561: An Out of Bounds flaw was found fig2dev version 3.2.8a. A flawed bounds check in read_objects() coul An Out of Bounds flaw was found fig2dev version 3.2.8a. A flawed bounds check in read_objects() could allow an attacker to provide a crafted malicious input causing the application to either crash or in some cases cause memory corruption. The highest threat from this vulnerability is to integrity as well as system availability.
nvd
CVE-2020-16135P4MEDIUMCVSS 5.9v9.02020-07-29
CVE-2020-16135 [MEDIUM] CWE-476 CVE-2020-16135: libssh 0.9.4 has a NULL pointer dereference in tftpserver.c if ssh_buffer_new returns NULL. libssh 0.9.4 has a NULL pointer dereference in tftpserver.c if ssh_buffer_new returns NULL.
nvd
CVE-2007-2444P4HIGHCVSS 7.2v4.0v5.02007-05-14
CVE-2007-2444 [HIGH] CWE-269 CVE-2007-2444: Logic error in the SID/Name translation functionality in smbd in Samba 3.0.23d through 3.0.25pre2 al Logic error in the SID/Name translation functionality in smbd in Samba 3.0.23d through 3.0.25pre2 allows local users to gain temporary privileges and execute SMB/CIFS protocol operations via unspecified vectors that cause the daemon to transition to the root user.
nvd
CVE-2015-2695P4MEDIUMCVSS 5.0v7.0v8.0+1 more2015-11-09
CVE-2015-2695 [MEDIUM] CWE-763 CVE-2015-2695: lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, which allows remote attackers to cause a denial of service (incorrect pointer read and process crash) via a crafted SPNEGO packet that is mishandled during a gss_inquire_context call.
nvd
CVE-2018-10914P4MEDIUMCVSS 6.5v8.0v9.02018-09-04
CVE-2018-10914 [MEDIUM] CWE-476 CVE-2018-10914: It was found that an attacker could issue a xattr request via glusterfs FUSE to cause gluster brick It was found that an attacker could issue a xattr request via glusterfs FUSE to cause gluster brick process to crash which will result in a remote denial of service. If gluster multiplexing is enabled this will result in a crash of multiple bricks and gluster volumes.
nvd
CVE-2013-7020P4MEDIUMCVSS 6.8v6.02013-12-09
CVE-2013-7020 [MEDIUM] CWE-119 CVE-2013-7020: The read_header function in libavcodec/ffv1dec.c in FFmpeg before 2.1 does not properly enforce cert The read_header function in libavcodec/ffv1dec.c in FFmpeg before 2.1 does not properly enforce certain bit-count and colorspace constraints, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted FFV1 data.
nvd
CVE-2017-18273P4MEDIUMCVSS 6.5v7.02018-05-18
CVE-2017-18273 [MEDIUM] CWE-835 CVE-2017-18273: In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-22, an infinite loop vulnerability was found in the funct In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-22, an infinite loop vulnerability was found in the function ReadTXTImage in coders/txt.c, which allows attackers to cause a denial of service (CPU exhaustion) via a crafted image file that is mishandled in a GetImageIndexInList call.
nvd
CVE-2018-17581P4MEDIUMCVSS 6.5v8.0v10.02018-09-28
CVE-2018-17581 [MEDIUM] CWE-400 CVE-2018-17581: CiffDirectory::readDirectory() at crwimage_int.cpp in Exiv2 0.26 has excessive stack consumption due CiffDirectory::readDirectory() at crwimage_int.cpp in Exiv2 0.26 has excessive stack consumption due to a recursive function, leading to Denial of service.
nvd
CVE-2022-22818P4MEDIUMCVSS 6.1v11.02022-02-03
CVE-2022-22818 [MEDIUM] CWE-79 CVE-2022-22818: The template tag in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2 do The {% debug %} template tag in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2 does not properly encode the current context. This may lead to XSS.
nvd
CVE-2023-0412P4HIGHCVSS 7.1v10.02023-01-26
CVE-2023-0412 [HIGH] CWE-404 CVE-2023-0412: TIPC dissector crash in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service vi TIPC dissector crash in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture file
nvd
CVE-2018-20189P4MEDIUMCVSS 6.5v8.02018-12-17
CVE-2018-20189 [MEDIUM] CWE-20 CVE-2018-20189: In GraphicsMagick 1.3.31, the ReadDIBImage function of coders/dib.c has a vulnerability allowing a c In GraphicsMagick 1.3.31, the ReadDIBImage function of coders/dib.c has a vulnerability allowing a crash and denial of service via a dib file that is crafted to appear with direct pixel values and also colormapping (which is not available beyond 8-bits/sample), and therefore lacks indexes initialization.
nvd
CVE-2018-10877P4MEDIUMCVSS 6.5v8.02018-07-18
CVE-2018-10877 [MEDIUM] CWE-125 CVE-2018-10877: Linux kernel ext4 filesystem is vulnerable to an out-of-bound access in the ext4_ext_drop_refs() fun Linux kernel ext4 filesystem is vulnerable to an out-of-bound access in the ext4_ext_drop_refs() function when operating on a crafted ext4 filesystem image.
nvd
CVE-2007-1320P4HIGHCVSS 7.2v3.1v4.02007-05-02
CVE-2007-1320 [HIGH] CWE-787 CVE-2007-1320: Multiple heap-based buffer overflows in the cirrus_invalidate_region function in the Cirrus VGA exte Multiple heap-based buffer overflows in the cirrus_invalidate_region function in the Cirrus VGA extension in QEMU 0.8.2, as used in Xen and possibly other products, might allow local users to execute arbitrary code via unspecified vectors related to "attempting to mark non-existent regions as dirty," aka the "bitblt" heap overflow.
nvd
CVE-2017-17760P4MEDIUMCVSS 6.5v7.0v8.0+1 more2017-12-29
CVE-2017-17760 [MEDIUM] CWE-119 CVE-2017-17760: OpenCV 3.3.1 has a Buffer Overflow in the cv::PxMDecoder::readData function in grfmt_pxm.cpp, becaus OpenCV 3.3.1 has a Buffer Overflow in the cv::PxMDecoder::readData function in grfmt_pxm.cpp, because an incorrect size value is used.
nvd
CVE-2018-18073P4MEDIUMCVSS 6.3v8.0v9.02018-10-15
CVE-2018-18073 [MEDIUM] CWE-200 CVE-2018-18073: Artifex Ghostscript allows attackers to bypass a sandbox protection mechanism by leveraging exposure Artifex Ghostscript allows attackers to bypass a sandbox protection mechanism by leveraging exposure of system operators in the saved execution stack in an error object.
nvd
CVE-2019-12213P4MEDIUMCVSS 6.5v8.0v9.0+1 more2019-05-20
CVE-2019-12213 [MEDIUM] CWE-674 CVE-2019-12213: When FreeImage 3.18.0 reads a special TIFF file, the TIFFReadDirectory function in PluginTIFF.cpp al When FreeImage 3.18.0 reads a special TIFF file, the TIFFReadDirectory function in PluginTIFF.cpp always returns 1, leading to stack exhaustion.
nvd
CVE-2013-6461P4MEDIUMCVSS 6.5v8.0v9.0+1 more2019-11-05
CVE-2013-6461 [MEDIUM] CWE-776 CVE-2013-6461: Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits
nvd
CVE-2016-9572P4MEDIUMCVSS 6.5v8.02018-08-01
CVE-2016-9572 [MEDIUM] CWE-476 CVE-2016-9572: A NULL pointer dereference flaw was found in the way openjpeg 2.1.2 decoded certain input images. Du A NULL pointer dereference flaw was found in the way openjpeg 2.1.2 decoded certain input images. Due to a logic error in the code responsible for decoding the input image, an application using openjpeg to process image data could crash when processing a crafted image.
nvd
Debian Linux vulnerabilities | cvebase