cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 326 of 498
CVE-2020-28241P4MEDIUMCVSS 6.5v9.02020-11-06
CVE-2020-28241 [MEDIUM] CWE-125 CVE-2020-28241: libmaxminddb before 1.4.3 has a heap-based buffer over-read in dump_entry_data_list in maxminddb.c. libmaxminddb before 1.4.3 has a heap-based buffer over-read in dump_entry_data_list in maxminddb.c.
nvd
CVE-2019-20446P4MEDIUMCVSS 6.5v9.02020-02-02
CVE-2019-20446 [MEDIUM] CWE-400 CVE-2019-20446: In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial o In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processing. The attacker constructs pattern elements so that the number of final rendered objects grows exponentially.
nvd
CVE-2017-13768P4MEDIUMCVSS 6.5v8.0v9.02017-08-30
CVE-2017-13768 [MEDIUM] CWE-476 CVE-2017-13768: Null Pointer Dereference in the IdentifyImage function in MagickCore/identify.c in ImageMagick throu Null Pointer Dereference in the IdentifyImage function in MagickCore/identify.c in ImageMagick through 7.0.6-10 allows an attacker to perform denial of service by sending a crafted image file.
nvd
CVE-2017-14341P4MEDIUMCVSS 6.5v8.0v9.02017-09-12
CVE-2017-14341 [MEDIUM] CWE-400 CVE-2017-14341: ImageMagick 7.0.6-6 has a large loop vulnerability in ReadWPGImage in coders/wpg.c, causing CPU exha ImageMagick 7.0.6-6 has a large loop vulnerability in ReadWPGImage in coders/wpg.c, causing CPU exhaustion via a crafted wpg image file.
nvd
CVE-2011-3632P4HIGHCVSS 7.1v8.0v9.0+1 more2019-11-26
CVE-2011-3632 [HIGH] CWE-59 CVE-2011-3632: Hardlink before 0.1.2 operates on full file system objects path names which can allow a local attack Hardlink before 0.1.2 operates on full file system objects path names which can allow a local attacker to use this flaw to conduct symlink attacks.
nvd
CVE-2019-12221P4MEDIUMCVSS 6.5v8.02019-05-20
CVE-2019-12221 [MEDIUM] CWE-787 CVE-2019-12221: An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunctio An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image.a in SDL2_image 2.0.4. There is a SEGV in the SDL function SDL_free_REAL at stdlib/SDL_malloc.c.
nvd
CVE-2017-14173P4MEDIUMCVSS 6.5v8.0v9.02017-09-07
CVE-2017-14173 [MEDIUM] CWE-190 CVE-2017-14173: In the function ReadTXTImage() in coders/txt.c in ImageMagick 7.0.6-10, an integer overflow might oc In the function ReadTXTImage() in coders/txt.c in ImageMagick 7.0.6-10, an integer overflow might occur for the addition operation "GetQuantumRange(depth)+1" when "depth" is large, producing a smaller value than expected. As a result, an infinite loop would occur for a crafted TXT file that claims a very large "max_value" value.
nvd
CVE-2017-14633P4MEDIUMCVSS 6.5v7.0v8.0+1 more2017-09-21
CVE-2017-14633 [MEDIUM] CWE-125 CVE-2017-14633: In Xiph.Org libvorbis 1.3.5, an out-of-bounds array read vulnerability exists in the function mappin In Xiph.Org libvorbis 1.3.5, an out-of-bounds array read vulnerability exists in the function mapping0_forward() in mapping0.c, which may lead to DoS when operating on a crafted audio file with vorbis_analysis().
nvd
CVE-2017-2624P4HIGHCVSS 7.0v7.02018-07-27
CVE-2017-2624 [HIGH] CWE-385 CVE-2017-2624: It was found that xorg-x11-server before 1.19.0 including uses memcmp() to check the received MIT co It was found that xorg-x11-server before 1.19.0 including uses memcmp() to check the received MIT cookie against a series of valid cookies. If the cookie is correct, it is allowed to attach to the Xorg session. Since most memcmp() implementations return after an invalid byte is seen, this causes a time difference between a valid and invalid byte, which
nvd
CVE-2018-10195P4HIGHCVSS 7.1v9.02021-06-02
CVE-2018-10195 [HIGH] CWE-190 CVE-2018-10195: lrzsz before version 0.12.21~rc can leak information to the receiving side due to an incorrect lengt lrzsz before version 0.12.21~rc can leak information to the receiving side due to an incorrect length check in the function zsdata that causes a size_t to wrap around.
nvd
CVE-2019-3459P4MEDIUMCVSS 6.5v8.02019-04-11
CVE-2019-3459 [MEDIUM] CWE-125 CVE-2019-3459: A heap address information leak while using L2CAP_GET_CONF_OPT was discovered in the Linux kernel be A heap address information leak while using L2CAP_GET_CONF_OPT was discovered in the Linux kernel before 5.1-rc1.
nvd
CVE-2010-4653P4MEDIUMCVSS 6.5v8.0v9.0+1 more2019-11-13
CVE-2010-4653 [MEDIUM] CWE-190 CVE-2010-4653: An integer overflow condition in poppler before 0.16.3 can occur when parsing CharCodes for fonts. An integer overflow condition in poppler before 0.16.3 can occur when parsing CharCodes for fonts.
nvd
CVE-2014-5461P4MEDIUMCVSS 5.0v7.02014-09-04
CVE-2014-5461 [MEDIUM] CWE-119 CVE-2014-5461: Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows contex Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attackers to cause a denial of service (crash) via a small number of arguments to a function with a large number of fixed arguments.
nvd
CVE-2018-1000078P4MEDIUMCVSS 6.1v7.02018-03-13
CVE-2018-1000078 [MEDIUM] CWE-79 CVE-2018-1000078: RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 se RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Cross Site Scripting (XSS) vulnerability in gem server display of homepage attribute that can result in XSS. This attack appear to be exploitable
nvd
CVE-2023-2856P4MEDIUMCVSS 6.5v10.0v12.02023-05-26
CVE-2023-2856 [MEDIUM] CWE-787 CVE-2023-2856: VMS TCPIPtrace file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of se VMS TCPIPtrace file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file
nvd
CVE-2023-2858P4MEDIUMCVSS 6.5v10.0v12.02023-05-26
CVE-2023-2858 [MEDIUM] CWE-787 CVE-2023-2858: NetScaler file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service NetScaler file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file
nvd
CVE-2018-10101P4MEDIUMCVSS 6.1v8.0v9.02018-04-16
CVE-2018-10101 [MEDIUM] CWE-601 CVE-2018-10101: Before WordPress 4.9.5, the URL validator assumed URLs with the hostname localhost were on the same Before WordPress 4.9.5, the URL validator assumed URLs with the hostname localhost were on the same host as the WordPress server.
nvd
CVE-2024-26665P4HIGHCVSS 7.1v10.02024-04-02
CVE-2024-26665 [HIGH] CWE-125 CVE-2024-26665: In the Linux kernel, the following vulnerability has been resolved: tunnels: fix out of bounds acce In the Linux kernel, the following vulnerability has been resolved: tunnels: fix out of bounds access when building IPv6 PMTU error If the ICMPv6 error is built from a non-linear skb we get the following splat, BUG: KASAN: slab-out-of-bounds in do_csum+0x220/0x240 Read of size 4 at addr ffff88811d402c80 by task netperf/820 CPU: 0 PID: 820 Comm: netp
nvd
CVE-2025-21950P4HIGHCVSS 7.1v11.02025-04-01
CVE-2025-21950 [HIGH] CVE-2025-21950: In the Linux kernel, the following vulnerability has been resolved: drivers: virt: acrn: hsm: Use k In the Linux kernel, the following vulnerability has been resolved: drivers: virt: acrn: hsm: Use kzalloc to avoid info leak in pmcmd_ioctl In the "pmcmd_ioctl" function, three memory objects allocated by kmalloc are initialized by "hcall_get_cpu_state", which are then copied to user space. The initializer is indeed implemented in "acrn_hypercall2" (arch/x86
nvd
CVE-2025-38530P4HIGHCVSS 7.1v11.02025-08-16
CVE-2025-38530 [HIGH] CWE-125 CVE-2025-38530: In the Linux kernel, the following vulnerability has been resolved: comedi: pcl812: Fix bit shift o In the Linux kernel, the following vulnerability has been resolved: comedi: pcl812: Fix bit shift out of bounds When checking for a supported IRQ number, the following test is used: if ((1 options[1]) & board->irq_bits) { However, `it->options[i]` is an unchecked `int` value from userspace, so the shift amount could be negative or out of bounds. Fi
nvd
Debian Linux vulnerabilities | cvebase