cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 336 of 498
CVE-2013-2862P4HIGHCVSS 7.5v7.02013-06-05
CVE-2013-2862 [HIGH] CWE-119 CVE-2013-2862: Skia, as used in Google Chrome before 27.0.1453.110, does not properly handle GPU acceleration, whic Skia, as used in Google Chrome before 27.0.1453.110, does not properly handle GPU acceleration, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2016-9559P4MEDIUMCVSS 6.5v8.02017-03-01
CVE-2016-9559 [MEDIUM] CWE-476 CVE-2016-9559: coders/tiff.c in ImageMagick before 7.0.3.7 allows remote attackers to cause a denial of service (NU coders/tiff.c in ImageMagick before 7.0.3.7 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted image.
nvd
CVE-2016-7799P4MEDIUMCVSS 6.5v8.02017-01-18
CVE-2016-7799 [MEDIUM] CWE-125 CVE-2016-7799: MagickCore/profile.c in ImageMagick before 7.0.3-2 allows remote attackers to cause a denial of serv MagickCore/profile.c in ImageMagick before 7.0.3-2 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file.
nvd
CVE-2005-4178P4MEDIUMCVSS 6.5v3.0v3.12005-12-12
CVE-2005-4178 [MEDIUM] CVE-2005-4178: Buffer overflow in Dropbear server before 0.47 allows authenticated users to execute arbitrary code Buffer overflow in Dropbear server before 0.47 allows authenticated users to execute arbitrary code via unspecified inputs that cause insufficient memory to be allocated due to an incorrect expression that does not enforce the proper order of operations.
nvd
CVE-2018-10102P4MEDIUMCVSS 6.1v8.0v9.02018-04-16
CVE-2018-10102 [MEDIUM] CWE-79 CVE-2018-10102: Before WordPress 4.9.5, the version string was not escaped in the get_the_generator function, and co Before WordPress 4.9.5, the version string was not escaped in the get_the_generator function, and could lead to XSS in a generator tag.
nvd
CVE-2016-6132P4MEDIUMCVSS 6.5v8.02016-08-12
CVE-2016-6132 [MEDIUM] CWE-125 CVE-2016-6132: The gdImageCreateFromTgaCtx function in the GD Graphics Library (aka libgd) before 2.2.3 allows remo The gdImageCreateFromTgaCtx function in the GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TGA file.
nvd
CVE-2017-14166P4MEDIUMCVSS 6.5v8.0v9.02017-09-06
CVE-2017-14166 [MEDIUM] CWE-125 CVE-2017-14166: libarchive 3.3.2 allows remote attackers to cause a denial of service (xml_data heap-based buffer ov libarchive 3.3.2 allows remote attackers to cause a denial of service (xml_data heap-based buffer over-read and application crash) via a crafted xar archive, related to the mishandling of empty strings in the atol8 function in archive_read_support_format_xar.c.
nvd
CVE-2018-16645P4MEDIUMCVSS 6.5v8.0v9.02018-09-06
CVE-2018-16645 [MEDIUM] CWE-770 CVE-2018-16645: There is an excessive memory allocation issue in the functions ReadBMPImage of coders/bmp.c and Read There is an excessive memory allocation issue in the functions ReadBMPImage of coders/bmp.c and ReadDIBImage of coders/dib.c in ImageMagick 7.0.8-11, which allows remote attackers to cause a denial of service via a crafted image file.
nvd
CVE-2016-6214P4MEDIUMCVSS 6.5v8.02016-08-12
CVE-2016-6214 [MEDIUM] CWE-125 CVE-2016-6214: gd_tga.c in the GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a deni gd_tga.c in the GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TGA file.
nvd
CVE-2017-14107P4MEDIUMCVSS 6.5v9.02017-09-01
CVE-2017-14107 [MEDIUM] CWE-770 CVE-2017-14107: The _zip_read_eocd64 function in zip_open.c in libzip before 1.3.0 mishandles EOCD records, which al The _zip_read_eocd64 function in zip_open.c in libzip before 1.3.0 mishandles EOCD records, which allows remote attackers to cause a denial of service (memory allocation failure in _zip_cdir_grow in zip_dirent.c) via a crafted ZIP archive.
nvd
CVE-2015-8504P4MEDIUMCVSS 6.5v7.0v8.02017-04-11
CVE-2015-8504 [MEDIUM] CWE-369 CVE-2015-8504: Qemu, when built with VNC display driver support, allows remote attackers to cause a denial of servi Qemu, when built with VNC display driver support, allows remote attackers to cause a denial of service (arithmetic exception and application crash) via crafted SetPixelFormat messages from a client.
nvd
CVE-2018-20467P4MEDIUMCVSS 6.5v9.02018-12-26
CVE-2018-20467 [MEDIUM] CWE-835 CVE-2018-20467: In coders/bmp.c in ImageMagick before 7.0.8-16, an input file can result in an infinite loop and han In coders/bmp.c in ImageMagick before 7.0.8-16, an input file can result in an infinite loop and hang, with high CPU and memory consumption. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file.
nvd
CVE-2018-14498P4MEDIUMCVSS 6.5v8.02019-03-07
CVE-2018-14498 [MEDIUM] CWE-125 CVE-2018-14498: get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers t get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted 8-bit BMP in which one or more of the color indices is out of range for the number of palette entries.
nvd
CVE-2018-16643P4MEDIUMCVSS 6.5v8.02018-09-06
CVE-2018-16643 [MEDIUM] CWE-252 CVE-2018-16643: The functions ReadDCMImage in coders/dcm.c, ReadPWPImage in coders/pwp.c, ReadCALSImage in coders/ca The functions ReadDCMImage in coders/dcm.c, ReadPWPImage in coders/pwp.c, ReadCALSImage in coders/cals.c, and ReadPICTImage in coders/pict.c in ImageMagick 7.0.8-4 do not check the return value of the fputc function, which allows remote attackers to cause a denial of service via a crafted image file.
nvd
CVE-2014-3467P4MEDIUMCVSS 5.0v7.02014-06-05
CVE-2014-3467 [MEDIUM] CVE-2014-3467: Multiple unspecified vulnerabilities in the DER decoder in GNU Libtasn1 before 3.6, as used in GnuTL Multiple unspecified vulnerabilities in the DER decoder in GNU Libtasn1 before 3.6, as used in GnuTLS, allow remote attackers to cause a denial of service (out-of-bounds read) via crafted ASN.1 data.
nvd
CVE-2022-21127P4MEDIUMCVSS 5.5v10.0v11.02022-06-15
CVE-2022-21127 [MEDIUM] CWE-459 CVE-2022-21127: Incomplete cleanup in specific special register read operations for some Intel(R) Processors may all Incomplete cleanup in specific special register read operations for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
nvd
CVE-2005-2088P4MEDIUMCVSS 4.3v3.0v3.12005-07-05
CVE-2005-2088 [MEDIUM] CWE-444 CVE-2005-2088: The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an HTTP proxy, allows The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an HTTP proxy, allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes Apache to incorrectly handle and f
nvd
CVE-2017-14994P4MEDIUMCVSS 6.5v8.0v9.02017-10-04
CVE-2017-14994 [MEDIUM] CWE-476 CVE-2017-14994: ReadDCMImage in coders/dcm.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of s ReadDCMImage in coders/dcm.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted DICOM image, related to the ability of DCM_ReadNonNativeImages to yield an image list with zero frames.
nvd
CVE-2017-11683P4MEDIUMCVSS 6.5v10.02017-07-27
CVE-2017-11683 [MEDIUM] CWE-617 CVE-2017-11683: There is a reachable assertion in the Internal::TiffReader::visitDirectory function in tiffvisitor.c There is a reachable assertion in the Internal::TiffReader::visitDirectory function in tiffvisitor.cpp of Exiv2 0.26 that will lead to a remote denial of service attack via crafted input.
nvd
CVE-2023-35936P4MEDIUMCVSS 5.0v10.02023-07-05
CVE-2023-35936 [MEDIUM] CWE-20 CVE-2023-35936: Pandoc is a Haskell library for converting from one markup format to another, and a command-line too Pandoc is a Haskell library for converting from one markup format to another, and a command-line tool that uses this library. Starting in version 1.13 and prior to version 3.1.4, Pandoc is susceptible to an arbitrary file write vulnerability, which can be triggered by providing a specially crafted image element in the input when generating files usin
nvd
Debian Linux vulnerabilities | cvebase