Debian Linux vulnerabilities
9,954 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358
Vulnerabilities
Page 337 of 498
CVE-2017-14223P4MEDIUMCVSS 6.5v8.0v9.02017-09-09
CVE-2017-14223 [MEDIUM] CWE-400 CVE-2017-14223: In libavformat/asfdec_f.c in FFmpeg 3.3.3, a DoS in asf_build_simple_index() due to lack of an EOF (
In libavformat/asfdec_f.c in FFmpeg 3.3.3, a DoS in asf_build_simple_index() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted ASF file, which claims a large "ict" field in the header but does not contain sufficient backing data, is provided, the for loop would consume huge CPU and memory resources, since the
nvd
CVE-2014-9655P4MEDIUMCVSS 6.5v7.0v8.02016-04-13
CVE-2014-9655 [MEDIUM] CWE-119 CVE-2014-9655: The (1) putcontig8bitYCbCr21tile function in tif_getimage.c or (2) NeXTDecode function in tif_next.c
The (1) putcontig8bitYCbCr21tile function in tif_getimage.c or (2) NeXTDecode function in tif_next.c in LibTIFF allows remote attackers to cause a denial of service (uninitialized memory access) via a crafted TIFF image, as demonstrated by libtiff-cvs-1.tif and libtiff-cvs-2.tif.
nvd
CVE-2016-0775P4MEDIUMCVSS 6.5v7.0v8.02016-04-13
CVE-2016-0775 [MEDIUM] CWE-119 CVE-2016-0775: Buffer overflow in the ImagingFliDecode function in libImaging/FliDecode.c in Pillow before 3.1.1 al
Buffer overflow in the ImagingFliDecode function in libImaging/FliDecode.c in Pillow before 3.1.1 allows remote attackers to cause a denial of service (crash) via a crafted FLI file.
nvd
CVE-2016-6316P4MEDIUMCVSS 6.1v8.02016-09-07
CVE-2016-6316 [MEDIUM] CWE-79 CVE-2016-6316: Cross-site scripting (XSS) vulnerability in Action View in Ruby on Rails 3.x before 3.2.22.3, 4.x be
Cross-site scripting (XSS) vulnerability in Action View in Ruby on Rails 3.x before 3.2.22.3, 4.x before 4.2.7.1, and 5.x before 5.0.0.1 might allow remote attackers to inject arbitrary web script or HTML via text declared as "HTML safe" and used as attribute values in tag handlers.
nvd
CVE-2010-0298P4MEDIUMCVSS 6.5v5.02010-02-12
CVE-2010-0298 [MEDIUM] CWE-264 CVE-2010-0298: The x86 emulator in KVM 83 does not use the Current Privilege Level (CPL) and I/O Privilege Level (I
The x86 emulator in KVM 83 does not use the Current Privilege Level (CPL) and I/O Privilege Level (IOPL) in determining the memory access available to CPL3 code, which allows guest OS users to cause a denial of service (guest OS crash) or gain privileges on the guest OS by leveraging access to a (1) IO port or (2) MMIO region, a related issue to CVE-2
nvd
CVE-2019-9903P4MEDIUMCVSS 6.5v10.02019-03-21
CVE-2019-9903 [MEDIUM] CWE-787 CVE-2019-9903: PDFDoc::markObject in PDFDoc.cc in Poppler 0.74.0 mishandles dict marking, leading to stack consumpt
PDFDoc::markObject in PDFDoc.cc in Poppler 0.74.0 mishandles dict marking, leading to stack consumption in the function Dict::find() located at Dict.cc, which can (for example) be triggered by passing a crafted pdf file to the pdfunite binary.
nvd
CVE-2013-2927P4MEDIUMCVSS 6.8v7.0v8.02013-10-16
CVE-2013-2927 [MEDIUM] CWE-399 CVE-2013-2927: Use-after-free vulnerability in the HTMLFormElement::prepareForSubmission function in core/html/HTML
Use-after-free vulnerability in the HTMLFormElement::prepareForSubmission function in core/html/HTMLFormElement.cpp in Blink, as used in Google Chrome before 30.0.1599.101, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to submission for FORM elements.
nvd
CVE-2018-12373P4MEDIUMCVSS 6.5v8.0v9.02018-10-18
CVE-2018-12373 [MEDIUM] CWE-200 CVE-2018-12373: dDecrypted S/MIME parts hidden with CSS or the plaintext HTML tag can leak plaintext when included i
dDecrypted S/MIME parts hidden with CSS or the plaintext HTML tag can leak plaintext when included in a HTML reply/forward. This vulnerability affects Thunderbird < 52.9.
nvd
CVE-2017-13776P4MEDIUMCVSS 6.5v8.0v9.02017-08-30
CVE-2017-13776 [MEDIUM] CWE-834 CVE-2017-13776: GraphicsMagick 1.3.26 has a denial of service issue in ReadXBMImage() in a coders/xbm.c "Read hex im
GraphicsMagick 1.3.26 has a denial of service issue in ReadXBMImage() in a coders/xbm.c "Read hex image data" version!=10 case that results in the reader not returning; it would cause large amounts of CPU and memory consumption although the crafted file itself does not request it.
nvd
CVE-2017-18229P4MEDIUMCVSS 6.5v7.0v8.0+1 more2018-03-14
CVE-2017-18229 [MEDIUM] CWE-770 CVE-2017-18229: An issue was discovered in GraphicsMagick 1.3.26. An allocation failure vulnerability was found in t
An issue was discovered in GraphicsMagick 1.3.26. An allocation failure vulnerability was found in the function ReadTIFFImage in coders/tiff.c, which allows attackers to cause a denial of service via a crafted file, because file size is not properly used to restrict scanline, strip, and tile allocations.
nvd
CVE-2020-1983P4MEDIUMCVSS 6.5v8.0v9.02020-04-22
CVE-2020-1983 [MEDIUM] CWE-416 CVE-2020-1983: A use after free vulnerability in ip_reass() in ip_input.c of libslirp 4.2.0 and prior releases allo
A use after free vulnerability in ip_reass() in ip_input.c of libslirp 4.2.0 and prior releases allows crafted packets to cause a denial of service.
nvd
CVE-2018-20097P4MEDIUMCVSS 6.5v8.0v10.02018-12-12
CVE-2018-20097 [MEDIUM] CWE-119 CVE-2018-20097: There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv
There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack.
nvd
CVE-2015-9383P4MEDIUMCVSS 6.5v8.02019-09-03
CVE-2015-9383 [MEDIUM] CWE-125 CVE-2015-9383: FreeType before 2.6.2 has a heap-based buffer over-read in tt_cmap14_validate in sfnt/ttcmap.c.
FreeType before 2.6.2 has a heap-based buffer over-read in tt_cmap14_validate in sfnt/ttcmap.c.
nvd
CVE-2017-14174P4MEDIUMCVSS 6.5v9.0v10.02017-09-07
CVE-2017-14174 [MEDIUM] CWE-834 CVE-2017-14174: In coders/psd.c in ImageMagick 7.0.7-0 Q16, a DoS in ReadPSDLayersInternal() due to lack of an EOF (
In coders/psd.c in ImageMagick 7.0.7-0 Q16, a DoS in ReadPSDLayersInternal() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted PSD file, which claims a large "length" field in the header but does not contain sufficient backing data, is provided, the loop over "length" would consume huge CPU resources, since t
nvd
CVE-2017-18271P4MEDIUMCVSS 6.5v7.02018-05-18
CVE-2017-18271 [MEDIUM] CWE-835 CVE-2017-18271: In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-22, an infinite loop vulnerability was found in the funct
In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-22, an infinite loop vulnerability was found in the function ReadMIFFImage in coders/miff.c, which allows attackers to cause a denial of service (CPU exhaustion) via a crafted MIFF image file.
nvd
CVE-2018-20570P4MEDIUMCVSS 6.5v8.02018-12-28
CVE-2018-20570 [MEDIUM] CWE-125 CVE-2018-20570: jp2_encode in jp2/jp2_enc.c in JasPer 2.0.14 has a heap-based buffer over-read.
jp2_encode in jp2/jp2_enc.c in JasPer 2.0.14 has a heap-based buffer over-read.
nvd
CVE-2018-20430P4MEDIUMCVSS 6.5v8.0v9.02018-12-24
CVE-2018-20430 [MEDIUM] CWE-125 CVE-2018-20430: GNU Libextractor through 1.8 has an out-of-bounds read vulnerability in the function history_extract
GNU Libextractor through 1.8 has an out-of-bounds read vulnerability in the function history_extract() in plugins/ole2_extractor.c, related to EXTRACTOR_common_convert_to_utf8 in common/convert.c.
nvd
CVE-2019-7149P4MEDIUMCVSS 6.5v8.02019-01-29
CVE-2019-7149 [MEDIUM] CWE-125 CVE-2019-7149: A heap-based buffer over-read was discovered in the function read_srclines in dwarf_getsrclines.c in
A heap-based buffer over-read was discovered in the function read_srclines in dwarf_getsrclines.c in libdw in elfutils 0.175. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by eu-nm.
nvd
CVE-2017-14172P4MEDIUMCVSS 6.5v8.0v9.02017-09-07
CVE-2017-14172 [MEDIUM] CWE-834 CVE-2017-14172: In coders/ps.c in ImageMagick 7.0.7-0 Q16, a DoS in ReadPSImage() due to lack of an EOF (End of File
In coders/ps.c in ImageMagick 7.0.7-0 Q16, a DoS in ReadPSImage() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted PSD file, which claims a large "extent" field in the header but does not contain sufficient backing data, is provided, the loop over "length" would consume huge CPU resources, since there is no
nvd
CVE-2023-20569P4MEDIUMCVSS 4.7v10.0v11.0+1 more2023-08-08
CVE-2023-20569 [MEDIUM] CWE-203 CVE-2023-20569: A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the retur
A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction. This may result in speculative execution at an attacker-controlled address, potentially leading to information disclosure.
nvd