cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 338 of 498
CVE-2015-8317P4MEDIUMCVSS 5.0v7.0v8.02015-12-15
CVE-2015-8317 [MEDIUM] CWE-119 CVE-2015-8317: The xmlParseXMLDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers The xmlParseXMLDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive information via an (1) unterminated encoding value or (2) incomplete XML declaration in XML data, which triggers an out-of-bounds heap read.
nvd
CVE-2014-3689P4HIGHCVSS 7.2v7.02014-11-14
CVE-2014-3689 [HIGH] CWE-269 CVE-2014-3689: The vmware-vga driver (hw/display/vmware_vga.c) in QEMU allows local guest users to write to qemu me The vmware-vga driver (hw/display/vmware_vga.c) in QEMU allows local guest users to write to qemu memory locations and gain privileges via unspecified parameters related to rectangle handling.
nvd
CVE-2017-13777P4MEDIUMCVSS 6.5v8.0v9.02017-08-30
CVE-2017-13777 [MEDIUM] CWE-834 CVE-2017-13777: GraphicsMagick 1.3.26 has a denial of service issue in ReadXBMImage() in a coders/xbm.c "Read hex im GraphicsMagick 1.3.26 has a denial of service issue in ReadXBMImage() in a coders/xbm.c "Read hex image data" version==10 case that results in the reader not returning; it would cause large amounts of CPU and memory consumption although the crafted file itself does not request it.
nvd
CVE-2017-14175P4MEDIUMCVSS 6.5v8.0v9.02017-09-07
CVE-2017-14175 [MEDIUM] CWE-834 CVE-2017-14175: In coders/xbm.c in ImageMagick 7.0.6-1 Q16, a DoS in ReadXBMImage() due to lack of an EOF (End of Fi In coders/xbm.c in ImageMagick 7.0.6-1 Q16, a DoS in ReadXBMImage() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted XBM file, which claims large rows and columns fields in the header but does not contain sufficient backing data, is provided, the loop over the rows would consume huge CPU resources, since the
nvd
CVE-2017-7700P4MEDIUMCVSS 6.5v8.02017-04-12
CVE-2017-7700 [MEDIUM] CWE-835 CVE-2017-7700: In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the NetScaler file parser could go into an infinite In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the NetScaler file parser could go into an infinite loop, triggered by a malformed capture file. This was addressed in wiretap/netscaler.c by ensuring a nonzero record size.
nvd
CVE-2013-6460P4MEDIUMCVSS 6.5v8.0v9.0+1 more2019-11-05
CVE-2013-6460 [MEDIUM] CWE-776 CVE-2013-6460: Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents
nvd
CVE-2017-13775P4MEDIUMCVSS 6.5v8.0v9.02017-08-30
CVE-2017-13775 [MEDIUM] CVE-2017-13775: GraphicsMagick 1.3.26 has a denial of service issue in ReadJNXImage() in coders/jnx.c whereby large GraphicsMagick 1.3.26 has a denial of service issue in ReadJNXImage() in coders/jnx.c whereby large amounts of CPU and memory resources may be consumed although the file itself does not support the requests.
nvd
CVE-2018-5801P4MEDIUMCVSS 6.5v8.02018-12-07
CVE-2018-5801 [MEDIUM] CWE-476 CVE-2018-5801: An error within the "LibRaw::unpack()" function (src/libraw_cxx.cpp) in LibRaw versions prior to 0.1 An error within the "LibRaw::unpack()" function (src/libraw_cxx.cpp) in LibRaw versions prior to 0.18.7 can be exploited to trigger a NULL pointer dereference.
nvd
CVE-2024-30205P4HIGHCVSS 7.1v10.02024-03-25
CVE-2024-30205 [HIGH] CWE-494 CVE-2024-30205: In Emacs before 29.3, Org mode considers contents of remote files to be trusted. This affects Org Mo In Emacs before 29.3, Org mode considers contents of remote files to be trusted. This affects Org Mode before 9.6.23.
nvd
CVE-2018-19539P4MEDIUMCVSS 6.5v8.02018-11-26
CVE-2018-19539 [MEDIUM] CWE-617 CVE-2018-19539: An issue was discovered in JasPer 2.0.14. There is an access violation in the function jas_image_rea An issue was discovered in JasPer 2.0.14. There is an access violation in the function jas_image_readcmpt in libjasper/base/jas_image.c, leading to a denial of service.
nvd
CVE-2020-27792P4HIGHCVSS 7.1v10.02022-08-19
CVE-2020-27792 [HIGH] CWE-119 CVE-2020-27792: A heap-based buffer overwrite vulnerability was found in GhostScript's lp8000_print_page() function A heap-based buffer overwrite vulnerability was found in GhostScript's lp8000_print_page() function in the gdevlp8k.c file. This flaw allows an attacker to trick a user into opening a crafted PDF file, triggering the heap buffer overflow that could lead to memory corruption or a denial of service.
nvd
CVE-2018-19108P4MEDIUMCVSS 6.5v8.0v10.02018-11-08
CVE-2018-19108 [MEDIUM] CWE-835 CVE-2018-19108: In Exiv2 0.26, Exiv2::PsdImage::readMetadata in psdimage.cpp in the PSD image reader may suffer from In Exiv2 0.26, Exiv2::PsdImage::readMetadata in psdimage.cpp in the PSD image reader may suffer from a denial of service (infinite loop) caused by an integer overflow via a crafted PSD image file.
nvd
CVE-2018-5335P4MEDIUMCVSS 6.5v7.0v8.0+1 more2018-01-11
CVE-2018-5335 [MEDIUM] CWE-119 CVE-2018-5335: In Wireshark 2.4.0 to 2.4.3 and 2.2.0 to 2.2.11, the WCP dissector could crash. This was addressed i In Wireshark 2.4.0 to 2.4.3 and 2.2.0 to 2.2.11, the WCP dissector could crash. This was addressed in epan/dissectors/packet-wcp.c by validating the available buffer length.
nvd
CVE-2019-17402P4MEDIUMCVSS 6.5v8.0v10.02019-10-09
CVE-2019-17402 [MEDIUM] CWE-120 CVE-2019-17402: Exiv2 0.27.2 allows attackers to trigger a crash in Exiv2::getULong in types.cpp when called from Ex Exiv2 0.27.2 allows attackers to trigger a crash in Exiv2::getULong in types.cpp when called from Exiv2::Internal::CiffDirectory::readDirectory in crwimage_int.cpp, because there is no validation of the relationship of the total size to the offset and size.
nvd
CVE-2019-18390P4HIGHCVSS 7.1v10.02019-12-23
CVE-2019-18390 [HIGH] CWE-125 CVE-2019-18390: An out-of-bounds read in the vrend_blit_need_swizzle function in vrend_renderer.c in virglrenderer t An out-of-bounds read in the vrend_blit_need_swizzle function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service via VIRGL_CCMD_BLIT commands.
nvd
CVE-2018-10888P4MEDIUMCVSS 6.5v8.0v9.02018-07-10
CVE-2018-10888 [MEDIUM] CWE-20 CVE-2018-10888: A flaw was found in libgit2 before version 0.27.3. A missing check in git_delta_apply function in de A flaw was found in libgit2 before version 0.27.3. A missing check in git_delta_apply function in delta.c file, may lead to an out-of-bound read while reading a binary delta file. An attacker may use this flaw to cause a Denial of Service.
nvd
CVE-2017-11352P4MEDIUMCVSS 6.5v8.02017-07-17
CVE-2017-11352 [MEDIUM] CVE-2017-11352: In ImageMagick before 7.0.5-10, a crafted RLE image can trigger a crash because of incorrect EOF han In ImageMagick before 7.0.5-10, a crafted RLE image can trigger a crash because of incorrect EOF handling in coders/rle.c. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-9144.
nvd
CVE-2016-9964P4MEDIUMCVSS 6.5v8.02016-12-16
CVE-2016-9964 [MEDIUM] CWE-93 CVE-2016-9964: redirect() in bottle.py in bottle 0.12.10 doesn't filter a "\r\n" sequence, which leads to a CRLF at redirect() in bottle.py in bottle 0.12.10 doesn't filter a "\r\n" sequence, which leads to a CRLF attack, as demonstrated by a redirect("233\r\nSet-Cookie: name=salt") call.
nvd
CVE-2024-26673P4HIGHCVSS 7.1v10.02024-04-02
CVE-2024-26673 [HIGH] CVE-2024-26673: In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_ct: sanitize lay In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_ct: sanitize layer 3 and 4 protocol number in custom expectations - Disallow families other than NFPROTO_{IPV4,IPV6,INET}. - Disallow layer 4 protocol with no ports, since destination port is a mandatory attribute for this object.
nvd
CVE-2022-34526P4MEDIUMCVSS 6.5v10.0v11.02022-07-29
CVE-2022-34526 [MEDIUM] CWE-787 CVE-2022-34526: A stack overflow was discovered in the _TIFFVGetField function of Tiffsplit v4.4.0. This vulnerabili A stack overflow was discovered in the _TIFFVGetField function of Tiffsplit v4.4.0. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted TIFF file parsed by the "tiffsplit" or "tiffcrop" utilities.
nvd
Debian Linux vulnerabilities | cvebase