Debian Linux vulnerabilities
9,954 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358
Vulnerabilities
Page 339 of 498
CVE-2015-5316P4MEDIUMCVSS 5.9v8.02018-02-21
CVE-2015-5316 [MEDIUM] CWE-476 CVE-2015-5316: The eap_pwd_perform_confirm_exchange function in eap_peer/eap_pwd.c in wpa_supplicant 2.x before 2.6
The eap_pwd_perform_confirm_exchange function in eap_peer/eap_pwd.c in wpa_supplicant 2.x before 2.6, when EAP-pwd is enabled in a network configuration profile, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an EAP-pwd Confirm message followed by the Identity exchange.
nvd
CVE-2020-22021P4MEDIUMCVSS 6.5v9.0v10.02021-05-26
CVE-2020-22021 [MEDIUM] CWE-120 CVE-2020-22021: Buffer Overflow vulnerability in FFmpeg 4.2 at filter_edges function in libavfilter/vf_yadif.c, whic
Buffer Overflow vulnerability in FFmpeg 4.2 at filter_edges function in libavfilter/vf_yadif.c, which could let a remote malicious user cause a Denial of Service.
nvd
CVE-2025-38204P4HIGHCVSS 7.1v11.02025-07-04
CVE-2025-38204 [HIGH] CWE-125 CVE-2025-38204: In the Linux kernel, the following vulnerability has been resolved: jfs: fix array-index-out-of-bou
In the Linux kernel, the following vulnerability has been resolved:
jfs: fix array-index-out-of-bounds read in add_missing_indices
stbl is s8 but it must contain offsets into slot which can go from 0 to
127.
Added a bound check for that error and return -EIO if the check fails.
Also make jfs_readdir return with error if add_missing_indices returns
w
nvd
CVE-2023-2855P4MEDIUMCVSS 6.5v12.02023-05-26
CVE-2023-2855 [MEDIUM] CWE-787 CVE-2023-2855: Candump log parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service vi
Candump log parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file
nvd
CVE-2017-17504P4MEDIUMCVSS 6.5v7.0v8.0+1 more2017-12-11
CVE-2017-17504 [MEDIUM] CWE-125 CVE-2017-17504: ImageMagick before 7.0.7-12 has a coders/png.c Magick_png_read_raw_profile heap-based buffer over-re
ImageMagick before 7.0.7-12 has a coders/png.c Magick_png_read_raw_profile heap-based buffer over-read via a crafted file, related to ReadOneMNGImage.
nvd
CVE-2021-43545P4MEDIUMCVSS 6.5v9.0v10.0+1 more2021-12-08
CVE-2021-43545 [MEDIUM] CWE-834 CVE-2021-43545: Using the Location API in a loop could have caused severe application hangs and crashes. This vulner
Using the Location API in a loop could have caused severe application hangs and crashes. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
nvd
CVE-2020-19144P4MEDIUMCVSS 6.5v9.02021-09-09
CVE-2020-19144 [MEDIUM] CWE-787 CVE-2020-19144: Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the 'in _TIFFme
Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the 'in _TIFFmemcpy' funtion in the component 'tif_unix.c'.
nvd
CVE-2017-13145P4MEDIUMCVSS 6.5v8.0v9.02017-08-23
CVE-2017-13145 [MEDIUM] CWE-20 CVE-2017-13145: In ImageMagick before 6.9.8-8 and 7.x before 7.0.5-9, the ReadJP2Image function in coders/jp2.c does
In ImageMagick before 6.9.8-8 and 7.x before 7.0.5-9, the ReadJP2Image function in coders/jp2.c does not properly validate the channel geometry, leading to a crash.
nvd
CVE-2018-5185P4MEDIUMCVSS 6.5v7.0v8.0+1 more2018-06-11
CVE-2018-5185 [MEDIUM] CWE-311 CVE-2018-5185: Plaintext of decrypted emails can leak through by user submitting an embedded form. This vulnerabili
Plaintext of decrypted emails can leak through by user submitting an embedded form. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
nvd
CVE-2018-19497P4MEDIUMCVSS 6.5v8.0v9.02018-11-29
CVE-2018-19497 [MEDIUM] CWE-125 CVE-2018-19497: In The Sleuth Kit (TSK) through 4.6.4, hfs_cat_traverse in tsk/fs/hfs.c does not properly determine
In The Sleuth Kit (TSK) through 4.6.4, hfs_cat_traverse in tsk/fs/hfs.c does not properly determine when a key length is too large, which allows attackers to cause a denial of service (SEGV on unknown address with READ memory access in a tsk_getu16 call in hfs_dir_open_meta_cb in tsk/fs/hfs_dent.c).
nvd
CVE-2020-22033P4MEDIUMCVSS 6.5v10.02021-05-27
CVE-2020-22033 [MEDIUM] CWE-787 CVE-2020-22033: A heap-based Buffer Overflow Vulnerability exists FFmpeg 4.2 at libavfilter/vf_vmafmotion.c in convo
A heap-based Buffer Overflow Vulnerability exists FFmpeg 4.2 at libavfilter/vf_vmafmotion.c in convolution_y_8bit, which could let a remote malicious user cause a Denial of Service.
nvd
CVE-2022-31160P4MEDIUMCVSS 6.1v10.02022-07-20
CVE-2022-31160 [MEDIUM] CWE-79 CVE-2022-31160: jQuery UI is a curated set of user interface interactions, effects, widgets, and themes built on top
jQuery UI is a curated set of user interface interactions, effects, widgets, and themes built on top of jQuery. Versions prior to 1.13.2 are potentially vulnerable to cross-site scripting. Initializing a checkboxradio widget on an input enclosed within a label makes that parent label contents considered as the input label. Calling `.checkboxradio( "r
nvd
CVE-2020-19143P4MEDIUMCVSS 6.5v11.02021-09-09
CVE-2020-19143 [MEDIUM] CWE-787 CVE-2020-19143: Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the "TIFFVGetFi
Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the "TIFFVGetField" funtion in the component 'libtiff/tif_dir.c'.
nvd
CVE-2018-6108P4MEDIUMCVSS 6.5v8.0v9.02018-12-04
CVE-2018-6108 [MEDIUM] CVE-2018-6108: Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117
Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted HTML page.
nvd
CVE-2017-5093P4MEDIUMCVSS 6.5v9.02017-10-27
CVE-2017-5093 [MEDIUM] CWE-20 CVE-2017-5093: Inappropriate implementation in modal dialog handling in Blink in Google Chrome prior to 60.0.3112.7
Inappropriate implementation in modal dialog handling in Blink in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to prevent a full screen warning from being displayed via a crafted HTML page.
nvd
CVE-2017-5104P4MEDIUMCVSS 6.5v9.02017-10-27
CVE-2017-5104 [MEDIUM] CWE-20 CVE-2017-5104: Inappropriate implementation in interstitials in Google Chrome prior to 60.0.3112.78 for Mac allowed
Inappropriate implementation in interstitials in Google Chrome prior to 60.0.3112.78 for Mac allowed a remote attacker to spoof the contents of the omnibox via a crafted HTML page.
nvd
CVE-2017-5101P4MEDIUMCVSS 6.5v9.02017-10-27
CVE-2017-5101 [MEDIUM] CVE-2017-5101: Inappropriate implementation in Omnibox in Google Chrome prior to 60.0.3112.78 for Linux, Windows, a
Inappropriate implementation in Omnibox in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed a remote attacker to spoof the contents of the Omnibox via a crafted HTML page.
nvd
CVE-2014-8132P4MEDIUMCVSS 5.0v7.0v8.02014-12-29
CVE-2014-8132 [MEDIUM] CVE-2014-8132: Double free vulnerability in the ssh_packet_kexinit function in kex.c in libssh 0.5.x and 0.6.x befo
Double free vulnerability in the ssh_packet_kexinit function in kex.c in libssh 0.5.x and 0.6.x before 0.6.4 allows remote attackers to cause a denial of service via a crafted kexinit packet.
nvd
CVE-2019-17023P4MEDIUMCVSS 6.5v10.02020-01-08
CVE-2019-17023 [MEDIUM] CWE-287 CVE-2019-17023: After a HelloRetryRequest has been sent, the client may negotiate a lower protocol that TLS 1.3, res
After a HelloRetryRequest has been sent, the client may negotiate a lower protocol that TLS 1.3, resulting in an invalid state transition in the TLS State Machine. If the client gets into this state, incoming Application Data records will be ignored. This vulnerability affects Firefox < 72.
nvd
CVE-2018-7877P4MEDIUMCVSS 6.5v7.02018-03-08
CVE-2018-7877 [MEDIUM] CWE-787 CVE-2018-7877: There is a heap-based buffer overflow in the getString function of util/decompile.c in libming 0.4.8
There is a heap-based buffer overflow in the getString function of util/decompile.c in libming 0.4.8 for DOUBLE data. A Crafted input will lead to a denial of service attack.
nvd