Debian Linux vulnerabilities
9,954 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358
Vulnerabilities
Page 341 of 498
CVE-2022-3626P4MEDIUMCVSS 6.5v10.02022-10-21
CVE-2022-3626 [MEDIUM] CWE-787 CVE-2022-3626: LibTIFF 4.4.0 has an out-of-bounds write in _TIFFmemset in libtiff/tif_unix.c:340 when called from p
LibTIFF 4.4.0 has an out-of-bounds write in _TIFFmemset in libtiff/tif_unix.c:340 when called from processCropSelections, tools/tiffcrop.c:7619, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 236b7191.
nvd
CVE-2020-0256P4MEDIUMCVSS 6.8v9.02020-08-11
CVE-2020-0256 [MEDIUM] CWE-787 CVE-2020-0256: In LoadPartitionTable of gpt.cc, there is a possible out of bounds write due to a missing bounds che
In LoadPartitionTable of gpt.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege when inserting a malicious USB device, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Androi
nvd
CVE-2018-1068P4MEDIUMCVSS 6.7v7.0v8.0+1 more2018-03-16
CVE-2018-1068 [MEDIUM] CWE-119 CVE-2018-1068: A flaw was found in the Linux 4.x kernel's implementation of 32-bit syscall interface for bridging.
A flaw was found in the Linux 4.x kernel's implementation of 32-bit syscall interface for bridging. This allowed a privileged user to arbitrarily write to a limited range of kernel memory.
nvd
CVE-2022-2520P4MEDIUMCVSS 6.5v11.02022-08-31
CVE-2022-2520 [MEDIUM] CWE-131 CVE-2022-2520: A flaw was found in libtiff 4.4.0rc1. There is a sysmalloc assertion fail in rotateImage() at tiffcr
A flaw was found in libtiff 4.4.0rc1. There is a sysmalloc assertion fail in rotateImage() at tiffcrop.c:8621 that can cause program crash when reading a crafted input.
nvd
CVE-2022-30783P4MEDIUMCVSS 6.7v9.0v10.0+1 more2022-05-26
CVE-2022-30783 [MEDIUM] CWE-252 CVE-2022-30783: An invalid return code in fuse_kern_mount enables intercepting of libfuse-lite protocol traffic betw
An invalid return code in fuse_kern_mount enables intercepting of libfuse-lite protocol traffic between NTFS-3G and the kernel in NTFS-3G through 2021.8.22 when using libfuse-lite.
nvd
CVE-2022-37050P4MEDIUMCVSS 6.5v10.02023-08-22
CVE-2022-37050 [MEDIUM] CVE-2022-37050: In Poppler 22.07.0, PDFDoc::savePageAs in PDFDoc.c callows attackers to cause a denial-of-service (a
In Poppler 22.07.0, PDFDoc::savePageAs in PDFDoc.c callows attackers to cause a denial-of-service (application crashes with SIGABRT) by crafting a PDF file in which the xref data structure is mishandled in getCatalog processing. Note that this vulnerability is caused by the incomplete patch of CVE-2018-20662.
nvd
CVE-2012-6702P4MEDIUMCVSS 5.9v8.02016-06-16
CVE-2012-6702 [MEDIUM] CWE-310 CVE-2012-6702: Expat, when used in a parser that has not called XML_SetHashSalt or passed it a seed of 0, makes it
Expat, when used in a parser that has not called XML_SetHashSalt or passed it a seed of 0, makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms via vectors involving use of the srand function.
nvd
CVE-2019-10785P4MEDIUMCVSS 6.1v8.02020-02-13
CVE-2019-10785 [MEDIUM] CWE-79 CVE-2019-10785: dojox is vulnerable to Cross-site Scripting in all versions before version 1.16.1, 1.15.2, 1.14.5, 1
dojox is vulnerable to Cross-site Scripting in all versions before version 1.16.1, 1.15.2, 1.14.5, 1.13.6, 1.12.7 and 1.11.9. This is due to dojox.xmpp.util.xmlEncode only encoding the first occurrence of each character, not all of them.
nvd
CVE-2022-26363P4MEDIUMCVSS 6.7v11.02022-06-09
CVE-2022-26363 [MEDIUM] CVE-2022-26363: x86 pv: Insufficient care with non-coherent mappings T[his CNA information record relates to multipl
x86 pv: Insufficient care with non-coherent mappings T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Xen maintains a type reference count for pages, in addition to a regular reference count. This scheme is used to maintain invariants required for Xen's safety, e.g. PV guests ma
nvd
CVE-2016-2373P4MEDIUMCVSS 5.9v8.02017-01-06
CVE-2016-2373 [MEDIUM] CWE-125 CVE-2016-2373: A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially c
A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in an out-of-bounds read. A malicious server or user can send an invalid mood to trigger this vulnerability.
nvd
CVE-2016-2369P4MEDIUMCVSS 5.9v8.02017-01-06
CVE-2016-2369 [MEDIUM] CWE-476 CVE-2016-2369: A NULL pointer dereference vulnerability exists in the handling of the MXIT protocol in Pidgin. Spec
A NULL pointer dereference vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in a denial of service vulnerability. A malicious server can send a packet starting with a NULL byte triggering the vulnerability.
nvd
CVE-2023-6174P4MEDIUMCVSS 6.5v12.02023-11-16
CVE-2023-6174 [MEDIUM] CWE-125 CVE-2023-6174: SSH dissector crash in Wireshark 4.0.0 to 4.0.10 allows denial of service via packet injection or cr
SSH dissector crash in Wireshark 4.0.0 to 4.0.10 allows denial of service via packet injection or crafted capture file
nvd
CVE-2022-2928P4MEDIUMCVSS 6.5v10.02022-10-07
CVE-2022-2928 [MEDIUM] CWE-476 CVE-2022-2928: In ISC DHCP 4.4.0 -> 4.4.3, ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16-P1, when the function option_code_has
In ISC DHCP 4.4.0 -> 4.4.3, ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16-P1, when the function option_code_hash_lookup() is called from add_option(), it increases the option's refcount field. However, there is not a corresponding call to option_dereference() to decrement the refcount field. The function add_option() is only used in server responses to lease que
nvd
CVE-2016-4079P4MEDIUMCVSS 5.9v8.02016-04-25
CVE-2016-4079 [MEDIUM] CWE-119 CVE-2016-4079: epan/dissectors/packet-pktc.c in the PKTC dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x bef
epan/dissectors/packet-pktc.c in the PKTC dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 does not verify BER identifiers, which allows remote attackers to cause a denial of service (out-of-bounds write and application crash) via a crafted packet.
nvd
CVE-2022-0235P4MEDIUMCVSS 6.1v10.02022-01-16
CVE-2022-0235 [MEDIUM] CWE-200 CVE-2022-0235: node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
nvd
CVE-2022-2929P4MEDIUMCVSS 6.5v10.02022-10-07
CVE-2022-2929 [MEDIUM] CWE-770 CVE-2022-2929: In ISC DHCP 1.0 -> 4.4.3, ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16-P1 a system with access to a DHCP serve
In ISC DHCP 1.0 -> 4.4.3, ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16-P1 a system with access to a DHCP server, sending DHCP packets crafted to include fqdn labels longer than 63 bytes, could eventually cause the server to run out of memory.
nvd
CVE-2022-27777P4MEDIUMCVSS 6.1v10.02022-05-26
CVE-2022-27777 [MEDIUM] CWE-79 CVE-2022-27777: A XSS Vulnerability in Action View tag helpers >= 5.2.0 and < 5.2.0 which would allow an attacker to
A XSS Vulnerability in Action View tag helpers >= 5.2.0 and < 5.2.0 which would allow an attacker to inject content if able to control input into specific attributes.
nvd
CVE-2019-10904P4MEDIUMCVSS 6.1v8.02019-04-06
CVE-2019-10904 [MEDIUM] CWE-79 CVE-2019-10904: Roundup 1.6 allows XSS via the URI because frontends/roundup.cgi and roundup/cgi/wsgi_handler.py mis
Roundup 1.6 allows XSS via the URI because frontends/roundup.cgi and roundup/cgi/wsgi_handler.py mishandle 404 errors.
nvd
CVE-2019-5754P4MEDIUMCVSS 6.5v9.02019-02-19
CVE-2019-5754 [MEDIUM] CWE-327 CVE-2019-5754: Implementation error in QUIC Networking in Google Chrome prior to 72.0.3626.81 allowed an attacker r
Implementation error in QUIC Networking in Google Chrome prior to 72.0.3626.81 allowed an attacker running or able to cause use of a proxy server to obtain cleartext of transport encryption via malicious network proxy.
nvd
CVE-2020-1760P4MEDIUMCVSS 6.1v9.02020-04-23
CVE-2020-1760 [MEDIUM] CWE-79 CVE-2020-1760: A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in
A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS attacks due to the lack of proper neutralization of untrusted input.
nvd