cbcvebase.

Debian Linux vulnerabilities

9,955 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358

Vulnerabilities

Page 346 of 498
CVE-2011-2192P4MEDIUMCVSS 4.3v5.0v6.0+1 more2011-07-07
CVE-2011-2192 [MEDIUM] CWE-255 CVE-2011-2192: The Curl_input_negotiate function in http_negotiate.c in libcurl 7.10.6 through 7.21.6, as used in c The Curl_input_negotiate function in http_negotiate.c in libcurl 7.10.6 through 7.21.6, as used in curl and other products, always performs credential delegation during GSSAPI authentication, which allows remote servers to impersonate clients via GSSAPI requests.
nvd
CVE-2017-8363P4MEDIUMCVSS 6.5v8.02017-04-30
CVE-2017-8363 [MEDIUM] CWE-125 CVE-2017-8363: The flac_buffer_copy function in flac.c in libsndfile 1.0.28 allows remote attackers to cause a deni The flac_buffer_copy function in flac.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted audio file.
nvd
CVE-2018-14679P4MEDIUMCVSS 6.5v8.0v9.02018-07-28
CVE-2018-14679 [MEDIUM] CWE-193 CVE-2018-14679: An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the CHM PMGI/PMGL chunk number validity checks, which could lead to denial of service (uninitialized data dereference and application crash).
nvd
CVE-2015-8916P4MEDIUMCVSS 6.5v7.0v8.02016-09-20
CVE-2015-8916 [MEDIUM] CWE-476 CVE-2015-8916: bsdtar in libarchive before 3.2.0 returns a success code without filling the entry when the header i bsdtar in libarchive before 3.2.0 returns a success code without filling the entry when the header is a "split file in multivolume RAR," which allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted rar file.
nvd
CVE-2018-9018P4MEDIUMCVSS 6.5v7.0v8.0+1 more2018-03-25
CVE-2018-9018 [MEDIUM] CWE-369 CVE-2018-9018: In GraphicsMagick 1.3.28, there is a divide-by-zero in the ReadMNGImage function of coders/png.c. Re In GraphicsMagick 1.3.28, there is a divide-by-zero in the ReadMNGImage function of coders/png.c. Remote attackers could leverage this vulnerability to cause a crash and denial of service via a crafted mng file.
nvd
CVE-2015-3165P4MEDIUMCVSS 4.3v7.0v8.02015-05-28
CVE-2015-3165 [MEDIUM] CVE-2015-3165: Double free vulnerability in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3 Double free vulnerability in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 allows remote attackers to cause a denial of service (crash) by closing an SSL session at a time when the authentication timeout will expire during the session shutdown sequence.
nvd
CVE-2020-14152P4HIGHCVSS 7.1v9.02020-06-15
CVE-2020-14152 [HIGH] CWE-400 CVE-2020-14152: In IJG JPEG (aka libjpeg) before 9d, jpeg_mem_available() in jmemnobs.c in djpeg does not honor the In IJG JPEG (aka libjpeg) before 9d, jpeg_mem_available() in jmemnobs.c in djpeg does not honor the max_memory_to_use setting, possibly causing excessive memory consumption.
nvd
CVE-2017-17682P4MEDIUMCVSS 6.5v7.02017-12-14
CVE-2017-17682 [MEDIUM] CWE-400 CVE-2017-17682: In ImageMagick 7.0.7-12 Q16, a large loop vulnerability was found in the function ExtractPostscript In ImageMagick 7.0.7-12 Q16, a large loop vulnerability was found in the function ExtractPostscript in coders/wpg.c, which allows attackers to cause a denial of service (CPU exhaustion) via a crafted wpg image file that triggers a ReadWPGImage call.
nvd
CVE-2018-19432P4MEDIUMCVSS 6.5v8.02018-11-22
CVE-2018-19432 [MEDIUM] CWE-476 CVE-2018-19432: An issue was discovered in libsndfile 1.0.28. There is a NULL pointer dereference in the function sf An issue was discovered in libsndfile 1.0.28. There is a NULL pointer dereference in the function sf_write_int in sndfile.c, which will lead to a denial of service.
nvd
CVE-2014-9672P4MEDIUMCVSS 5.8v7.02015-02-08
CVE-2014-9672 [MEDIUM] CWE-119 CVE-2014-9672: Array index error in the parse_fond function in base/ftmac.c in FreeType before 2.5.4 allows remote Array index error in the parse_fond function in base/ftmac.c in FreeType before 2.5.4 allows remote attackers to cause a denial of service (out-of-bounds read) or obtain sensitive information from process memory via a crafted FOND resource in a Mac font file.
nvd
CVE-2017-1000476P4MEDIUMCVSS 6.5v7.02018-01-03
CVE-2017-1000476 [MEDIUM] CWE-400 CVE-2017-1000476: ImageMagick 7.0.7-12 Q16, a CPU exhaustion vulnerability was found in the function ReadDDSInfo in co ImageMagick 7.0.7-12 Q16, a CPU exhaustion vulnerability was found in the function ReadDDSInfo in coders/dds.c, which allows attackers to cause a denial of service.
nvd
CVE-2015-8782P4MEDIUMCVSS 6.5v7.0v8.02016-02-01
CVE-2015-8782 [MEDIUM] CVE-2015-8782: tif_luv.c in libtiff allows attackers to cause a denial of service (out-of-bounds writes) via a craf tif_luv.c in libtiff allows attackers to cause a denial of service (out-of-bounds writes) via a crafted TIFF image, a different vulnerability than CVE-2015-8781.
nvd
CVE-2018-11213P4MEDIUMCVSS 6.5v8.02018-05-16
CVE-2018-11213 [MEDIUM] CVE-2018-11213: An issue was discovered in libjpeg 9a. The get_text_gray_row function in rdppm.c allows remote attac An issue was discovered in libjpeg 9a. The get_text_gray_row function in rdppm.c allows remote attackers to cause a denial of service (Segmentation fault) via a crafted file.
nvd
CVE-2018-18025P4MEDIUMCVSS 6.5v8.02018-10-07
CVE-2018-18025 [MEDIUM] CWE-125 CVE-2018-18025: In ImageMagick 7.0.8-13 Q16, there is a heap-based buffer over-read in the EncodeImage function of c In ImageMagick 7.0.8-13 Q16, there is a heap-based buffer over-read in the EncodeImage function of coders/pict.c, which allows attackers to cause a denial of service via a crafted SVG image file.
nvd
CVE-2020-0556P4HIGHCVSS 7.1v8.0v9.0+1 more2020-03-12
CVE-2020-0556 [HIGH] CVE-2020-0556: Improper access control in subsystem for BlueZ before version 5.54 may allow an unauthenticated user Improper access control in subsystem for BlueZ before version 5.54 may allow an unauthenticated user to potentially enable escalation of privilege and denial of service via adjacent access
nvd
CVE-2018-10958P4MEDIUMCVSS 6.5v8.0v9.02018-05-10
CVE-2018-10958 [MEDIUM] CWE-119 CVE-2018-10958: In types.cpp in Exiv2 0.26, a large size value may lead to a SIGABRT during an attempt at memory all In types.cpp in Exiv2 0.26, a large size value may lead to a SIGABRT during an attempt at memory allocation for an Exiv2::Internal::PngChunk::zlibUncompress call.
nvd
CVE-2017-12643P4MEDIUMCVSS 6.5v8.0v9.02017-08-07
CVE-2017-12643 [MEDIUM] CWE-770 CVE-2017-12643: ImageMagick 7.0.6-1 has a memory exhaustion vulnerability in ReadOneJNGImage in coders\png.c. ImageMagick 7.0.6-1 has a memory exhaustion vulnerability in ReadOneJNGImage in coders\png.c.
nvd
CVE-2018-11214P4MEDIUMCVSS 6.5v8.02018-05-16
CVE-2018-11214 [MEDIUM] CVE-2018-11214: An issue was discovered in libjpeg 9a. The get_text_rgb_row function in rdppm.c allows remote attack An issue was discovered in libjpeg 9a. The get_text_rgb_row function in rdppm.c allows remote attackers to cause a denial of service (Segmentation fault) via a crafted file.
nvd
CVE-2018-10768P4MEDIUMCVSS 6.5v8.02018-05-06
CVE-2018-10768 [MEDIUM] CWE-476 CVE-2018-10768: There is a NULL pointer dereference in the AnnotPath::getCoordsLength function in Annot.h in an Ubun There is a NULL pointer dereference in the AnnotPath::getCoordsLength function in Annot.h in an Ubuntu package for Poppler 0.24.5. A crafted input will lead to a remote denial of service attack. Later Ubuntu packages such as for Poppler 0.41.0 are not affected.
nvd
CVE-2018-10999P4MEDIUMCVSS 6.5v8.0v9.02018-05-12
CVE-2018-10999 [MEDIUM] CWE-125 CVE-2018-10999: An issue was discovered in Exiv2 0.26. The Exiv2::Internal::PngChunk::parseTXTChunk function has a h An issue was discovered in Exiv2 0.26. The Exiv2::Internal::PngChunk::parseTXTChunk function has a heap-based buffer over-read.
nvd
Debian Linux vulnerabilities | cvebase