Debian Linux vulnerabilities
9,955 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358
Vulnerabilities
Page 347 of 498
CVE-2012-1798P4MEDIUMCVSS 6.5v6.02012-06-05
CVE-2012-1798 [MEDIUM] CWE-125 CVE-2012-1798: The TIFFGetEXIFProperties function in coders/tiff.c in ImageMagick before 6.7.6-3 allows remote atta
The TIFFGetEXIFProperties function in coders/tiff.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted EXIF IFD in a TIFF image.
nvd
CVE-2019-13504P4MEDIUMCVSS 6.5v8.0v10.02019-07-11
CVE-2019-13504 [MEDIUM] CWE-125 CVE-2019-13504: There is an out-of-bounds read in Exiv2::MrwImage::readMetadata in mrwimage.cpp in Exiv2 through 0.2
There is an out-of-bounds read in Exiv2::MrwImage::readMetadata in mrwimage.cpp in Exiv2 through 0.27.2.
nvd
CVE-2012-0260P4MEDIUMCVSS 6.5v6.02012-06-05
CVE-2012-0260 [MEDIUM] CWE-400 CVE-2012-0260: The JPEGWarningHandler function in coders/jpeg.c in ImageMagick before 6.7.6-3 allows remote attacke
The JPEGWarningHandler function in coders/jpeg.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (memory consumption) via a JPEG image with a crafted sequence of restart markers.
nvd
CVE-2015-4551P4MEDIUMCVSS 4.3v7.0v8.02015-11-10
CVE-2015-4551 [MEDIUM] CWE-200 CVE-2015-4551: LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2 uses the stored LinkUpdateMode configura
LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2 uses the stored LinkUpdateMode configuration information in OpenDocument Format files and templates when handling links, which might allow remote attackers to obtain sensitive information via a crafted document, which embeds data from local files into (1) Calc or (2) Writer.
nvd
CVE-2017-12877P4MEDIUMCVSS 6.5v8.0v9.02017-08-28
CVE-2017-12877 [MEDIUM] CWE-416 CVE-2017-12877: Use-after-free vulnerability in the DestroyImage function in image.c in ImageMagick before 7.0.6-6 a
Use-after-free vulnerability in the DestroyImage function in image.c in ImageMagick before 7.0.6-6 allows remote attackers to cause a denial of service via a crafted file.
nvd
CVE-2017-1000445P4MEDIUMCVSS 6.5v7.0v8.0+1 more2018-01-02
CVE-2017-1000445 [MEDIUM] CWE-476 CVE-2017-1000445: ImageMagick 7.0.7-1 and older version are vulnerable to null pointer dereference in the MagickCore c
ImageMagick 7.0.7-1 and older version are vulnerable to null pointer dereference in the MagickCore component and might lead to denial of service
nvd
CVE-2018-20431P4MEDIUMCVSS 6.5v8.0v9.02018-12-24
CVE-2018-20431 [MEDIUM] CWE-476 CVE-2018-20431: GNU Libextractor through 1.8 has a NULL Pointer Dereference vulnerability in the function process_me
GNU Libextractor through 1.8 has a NULL Pointer Dereference vulnerability in the function process_metadata() in plugins/ole2_extractor.c.
nvd
CVE-2007-5191P4HIGHCVSS 7.2v3.12007-10-04
CVE-2007-5191 [HIGH] CWE-252 CVE-2007-5191: mount and umount in util-linux and loop-aes-utils call the setuid and setgid functions in the wrong
mount and umount in util-linux and loop-aes-utils call the setuid and setgid functions in the wrong order and do not check the return values, which might allow attackers to gain privileges via helpers such as mount.nfs.
nvd
CVE-2009-3080P4HIGHCVSS 7.2v4.02009-11-20
CVE-2009-3080 [HIGH] CWE-129 CVE-2009-3080: Array index error in the gdth_read_event function in drivers/scsi/gdth.c in the Linux kernel before
Array index error in the gdth_read_event function in drivers/scsi/gdth.c in the Linux kernel before 2.6.32-rc8 allows local users to cause a denial of service or possibly gain privileges via a negative event index in an IOCTL request.
nvd
CVE-2022-28041P4MEDIUMCVSS 6.5v10.02022-04-15
CVE-2022-28041 [MEDIUM] CWE-190 CVE-2022-28041: stb_image.h v2.27 was discovered to contain an integer overflow via the function stbi__jpeg_decode_b
stb_image.h v2.27 was discovered to contain an integer overflow via the function stbi__jpeg_decode_block_prog_dc. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecified vectors.
nvd
CVE-2017-14634P4MEDIUMCVSS 6.5v8.02017-09-21
CVE-2017-14634 [MEDIUM] CWE-369 CVE-2017-14634: In libsndfile 1.0.28, a divide-by-zero error exists in the function double64_init() in double64.c, w
In libsndfile 1.0.28, a divide-by-zero error exists in the function double64_init() in double64.c, which may lead to DoS when playing a crafted audio file.
nvd
CVE-2017-9988P4MEDIUMCVSS 6.5v7.02017-06-28
CVE-2017-9988 [MEDIUM] CWE-476 CVE-2017-9988: The readEncUInt30 function in util/read.c in libming 0.4.8 mishandles memory allocation. A crafted i
The readEncUInt30 function in util/read.c in libming 0.4.8 mishandles memory allocation. A crafted input will lead to a remote denial of service (NULL pointer dereference) attack against parser.c.
nvd
CVE-2016-2822P4MEDIUMCVSS 6.5v8.02016-06-13
CVE-2016-2822 [MEDIUM] CWE-284 CVE-2016-2822: Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to spoof the add
Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to spoof the address bar via a SELECT element with a persistent menu.
nvd
CVE-2019-13110P4MEDIUMCVSS 6.5v10.02019-06-30
CVE-2019-13110 [MEDIUM] CWE-125 CVE-2019-13110: A CiffDirectory::readDirectory integer overflow and out-of-bounds read in Exiv2 through 0.27.1 allow
A CiffDirectory::readDirectory integer overflow and out-of-bounds read in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV) via a crafted CRW image file.
nvd
CVE-2019-13147P4MEDIUMCVSS 6.5v10.02019-07-02
CVE-2019-13147 [MEDIUM] CWE-476 CVE-2019-13147: In Audio File Library (aka audiofile) 0.3.6, there exists one NULL pointer dereference bug in ulaw2l
In Audio File Library (aka audiofile) 0.3.6, there exists one NULL pointer dereference bug in ulaw2linear_buf in G711.cpp in libmodules.a that allows an attacker to cause a denial of service via a crafted file.
nvd
CVE-2018-5334P4MEDIUMCVSS 6.5v7.0v8.0+1 more2018-01-11
CVE-2018-5334 [MEDIUM] CWE-119 CVE-2018-5334: In Wireshark 2.4.0 to 2.4.3 and 2.2.0 to 2.2.11, the IxVeriWave file parser could crash. This was ad
In Wireshark 2.4.0 to 2.4.3 and 2.2.0 to 2.2.11, the IxVeriWave file parser could crash. This was addressed in wiretap/vwr.c by correcting the signature timestamp bounds checks.
nvd
CVE-2018-7557P4MEDIUMCVSS 6.5v8.0v9.02018-02-28
CVE-2018-7557 [MEDIUM] CWE-125 CVE-2018-7557: The decode_init function in libavcodec/utvideodec.c in FFmpeg 2.8 through 3.4.2 allows remote attack
The decode_init function in libavcodec/utvideodec.c in FFmpeg 2.8 through 3.4.2 allows remote attackers to cause a denial of service (Out of array read) via an AVI file with crafted dimensions within chroma subsampling data.
nvd
CVE-2018-20544P4MEDIUMCVSS 6.5v8.02018-12-28
CVE-2018-20544 [MEDIUM] CWE-369 CVE-2018-20544: There is floating point exception at caca/dither.c (function caca_dither_bitmap) in libcaca 0.99.bet
There is floating point exception at caca/dither.c (function caca_dither_bitmap) in libcaca 0.99.beta19.
nvd
CVE-2017-9144P4MEDIUMCVSS 6.5v8.0v9.02017-05-22
CVE-2017-9144 [MEDIUM] CWE-20 CVE-2017-9144: In ImageMagick 7.0.5-5, a crafted RLE image can trigger a crash because of incorrect EOF handling in
In ImageMagick 7.0.5-5, a crafted RLE image can trigger a crash because of incorrect EOF handling in coders/rle.c.
nvd
CVE-2014-7817P4MEDIUMCVSS 4.6v7.02014-11-24
CVE-2014-7817 [MEDIUM] CWE-20 CVE-2014-7817: The wordexp function in GNU C Library (aka glibc) 2.21 does not enforce the WRDE_NOCMD flag, which a
The wordexp function in GNU C Library (aka glibc) 2.21 does not enforce the WRDE_NOCMD flag, which allows context-dependent attackers to execute arbitrary commands, as demonstrated by input containing "$((`...`))".
nvd