cbcvebase.

Debian Linux vulnerabilities

9,955 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358

Vulnerabilities

Page 348 of 498
CVE-2017-13305P4HIGHCVSS 7.1v8.02018-04-04
CVE-2017-13305 [HIGH] CWE-125 CVE-2017-13305: A information disclosure vulnerability in the Upstream kernel encrypted-keys. Product: Android. Vers A information disclosure vulnerability in the Upstream kernel encrypted-keys. Product: Android. Versions: Android kernel. Android ID: A-70526974.
nvd
CVE-2022-34677P4HIGHCVSS 7.1v10.02022-12-30
CVE-2022-34677 [HIGH] CWE-125 CVE-2022-34677: NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an unprivileged regular user can cause an integer to be truncated, which may lead to denial of service or data tampering.
nvd
CVE-2020-25706P4MEDIUMCVSS 6.1v10.02020-11-12
CVE-2020-25706 [MEDIUM] CWE-79 CVE-2020-25706: A cross-site scripting (XSS) vulnerability exists in templates_import.php (Cacti 1.2.13) due to Impr A cross-site scripting (XSS) vulnerability exists in templates_import.php (Cacti 1.2.13) due to Improper escaping of error message during template import preview in the xml_path field
nvd
CVE-2017-6815P4MEDIUMCVSS 6.1v8.0v9.02017-03-12
CVE-2017-6815 [MEDIUM] CWE-20 CVE-2017-6815: In WordPress before 4.7.3 (wp-includes/pluggable.php), control characters can trick redirect URL val In WordPress before 4.7.3 (wp-includes/pluggable.php), control characters can trick redirect URL validation.
nvd
CVE-2018-14347P4MEDIUMCVSS 6.5v8.0v9.02018-07-17
CVE-2018-14347 [MEDIUM] CWE-835 CVE-2018-14347: GNU Libextractor before 1.7 contains an infinite loop vulnerability in EXTRACTOR_mpeg_extract_method GNU Libextractor before 1.7 contains an infinite loop vulnerability in EXTRACTOR_mpeg_extract_method (mpeg_extractor.c).
nvd
CVE-2019-15531P4MEDIUMCVSS 6.5v8.0v9.02019-08-23
CVE-2019-15531 [MEDIUM] CWE-125 CVE-2019-15531: GNU Libextractor through 1.9 has a heap-based buffer over-read in the function EXTRACTOR_dvi_extract GNU Libextractor through 1.9 has a heap-based buffer over-read in the function EXTRACTOR_dvi_extract_method in plugins/dvi_extractor.c.
nvd
CVE-2020-22028P4MEDIUMCVSS 6.5v9.0v10.02021-05-26
CVE-2020-22028 [MEDIUM] CWE-120 CVE-2020-22028: Buffer Overflow vulnerability exists in FFmpeg 4.2 in filter_vertically_8 at libavfilter/vf_avgblur. Buffer Overflow vulnerability exists in FFmpeg 4.2 in filter_vertically_8 at libavfilter/vf_avgblur.c, which could cause a remote Denial of Service.
nvd
CVE-2018-19758P4MEDIUMCVSS 6.5v8.02018-11-30
CVE-2018-19758 [MEDIUM] CWE-125 CVE-2018-19758: There is a heap-based buffer over-read at wav.c in wav_write_header in libsndfile 1.0.28 that will c There is a heap-based buffer over-read at wav.c in wav_write_header in libsndfile 1.0.28 that will cause a denial of service.
nvd
CVE-2015-9382P4MEDIUMCVSS 6.5v8.02019-09-03
CVE-2015-9382 [MEDIUM] CWE-125 CVE-2015-9382: FreeType before 2.6.1 has a buffer over-read in skip_comment in psaux/psobjs.c because ps_parser_ski FreeType before 2.6.1 has a buffer over-read in skip_comment in psaux/psobjs.c because ps_parser_skip_PS_token is mishandled in an FT_New_Memory_Face operation.
nvd
CVE-2021-32436P4MEDIUMCVSS 6.5v9.02022-03-10
CVE-2021-32436 [MEDIUM] CWE-125 CVE-2021-32436: An out-of-bounds read in the function write_title() in subs.c of abcm2ps v8.14.11 allows remote atta An out-of-bounds read in the function write_title() in subs.c of abcm2ps v8.14.11 allows remote attackers to cause a Denial of Service (DoS) via unspecified vectors.
nvd
CVE-2013-4560P4MEDIUMCVSS 5.0v6.0v7.0+1 more2013-11-20
CVE-2013-4560 [MEDIUM] CWE-416 CVE-2013-4560: Use-after-free vulnerability in lighttpd before 1.4.33 allows remote attackers to cause a denial of Use-after-free vulnerability in lighttpd before 1.4.33 allows remote attackers to cause a denial of service (segmentation fault and crash) via unspecified vectors that trigger FAMMonitorDirectory failures.
nvd
CVE-2016-1837P4MEDIUMCVSS 5.5v8.02016-05-20
CVE-2016-1837 [MEDIUM] CWE-416 CVE-2016-1837: Multiple use-after-free vulnerabilities in the (1) htmlPArsePubidLiteral and (2) htmlParseSystemiter Multiple use-after-free vulnerabilities in the (1) htmlPArsePubidLiteral and (2) htmlParseSystemiteral functions in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allow remote attackers to cause a denial of service via a crafted XML document.
nvd
CVE-2018-7868P4MEDIUMCVSS 6.5v7.02018-03-08
CVE-2018-7868 [MEDIUM] CWE-125 CVE-2018-7868: There is a heap-based buffer over-read in the getName function of util/decompile.c in libming 0.4.8 There is a heap-based buffer over-read in the getName function of util/decompile.c in libming 0.4.8 for CONSTANT8 data. A Crafted input will lead to a denial of service attack.
nvd
CVE-2018-7875P4MEDIUMCVSS 6.5v7.02018-03-08
CVE-2018-7875 [MEDIUM] CWE-125 CVE-2018-7875: There is a heap-based buffer over-read in the getString function of util/decompile.c in libming 0.4. There is a heap-based buffer over-read in the getString function of util/decompile.c in libming 0.4.8 for CONSTANT8 data. A Crafted input will lead to a denial of service attack.
nvd
CVE-2019-9718P4MEDIUMCVSS 6.5v9.02019-03-12
CVE-2019-9718 [MEDIUM] CWE-125 CVE-2019-9718: In FFmpeg 3.2 and 4.1, a denial of service in the subtitle decoder allows attackers to hog the CPU v In FFmpeg 3.2 and 4.1, a denial of service in the subtitle decoder allows attackers to hog the CPU via a crafted video file in Matroska format, because ff_htmlmarkup_to_ass in libavcodec/htmlsubtitles.c has a complex format argument to sscanf.
nvd
CVE-2019-15133P4MEDIUMCVSS 6.5v10.02019-08-17
CVE-2019-15133 [MEDIUM] CWE-369 CVE-2019-15133: In GIFLIB before 2019-02-16, a malformed GIF file triggers a divide-by-zero exception in the decoder In GIFLIB before 2019-02-16, a malformed GIF file triggers a divide-by-zero exception in the decoder function DGifSlurp in dgif_lib.c if the height field of the ImageSize data structure is equal to zero.
nvd
CVE-2018-12458P4MEDIUMCVSS 6.5v9.02018-06-15
CVE-2018-12458 [MEDIUM] CWE-20 CVE-2018-12458: An improper integer type in the mpeg4_encode_gop_header function in libavcodec/mpeg4videoenc.c in FF An improper integer type in the mpeg4_encode_gop_header function in libavcodec/mpeg4videoenc.c in FFmpeg 2.8 and 4.0 may trigger an assertion violation while converting a crafted AVI file to MPEG4, leading to a denial of service.
nvd
CVE-2020-22020P4MEDIUMCVSS 6.5v9.0v10.02021-05-26
CVE-2020-22020 [MEDIUM] CWE-120 CVE-2020-22020: Buffer Overflow vulnerability in FFmpeg 4.2 in the build_diff_map function in libavfilter/vf_fieldma Buffer Overflow vulnerability in FFmpeg 4.2 in the build_diff_map function in libavfilter/vf_fieldmatch.c, which could let a remote malicious user cause a Denial of Service.
nvd
CVE-2014-8738P4MEDIUMCVSS 5.0v7.02015-01-15
CVE-2014-8738 [MEDIUM] CWE-119 CVE-2014-8738: The _bfd_slurp_extended_name_table function in bfd/archive.c in GNU binutils 2.24 and earlier allows The _bfd_slurp_extended_name_table function in bfd/archive.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (invalid write, segmentation fault, and crash) via a crafted extended name table in an archive.
nvd
CVE-2016-1836P4MEDIUMCVSS 5.5v8.02016-05-20
CVE-2016-1836 [MEDIUM] CWE-416 CVE-2016-1836: Use-after-free vulnerability in the xmlDictComputeFastKey function in libxml2 before 2.9.4, as used Use-after-free vulnerability in the xmlDictComputeFastKey function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service via a crafted XML document.
nvd
Debian Linux vulnerabilities | cvebase