Debian Linux vulnerabilities
9,955 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358
Vulnerabilities
Page 349 of 498
CVE-2018-8098P4MEDIUMCVSS 6.5v9.02018-03-14
CVE-2018-8098 [MEDIUM] CWE-190 CVE-2018-8098: Integer overflow in the index.c:read_entry() function while decompressing a compressed prefix length
Integer overflow in the index.c:read_entry() function while decompressing a compressed prefix length in libgit2 before v0.26.2 allows an attacker to cause a denial of service (out-of-bounds read) via a crafted repository index file.
nvd
CVE-2021-23973P4MEDIUMCVSS 6.5v9.0v10.02021-02-26
CVE-2021-23973 [MEDIUM] CWE-209 CVE-2021-23973: When trying to load a cross-origin resource in an audio/video context a decoding error may have resu
When trying to load a cross-origin resource in an audio/video context a decoding error may have resulted, and the content of that error may have revealed information about the resource. This vulnerability affects Firefox < 86, Thunderbird < 78.8, and Firefox ESR < 78.8.
nvd
CVE-2024-25081P4MEDIUMCVSS 4.2v10.02024-02-26
CVE-2024-25081 [MEDIUM] CWE-77 CVE-2024-25081: Splinefont in FontForge through 20230101 allows command injection via crafted filenames.
Splinefont in FontForge through 20230101 allows command injection via crafted filenames.
nvd
CVE-2016-1702P4MEDIUMCVSS 6.5v8.02016-06-05
CVE-2016-1702 [MEDIUM] CWE-119 CVE-2016-1702: The SkRegion::readFromMemory function in core/SkRegion.cpp in Skia, as used in Google Chrome before
The SkRegion::readFromMemory function in core/SkRegion.cpp in Skia, as used in Google Chrome before 51.0.2704.79, does not validate the interval count, which allows remote attackers to cause a denial of service (out-of-bounds read) via crafted serialized data.
nvd
CVE-2020-15562P4MEDIUMCVSS 6.1v10.02020-07-06
CVE-2020-15562 [MEDIUM] CWE-79 CVE-2020-15562: An issue was discovered in Roundcube Webmail before 1.2.11, 1.3.x before 1.3.14, and 1.4.x before 1.
An issue was discovered in Roundcube Webmail before 1.2.11, 1.3.x before 1.3.14, and 1.4.x before 1.4.7. It allows XSS via a crafted HTML e-mail message, as demonstrated by a JavaScript payload in the xmlns (aka XML namespace) attribute of a HEAD element when an SVG element exists.
nvd
CVE-2010-3299P4MEDIUMCVSS 6.5v8.0v9.0+1 more2019-11-12
CVE-2010-3299 [MEDIUM] CWE-311 CVE-2010-3299: The encrypt/decrypt functions in Ruby on Rails 2.3 are vulnerable to padding oracle attacks.
The encrypt/decrypt functions in Ruby on Rails 2.3 are vulnerable to padding oracle attacks.
nvd
CVE-2023-28484P4MEDIUMCVSS 6.5v10.02023-04-24
CVE-2023-28484 [MEDIUM] CWE-476 CVE-2023-28484: In libxml2 before 2.10.4, parsing of certain invalid XSD schemas can lead to a NULL pointer derefere
In libxml2 before 2.10.4, parsing of certain invalid XSD schemas can lead to a NULL pointer dereference and subsequently a segfault. This occurs in xmlSchemaFixupComplexType in xmlschemas.c.
nvd
CVE-2015-8807P4MEDIUMCVSS 6.1v8.02016-04-13
CVE-2015-8807 [MEDIUM] CWE-79 CVE-2015-8807: Cross-site scripting (XSS) vulnerability in the _renderVarInput_number function in horde/framework/C
Cross-site scripting (XSS) vulnerability in the _renderVarInput_number function in horde/framework/Core/lib/Horde/Core/Ui/VarRenderer/Html.php in Horde Groupware before 5.2.12 and Horde Groupware Webmail Edition before 5.2.12 allows remote attackers to inject arbitrary web script or HTML via vectors involving numeric form fields.
nvd
CVE-2018-1050P4MEDIUMCVSS 4.3v7.0v8.0+1 more2018-03-13
CVE-2018-1050 [MEDIUM] CWE-476 CVE-2018-1050: All versions of Samba from 4.0.0 onwards are vulnerable to a denial of service attack when the RPC s
All versions of Samba from 4.0.0 onwards are vulnerable to a denial of service attack when the RPC spoolss service is configured to be run as an external daemon. Missing input sanitization checks on some of the input parameters to spoolss RPC calls could cause the print spooler service to crash.
nvd
CVE-2017-9525P4MEDIUMCVSS 6.7v8.0v9.02017-06-09
CVE-2017-9525 [MEDIUM] CWE-59 CVE-2017-9525: In the cron package through 3.0pl1-128 on Debian, and through 3.0pl1-128ubuntu2 on Ubuntu, the posti
In the cron package through 3.0pl1-128 on Debian, and through 3.0pl1-128ubuntu2 on Ubuntu, the postinst maintainer script allows for group-crontab-to-root privilege escalation via symlink attacks against unsafe usage of the chown and chmod programs.
nvd
CVE-2022-2521P4MEDIUMCVSS 6.5v11.02022-08-31
CVE-2022-2521 [MEDIUM] CWE-763 CVE-2022-2521: It was found in libtiff 4.4.0rc1 that there is an invalid pointer free operation in TIFFClose() at t
It was found in libtiff 4.4.0rc1 that there is an invalid pointer free operation in TIFFClose() at tif_close.c:131 called by tiffcrop.c:2522 that can cause a program crash and denial of service while processing crafted input.
nvd
CVE-2022-2519P4MEDIUMCVSS 6.5v11.02022-08-31
CVE-2022-2519 [MEDIUM] CWE-415 CVE-2022-2519: There is a double free or corruption in rotateImage() at tiffcrop.c:8839 found in libtiff 4.4.0rc1
There is a double free or corruption in rotateImage() at tiffcrop.c:8839 found in libtiff 4.4.0rc1
nvd
CVE-2014-4260P4MEDIUMCVSS 5.5v7.02014-07-17
CVE-2014-4260 [MEDIUM] CVE-2014-4260: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier, and 5.6.
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier, and 5.6.17 and earlier, allows remote authenticated users to affect integrity and availability via vectors related to SRCHAR.
nvd
CVE-2022-3598P4MEDIUMCVSS 6.5v10.02022-10-21
CVE-2022-3598 [MEDIUM] CWE-787 CVE-2022-3598: LibTIFF 4.4.0 has an out-of-bounds write in extractContigSamplesShifted24bits in tools/tiffcrop.c:36
LibTIFF 4.4.0 has an out-of-bounds write in extractContigSamplesShifted24bits in tools/tiffcrop.c:3604, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit cfbb883b.
nvd
CVE-2022-37051P4MEDIUMCVSS 6.5v10.02023-08-22
CVE-2022-37051 [MEDIUM] CWE-617 CVE-2022-37051: An issue was discovered in Poppler 22.07.0. There is a reachable abort which leads to denial of serv
An issue was discovered in Poppler 22.07.0. There is a reachable abort which leads to denial of service because the main function in pdfunite.cc lacks a stream check before saving an embedded file.
nvd
CVE-2017-3312P4MEDIUMCVSS 6.7v8.02017-01-27
CVE-2017-3312 [MEDIUM] CVE-2017-3312: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Packaging). Suppo
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Packaging). Supported versions that are affected are 5.5.53 and earlier, 5.6.34 and earlier and 5.7.16 and earlier. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Success
nvd
CVE-2019-14380P4MEDIUMCVSS 6.5v10.02019-07-30
CVE-2019-14380 [MEDIUM] CWE-125 CVE-2019-14380: libopenmpt before 0.4.5 allows a crash during playback due to an out-of-bounds read in XM and MT2 fi
libopenmpt before 0.4.5 allows a crash during playback due to an out-of-bounds read in XM and MT2 files.
nvd
CVE-2023-29415P4MEDIUMCVSS 6.5v12.02023-04-06
CVE-2023-29415 [MEDIUM] CVE-2023-29415: An issue was discovered in libbzip3.a in bzip3 before 1.3.0. A denial of service (process hang) can
An issue was discovered in libbzip3.a in bzip3 before 1.3.0. A denial of service (process hang) can occur with a crafted archive because bzip3 does not follow the required procedure for interacting with libsais.
nvd
CVE-2019-16219P4MEDIUMCVSS 6.1v8.0v9.0+1 more2019-09-11
CVE-2019-16219 [MEDIUM] CWE-79 CVE-2019-16219: WordPress before 5.2.3 allows XSS in shortcode previews.
WordPress before 5.2.3 allows XSS in shortcode previews.
nvd
CVE-2023-2854P4MEDIUMCVSS 6.5v12.02023-05-26
CVE-2023-2854 [MEDIUM] CWE-787 CVE-2023-2854: BLF file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via c
BLF file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file
nvd