cbcvebase.

Debian Linux vulnerabilities

9,955 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358

Vulnerabilities

Page 350 of 498
CVE-2023-2857P4MEDIUMCVSS 6.5v12.02023-05-26
CVE-2023-2857 [MEDIUM] CWE-787 CVE-2023-2857: BLF file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via c BLF file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file
nvd
CVE-2016-2228P4MEDIUMCVSS 6.1v8.02016-04-13
CVE-2016-2228 [MEDIUM] CWE-79 CVE-2016-2228: Cross-site scripting (XSS) vulnerability in horde/templates/topbar/_menubar.html.php in Horde Groupw Cross-site scripting (XSS) vulnerability in horde/templates/topbar/_menubar.html.php in Horde Groupware before 5.2.12 and Horde Groupware Webmail Edition before 5.2.12 allows remote attackers to inject arbitrary web script or HTML via the searchfield parameter, as demonstrated by a request to xplorer/gollem/manager.php.
nvd
CVE-2022-43242P4MEDIUMCVSS 6.5v10.0v11.02022-11-02
CVE-2022-43242 [MEDIUM] CWE-787 CVE-2022-43242: Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via mc_luma<unsigned Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via mc_luma in motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.
nvd
CVE-2022-43237P4MEDIUMCVSS 6.5v10.0v11.02022-11-02
CVE-2022-43237 [MEDIUM] CWE-787 CVE-2022-43237: Libde265 v1.0.8 was discovered to contain a stack-buffer-overflow vulnerability via void put_epel_hv Libde265 v1.0.8 was discovered to contain a stack-buffer-overflow vulnerability via void put_epel_hv_fallback in fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.
nvd
CVE-2022-43236P4MEDIUMCVSS 6.5v10.0v11.02022-11-02
CVE-2022-43236 [MEDIUM] CWE-787 CVE-2022-43236: Libde265 v1.0.8 was discovered to contain a stack-buffer-overflow vulnerability via put_qpel_fallbac Libde265 v1.0.8 was discovered to contain a stack-buffer-overflow vulnerability via put_qpel_fallback in fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.
nvd
CVE-2022-43248P4MEDIUMCVSS 6.5v10.0v11.02022-11-02
CVE-2022-43248 [MEDIUM] CWE-787 CVE-2022-43248: Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via put_weighted_pred Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via put_weighted_pred_avg_16_fallback in fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.
nvd
CVE-2022-43250P4MEDIUMCVSS 6.5v10.0v11.02022-11-02
CVE-2022-43250 [MEDIUM] CWE-787 CVE-2022-43250: Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via put_qpel_0_0_fall Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via put_qpel_0_0_fallback_16 in fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.
nvd
CVE-2022-43240P4MEDIUMCVSS 6.5v10.0v11.02022-11-02
CVE-2022-43240 [MEDIUM] CWE-787 CVE-2022-43240: Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via ff_hevc_put_hevc_ Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via ff_hevc_put_hevc_qpel_h_2_v_1_sse in sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.
nvd
CVE-2022-43243P4MEDIUMCVSS 6.5v10.0v11.02022-11-02
CVE-2022-43243 [MEDIUM] CWE-787 CVE-2022-43243: Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via ff_hevc_put_weigh Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via ff_hevc_put_weighted_pred_avg_8_sse in sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.
nvd
CVE-2022-43253P4MEDIUMCVSS 6.5v10.0v11.02022-11-02
CVE-2022-43253 [MEDIUM] CWE-787 CVE-2022-43253: Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via put_unweighted_pr Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via put_unweighted_pred_16_fallback in fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.
nvd
CVE-2022-43239P4MEDIUMCVSS 6.5v10.0v11.02022-11-02
CVE-2022-43239 [MEDIUM] CWE-787 CVE-2022-43239: Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via mc_chroma<unsigne Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via mc_chroma in motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.
nvd
CVE-2022-43244P4MEDIUMCVSS 6.5v10.0v11.02022-11-02
CVE-2022-43244 [MEDIUM] CWE-787 CVE-2022-43244: Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via put_qpel_fallback Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via put_qpel_fallback in fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.
nvd
CVE-2022-43252P4MEDIUMCVSS 6.5v10.0v11.02022-11-02
CVE-2022-43252 [MEDIUM] CWE-787 CVE-2022-43252: Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via put_epel_16_fallb Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via put_epel_16_fallback in fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.
nvd
CVE-2022-43249P4MEDIUMCVSS 6.5v10.0v11.02022-11-02
CVE-2022-43249 [MEDIUM] CWE-787 CVE-2022-43249: Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via put_epel_hv_fallb Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via put_epel_hv_fallback in fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.
nvd
CVE-2022-43235P4MEDIUMCVSS 6.5v10.0v11.02022-11-02
CVE-2022-43235 [MEDIUM] CWE-787 CVE-2022-43235: Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via ff_hevc_put_hevc_ Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via ff_hevc_put_hevc_epel_pixels_8_sse in sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.
nvd
CVE-2021-3912P4MEDIUMCVSS 6.5v11.02021-11-11
CVE-2021-3912 [MEDIUM] CWE-400 CVE-2021-3912: OctoRPKI tries to load the entire contents of a repository in memory, and in the case of a GZIP bomb OctoRPKI tries to load the entire contents of a repository in memory, and in the case of a GZIP bomb, unzip it in memory, making it possible to create a repository that makes OctoRPKI run out of memory (and thus crash).
nvd
CVE-2022-41804P4MEDIUMCVSS 6.7v11.0v12.02023-08-11
CVE-2022-41804 [MEDIUM] CWE-1334 CVE-2022-41804: Unauthorized error injection in Intel(R) SGX or Intel(R) TDX for some Intel(R) Xeon(R) Processors ma Unauthorized error injection in Intel(R) SGX or Intel(R) TDX for some Intel(R) Xeon(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
nvd
CVE-2010-4199P4HIGHCVSS 8.8v6.0v7.02010-11-06
CVE-2010-4199 [HIGH] CWE-20 CVE-2010-4199: Google Chrome before 7.0.517.44 does not properly perform a cast of an unspecified variable during p Google Chrome before 7.0.517.44 does not properly perform a cast of an unspecified variable during processing of an SVG use element, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted SVG document.
nvd
CVE-2021-28038P4MEDIUMCVSS 6.5v9.02021-03-05
CVE-2021-28038 [MEDIUM] CVE-2021-28038: An issue was discovered in the Linux kernel through 5.11.3, as used with Xen PV. A certain part of t An issue was discovered in the Linux kernel through 5.11.3, as used with Xen PV. A certain part of the netback driver lacks necessary treatment of errors such as failed memory allocations (as a result of changes to the handling of grant mapping errors). A host OS denial of service may occur during misbehavior of a networking frontend driver. NOTE: this issu
nvd
CVE-2015-2188P4MEDIUMCVSS 5.0v7.0v8.02015-03-08
CVE-2015-2188 [MEDIUM] CWE-19 CVE-2015-2188: epan/dissectors/packet-wcp.c in the WCP dissector in Wireshark 1.10.x before 1.10.13 and 1.12.x befo epan/dissectors/packet-wcp.c in the WCP dissector in Wireshark 1.10.x before 1.10.13 and 1.12.x before 1.12.4 does not properly initialize a data structure, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet that is improperly handled during decompression.
nvd
Debian Linux vulnerabilities | cvebase