Debian Linux vulnerabilities
9,955 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358
Vulnerabilities
Page 356 of 498
CVE-2014-1523P4MEDIUMCVSS 6.5v7.0v8.02014-04-30
CVE-2014-1523 [MEDIUM] CWE-787 CVE-2014-1523: Heap-based buffer overflow in the read_u32 function in Mozilla Firefox before 29.0, Firefox ESR 24.x
Heap-based buffer overflow in the read_u32 function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted JPEG image.
nvd
CVE-2004-1051P4HIGHCVSS 7.2v3.02005-03-01
CVE-2004-1051 [HIGH] CVE-2004-1051: sudo before 1.6.8p2 allows local users to execute arbitrary commands by using "()" style environment
sudo before 1.6.8p2 allows local users to execute arbitrary commands by using "()" style environment variables to create functions that have the same name as any program within the bash script that is called without using the program's full pathname.
nvd
CVE-2018-20622P4MEDIUMCVSS 6.5v8.02018-12-31
CVE-2018-20622 [MEDIUM] CWE-772 CVE-2018-20622: JasPer 2.0.14 has a memory leak in base/jas_malloc.c in libjasper.a when "--output-format jp2" is us
JasPer 2.0.14 has a memory leak in base/jas_malloc.c in libjasper.a when "--output-format jp2" is used.
nvd
CVE-2018-20584P4MEDIUMCVSS 6.5v8.02018-12-30
CVE-2018-20584 [MEDIUM] CVE-2018-20584: JasPer 2.0.14 allows remote attackers to cause a denial of service (application hang) via an attempt
JasPer 2.0.14 allows remote attackers to cause a denial of service (application hang) via an attempted conversion to the jp2 format.
nvd
CVE-2008-5506P4MEDIUMCVSS 6.8v4.0v5.02008-12-17
CVE-2008-5506 [MEDIUM] CWE-264 CVE-2008-5506: Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMo
Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to bypass the same origin policy by causing the browser to issue an XMLHttpRequest to an attacker-controlled resource that uses a 302 redirect to a resource in a different domain, then reading content from
nvd
CVE-2018-6869P4MEDIUMCVSS 6.5v7.02018-02-09
CVE-2018-6869 [MEDIUM] CWE-770 CVE-2018-6869: In ZZIPlib 0.13.68, there is an uncontrolled memory allocation and a crash in the __zzip_parse_root_
In ZZIPlib 0.13.68, there is an uncontrolled memory allocation and a crash in the __zzip_parse_root_directory function of zzip/zip.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted zip file.
nvd
CVE-2018-18520P4MEDIUMCVSS 6.5v8.0v9.02018-10-19
CVE-2018-18520 [MEDIUM] CWE-119 CVE-2018-18520: An Invalid Memory Address Dereference exists in the function elf_end in libelf in elfutils through v
An Invalid Memory Address Dereference exists in the function elf_end in libelf in elfutils through v0.174. Although eu-size is intended to support ar files inside ar files, handle_ar in size.c closes the outer ar file before handling all inner entries. The vulnerability allows attackers to cause a denial of service (application crash) with a crafted
nvd
CVE-2016-6161P4MEDIUMCVSS 6.5v8.02016-08-12
CVE-2016-6161 [MEDIUM] CWE-125 CVE-2016-6161: The output function in gd_gif_out.c in the GD Graphics Library (aka libgd) allows remote attackers t
The output function in gd_gif_out.c in the GD Graphics Library (aka libgd) allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted image.
nvd
CVE-2018-20650P4MEDIUMCVSS 6.5v8.0v9.0+1 more2019-01-01
CVE-2018-20650 [MEDIUM] CWE-20 CVE-2018-20650: A reachable Object::dictLookup assertion in Poppler 0.72.0 allows attackers to cause a denial of ser
A reachable Object::dictLookup assertion in Poppler 0.72.0 allows attackers to cause a denial of service due to the lack of a check for the dict data type, as demonstrated by use of the FileSpec class (in FileSpec.cc) in pdfdetach.
nvd
CVE-2015-8783P4MEDIUMCVSS 6.5v7.0v8.02016-02-01
CVE-2015-8783 [MEDIUM] CWE-125 CVE-2015-8783: tif_luv.c in libtiff allows attackers to cause a denial of service (out-of-bounds reads) via a craft
tif_luv.c in libtiff allows attackers to cause a denial of service (out-of-bounds reads) via a crafted TIFF image.
nvd
CVE-2015-1245P4MEDIUMCVSS 6.8v7.02015-04-19
CVE-2015-1245 [MEDIUM] CVE-2015-1245: Use-after-free vulnerability in the OpenPDFInReaderView::Update function in browser/ui/views/locatio
Use-after-free vulnerability in the OpenPDFInReaderView::Update function in browser/ui/views/location_bar/open_pdf_in_reader_view.cc in Google Chrome before 41.0.2272.76 might allow user-assisted remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact by triggering interaction with a PDFium "Open PDF in
nvd
CVE-2019-16710P4MEDIUMCVSS 6.5v10.02019-09-23
CVE-2019-16710 [MEDIUM] CWE-401 CVE-2019-16710: ImageMagick 7.0.8-35 has a memory leak in coders/dot.c, as demonstrated by AcquireMagickMemory in Ma
ImageMagick 7.0.8-35 has a memory leak in coders/dot.c, as demonstrated by AcquireMagickMemory in MagickCore/memory.c.
nvd
CVE-2019-16713P4MEDIUMCVSS 6.5v10.02019-09-23
CVE-2019-16713 [MEDIUM] CWE-401 CVE-2019-16713: ImageMagick 7.0.8-43 has a memory leak in coders/dot.c, as demonstrated by PingImage in MagickCore/c
ImageMagick 7.0.8-43 has a memory leak in coders/dot.c, as demonstrated by PingImage in MagickCore/constitute.c.
nvd
CVE-2019-13220P4HIGHCVSS 7.1v10.02019-08-15
CVE-2019-13220 [HIGH] CWE-908 CVE-2019-13220: Use of uninitialized stack variables in the start_decoder function in stb_vorbis through 2019-03-04
Use of uninitialized stack variables in the start_decoder function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service or disclose sensitive information by opening a crafted Ogg Vorbis file.
nvd
CVE-2018-10998P4MEDIUMCVSS 6.5v8.0v9.02018-05-12
CVE-2018-10998 [MEDIUM] CVE-2018-10998: An issue was discovered in Exiv2 0.26. readMetadata in jp2image.cpp allows remote attackers to cause
An issue was discovered in Exiv2 0.26. readMetadata in jp2image.cpp allows remote attackers to cause a denial of service (SIGABRT) by triggering an incorrect Safe::add call.
nvd
CVE-2007-2138P4MEDIUMCVSS 6.0v3.1v4.02007-04-24
CVE-2007-2138 [MEDIUM] CWE-264 CVE-2007-2138: Untrusted search path vulnerability in PostgreSQL before 7.3.19, 7.4.x before 7.4.17, 8.0.x before 8
Untrusted search path vulnerability in PostgreSQL before 7.3.19, 7.4.x before 7.4.17, 8.0.x before 8.0.13, 8.1.x before 8.1.9, and 8.2.x before 8.2.4 allows remote authenticated users, when permitted to call a SECURITY DEFINER function, to gain the privileges of the function owner, related to "search_path settings."
nvd
CVE-2018-10001P4MEDIUMCVSS 6.5v9.02018-04-11
CVE-2018-10001 [MEDIUM] CWE-125 CVE-2018-10001: The decode_init function in libavcodec/utvideodec.c in FFmpeg through 3.4.2 allows remote attackers
The decode_init function in libavcodec/utvideodec.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial of service (out of array read) via an AVI file.
nvd
CVE-2017-14504P4MEDIUMCVSS 6.5v8.0v9.02017-09-17
CVE-2017-14504 [MEDIUM] CWE-476 CVE-2017-14504: ReadPNMImage in coders/pnm.c in GraphicsMagick 1.3.26 does not ensure the correct number of colors f
ReadPNMImage in coders/pnm.c in GraphicsMagick 1.3.26 does not ensure the correct number of colors for the XV 332 format, leading to a NULL Pointer Dereference.
nvd
CVE-2011-1440P4MEDIUMCVSS 6.8v6.0v7.02011-05-03
CVE-2011-1440 [MEDIUM] CWE-416 CVE-2011-1440: Use-after-free vulnerability in Google Chrome before 11.0.696.57 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 11.0.696.57 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the ruby element and Cascading Style Sheets (CSS) token sequences.
nvd
CVE-2018-5785P4MEDIUMCVSS 6.5v9.02018-01-19
CVE-2018-5785 [MEDIUM] CWE-190 CVE-2018-5785: In OpenJPEG 2.3.0, there is an integer overflow caused by an out-of-bounds left shift in the opj_j2k
In OpenJPEG 2.3.0, there is an integer overflow caused by an out-of-bounds left shift in the opj_j2k_setup_encoder function (openjp2/j2k.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file.
nvd