cbcvebase.

Debian Linux vulnerabilities

9,955 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358

Vulnerabilities

Page 357 of 498
CVE-2015-1282P4MEDIUMCVSS 6.8v8.02015-07-23
CVE-2015-1282 [MEDIUM] CVE-2015-1282: Multiple use-after-free vulnerabilities in fpdfsdk/src/javascript/Document.cpp in PDFium, as used in Multiple use-after-free vulnerabilities in fpdfsdk/src/javascript/Document.cpp in PDFium, as used in Google Chrome before 44.0.2403.89, allow remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted PDF document, related to the (1) Document::delay and (2) Document::DoFieldDelay functions.
nvd
CVE-2016-2073P4MEDIUMCVSS 6.5v8.02016-02-12
CVE-2016-2073 [MEDIUM] CWE-119 CVE-2016-2073: The htmlParseNameComplex function in HTMLparser.c in libxml2 allows attackers to cause a denial of s The htmlParseNameComplex function in HTMLparser.c in libxml2 allows attackers to cause a denial of service (out-of-bounds read) via a crafted XML document.
nvd
CVE-2018-16749P4MEDIUMCVSS 6.5v8.0v9.02018-09-09
CVE-2018-16749 [MEDIUM] CWE-476 CVE-2018-16749: In ImageMagick 7.0.7-29 and earlier, a missing NULL check in ReadOneJNGImage in coders/png.c allows In ImageMagick 7.0.7-29 and earlier, a missing NULL check in ReadOneJNGImage in coders/png.c allows an attacker to cause a denial of service (WriteBlob assertion failure and application exit) via a crafted file.
nvd
CVE-2007-1321P4HIGHCVSS 7.2v3.1v4.02007-10-30
CVE-2007-1321 [HIGH] CVE-2007-1321: Integer signedness error in the NE2000 emulator in QEMU 0.8.2, as used in Xen and possibly other pro Integer signedness error in the NE2000 emulator in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to trigger a heap-based buffer overflow via certain register values that bypass sanity checks, aka QEMU NE2000 "receive" integer signedness error. NOTE: this identifier was inadvertently used by some sources to cover multiple issues that
nvd
CVE-2015-1255P4MEDIUMCVSS 6.8v8.02015-05-20
CVE-2015-1255 [MEDIUM] CVE-2015-1255: Use-after-free vulnerability in content/renderer/media/webaudio_capturer_source.cc in the WebAudio i Use-after-free vulnerability in content/renderer/media/webaudio_capturer_source.cc in the WebAudio implementation in Google Chrome before 43.0.2357.65 allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact by leveraging improper handling of a stop action for an audio track.
nvd
CVE-2015-4819P4HIGHCVSS 7.2v7.0v8.02015-10-21
CVE-2015-4819 [HIGH] CVE-2015-4819: Unspecified vulnerability in Oracle MySQL Server 5.5.44 and earlier, and 5.6.25 and earlier, allows Unspecified vulnerability in Oracle MySQL Server 5.5.44 and earlier, and 5.6.25 and earlier, allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Client programs.
nvd
CVE-2009-0029P4HIGHCVSS 7.2v4.0v5.02009-01-15
CVE-2009-0029 [HIGH] CWE-20 CVE-2009-0029: The ABI in the Linux kernel 2.6.28 and earlier on s390, powerpc, sparc64, and mips 64-bit platforms The ABI in the Linux kernel 2.6.28 and earlier on s390, powerpc, sparc64, and mips 64-bit platforms requires that a 32-bit argument in a 64-bit register was properly sign extended when sent from a user-mode application, but cannot verify this, which allows local users to cause a denial of service (crash) or possibly gain privileges via a crafted system ca
nvd
CVE-2015-7500P4MEDIUMCVSS 5.0v7.0v8.02015-12-15
CVE-2015-7500 [MEDIUM] CWE-119 CVE-2015-7500: The xmlParseMisc function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to The xmlParseMisc function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (out-of-bounds heap read) via unspecified vectors related to incorrect entities boundaries and start tags.
nvd
CVE-2019-11474P4MEDIUMCVSS 6.5v8.0v9.0+1 more2019-04-23
CVE-2019-11474 [MEDIUM] CVE-2019-11474: coders/xwd.c in GraphicsMagick 1.3.31 allows attackers to cause a denial of service (floating-point coders/xwd.c in GraphicsMagick 1.3.31 allows attackers to cause a denial of service (floating-point exception and application crash) by crafting an XWD image file, a different vulnerability than CVE-2019-11008 and CVE-2019-11009.
nvd
CVE-2015-0247P4MEDIUMCVSS 4.6v7.02015-02-17
CVE-2015-0247 [MEDIUM] CWE-119 CVE-2015-0247: Heap-based buffer overflow in openfs.c in the libext2fs library in e2fsprogs before 1.42.12 allows l Heap-based buffer overflow in openfs.c in the libext2fs library in e2fsprogs before 1.42.12 allows local users to execute arbitrary code via crafted block group descriptor data in a filesystem image.
nvd
CVE-2019-13114P4MEDIUMCVSS 6.5v10.02019-06-30
CVE-2019-13114 [MEDIUM] CWE-476 CVE-2019-13114: http.c in Exiv2 through 0.27.1 allows a malicious http server to cause a denial of service (crash du http.c in Exiv2 through 0.27.1 allows a malicious http server to cause a denial of service (crash due to a NULL pointer dereference) by returning a crafted response that lacks a space character.
nvd
CVE-2018-8976P4MEDIUMCVSS 6.5v10.02018-03-25
CVE-2018-8976 [MEDIUM] CWE-125 CVE-2018-8976: In Exiv2 0.26, jpgimage.cpp allows remote attackers to cause a denial of service (image.cpp Exiv2::I In Exiv2 0.26, jpgimage.cpp allows remote attackers to cause a denial of service (image.cpp Exiv2::Internal::stringFormat out-of-bounds read) via a crafted file.
nvd
CVE-2018-19661P4MEDIUMCVSS 6.5v8.02018-11-29
CVE-2018-19661 [MEDIUM] CWE-125 CVE-2018-19661: An issue was discovered in libsndfile 1.0.28. There is a buffer over-read in the function i2ulaw_arr An issue was discovered in libsndfile 1.0.28. There is a buffer over-read in the function i2ulaw_array in ulaw.c that will lead to a denial of service.
nvd
CVE-2018-18088P4MEDIUMCVSS 6.5v8.0v9.02018-10-09
CVE-2018-18088 [MEDIUM] CWE-476 CVE-2018-18088: OpenJPEG 2.3.0 has a NULL pointer dereference for "red" in the imagetopnm function of jp2/convert.c OpenJPEG 2.3.0 has a NULL pointer dereference for "red" in the imagetopnm function of jp2/convert.c
nvd
CVE-2016-1688P4MEDIUMCVSS 6.5v8.02016-06-05
CVE-2016-1688 [MEDIUM] CWE-119 CVE-2016-1688: The regexp (aka regular expression) implementation in Google V8 before 5.0.71.40, as used in Google The regexp (aka regular expression) implementation in Google V8 before 5.0.71.40, as used in Google Chrome before 51.0.2704.63, mishandles external string sizes, which allows remote attackers to cause a denial of service (out-of-bounds read) via crafted JavaScript code.
nvd
CVE-2017-14733P4MEDIUMCVSS 6.5v8.0v9.02017-09-25
CVE-2017-14733 [MEDIUM] CWE-125 CVE-2017-14733: ReadRLEImage in coders/rle.c in GraphicsMagick 1.3.26 mishandles RLE headers that specify too few co ReadRLEImage in coders/rle.c in GraphicsMagick 1.3.26 mishandles RLE headers that specify too few colors, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.
nvd
CVE-2013-0900P4MEDIUMCVSS 6.8v6.02013-02-23
CVE-2013-0900 [MEDIUM] CWE-362 CVE-2013-0900: Race condition in the International Components for Unicode (ICU) functionality in Google Chrome befo Race condition in the International Components for Unicode (ICU) functionality in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2017-9989P4MEDIUMCVSS 6.5v7.02017-06-28
CVE-2017-9989 [MEDIUM] CWE-476 CVE-2017-9989: util/outputtxt.c in libming 0.4.8 mishandles memory allocation. A crafted input will lead to a remot util/outputtxt.c in libming 0.4.8 mishandles memory allocation. A crafted input will lead to a remote denial of service (NULL pointer dereference) attack.
nvd
CVE-2019-13112P4MEDIUMCVSS 6.5v10.02019-06-30
CVE-2019-13112 [MEDIUM] CWE-770 CVE-2019-13112: A PngChunk::parseChunkContent uncontrolled memory allocation in Exiv2 through 0.27.1 allows an attac A PngChunk::parseChunkContent uncontrolled memory allocation in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (crash due to an std::bad_alloc exception) via a crafted PNG image file.
nvd
CVE-2018-19542P4MEDIUMCVSS 6.5v8.02018-11-26
CVE-2018-19542 [MEDIUM] CWE-476 CVE-2018-19542: An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function jp2_de An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function jp2_decode in libjasper/jp2/jp2_dec.c, leading to a denial of service.
nvd
Debian Linux vulnerabilities | cvebase