cbcvebase.

Debian Linux vulnerabilities

9,955 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358

Vulnerabilities

Page 358 of 498
CVE-2018-5685P4MEDIUMCVSS 6.5v7.0v8.0+1 more2018-01-14
CVE-2018-5685 [MEDIUM] CWE-835 CVE-2018-5685: In GraphicsMagick 1.3.27, there is an infinite loop and application hang in the ReadBMPImage functio In GraphicsMagick 1.3.27, there is an infinite loop and application hang in the ReadBMPImage function (coders/bmp.c). Remote attackers could leverage this vulnerability to cause a denial of service via an image file with a crafted bit-field mask value.
nvd
CVE-2019-13137P4MEDIUMCVSS 6.5v10.02019-07-01
CVE-2019-13137 [MEDIUM] CWE-401 CVE-2019-13137: ImageMagick before 7.0.8-50 has a memory leak vulnerability in the function ReadPSImage in coders/ps ImageMagick before 7.0.8-50 has a memory leak vulnerability in the function ReadPSImage in coders/ps.c.
nvd
CVE-2018-5294P4MEDIUMCVSS 6.5v7.02018-01-08
CVE-2018-5294 [MEDIUM] CWE-190 CVE-2018-5294: In libming 0.4.8, there is an integer overflow (caused by an out-of-range left shift) in the readUIn In libming 0.4.8, there is an integer overflow (caused by an out-of-range left shift) in the readUInt32 function (util/read.c). Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted swf file.
nvd
CVE-2018-19058P4MEDIUMCVSS 6.5v8.0v9.0+1 more2018-11-07
CVE-2018-19058 [MEDIUM] CWE-670 CVE-2018-19058: An issue was discovered in Poppler 0.71.0. There is a reachable abort in Object.h, will lead to deni An issue was discovered in Poppler 0.71.0. There is a reachable abort in Object.h, will lead to denial of service because EmbFile::save2 in FileSpec.cc lacks a stream check before saving an embedded file.
nvd
CVE-2018-10100P4MEDIUMCVSS 6.1v8.0v9.02018-04-16
CVE-2018-10100 [MEDIUM] CWE-601 CVE-2018-10100: Before WordPress 4.9.5, the redirection URL for the login page was not validated or sanitized if for Before WordPress 4.9.5, the redirection URL for the login page was not validated or sanitized if forced to use HTTPS.
nvd
CVE-2015-1288P4MEDIUMCVSS 6.8v8.02015-07-23
CVE-2015-1288 [MEDIUM] CVE-2015-1288: The Spellcheck API implementation in Google Chrome before 44.0.2403.89 does not use an HTTPS session The Spellcheck API implementation in Google Chrome before 44.0.2403.89 does not use an HTTPS session for downloading a Hunspell dictionary, which allows man-in-the-middle attackers to deliver incorrect spelling suggestions or possibly have unspecified other impact via a crafted file, a related issue to CVE-2015-1263.
nvd
CVE-2019-3874P4MEDIUMCVSS 6.5v8.02019-03-25
CVE-2019-3874 [MEDIUM] CWE-400 CVE-2019-3874: The SCTP socket buffer used by a userspace application is not accounted by the cgroups subsystem. An The SCTP socket buffer used by a userspace application is not accounted by the cgroups subsystem. An attacker can use this flaw to cause a denial of service attack. Kernel 3.10.x and 4.18.x branches are believed to be vulnerable.
nvd
CVE-2017-13065P4MEDIUMCVSS 6.5v8.0v9.02017-08-22
CVE-2017-13065 [MEDIUM] CWE-476 CVE-2017-13065: GraphicsMagick 1.3.26 has a NULL pointer dereference vulnerability in the function SVGStartElement i GraphicsMagick 1.3.26 has a NULL pointer dereference vulnerability in the function SVGStartElement in coders/svg.c.
nvd
CVE-2018-6392P4MEDIUMCVSS 6.5v9.02018-01-29
CVE-2018-6392 [MEDIUM] CWE-125 CVE-2018-6392: The filter_slice function in libavfilter/vf_transpose.c in FFmpeg through 3.4.1 allows remote attack The filter_slice function in libavfilter/vf_transpose.c in FFmpeg through 3.4.1 allows remote attackers to cause a denial of service (out-of-array access) via a crafted MP4 file.
nvd
CVE-2022-27337P4MEDIUMCVSS 6.5v10.0v11.02022-05-05
CVE-2022-27337 [MEDIUM] CVE-2022-27337: A logic error in the Hints::Hints function of Poppler v22.03.0 allows attackers to cause a Denial of A logic error in the Hints::Hints function of Poppler v22.03.0 allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.
nvd
CVE-2020-22037P4MEDIUMCVSS 6.5v9.0v10.0+1 more2021-06-01
CVE-2020-22037 [MEDIUM] CWE-401 CVE-2020-22037: A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in avcodec_alloc_context A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in avcodec_alloc_context3 at options.c.
nvd
CVE-2017-18249P4HIGHCVSS 7.0v8.02018-03-26
CVE-2017-18249 [HIGH] CWE-362 CVE-2017-18249: The add_free_nid function in fs/f2fs/node.c in the Linux kernel before 4.12 does not properly track The add_free_nid function in fs/f2fs/node.c in the Linux kernel before 4.12 does not properly track an allocated nid, which allows local users to cause a denial of service (race condition) or possibly have unspecified other impact via concurrent threads.
nvd
CVE-2012-5521P4MEDIUMCVSS 6.5v8.0v9.0+1 more2019-11-25
CVE-2012-5521 [MEDIUM] CWE-617 CVE-2012-5521: quagga (ospf6d) 0.99.21 has a DoS flaw in the way the ospf6d daemon performs routes removal quagga (ospf6d) 0.99.21 has a DoS flaw in the way the ospf6d daemon performs routes removal
nvd
CVE-2018-19787P4MEDIUMCVSS 6.1v8.02018-12-02
CVE-2018-19787 [MEDIUM] CVE-2018-19787: An issue was discovered in lxml before 4.2.5. lxml/html/clean.py in the lxml.html.clean module does An issue was discovered in lxml before 4.2.5. lxml/html/clean.py in the lxml.html.clean module does not remove javascript: URLs that use escaping, allowing a remote attacker to conduct XSS attacks, as demonstrated by "j a v a s c r i p t:" in Internet Explorer. This is a similar issue to CVE-2014-3146.
nvd
CVE-2018-8099P4MEDIUMCVSS 6.5v9.02018-03-14
CVE-2018-8099 [MEDIUM] CWE-415 CVE-2018-8099: Incorrect returning of an error code in the index.c:read_entry() function leads to a double free in Incorrect returning of an error code in the index.c:read_entry() function leads to a double free in libgit2 before v0.26.2, which allows an attacker to cause a denial of service via a crafted repository index file.
nvd
CVE-2020-22026P4MEDIUMCVSS 6.5v9.0v10.02021-05-26
CVE-2020-22026 [MEDIUM] CWE-120 CVE-2020-22026: Buffer Overflow vulnerability exists in FFmpeg 4.2 in the config_input function at libavfilter/af_tr Buffer Overflow vulnerability exists in FFmpeg 4.2 in the config_input function at libavfilter/af_tremolo.c, which could let a remote malicious user cause a Denial of Service.
nvd
CVE-2016-1686P4MEDIUMCVSS 6.5v8.02016-06-05
CVE-2016-1686 [MEDIUM] CWE-119 CVE-2016-1686: The CPDF_DIBSource::CreateDecoder function in core/fpdfapi/fpdf_render/fpdf_render_loadimage.cpp in The CPDF_DIBSource::CreateDecoder function in core/fpdfapi/fpdf_render/fpdf_render_loadimage.cpp in PDFium, as used in Google Chrome before 51.0.2704.63, mishandles decoder-initialization failure, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PDF document.
nvd
CVE-2019-19531P4MEDIUMCVSS 6.8v8.02019-12-03
CVE-2019-19531 [MEDIUM] CWE-416 CVE-2019-19531: In the Linux kernel before 5.2.9, there is a use-after-free bug that can be caused by a malicious US In the Linux kernel before 5.2.9, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/usb/misc/yurex.c driver, aka CID-fc05481b2fca.
nvd
CVE-2015-6748P4MEDIUMCVSS 6.1v8.02017-09-25
CVE-2015-6748 [MEDIUM] CWE-79 CVE-2015-6748: Cross-site scripting (XSS) vulnerability in jsoup before 1.8.3. Cross-site scripting (XSS) vulnerability in jsoup before 1.8.3.
nvd
CVE-2021-28694P4MEDIUMCVSS 6.8v11.02021-08-27
CVE-2021-28694 [MEDIUM] CVE-2021-28694: IOMMU page mapping issues on x86 T[his CNA information record relates to multiple CVEs; the text exp IOMMU page mapping issues on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Both AMD and Intel allow ACPI tables to specify regions of memory which should be left untranslated, which typically means these addresses should pass the translation phase unaltered. While these a
nvd
Debian Linux vulnerabilities | cvebase