cbcvebase.

Debian Linux vulnerabilities

9,955 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358

Vulnerabilities

Page 363 of 498
CVE-2022-34674P4MEDIUMCVSS 6.1v10.02022-12-30
CVE-2022-34674 [MEDIUM] CWE-200 CVE-2022-34674: NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where a helper function maps more physical pages than were requested, which may lead to undefined behavior or an information leak.
nvd
CVE-2017-6817P4MEDIUMCVSS 5.4v8.0v9.02017-03-12
CVE-2017-6817 [MEDIUM] CWE-79 CVE-2017-6817: In WordPress before 4.7.3 (wp-includes/embed.php), there is authenticated Cross-Site Scripting (XSS) In WordPress before 4.7.3 (wp-includes/embed.php), there is authenticated Cross-Site Scripting (XSS) in YouTube URL Embeds.
nvd
CVE-2019-1787P4MEDIUMCVSS 5.5v8.02019-04-08
CVE-2019-1787 [MEDIUM] CWE-20 CVE-2019-1787: A vulnerability in the Portable Document Format (PDF) scanning functionality of Clam AntiVirus (Clam A vulnerability in the Portable Document Format (PDF) scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and prior could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a lack of proper data handling mechanisms within the device buffer whi
nvd
CVE-2020-27843P4MEDIUMCVSS 5.5v9.0v10.02021-01-05
CVE-2020-27843 [MEDIUM] CWE-125 CVE-2020-27843: A flaw was found in OpenJPEG in versions prior to 2.4.0. This flaw allows an attacker to provide spe A flaw was found in OpenJPEG in versions prior to 2.4.0. This flaw allows an attacker to provide specially crafted input to the conversion or encoding functionality, causing an out-of-bounds read. The highest threat from this vulnerability is system availability.
nvd
CVE-2014-1491P4MEDIUMCVSS 4.3v7.0v8.02014-02-06
CVE-2014-1491 [MEDIUM] CWE-326 CVE-2014-1491: Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firef Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, does not properly restrict public values in Diffie-Hellman key exchanges, which makes it easier for remote attackers to bypass cryptographic protection mechanis
nvd
CVE-2019-11717P4MEDIUMCVSS 5.3v8.02019-07-23
CVE-2019-11717 [MEDIUM] CWE-116 CVE-2019-11717: A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for possible spoofing of origin attributes. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
nvd
CVE-2019-2975P4MEDIUMCVSS 4.8v9.0v10.02019-10-16
CVE-2019-2975 [MEDIUM] CVE-2019-2975: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Scripting). Sup Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Scripting). Supported versions that are affected are Java SE: 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attac
nvd
CVE-2017-3635P4MEDIUMCVSS 5.3v8.02017-08-08
CVE-2017-3635 [MEDIUM] CVE-2017-3635: Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/C). Support Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/C). Supported versions that are affected are 6.1.10 and earlier. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorize
nvd
CVE-2017-7764P4MEDIUMCVSS 5.3v8.0v9.02018-06-11
CVE-2017-7764 [MEDIUM] CWE-20 CVE-2017-7764: Characters from the "Canadian Syllabics" unicode block can be mixed with characters from other unico Characters from the "Canadian Syllabics" unicode block can be mixed with characters from other unicode blocks in the addressbar instead of being rendered as their raw "punycode" form, allowing for domain name spoofing attacks through character confusion. The current Unicode standard allows characters from "Aspirational Use Scripts" such as Canadian Syl
nvd
CVE-2019-20208P4MEDIUMCVSS 5.5v8.02020-01-02
CVE-2019-20208 [MEDIUM] CWE-787 CVE-2019-20208: dimC_Read in isomedia/box_code_3gpp.c in GPAC from 0.5.2 to 0.8.0 has a stack-based buffer overflow. dimC_Read in isomedia/box_code_3gpp.c in GPAC from 0.5.2 to 0.8.0 has a stack-based buffer overflow.
nvd
CVE-2018-16539P4MEDIUMCVSS 5.5v8.0v9.02018-09-05
CVE-2018-16539 [MEDIUM] CWE-200 CVE-2018-16539: In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use inco In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use incorrect access checking in temp file handling to disclose contents of files on the system otherwise not readable.
nvd
CVE-2007-2691P4MEDIUMCVSS 4.9v3.1v4.02007-05-16
CVE-2007-2691 [MEDIUM] CVE-2007-2691: MySQL before 4.1.23, 5.0.x before 5.0.42, and 5.1.x before 5.1.18 does not require the DROP privileg MySQL before 4.1.23, 5.0.x before 5.0.42, and 5.1.x before 5.1.18 does not require the DROP privilege for RENAME TABLE statements, which allows remote authenticated users to rename arbitrary tables.
nvd
CVE-2019-16738P4MEDIUMCVSS 5.3v9.0v10.02019-09-26
CVE-2019-16738 [MEDIUM] CWE-862 CVE-2019-16738: In MediaWiki through 1.33.0, Special:Redirect allows information disclosure of suppressed usernames In MediaWiki through 1.33.0, Special:Redirect allows information disclosure of suppressed usernames via a User ID Lookup.
nvd
CVE-2020-11095P4MEDIUMCVSS 5.4v10.02020-06-22
CVE-2020-11095 [MEDIUM] CWE-125 CVE-2020-11095: In FreeRDP before version 2.1.2, an out of bound reads occurs resulting in accessing a memory locati In FreeRDP before version 2.1.2, an out of bound reads occurs resulting in accessing a memory location that is outside of the boundaries of the static array PRIMARY_DRAWING_ORDER_FIELD_BYTES. This is fixed in version 2.1.2.
nvd
CVE-2020-11086P4MEDIUMCVSS 5.4v10.02020-05-29
CVE-2020-11086 [MEDIUM] CWE-125 CVE-2020-11086: In FreeRDP less than or equal to 2.0.0, there is an out-of-bound read in ntlm_read_ntlm_v2_client_ch In FreeRDP less than or equal to 2.0.0, there is an out-of-bound read in ntlm_read_ntlm_v2_client_challenge that reads up to 28 bytes out-of-bound to an internal structure. This has been fixed in 2.1.0.
nvd
CVE-2020-11097P4MEDIUMCVSS 5.4v10.02020-06-22
CVE-2020-11097 [MEDIUM] CWE-125 CVE-2020-11097: In FreeRDP before version 2.1.2, an out of bounds read occurs resulting in accessing a memory locati In FreeRDP before version 2.1.2, an out of bounds read occurs resulting in accessing a memory location that is outside of the boundaries of the static array PRIMARY_DRAWING_ORDER_FIELD_BYTES. This is fixed in version 2.1.2.
nvd
CVE-2022-0544P4MEDIUMCVSS 5.5v9.0v10.02022-02-24
CVE-2022-0544 [MEDIUM] CWE-191 CVE-2022-0544: An integer underflow in the DDS loader of Blender leads to an out-of-bounds read, possibly allowing An integer underflow in the DDS loader of Blender leads to an out-of-bounds read, possibly allowing an attacker to read sensitive data using a crafted DDS image file. This flaw affects Blender versions prior to 2.83.19, 2.93.8 and 3.1.
nvd
CVE-2019-16781P4MEDIUMCVSS 5.4v9.0v10.02019-12-26
CVE-2019-16781 [MEDIUM] CWE-79 CVE-2019-16781: In WordPress before 5.3.1, authenticated users with lower privileges (like contributors) can inject In WordPress before 5.3.1, authenticated users with lower privileges (like contributors) can inject JavaScript code in the block editor, which is executed within the dashboard. It can lead to an admin opening the affected post in the editor leading to XSS.
nvd
CVE-2014-0459P4MEDIUMCVSS 4.3v6.0v7.0+1 more2014-04-16
CVE-2014-0459 [MEDIUM] CVE-2014-0459: Unspecified vulnerability in Oracle Java SE 7u51 and 8, and Java SE Embedded 7u51, allows remote att Unspecified vulnerability in Oracle Java SE 7u51 and 8, and Java SE Embedded 7u51, allows remote attackers to affect availability via unknown vectors related to 2D.
nvd
CVE-2017-8812P4MEDIUMCVSS 5.3v9.02017-11-15
CVE-2017-8812 [MEDIUM] CVE-2017-8812: MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows remote attackers to i MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows remote attackers to inject > (greater than) characters via the id attribute of a headline.
nvd
Debian Linux vulnerabilities | cvebase