Debian Linux vulnerabilities
9,955 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358
Vulnerabilities
Page 366 of 498
CVE-2019-9849P4MEDIUMCVSS 4.3v8.02019-07-17
CVE-2019-9849 [MEDIUM] CVE-2019-9849: LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed
LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed to retrieve remote resources. This mode is not the default mode, but can be enabled by users who want to disable LibreOffice's ability to include remote resources within a document. A flaw existed where bullet graphics were omitted from this protection prior t
nvd
CVE-2019-19269P4MEDIUMCVSS 4.9v8.02019-11-30
CVE-2019-19269 [MEDIUM] CWE-476 CVE-2019-19269: An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. A dereference of a NULL pointer
An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. A dereference of a NULL pointer may occur. This pointer is returned by the OpenSSL sk_X509_REVOKED_value() function when encountering an empty CRL installed by a system administrator. The dereference occurs when validating the certificate of a client connecting to the server in a T
nvd
CVE-2011-2501P4MEDIUMCVSS 6.5v5.0v6.02011-07-17
CVE-2011-2501 [MEDIUM] CVE-2011-2501: The png_format_buffer function in pngerror.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4
The png_format_buffer function in pngerror.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 allows remote attackers to cause a denial of service (application crash) via a crafted PNG image that triggers an out-of-bounds read during the copying of error-message data. NOTE: this vulnerability exists because of a C
nvd
CVE-2020-15863P4MEDIUMCVSS 5.3v10.02020-07-28
CVE-2020-15863 [MEDIUM] CWE-787 CVE-2020-15863: hw/net/xgmac.c in the XGMAC Ethernet controller in QEMU before 07-20-2020 has a buffer overflow. Thi
hw/net/xgmac.c in the XGMAC Ethernet controller in QEMU before 07-20-2020 has a buffer overflow. This occurs during packet transmission and affects the highbank and midway emulated machines. A guest user or process could use this flaw to crash the QEMU process on the host, resulting in a denial of service or potential privileged code execution. This
nvd
CVE-2014-3479P4MEDIUMCVSS 4.3v7.0v8.02014-07-09
CVE-2014-3479 [MEDIUM] CVE-2014-3479: The cdf_check_stream_offset function in cdf.c in file before 5.19, as used in the Fileinfo component
The cdf_check_stream_offset function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, relies on incorrect sector-size data, which allows remote attackers to cause a denial of service (application crash) via a crafted stream offset in a CDF file.
nvd
CVE-2017-8365P4MEDIUMCVSS 6.5v8.02017-04-30
CVE-2017-8365 [MEDIUM] CWE-125 CVE-2017-8365: The i2les_array function in pcm.c in libsndfile 1.0.28 allows remote attackers to cause a denial of
The i2les_array function in pcm.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted audio file.
nvd
CVE-2014-4341P4MEDIUMCVSS 5.0v7.02014-07-20
CVE-2014-4341 [MEDIUM] CWE-125 CVE-2014-4341: MIT Kerberos 5 (aka krb5) before 1.12.2 allows remote attackers to cause a denial of service (buffer
MIT Kerberos 5 (aka krb5) before 1.12.2 allows remote attackers to cause a denial of service (buffer over-read and application crash) by injecting invalid tokens into a GSSAPI application session.
nvd
CVE-2020-1774P4MEDIUMCVSS 4.9v8.02020-04-28
CVE-2020-1774 [MEDIUM] CWE-201 CVE-2020-1774: When user downloads PGP or S/MIME keys/certificates, exported file has same name for private and pub
When user downloads PGP or S/MIME keys/certificates, exported file has same name for private and public keys. Therefore it's possible to mix them and to send private key to the third-party instead of public key. This issue affects ((OTRS)) Community Edition: 5.0.42 and prior versions, 6.0.27 and prior versions. OTRS: 7.0.16 and prior versions.
nvd
CVE-2011-2834P4MEDIUMCVSS 6.8v5.0v6.0+1 more2011-09-19
CVE-2011-2834 [MEDIUM] CWE-415 CVE-2011-2834: Double free vulnerability in libxml2, as used in Google Chrome before 14.0.835.163, allows remote at
Double free vulnerability in libxml2, as used in Google Chrome before 14.0.835.163, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath handling.
nvd
CVE-2017-16899P4HIGHCVSS 7.1v8.0v9.02017-11-20
CVE-2017-16899 [HIGH] CWE-129 CVE-2017-16899: An array index error in the fig2dev program in Xfig 3.2.6a allows remote attackers to cause a denial
An array index error in the fig2dev program in Xfig 3.2.6a allows remote attackers to cause a denial-of-service attack or information disclosure with a maliciously crafted Fig format file, related to a negative font value in dev/gentikz.c, and the read_textobject functions in read.c and read1_3.c.
nvd
CVE-2022-29458P4HIGHCVSS 7.1v10.02022-04-18
CVE-2022-29458 [HIGH] CWE-125 CVE-2022-29458: ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_st
ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.
nvd
CVE-2015-8781P4MEDIUMCVSS 6.5v7.0v8.02016-02-01
CVE-2015-8781 [MEDIUM] CWE-787 CVE-2015-8781: tif_luv.c in libtiff allows attackers to cause a denial of service (out-of-bounds write) via an inva
tif_luv.c in libtiff allows attackers to cause a denial of service (out-of-bounds write) via an invalid number of samples per pixel in a LogL compressed TIFF image, a different vulnerability than CVE-2015-8782.
nvd
CVE-2019-13311P4MEDIUMCVSS 6.5v10.02019-07-05
CVE-2019-13311 [MEDIUM] CWE-401 CVE-2019-13311: ImageMagick 7.0.8-50 Q16 has memory leaks at AcquireMagickMemory because of a wand/mogrify.c error.
ImageMagick 7.0.8-50 Q16 has memory leaks at AcquireMagickMemory because of a wand/mogrify.c error.
nvd
CVE-2014-4342P4MEDIUMCVSS 5.0v7.02014-07-20
CVE-2014-4342 [MEDIUM] CWE-119 CVE-2014-4342: MIT Kerberos 5 (aka krb5) 1.7.x through 1.12.x before 1.12.2 allows remote attackers to cause a deni
MIT Kerberos 5 (aka krb5) 1.7.x through 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (buffer over-read or NULL pointer dereference, and application crash) by injecting invalid tokens into a GSSAPI application session.
nvd
CVE-2025-21502P4MEDIUMCVSS 4.8v11.02025-01-21
CVE-2025-21502 [MEDIUM] CWE-863 CVE-2025-21502: Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition produ
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u431-perf, 11.0.25, 17.0.13, 21.0.5, 23.0.1; Oracle GraalVM for JDK: 17.0.13, 21.0.5, 23.0.1; Oracle GraalVM Enterprise Edition: 20.3.16 and 21.3.12.
nvd
CVE-2019-13301P4MEDIUMCVSS 6.5v10.02019-07-05
CVE-2019-13301 [MEDIUM] CWE-401 CVE-2019-13301: ImageMagick 7.0.8-50 Q16 has memory leaks in AcquireMagickMemory because of an AnnotateImage error.
ImageMagick 7.0.8-50 Q16 has memory leaks in AcquireMagickMemory because of an AnnotateImage error.
nvd
CVE-2019-13309P4MEDIUMCVSS 6.5v10.02019-07-05
CVE-2019-13309 [MEDIUM] CWE-401 CVE-2019-13309: ImageMagick 7.0.8-50 Q16 has memory leaks at AcquireMagickMemory because of mishandling the NoSuchIm
ImageMagick 7.0.8-50 Q16 has memory leaks at AcquireMagickMemory because of mishandling the NoSuchImage error in CLIListOperatorImages in MagickWand/operation.c.
nvd
CVE-2019-6956P4HIGHCVSS 7.1v8.0v9.0+1 more2019-01-25
CVE-2019-6956 [HIGH] CWE-125 CVE-2019-6956: An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. It is a buffer over-read
An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. It is a buffer over-read in ps_mix_phase in libfaad/ps_dec.c.
nvd
CVE-2017-14528P4MEDIUMCVSS 6.5v9.02017-09-18
CVE-2017-14528 [MEDIUM] CWE-416 CVE-2017-14528: The TIFFSetProfiles function in coders/tiff.c in ImageMagick 7.0.6 has incorrect expectations about
The TIFFSetProfiles function in coders/tiff.c in ImageMagick 7.0.6 has incorrect expectations about whether LibTIFF TIFFGetField return values imply that data validation has occurred, which allows remote attackers to cause a denial of service (use-after-free after an invalid call to TIFFSetField, and application crash) via a crafted file.
nvd
CVE-2019-13222P4HIGHCVSS 7.1v10.02019-08-15
CVE-2019-13222 [HIGH] CWE-125 CVE-2019-13222: An out-of-bounds read of a global buffer in the draw_line function in stb_vorbis through 2019-03-04
An out-of-bounds read of a global buffer in the draw_line function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service or disclose sensitive information by opening a crafted Ogg Vorbis file.
nvd