Debian Linux vulnerabilities
9,955 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358
Vulnerabilities
Page 367 of 498
CVE-2006-0042P4MEDIUMCVSS 5.0v3.0v3.12006-02-18
CVE-2006-0042 [MEDIUM] CVE-2006-0042: Unspecified vulnerability in (1) apreq_parse_headers and (2) apreq_parse_urlencoded functions in Apa
Unspecified vulnerability in (1) apreq_parse_headers and (2) apreq_parse_urlencoded functions in Apache2::Request (Libapreq2) before 2.07 allows remote attackers to cause a denial of service (CPU consumption) via unknown attack vectors that result in quadratic computational complexity.
nvd
CVE-2004-0455P4HIGHCVSS 7.2v3.02004-12-06
CVE-2004-0455 [HIGH] CWE-120 CVE-2004-0455: Buffer overflow in cgi.c in www-sql before 0.5.7 allows local users to execute arbitrary code via a
Buffer overflow in cgi.c in www-sql before 0.5.7 allows local users to execute arbitrary code via a web page that is processed by www-sql.
nvd
CVE-2025-4598P4MEDIUMCVSS 4.7v11.0v12.02025-05-30
CVE-2025-4598 [MEDIUM] CWE-364 CVE-2025-4598: A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process
A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original's privileged process coredump, allowing the attacker to read sensitive data, such as /etc/shadow content, loaded by the original process.
A SUID binary or process has a special type o
nvd
CVE-2018-6621P4MEDIUMCVSS 6.5v8.0v9.02018-02-05
CVE-2018-6621 [MEDIUM] CWE-125 CVE-2018-6621: The decode_frame function in libavcodec/utvideodec.c in FFmpeg through 3.2 allows remote attackers t
The decode_frame function in libavcodec/utvideodec.c in FFmpeg through 3.2 allows remote attackers to cause a denial of service (out of array read) via a crafted AVI file.
nvd
CVE-2011-2818P4MEDIUMCVSS 6.8v6.0v7.02011-08-03
CVE-2011-2818 [MEDIUM] CWE-416 CVE-2011-2818: Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to display box rendering.
nvd
CVE-2018-19535P4MEDIUMCVSS 6.5v8.0v10.02018-11-26
CVE-2018-19535 [MEDIUM] CWE-125 CVE-2018-19535: In Exiv2 0.26 and previous versions, PngChunk::readRawProfile in pngchunk_int.cpp may cause a denial
In Exiv2 0.26 and previous versions, PngChunk::readRawProfile in pngchunk_int.cpp may cause a denial of service (application crash due to a heap-based buffer over-read) via a crafted PNG file.
nvd
CVE-2013-6645P4MEDIUMCVSS 6.8v7.0v8.02014-01-16
CVE-2013-6645 [MEDIUM] CWE-416 CVE-2013-6645: Use-after-free vulnerability in the OnWindowRemovingFromRootWindow function in content/browser/web_c
Use-after-free vulnerability in the OnWindowRemovingFromRootWindow function in content/browser/web_contents/web_contents_view_aura.cc in Google Chrome before 32.0.1700.76 on Windows and before 32.0.1700.77 on Mac OS X and Linux allows user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact via vectors invo
nvd
CVE-2017-17914P4MEDIUMCVSS 6.5v7.02017-12-27
CVE-2017-17914 [MEDIUM] CWE-834 CVE-2017-17914: In ImageMagick 7.0.7-16 Q16, a vulnerability was found in the function ReadOnePNGImage in coders/png
In ImageMagick 7.0.7-16 Q16, a vulnerability was found in the function ReadOnePNGImage in coders/png.c, which allows attackers to cause a denial of service (ReadOneMNGImage large loop) via a crafted mng image file.
nvd
CVE-2018-7876P4MEDIUMCVSS 6.5v7.02018-03-08
CVE-2018-7876 [MEDIUM] CWE-400 CVE-2018-7876: In libming 0.4.8, a memory exhaustion vulnerability was found in the function parseSWF_ACTIONRECORD
In libming 0.4.8, a memory exhaustion vulnerability was found in the function parseSWF_ACTIONRECORD in util/parser.c, which allows remote attackers to cause a denial of service via a crafted file.
nvd
CVE-2018-18897P4MEDIUMCVSS 6.5v10.02018-11-02
CVE-2018-18897 [MEDIUM] CWE-772 CVE-2018-18897: An issue was discovered in Poppler 0.71.0. There is a memory leak in GfxColorSpace::setDisplayProfil
An issue was discovered in Poppler 0.71.0. There is a memory leak in GfxColorSpace::setDisplayProfile in GfxState.cc, as demonstrated by pdftocairo.
nvd
CVE-2017-5612P4MEDIUMCVSS 6.1v8.0v9.02017-01-30
CVE-2017-5612 [MEDIUM] CWE-79 CVE-2017-5612: Cross-site scripting (XSS) vulnerability in wp-admin/includes/class-wp-posts-list-table.php in the p
Cross-site scripting (XSS) vulnerability in wp-admin/includes/class-wp-posts-list-table.php in the posts list table in WordPress before 4.7.2 allows remote attackers to inject arbitrary web script or HTML via a crafted excerpt.
nvd
CVE-2016-10742P4MEDIUMCVSS 6.1v8.02019-02-17
CVE-2016-10742 [MEDIUM] CWE-601 CVE-2016-10742: Zabbix before 2.2.21rc1, 3.x before 3.0.13rc1, 3.1.x and 3.2.x before 3.2.10rc1, and 3.3.x and 3.4.x
Zabbix before 2.2.21rc1, 3.x before 3.0.13rc1, 3.1.x and 3.2.x before 3.2.10rc1, and 3.3.x and 3.4.x before 3.4.4rc1 allows open redirect via the request parameter.
nvd
CVE-2017-14314P4MEDIUMCVSS 6.5v8.0v9.02017-09-12
CVE-2017-14314 [MEDIUM] CWE-125 CVE-2017-14314: Off-by-one error in the DrawImage function in magick/render.c in GraphicsMagick 1.3.26 allows remote
Off-by-one error in the DrawImage function in magick/render.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (DrawDashPolygon heap-based buffer over-read and application crash) via a crafted file.
nvd
CVE-2018-5251P4MEDIUMCVSS 6.5v7.02018-01-05
CVE-2018-5251 [MEDIUM] CWE-681 CVE-2018-5251: In libming 0.4.8, there is an integer signedness error vulnerability (left shift of a negative value
In libming 0.4.8, there is an integer signedness error vulnerability (left shift of a negative value) in the readSBits function (util/read.c). Remote attackers can leverage this vulnerability to cause a denial of service via a crafted swf file.
nvd
CVE-2018-7866P4MEDIUMCVSS 6.5v7.02018-03-08
CVE-2018-7866 [MEDIUM] CWE-476 CVE-2018-7866: A NULL pointer dereference was discovered in newVar3 in util/decompile.c in libming 0.4.8. The vulne
A NULL pointer dereference was discovered in newVar3 in util/decompile.c in libming 0.4.8. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.
nvd
CVE-2020-12625P4MEDIUMCVSS 6.1v9.0v10.02020-05-04
CVE-2020-12625 [MEDIUM] CWE-79 CVE-2020-12625: An issue was discovered in Roundcube Webmail before 1.4.4. There is a cross-site scripting (XSS) vul
An issue was discovered in Roundcube Webmail before 1.4.4. There is a cross-site scripting (XSS) vulnerability in rcube_washtml.php because JavaScript code can occur in the CDATA of an HTML message.
nvd
CVE-2018-9132P4MEDIUMCVSS 6.5v7.02018-03-30
CVE-2018-9132 [MEDIUM] CWE-476 CVE-2018-9132: libming 0.4.8 has a NULL pointer dereference in the getInt function of the decompile.c file. Remote
libming 0.4.8 has a NULL pointer dereference in the getInt function of the decompile.c file. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted swf file.
nvd
CVE-2017-18230P4MEDIUMCVSS 6.5v7.0v8.0+1 more2018-03-14
CVE-2017-18230 [MEDIUM] CWE-476 CVE-2017-18230: An issue was discovered in GraphicsMagick 1.3.26. A NULL pointer dereference vulnerability was found
An issue was discovered in GraphicsMagick 1.3.26. A NULL pointer dereference vulnerability was found in the function ReadCINEONImage in coders/cineon.c, which allows attackers to cause a denial of service via a crafted file.
nvd
CVE-2021-42096P4MEDIUMCVSS 4.3v10.02021-10-21
CVE-2021-42096 [MEDIUM] CWE-307 CVE-2021-42096: GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A certain csrf_token value is deriv
GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A certain csrf_token value is derived from the admin password, and may be useful in conducting a brute-force attack against that password.
nvd
CVE-2017-18231P4MEDIUMCVSS 6.5v7.0v8.0+1 more2018-03-14
CVE-2017-18231 [MEDIUM] CWE-476 CVE-2017-18231: An issue was discovered in GraphicsMagick 1.3.26. A NULL pointer dereference vulnerability was found
An issue was discovered in GraphicsMagick 1.3.26. A NULL pointer dereference vulnerability was found in the function ReadEnhMetaFile in coders/emf.c, which allows attackers to cause a denial of service via a crafted file.
nvd