cbcvebase.

Debian Linux vulnerabilities

9,955 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358

Vulnerabilities

Page 368 of 498
CVE-2015-0861P4MEDIUMCVSS 4.3v8.02016-04-13
CVE-2015-0861 [MEDIUM] CWE-264 CVE-2015-0861: model/modelstorage.py in trytond 3.2.x before 3.2.10, 3.4.x before 3.4.8, 3.6.x before 3.6.5, and 3. model/modelstorage.py in trytond 3.2.x before 3.2.10, 3.4.x before 3.4.8, 3.6.x before 3.6.5, and 3.8.x before 3.8.1 allows remote authenticated users to bypass intended access restrictions and write to arbitrary fields via a sequence of records.
nvd
CVE-2010-3689P4MEDIUMCVSS 6.9v5.0v6.02011-01-28
CVE-2010-3689 [MEDIUM] CWE-22 CVE-2010-3689: soffice in OpenOffice.org (OOo) 3.x before 3.3 places a zero-length directory name in the LD_LIBRARY soffice in OpenOffice.org (OOo) 3.x before 3.3 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
nvd
CVE-2019-16220P4MEDIUMCVSS 6.1v8.0v9.0+1 more2019-09-11
CVE-2019-16220 [MEDIUM] CWE-601 CVE-2019-16220: In WordPress before 5.2.3, validation and sanitization of a URL in wp_validate_redirect in wp-includ In WordPress before 5.2.3, validation and sanitization of a URL in wp_validate_redirect in wp-includes/pluggable.php could lead to an open redirect if a provided URL path does not start with a forward slash.
nvd
CVE-2022-0865P4MEDIUMCVSS 6.5v10.0v11.02022-03-10
CVE-2022-0865 [MEDIUM] CWE-617 CVE-2022-0865: Reachable Assertion in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service via a c Reachable Assertion in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 5e180045.
nvd
CVE-2021-40732P4MEDIUMCVSS 6.1v10.02021-10-13
CVE-2021-40732 [MEDIUM] CWE-476 CVE-2021-40732: XMP Toolkit version 2020.1 (and earlier) is affected by a null pointer dereference vulnerability tha XMP Toolkit version 2020.1 (and earlier) is affected by a null pointer dereference vulnerability that could result in leaking data from certain memory locations and causing a local denial of service in the context of the current user. User interaction is required to exploit this vulnerability in that the victim will need to open a specially crafted
nvd
CVE-2014-8159P4MEDIUMCVSS 6.9v7.0v8.02015-03-16
CVE-2014-8159 [MEDIUM] CWE-264 CVE-2014-8159: The InfiniBand (IB) implementation in the Linux kernel package before 2.6.32-504.12.2 on Red Hat Ent The InfiniBand (IB) implementation in the Linux kernel package before 2.6.32-504.12.2 on Red Hat Enterprise Linux (RHEL) 6 does not properly restrict use of User Verbs for registration of memory regions, which allows local users to access arbitrary physical memory locations, and consequently cause a denial of service (system crash) or gain privileges,
nvd
CVE-2017-13769P4MEDIUMCVSS 6.5v8.0v9.02017-08-30
CVE-2017-13769 [MEDIUM] CWE-125 CVE-2017-13769: The WriteTHUMBNAILImage function in coders/thumbnail.c in ImageMagick through 7.0.6-10 allows an att The WriteTHUMBNAILImage function in coders/thumbnail.c in ImageMagick through 7.0.6-10 allows an attacker to cause a denial of service (buffer over-read) by sending a crafted JPEG file.
nvd
CVE-2010-3859P4MEDIUMCVSS 6.9v5.02010-12-29
CVE-2010-3859 [MEDIUM] CWE-787 CVE-2010-3859: Multiple integer signedness errors in the TIPC implementation in the Linux kernel before 2.6.36.2 al Multiple integer signedness errors in the TIPC implementation in the Linux kernel before 2.6.36.2 allow local users to gain privileges via a crafted sendmsg call that triggers a heap-based buffer overflow, related to the tipc_msg_build function in net/tipc/msg.c and the verify_iovec function in net/core/iovec.c.
nvd
CVE-2018-21016P4MEDIUMCVSS 6.5v8.02019-09-16
CVE-2018-21016 [MEDIUM] CWE-125 CVE-2018-21016: audio_sample_entry_AddBox() at isomedia/box_code_base.c in GPAC 0.7.1 allows remote attackers to cau audio_sample_entry_AddBox() at isomedia/box_code_base.c in GPAC 0.7.1 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.
nvd
CVE-2018-11496P4MEDIUMCVSS 6.5v9.02018-05-26
CVE-2018-11496 [MEDIUM] CWE-416 CVE-2018-11496: In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in read_stream in stream.c, because d In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in read_stream in stream.c, because decompress_file in lrzip.c lacks certain size validation.
nvd
CVE-2018-20169P4MEDIUMCVSS 6.8v8.02018-12-17
CVE-2018-20169 [MEDIUM] CWE-400 CVE-2018-20169: An issue was discovered in the Linux kernel before 4.19.9. The USB subsystem mishandles size checks An issue was discovered in the Linux kernel before 4.19.9. The USB subsystem mishandles size checks during the reading of an extra descriptor, related to __usb_get_extra_descriptor in drivers/usb/core/usb.c.
nvd
CVE-2020-22049P4MEDIUMCVSS 6.5v9.0v10.02021-06-02
CVE-2020-22049 [MEDIUM] CWE-401 CVE-2020-22049: A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the wtvfile_open_sect A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the wtvfile_open_sector function in wtvdec.c.
nvd
CVE-2020-22054P4MEDIUMCVSS 6.5v9.0v10.02021-06-02
CVE-2020-22054 [MEDIUM] CWE-401 CVE-2020-22054: A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the av_dict_set funct A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the av_dict_set function in dict.c.
nvd
CVE-2022-2058P4MEDIUMCVSS 6.5v10.0v11.02022-06-30
CVE-2022-2058 [MEDIUM] CWE-369 CVE-2022-2058: Divide By Zero error in tiffcrop in libtiff 4.4.0 allows attackers to cause a denial-of-service via Divide By Zero error in tiffcrop in libtiff 4.4.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit f3a5e010.
nvd
CVE-2023-41900P4MEDIUMCVSS 4.3v11.0v12.02023-09-15
CVE-2023-41900 [MEDIUM] CWE-1390 CVE-2023-41900: Jetty is a Java based web server and servlet engine. Versions 9.4.21 through 9.4.51, 10.0.15, and 11 Jetty is a Java based web server and servlet engine. Versions 9.4.21 through 9.4.51, 10.0.15, and 11.0.15 are vulnerable to weak authentication. If a Jetty `OpenIdAuthenticator` uses the optional nested `LoginService`, and that `LoginService` decides to revoke an already authenticated user, then the current request will still treat the user as auth
nvd
CVE-2021-38199P4MEDIUMCVSS 6.5v9.0v11.02021-08-08
CVE-2021-38199 [MEDIUM] CVE-2021-38199: fs/nfs/nfs4client.c in the Linux kernel before 5.13.4 has incorrect connection-setup ordering, which fs/nfs/nfs4client.c in the Linux kernel before 5.13.4 has incorrect connection-setup ordering, which allows operators of remote NFSv4 servers to cause a denial of service (hanging of mounts) by arranging for those servers to be unreachable during trunking detection.
nvd
CVE-2011-1783P4MEDIUMCVSS 4.3v5.0v6.02011-06-06
CVE-2011-1783 [MEDIUM] CVE-2011-1783: The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6 The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit option is enabled, allows remote attackers to cause a denial of service (infinite loop and memory consumption) in opportunistic circumstances by requesting data.
nvd
CVE-2022-2056P4MEDIUMCVSS 6.5v10.0v11.02022-06-30
CVE-2022-2056 [MEDIUM] CWE-369 CVE-2022-2056: Divide By Zero error in tiffcrop in libtiff 4.4.0 allows attackers to cause a denial-of-service via Divide By Zero error in tiffcrop in libtiff 4.4.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit f3a5e010.
nvd
CVE-2022-2057P4MEDIUMCVSS 6.5v10.0v11.02022-06-30
CVE-2022-2057 [MEDIUM] CWE-369 CVE-2022-2057: Divide By Zero error in tiffcrop in libtiff 4.4.0 allows attackers to cause a denial-of-service via Divide By Zero error in tiffcrop in libtiff 4.4.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit f3a5e010.
nvd
CVE-2019-14369P4MEDIUMCVSS 6.5v10.02019-07-28
CVE-2019-14369 [MEDIUM] CWE-125 CVE-2019-14369: Exiv2::PngImage::readMetadata() in pngimage.cpp in Exiv2 0.27.99.0 allows attackers to cause a denia Exiv2::PngImage::readMetadata() in pngimage.cpp in Exiv2 0.27.99.0 allows attackers to cause a denial of service (heap-based buffer over-read) via a crafted image file.
nvd
Debian Linux vulnerabilities | cvebase