cbcvebase.

Debian Linux vulnerabilities

9,955 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358

Vulnerabilities

Page 369 of 498
CVE-2022-38266P4MEDIUMCVSS 6.5v10.02022-09-09
CVE-2022-38266 [MEDIUM] CWE-369 CVE-2022-38266: An issue in the Leptonica linked library (v1.79.0) allows attackers to cause an arithmetic exception An issue in the Leptonica linked library (v1.79.0) allows attackers to cause an arithmetic exception leading to a Denial of Service (DoS) via a crafted JPEG file.
nvd
CVE-2023-33460P4MEDIUMCVSS 6.5v10.02023-06-06
CVE-2023-33460 [MEDIUM] CWE-401 CVE-2023-33460: There's a memory leak in yajl 2.1.0 with use of yajl_tree_parse function. which will cause out-of-me There's a memory leak in yajl 2.1.0 with use of yajl_tree_parse function. which will cause out-of-memory in server and cause crash.
nvd
CVE-2019-14370P4MEDIUMCVSS 6.5v10.02019-07-28
CVE-2019-14370 [MEDIUM] CWE-125 CVE-2019-14370: In Exiv2 0.27.99.0, there is an out-of-bounds read in Exiv2::MrwImage::readMetadata() in mrwimage.cp In Exiv2 0.27.99.0, there is an out-of-bounds read in Exiv2::MrwImage::readMetadata() in mrwimage.cpp. It could result in denial of service.
nvd
CVE-2021-38204P4MEDIUMCVSS 6.8v9.02021-08-08
CVE-2021-38204 [MEDIUM] CWE-416 CVE-2021-38204: drivers/usb/host/max3421-hcd.c in the Linux kernel before 5.13.6 allows physically proximate attacke drivers/usb/host/max3421-hcd.c in the Linux kernel before 5.13.6 allows physically proximate attackers to cause a denial of service (use-after-free and panic) by removing a MAX-3421 USB device in certain situations.
nvd
CVE-2020-22019P4MEDIUMCVSS 6.5v10.02021-05-26
CVE-2020-22019 [MEDIUM] CWE-120 CVE-2020-22019: Buffer Overflow vulnerability in FFmpeg 4.2 at convolution_y_10bit in libavfilter/vf_vmafmotion.c, w Buffer Overflow vulnerability in FFmpeg 4.2 at convolution_y_10bit in libavfilter/vf_vmafmotion.c, which could let a remote malicious user cause a Denial of Service.
nvd
CVE-2022-1789P4MEDIUMCVSS 6.8v11.02022-06-02
CVE-2022-1789 [MEDIUM] CWE-476 CVE-2022-1789: With shadow paging enabled, the INVPCID instruction results in a call to kvm_mmu_invpcid_gva. If INV With shadow paging enabled, the INVPCID instruction results in a call to kvm_mmu_invpcid_gva. If INVPCID is executed with CR0.PG=0, the invlpg callback is not set and the result is a NULL pointer dereference.
nvd
CVE-2019-17343P4MEDIUMCVSS 6.8v9.0v10.02019-10-08
CVE-2019-17343 [MEDIUM] CWE-667 CVE-2019-17343: An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of se An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges by leveraging incorrect use of the HVM physmap concept for PV domains.
nvd
CVE-2016-1689P4MEDIUMCVSS 6.5v8.02016-06-05
CVE-2016-1689 [MEDIUM] CWE-119 CVE-2016-1689: Heap-based buffer overflow in content/renderer/media/canvas_capture_handler.cc in Google Chrome befo Heap-based buffer overflow in content/renderer/media/canvas_capture_handler.cc in Google Chrome before 51.0.2704.63 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted web site.
nvd
CVE-2016-7176P4MEDIUMCVSS 5.9v8.02016-09-09
CVE-2016-7176 [MEDIUM] CWE-119 CVE-2016-7176: epan/dissectors/packet-h225.c in the H.225 dissector in Wireshark 2.x before 2.0.6 calls snprintf wi epan/dissectors/packet-h225.c in the H.225 dissector in Wireshark 2.x before 2.0.6 calls snprintf with one of its input buffers as the output buffer, which allows remote attackers to cause a denial of service (copy overlap and application crash) via a crafted packet.
nvd
CVE-2017-9063P4MEDIUMCVSS 6.1v8.0v9.02017-05-18
CVE-2017-9063 [MEDIUM] CWE-79 CVE-2017-9063: In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability related to the Customizer exis In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability related to the Customizer exists, involving an invalid customization session.
nvd
CVE-2022-3599P4MEDIUMCVSS 6.5v10.0v11.02022-10-21
CVE-2022-3599 [MEDIUM] CWE-125 CVE-2022-3599: LibTIFF 4.4.0 has an out-of-bounds read in writeSingleSection in tools/tiffcrop.c:7345, allowing att LibTIFF 4.4.0 has an out-of-bounds read in writeSingleSection in tools/tiffcrop.c:7345, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit e8131125.
nvd
CVE-2016-4082P4MEDIUMCVSS 5.9v8.02016-04-25
CVE-2016-4082 [MEDIUM] CWE-119 CVE-2016-4082: epan/dissectors/packet-gsm_cbch.c in the GSM CBCH dissector in Wireshark 1.12.x before 1.12.11 and 2 epan/dissectors/packet-gsm_cbch.c in the GSM CBCH dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 uses the wrong variable to index an array, which allows remote attackers to cause a denial of service (out-of-bounds access and application crash) via a crafted packet.
nvd
CVE-2021-3911P4MEDIUMCVSS 6.5v11.02021-11-11
CVE-2021-3911 [MEDIUM] CWE-20 CVE-2021-3911: If the ROA that a repository returns contains too many bits for the IP address then OctoRPKI will cr If the ROA that a repository returns contains too many bits for the IP address then OctoRPKI will crash.
nvd
CVE-2013-4082P4MEDIUMCVSS 5.0v7.02013-06-09
CVE-2013-4082 [MEDIUM] CWE-119 CVE-2013-4082: The vwr_read function in wiretap/vwr.c in the Ixia IxVeriWave file parser in Wireshark 1.8.x before The vwr_read function in wiretap/vwr.c in the Ixia IxVeriWave file parser in Wireshark 1.8.x before 1.8.8 does not validate the relationship between a record length and a trailer length, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) via a crafted packet.
nvd
CVE-2016-7178P4MEDIUMCVSS 5.9v8.02016-09-09
CVE-2016-7178 [MEDIUM] CWE-787 CVE-2016-7178: epan/dissectors/packet-umts_fp.c in the UMTS FP dissector in Wireshark 2.x before 2.0.6 does not ens epan/dissectors/packet-umts_fp.c in the UMTS FP dissector in Wireshark 2.x before 2.0.6 does not ensure that memory is allocated for certain data structures, which allows remote attackers to cause a denial of service (invalid write access and application crash) via a crafted packet.
nvd
CVE-2022-43245P4MEDIUMCVSS 6.5v10.0v11.02022-11-02
CVE-2022-43245 [MEDIUM] CWE-787 CVE-2022-43245: Libde265 v1.0.8 was discovered to contain a segmentation violation via apply_sao_internal<unsigned s Libde265 v1.0.8 was discovered to contain a segmentation violation via apply_sao_internal in sao.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.
nvd
CVE-2016-9895P4MEDIUMCVSS 6.1v9.02018-06-11
CVE-2016-9895 [MEDIUM] CWE-254 CVE-2016-9895: Event handlers on "marquee" elements were executed despite a strict Content Security Policy (CSP) th Event handlers on "marquee" elements were executed despite a strict Content Security Policy (CSP) that disallowed inline JavaScript. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
nvd
CVE-2016-2511P4MEDIUMCVSS 6.1v7.0v8.02016-04-07
CVE-2016-2511 [MEDIUM] CWE-79 CVE-2016-2511: Cross-site scripting (XSS) vulnerability in WebSVN 2.3.3 and earlier allows remote attackers to inje Cross-site scripting (XSS) vulnerability in WebSVN 2.3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the path parameter to log.php.
nvd
CVE-2019-16728P4MEDIUMCVSS 6.1v9.02019-09-24
CVE-2019-16728 [MEDIUM] CWE-79 CVE-2019-16728: DOMPurify before 2.0.1 allows XSS because of innerHTML mutation XSS (mXSS) for an SVG element or a M DOMPurify before 2.0.1 allows XSS because of innerHTML mutation XSS (mXSS) for an SVG element or a MATH element, as demonstrated by Chrome and Safari.
nvd
CVE-2017-6831P4MEDIUMCVSS 5.5v8.0v9.02017-03-20
CVE-2017-6831 [MEDIUM] CWE-119 CVE-2017-6831: Heap-based buffer overflow in the decodeBlockWAVE function in IMA.cpp in Audio File Library (aka aud Heap-based buffer overflow in the decodeBlockWAVE function in IMA.cpp in Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0 and 0.2.7 allows remote attackers to cause a denial of service (crash) via a crafted file.
nvd
Debian Linux vulnerabilities | cvebase