Debian Linux vulnerabilities
9,955 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358
Vulnerabilities
Page 378 of 498
CVE-2019-11010P4MEDIUMCVSS 6.5v8.02019-04-08
CVE-2019-11010 [MEDIUM] CWE-401 CVE-2019-11010: In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a memory leak in the function ReadMPCImage of c
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a memory leak in the function ReadMPCImage of coders/mpc.c, which allows attackers to cause a denial of service via a crafted image file.
nvd
CVE-2011-1444P4MEDIUMCVSS 6.8v6.0v7.02011-05-03
CVE-2011-1444 [MEDIUM] CWE-362 CVE-2011-1444: Race condition in the sandbox launcher implementation in Google Chrome before 11.0.696.57 on Linux a
Race condition in the sandbox launcher implementation in Google Chrome before 11.0.696.57 on Linux allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2015-3438P4MEDIUMCVSS 4.3v7.0v8.02015-08-05
CVE-2015-3438 [MEDIUM] CWE-79 CVE-2015-3438: Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 4.1.2, when MySQL is used wi
Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 4.1.2, when MySQL is used without strict mode, allow remote attackers to inject arbitrary web script or HTML via a (1) four-byte UTF-8 character or (2) invalid character that reaches the database layer, as demonstrated by a crafted character in a comment.
nvd
CVE-2018-7870P4MEDIUMCVSS 6.5v7.02018-03-08
CVE-2018-7870 [MEDIUM] CWE-476 CVE-2018-7870: An invalid memory address dereference was discovered in getString in util/decompile.c in libming 0.4
An invalid memory address dereference was discovered in getString in util/decompile.c in libming 0.4.8 for CONSTANT16 data. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.
nvd
CVE-2018-7872P4MEDIUMCVSS 6.5v7.02018-03-08
CVE-2018-7872 [MEDIUM] CWE-476 CVE-2018-7872: An invalid memory address dereference was discovered in the function getName in libming 0.4.8 for CO
An invalid memory address dereference was discovered in the function getName in libming 0.4.8 for CONSTANT16 data. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.
nvd
CVE-2020-7045P4MEDIUMCVSS 6.5v9.02020-01-16
CVE-2020-7045 [MEDIUM] CWE-476 CVE-2020-7045: In Wireshark 3.0.x before 3.0.8, the BT ATT dissector could crash. This was addressed in epan/dissec
In Wireshark 3.0.x before 3.0.8, the BT ATT dissector could crash. This was addressed in epan/dissectors/packet-btatt.c by validating opcodes.
nvd
CVE-2018-21015P4MEDIUMCVSS 6.5v8.02019-09-16
CVE-2018-21015 [MEDIUM] CWE-476 CVE-2018-21015: AVC_DuplicateConfig() at isomedia/avc_ext.c in GPAC 0.7.1 allows remote attackers to cause a denial
AVC_DuplicateConfig() at isomedia/avc_ext.c in GPAC 0.7.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file. There is "cfg_new->AVCLevelIndication = cfg->AVCLevelIndication;" but cfg could be NULL.
nvd
CVE-2014-9529P4MEDIUMCVSS 6.9v7.0v8.02015-01-09
CVE-2014-9529 [MEDIUM] CWE-362 CVE-2014-9529: Race condition in the key_gc_unused_keys function in security/keys/gc.c in the Linux kernel through
Race condition in the key_gc_unused_keys function in security/keys/gc.c in the Linux kernel through 3.18.2 allows local users to cause a denial of service (memory corruption or panic) or possibly have unspecified other impact via keyctl commands that trigger access to a key structure member during garbage collection of a key.
nvd
CVE-2014-1943P4MEDIUMCVSS 5.0v6.0v7.02014-02-18
CVE-2014-1943 [MEDIUM] CWE-755 CVE-2014-1943: Fine Free file before 5.17 allows context-dependent attackers to cause a denial of service (infinite
Fine Free file before 5.17 allows context-dependent attackers to cause a denial of service (infinite recursion, CPU consumption, and crash) via a crafted indirect offset value in the magic of a file.
nvd
CVE-2016-1685P4MEDIUMCVSS 6.5v8.02016-06-05
CVE-2016-1685 [MEDIUM] CWE-119 CVE-2016-1685: core/fxge/ge/fx_ge_text.cpp in PDFium, as used in Google Chrome before 51.0.2704.63, miscalculates c
core/fxge/ge/fx_ge_text.cpp in PDFium, as used in Google Chrome before 51.0.2704.63, miscalculates certain index values, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PDF document.
nvd
CVE-2021-36054P4MEDIUMCVSS 5.5v10.02021-09-01
CVE-2021-36054 [MEDIUM] CWE-122 CVE-2021-36054: XMP Toolkit SDK version 2020.1 (and earlier) is affected by a buffer overflow vulnerability potentia
XMP Toolkit SDK version 2020.1 (and earlier) is affected by a buffer overflow vulnerability potentially resulting in local application denial of service in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file.
nvd
CVE-2018-7874P4MEDIUMCVSS 6.5v7.02018-03-08
CVE-2018-7874 [MEDIUM] CWE-119 CVE-2018-7874: An invalid memory address dereference was discovered in strlenext in util/decompile.c in libming 0.4
An invalid memory address dereference was discovered in strlenext in util/decompile.c in libming 0.4.8. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.
nvd
CVE-2016-1654P4MEDIUMCVSS 6.5v8.02016-04-18
CVE-2016-1654 [MEDIUM] CWE-20 CVE-2016-1654: The media subsystem in Google Chrome before 50.0.2661.75 does not initialize an unspecified data str
The media subsystem in Google Chrome before 50.0.2661.75 does not initialize an unspecified data structure, which allows remote attackers to cause a denial of service (invalid read operation) via unknown vectors.
nvd
CVE-2015-1239P4MEDIUMCVSS 6.5v8.02017-10-18
CVE-2015-1239 [MEDIUM] CWE-415 CVE-2015-1239: Double free vulnerability in the j2k_read_ppm_v3 function in OpenJPEG before r2997, as used in PDFiu
Double free vulnerability in the j2k_read_ppm_v3 function in OpenJPEG before r2997, as used in PDFium in Google Chrome, allows remote attackers to cause a denial of service (process crash) via a crafted PDF.
nvd
CVE-2020-22044P4MEDIUMCVSS 6.5v9.02021-06-01
CVE-2020-22044 [MEDIUM] CWE-401 CVE-2020-22044: A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the url_open_dyn_buf_
A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the url_open_dyn_buf_internal function in libavformat/aviobuf.c.
nvd
CVE-2020-22046P4MEDIUMCVSS 6.5v9.02021-06-02
CVE-2020-22046 [MEDIUM] CWE-401 CVE-2020-22046: A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the avpriv_float_dsp_
A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the avpriv_float_dsp_allocl function in libavutil/float_dsp.c.
nvd
CVE-2020-22042P4MEDIUMCVSS 6.5v11.02021-06-01
CVE-2020-22042 [MEDIUM] CWE-401 CVE-2020-22042: A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak is affected by: memory l
A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak is affected by: memory leak in the link_filter_inouts function in libavfilter/graphparser.c.
nvd
CVE-2020-22048P4MEDIUMCVSS 6.5v9.02021-06-02
CVE-2020-22048 [MEDIUM] CWE-401 CVE-2020-22048: A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the ff_frame_pool_get
A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the ff_frame_pool_get function in framepool.c.
nvd
CVE-2020-22041P4MEDIUMCVSS 6.5v9.02021-06-01
CVE-2020-22041 [MEDIUM] CWE-401 CVE-2020-22041: A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the av_buffersrc_add_
A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the av_buffersrc_add_frame_flags function in buffersrc.
nvd
CVE-2022-43238P4MEDIUMCVSS 6.5v10.0v11.02022-11-02
CVE-2022-43238 [MEDIUM] CWE-400 CVE-2022-43238: Libde265 v1.0.8 was discovered to contain an unknown crash via ff_hevc_put_hevc_qpel_h_3_v_3_sse in
Libde265 v1.0.8 was discovered to contain an unknown crash via ff_hevc_put_hevc_qpel_h_3_v_3_sse in sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.
nvd