Debian Linux vulnerabilities
9,955 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358
Vulnerabilities
Page 379 of 498
CVE-2022-43241P4MEDIUMCVSS 6.5v10.0v11.02022-11-02
CVE-2022-43241 [MEDIUM] CWE-787 CVE-2022-43241: Libde265 v1.0.8 was discovered to contain an unknown crash via ff_hevc_put_hevc_qpel_v_3_8_sse in ss
Libde265 v1.0.8 was discovered to contain an unknown crash via ff_hevc_put_hevc_qpel_v_3_8_sse in sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.
nvd
CVE-2015-1207P4MEDIUMCVSS 6.5v8.02017-06-06
CVE-2015-1207 [MEDIUM] CWE-415 CVE-2015-1207: Double-free vulnerability in libavformat/mov.c in FFMPEG in Google Chrome 41.0.2251.0 allows remote
Double-free vulnerability in libavformat/mov.c in FFMPEG in Google Chrome 41.0.2251.0 allows remote attackers to cause a denial of service (memory corruption and crash) via a crafted .m4a file.
nvd
CVE-2023-24751P4MEDIUMCVSS 6.5v10.02023-03-01
CVE-2023-24751 [MEDIUM] CWE-476 CVE-2023-24751: libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the mc_chroma function at m
libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the mc_chroma function at motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.
nvd
CVE-2014-1530P4MEDIUMCVSS 6.1v7.0v8.02014-04-30
CVE-2014-1530 [MEDIUM] CWE-79 CVE-2014-1530: The docshell implementation in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbir
The docshell implementation in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to trigger the loading of a URL with a spoofed baseURI property, and conduct cross-site scripting (XSS) attacks, via a crafted web site that performs history navigation.
nvd
CVE-2017-16525P4MEDIUMCVSS 6.6v7.02017-11-04
CVE-2017-16525 [MEDIUM] CWE-416 CVE-2017-16525: The usb_serial_console_disconnect function in drivers/usb/serial/console.c in the Linux kernel befor
The usb_serial_console_disconnect function in drivers/usb/serial/console.c in the Linux kernel before 4.13.8 allows local users to cause a denial of service (use-after-free and system crash) or possibly have unspecified other impact via a crafted USB device, related to disconnection and failed setup.
nvd
CVE-2019-14587P4MEDIUMCVSS 6.5v9.02020-11-23
CVE-2019-14587 [MEDIUM] CVE-2019-14587: Logic issue EDK II may allow an unauthenticated user to potentially enable denial of service via adj
Logic issue EDK II may allow an unauthenticated user to potentially enable denial of service via adjacent access.
nvd
CVE-2016-7180P4MEDIUMCVSS 5.9v8.02016-09-09
CVE-2016-7180 [MEDIUM] CWE-416 CVE-2016-7180: epan/dissectors/packet-ipmi-trace.c in the IPMI trace dissector in Wireshark 2.x before 2.0.6 does n
epan/dissectors/packet-ipmi-trace.c in the IPMI trace dissector in Wireshark 2.x before 2.0.6 does not properly consider whether a string is constant, which allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted packet.
nvd
CVE-2015-7697P4MEDIUMCVSS 4.3v7.0v8.02015-11-06
CVE-2015-7697 [MEDIUM] CWE-399 CVE-2015-7697: Info-ZIP UnZip 6.0 allows remote attackers to cause a denial of service (infinite loop) via empty bz
Info-ZIP UnZip 6.0 allows remote attackers to cause a denial of service (infinite loop) via empty bzip2 data in a ZIP archive.
nvd
CVE-2016-9119P4MEDIUMCVSS 6.1v8.02017-01-30
CVE-2016-9119 [MEDIUM] CWE-79 CVE-2016-9119: Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.8
Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2018-12891P4MEDIUMCVSS 6.5v8.0v9.02018-07-02
CVE-2018-12891 [MEDIUM] CVE-2018-12891: An issue was discovered in Xen through 4.10.x. Certain PV MMU operations may take a long time to pro
An issue was discovered in Xen through 4.10.x. Certain PV MMU operations may take a long time to process. For that reason Xen explicitly checks for the need to preempt the current vCPU at certain points. A few rarely taken code paths did bypass such checks. By suitably enforcing the conditions through its own page table contents, a malicious guest may cause
nvd
CVE-2020-1950P4MEDIUMCVSS 5.5v8.02020-03-23
CVE-2020-1950 [MEDIUM] CWE-400 CVE-2020-1950: A carefully crafted or corrupt PSD file can cause excessive memory usage in Apache Tika's PSDParser
A carefully crafted or corrupt PSD file can cause excessive memory usage in Apache Tika's PSDParser in versions 1.0-1.23.
nvd
CVE-2018-10471P4MEDIUMCVSS 6.5v9.02018-04-27
CVE-2018-10471 [MEDIUM] CVE-2018-10471: An issue was discovered in Xen through 4.10.x allowing x86 PV guest OS users to cause a denial of se
An issue was discovered in Xen through 4.10.x allowing x86 PV guest OS users to cause a denial of service (out-of-bounds zero write and hypervisor crash) via unexpected INT 80 processing, because of an incorrect fix for CVE-2017-5754.
nvd
CVE-2018-15469P4MEDIUMCVSS 6.5v8.02018-08-17
CVE-2018-15469 [MEDIUM] CWE-400 CVE-2018-15469: An issue was discovered in Xen through 4.11.x. ARM never properly implemented grant table v2, either
An issue was discovered in Xen through 4.11.x. ARM never properly implemented grant table v2, either in the hypervisor or in Linux. Unfortunately, an ARM guest can still request v2 grant tables; they will simply not be properly set up, resulting in subsequent grant-related hypercalls hitting BUG() checks. An unprivileged guest can cause a BUG() chec
nvd
CVE-2021-45088P4MEDIUMCVSS 6.1v10.0v11.02021-12-16
CVE-2021-45088 [MEDIUM] CWE-79 CVE-2021-45088: XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an error page.
XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an error page.
nvd
CVE-2018-12893P4MEDIUMCVSS 6.5v9.02018-07-02
CVE-2018-12893 [MEDIUM] CVE-2018-12893: An issue was discovered in Xen through 4.10.x. One of the fixes in XSA-260 added some safety checks
An issue was discovered in Xen through 4.10.x. One of the fixes in XSA-260 added some safety checks to help prevent Xen livelocking with debug exceptions. Unfortunately, due to an oversight, at least one of these safety checks can be triggered by a guest. A malicious PV guest can crash Xen, leading to a Denial of Service. All Xen systems which have applied t
nvd
CVE-2020-24511P4MEDIUMCVSS 6.5v10.02021-06-09
CVE-2020-24511 [MEDIUM] CWE-668 CVE-2020-24511: Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user t
Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
nvd
CVE-2017-6836P4MEDIUMCVSS 5.5v8.0v9.02017-03-20
CVE-2017-6836 [MEDIUM] CWE-119 CVE-2017-6836: Heap-based buffer overflow in the Expand3To4Module::run function in libaudiofile/modules/SimpleModul
Heap-based buffer overflow in the Expand3To4Module::run function in libaudiofile/modules/SimpleModule.h in Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0 allows remote attackers to cause a denial of service (crash) via a crafted file.
nvd
CVE-2016-9911P4MEDIUMCVSS 6.5v8.02016-12-23
CVE-2016-9911 [MEDIUM] CWE-772 CVE-2016-9911: Quick Emulator (Qemu) built with the USB EHCI Emulation support is vulnerable to a memory leakage is
Quick Emulator (Qemu) built with the USB EHCI Emulation support is vulnerable to a memory leakage issue. It could occur while processing packet data in 'ehci_init_transfer'. A guest user/process could use this issue to leak host memory, resulting in DoS for a host.
nvd
CVE-2015-8683P4MEDIUMCVSS 5.5v7.0v8.02016-04-13
CVE-2015-8683 [MEDIUM] CWE-119 CVE-2015-8683: The putcontig8bitCIELab function in tif_getimage.c in LibTIFF 4.0.6 allows remote attackers to cause
The putcontig8bitCIELab function in tif_getimage.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) via a packed TIFF image.
nvd
CVE-2020-1951P4MEDIUMCVSS 5.5v8.02020-03-23
CVE-2020-1951 [MEDIUM] CWE-835 CVE-2020-1951: A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in ver
A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in versions 1.0-1.23.
nvd