cbcvebase.

Debian Linux vulnerabilities

9,955 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358

Vulnerabilities

Page 381 of 498
CVE-2018-13099P4MEDIUMCVSS 5.5v8.0v9.02018-07-03
CVE-2018-13099 [MEDIUM] CWE-125 CVE-2018-13099: An issue was discovered in fs/f2fs/inline.c in the Linux kernel through 4.4. A denial of service (ou An issue was discovered in fs/f2fs/inline.c in the Linux kernel through 4.4. A denial of service (out-of-bounds memory access and BUG) can occur for a modified f2fs filesystem image in which an inline inode contains an invalid reserved blkaddr.
nvd
CVE-2019-13274P4MEDIUMCVSS 6.1v8.02019-08-27
CVE-2019-13274 [MEDIUM] CWE-79 CVE-2019-13274: In Xymon through 4.3.28, an XSS vulnerability exists in the csvinfo CGI script due to insufficient f In Xymon through 4.3.28, an XSS vulnerability exists in the csvinfo CGI script due to insufficient filtering of the db parameter.
nvd
CVE-2018-6081P4MEDIUMCVSS 6.1v9.02018-11-14
CVE-2018-6081 [MEDIUM] CWE-79 CVE-2018-6081: XSS vulnerabilities in Interstitials in Google Chrome prior to 65.0.3325.146 allowed an attacker who XSS vulnerabilities in Interstitials in Google Chrome prior to 65.0.3325.146 allowed an attacker who convinced a user to install a malicious extension or open Developer Console to inject arbitrary scripts or HTML via a crafted HTML page.
nvd
CVE-2018-13100P4MEDIUMCVSS 5.5v8.02018-07-03
CVE-2018-13100 [MEDIUM] CWE-369 CVE-2018-13100: An issue was discovered in fs/f2fs/super.c in the Linux kernel through 4.17.3, which does not proper An issue was discovered in fs/f2fs/super.c in the Linux kernel through 4.17.3, which does not properly validate secs_per_zone in a corrupted f2fs image, as demonstrated by a divide-by-zero error.
nvd
CVE-2016-1236P4MEDIUMCVSS 6.1v8.02016-05-11
CVE-2016-1236 [MEDIUM] CWE-79 CVE-2016-1236: Multiple cross-site scripting (XSS) vulnerabilities in (1) revision.php, (2) log.php, (3) listing.ph Multiple cross-site scripting (XSS) vulnerabilities in (1) revision.php, (2) log.php, (3) listing.php, and (4) comp.php in WebSVN allow context-dependent attackers to inject arbitrary web script or HTML via the name of a (a) file or (b) directory in a repository.
nvd
CVE-2018-18605P4MEDIUMCVSS 5.5v7.0v8.0+1 more2018-10-23
CVE-2018-18605 [MEDIUM] CWE-125 CVE-2018-18605: A heap-based buffer over-read issue was discovered in the function sec_merge_hash_lookup in merge.c A heap-based buffer over-read issue was discovered in the function sec_merge_hash_lookup in merge.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31, because _bfd_add_merge_section mishandles section merges when size is not a multiple of entsize. A specially crafted ELF allows remote attackers to cause a d
nvd
CVE-2008-3325P4MEDIUMCVSS 6.0v4.02008-07-25
CVE-2008-3325 [MEDIUM] CWE-352 CVE-2008-3325: Cross-site request forgery (CSRF) vulnerability in Moodle 1.6.x before 1.6.7 and 1.7.x before 1.7.5 Cross-site request forgery (CSRF) vulnerability in Moodle 1.6.x before 1.6.7 and 1.7.x before 1.7.5 allows remote attackers to modify profile settings and gain privileges as other users via a link or IMG tag to the user edit profile page.
nvd
CVE-2015-4651P4MEDIUMCVSS 5.0v8.02015-07-22
CVE-2015-4651 [MEDIUM] CWE-399 CVE-2015-4651: The dissect_wccp2r1_address_table_info function in epan/dissectors/packet-wccp.c in the WCCP dissect The dissect_wccp2r1_address_table_info function in epan/dissectors/packet-wccp.c in the WCCP dissector in Wireshark 1.12.x before 1.12.6 does not properly determine whether enough memory is available for storing IP address strings, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
nvd
CVE-2020-16297P4MEDIUMCVSS 5.5v9.0v10.02020-08-13
CVE-2020-16297 [MEDIUM] CWE-787 CVE-2020-16297: A buffer overflow vulnerability in FloydSteinbergDitheringC() in contrib/gdevbjca.c of Artifex Softw A buffer overflow vulnerability in FloydSteinbergDitheringC() in contrib/gdevbjca.c of Artifex Software GhostScript v9.18 to v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
nvd
CVE-2009-0784P4MEDIUMCVSS 6.3v4.0v5.02009-03-25
CVE-2009-0784 [MEDIUM] CWE-362 CVE-2009-0784: Race condition in the SystemTap stap tool 0.0.20080705 and 0.0.20090314 allows local users in the st Race condition in the SystemTap stap tool 0.0.20080705 and 0.0.20090314 allows local users in the stapusr group to insert arbitrary SystemTap kernel modules and gain privileges via unknown vectors.
nvd
CVE-2012-6656P4MEDIUMCVSS 5.0v7.02014-12-05
CVE-2012-6656 [MEDIUM] CWE-20 CVE-2012-6656: iconvdata/ibm930.c in GNU C Library (aka glibc) before 2.16 allows context-dependent attackers to ca iconvdata/ibm930.c in GNU C Library (aka glibc) before 2.16 allows context-dependent attackers to cause a denial of service (out-of-bounds read) via a multibyte character value of "0xffff" to the iconv function when converting IBM930 encoded data to UTF-8.
nvd
CVE-2020-16296P4MEDIUMCVSS 5.5v9.0v10.02020-08-13
CVE-2020-16296 [MEDIUM] CWE-787 CVE-2020-16296: A buffer overflow vulnerability in GetNumWrongData() in contrib/lips4/gdevlips.c of Artifex Software A buffer overflow vulnerability in GetNumWrongData() in contrib/lips4/gdevlips.c of Artifex Software GhostScript from v9.18 to v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
nvd
CVE-2018-9251P4MEDIUMCVSS 5.3v8.02018-04-04
CVE-2018-9251 [MEDIUM] CVE-2018-9251: The xz_decomp function in xzlib.c in libxml2 2.9.8, if --with-lzma is used, allows remote attackers The xz_decomp function in xzlib.c in libxml2 2.9.8, if --with-lzma is used, allows remote attackers to cause a denial of service (infinite loop) via a crafted XML file that triggers LZMA_MEMLIMIT_ERROR, as demonstrated by xmllint, a different vulnerability than CVE-2015-8035.
nvd
CVE-2020-17538P4MEDIUMCVSS 5.5v9.0v10.02020-08-13
CVE-2020-17538 [MEDIUM] CWE-787 CVE-2020-17538: A buffer overflow vulnerability in GetNumSameData() in contrib/lips4/gdevlips.c of Artifex Software A buffer overflow vulnerability in GetNumSameData() in contrib/lips4/gdevlips.c of Artifex Software GhostScript from v9.18 to v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
nvd
CVE-2018-6187P4MEDIUMCVSS 5.5v9.02018-01-24
CVE-2018-6187 [MEDIUM] CWE-787 CVE-2018-6187: In Artifex MuPDF 1.12.0, there is a heap-based buffer overflow vulnerability in the do_pdf_save_docu In Artifex MuPDF 1.12.0, there is a heap-based buffer overflow vulnerability in the do_pdf_save_document function in the pdf/pdf-write.c file. Remote attackers could leverage the vulnerability to cause a denial of service via a crafted pdf file.
nvd
CVE-2020-11762P4MEDIUMCVSS 5.5v9.0v10.02020-04-14
CVE-2020-11762 [MEDIUM] CWE-125 CVE-2020-11762: An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read and write in DwaComp An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read and write in DwaCompressor::uncompress in ImfDwaCompressor.cpp when handling the UNKNOWN compression case.
nvd
CVE-2018-0618P4MEDIUMCVSS 5.4v8.0v9.02018-07-26
CVE-2018-0618 [MEDIUM] CWE-79 CVE-2018-0618: Cross-site scripting vulnerability in Mailman 2.1.26 and earlier allows remote authenticated attacke Cross-site scripting vulnerability in Mailman 2.1.26 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2018-2781P4MEDIUMCVSS 4.9v7.0v8.0+1 more2018-04-19
CVE-2018-2781 [MEDIUM] CVE-2018-2781: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Suppo Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.5.59 and prior, 5.6.39 and prior and 5.7.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulne
nvd
CVE-2020-11764P4MEDIUMCVSS 5.5v9.0v10.02020-04-14
CVE-2020-11764 [MEDIUM] CWE-787 CVE-2020-11764: An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds write in copyIntoFrameBuf An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds write in copyIntoFrameBuffer in ImfMisc.cpp.
nvd
CVE-2018-16435P4MEDIUMCVSS 5.5v8.0v9.02018-09-04
CVE-2018-16435 [MEDIUM] CWE-190 CVE-2018-16435: Little CMS (aka Little Color Management System) 2.9 has an integer overflow in the AllocateDataSet f Little CMS (aka Little Color Management System) 2.9 has an integer overflow in the AllocateDataSet function in cmscgats.c, leading to a heap-based buffer overflow in the SetData function via a crafted file in the second argument to cmsIT8LoadFromFile.
nvd
Debian Linux vulnerabilities | cvebase