cbcvebase.

Debian Linux vulnerabilities

9,955 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358

Vulnerabilities

Page 388 of 498
CVE-2017-8351P4MEDIUMCVSS 6.5v8.0v9.02017-04-30
CVE-2017-8351 [MEDIUM] CWE-772 CVE-2017-8351: In ImageMagick 7.0.5-5, the ReadPCDImage function in pcd.c allows attackers to cause a denial of ser In ImageMagick 7.0.5-5, the ReadPCDImage function in pcd.c allows attackers to cause a denial of service (memory leak) via a crafted file.
nvd
CVE-2017-8353P4MEDIUMCVSS 6.5v8.0v9.02017-04-30
CVE-2017-8353 [MEDIUM] CWE-772 CVE-2017-8353: In ImageMagick 7.0.5-5, the ReadPICTImage function in pict.c allows attackers to cause a denial of s In ImageMagick 7.0.5-5, the ReadPICTImage function in pict.c allows attackers to cause a denial of service (memory leak) via a crafted file.
nvd
CVE-2017-8344P4MEDIUMCVSS 6.5v8.0v9.02017-04-30
CVE-2017-8344 [MEDIUM] CWE-772 CVE-2017-8344: In ImageMagick 7.0.5-5, the ReadPCXImage function in pcx.c allows attackers to cause a denial of ser In ImageMagick 7.0.5-5, the ReadPCXImage function in pcx.c allows attackers to cause a denial of service (memory leak) via a crafted file.
nvd
CVE-2017-8350P4MEDIUMCVSS 6.5v8.0v9.02017-04-30
CVE-2017-8350 [MEDIUM] CWE-772 CVE-2017-8350: In ImageMagick 7.0.5-5, the ReadJNGImage function in png.c allows attackers to cause a denial of ser In ImageMagick 7.0.5-5, the ReadJNGImage function in png.c allows attackers to cause a denial of service (memory leak) via a crafted file.
nvd
CVE-2018-14851P4MEDIUMCVSS 5.5v8.0v9.02018-08-02
CVE-2018-14851 [MEDIUM] CWE-125 CVE-2018-14851: exif_process_IFD_in_MAKERNOTE in ext/exif/exif.c in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x be exif_process_IFD_in_MAKERNOTE in ext/exif/exif.c in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2.x before 7.2.8 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted JPEG file.
nvd
CVE-2015-4816P4MEDIUMCVSS 4.0v7.0v8.02015-10-21
CVE-2015-4816 [MEDIUM] CVE-2015-4816: Unspecified vulnerability in Oracle MySQL Server 5.5.44 and earlier allows remote authenticated user Unspecified vulnerability in Oracle MySQL Server 5.5.44 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : InnoDB.
nvd
CVE-2020-26558P4MEDIUMCVSS 4.2v9.02021-05-24
CVE-2020-26558 [MEDIUM] CWE-287 CVE-2020-26558: Bluetooth LE and BR/EDR secure pairing in Bluetooth Core Specification 2.1 through 5.2 may permit a Bluetooth LE and BR/EDR secure pairing in Bluetooth Core Specification 2.1 through 5.2 may permit a nearby man-in-the-middle attacker to identify the Passkey used during pairing (in the Passkey authentication procedure) by reflection of the public key and the authentication evidence of the initiating device, potentially permitting this attacker to co
nvd
CVE-2020-13696P4MEDIUMCVSS 4.4v8.02020-06-08
CVE-2020-13696 [MEDIUM] CWE-863 CVE-2020-13696: An issue was discovered in LinuxTV xawtv before 3.107. The function dev_open() in v4l-conf.c does no An issue was discovered in LinuxTV xawtv before 3.107. The function dev_open() in v4l-conf.c does not perform sufficient checks to prevent an unprivileged caller of the program from opening unintended filesystem paths. This allows a local attacker with access to the v4l-conf setuid-root program to test for the existence of arbitrary files and to tri
nvd
CVE-2020-9488P4LOWCVSS 3.7v9.0v10.0+1 more2020-04-27
CVE-2020-9488 [LOW] CWE-295 CVE-2020-9488: Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allo Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1
nvd
CVE-2018-12207P4MEDIUMCVSS 6.5v9.02019-11-14
CVE-2018-12207 [MEDIUM] CWE-20 CVE-2018-12207: Improper invalidation for page table updates by a virtual guest operating system for multiple Intel( Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to potentially enable denial of service of the host system via local access.
nvd
CVE-2005-2459P4MEDIUMCVSS 5.0v3.12005-08-23
CVE-2005-2459 [MEDIUM] CVE-2005-2459: The huft_build function in inflate.c in the zlib routines in the Linux kernel before 2.6.12.5 return The huft_build function in inflate.c in the zlib routines in the Linux kernel before 2.6.12.5 returns the wrong value, which allows remote attackers to cause a denial of service (kernel crash) via a certain compressed file that leads to a null pointer dereference, a different vulnerability than CVE-2005-2458.
nvd
CVE-2016-9955P4MEDIUMCVSS 6.3v7.02017-02-17
CVE-2016-9955 [MEDIUM] CWE-20 CVE-2016-9955: The SimpleSAML_XML_Validator class constructor in SimpleSAMLphp before 1.14.11 might allow remote at The SimpleSAML_XML_Validator class constructor in SimpleSAMLphp before 1.14.11 might allow remote attackers to spoof signatures on SAML 1 responses or possibly cause a denial of service (memory consumption) by leveraging improper conversion of return values to boolean.
nvd
CVE-2017-16527P4MEDIUMCVSS 6.6v7.02017-11-04
CVE-2017-16527 [MEDIUM] CWE-416 CVE-2017-16527: sound/usb/mixer.c in the Linux kernel before 4.13.8 allows local users to cause a denial of service sound/usb/mixer.c in the Linux kernel before 4.13.8 allows local users to cause a denial of service (snd_usb_mixer_interrupt use-after-free and system crash) or possibly have unspecified other impact via a crafted USB device.
nvd
CVE-2016-4561P4MEDIUMCVSS 6.1v8.02016-05-10
CVE-2016-4561 [MEDIUM] CWE-79 CVE-2016-4561: Cross-site scripting (XSS) vulnerability in the cgierror function in CGI.pm in ikiwiki before 3.2016 Cross-site scripting (XSS) vulnerability in the cgierror function in CGI.pm in ikiwiki before 3.20160506 might allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving an error message.
nvd
CVE-2018-19967P4MEDIUMCVSS 6.5v9.02018-12-08
CVE-2018-19967 [MEDIUM] CWE-20 CVE-2018-19967: An issue was discovered in Xen through 4.11.x on Intel x86 platforms allowing guest OS users to caus An issue was discovered in Xen through 4.11.x on Intel x86 platforms allowing guest OS users to cause a denial of service (host OS hang) because Xen does not work around Intel's mishandling of certain HLE transactions associated with the KACQUIRE instruction prefix.
nvd
CVE-2018-10981P4MEDIUMCVSS 6.5v7.0v8.0+1 more2018-05-10
CVE-2018-10981 [MEDIUM] CWE-835 CVE-2018-10981: An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users to cause a denial of s An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users to cause a denial of service (host OS infinite loop) in situations where a QEMU device model attempts to make invalid transitions between states of a request.
nvd
CVE-2018-7540P4MEDIUMCVSS 6.5v9.02018-02-27
CVE-2018-7540 [MEDIUM] CWE-400 CVE-2018-7540: An issue was discovered in Xen through 4.10.x allowing x86 PV guest OS users to cause a denial of se An issue was discovered in Xen through 4.10.x allowing x86 PV guest OS users to cause a denial of service (host OS CPU hang) via non-preemptable L3/L4 pagetable freeing.
nvd
CVE-2016-9907P4MEDIUMCVSS 6.5v8.02016-12-23
CVE-2016-9907 [MEDIUM] CWE-772 CVE-2016-9907: Quick Emulator (Qemu) built with the USB redirector usb-guest support is vulnerable to a memory leak Quick Emulator (Qemu) built with the USB redirector usb-guest support is vulnerable to a memory leakage flaw. It could occur while destroying the USB redirector in 'usbredir_handle_destroy'. A guest user/process could use this issue to leak host memory, resulting in DoS for a host.
nvd
CVE-2016-9921P4MEDIUMCVSS 6.5v8.02016-12-23
CVE-2016-9921 [MEDIUM] CWE-369 CVE-2016-9921: Quick emulator (Qemu) built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to a divide Quick emulator (Qemu) built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to a divide by zero issue. It could occur while copying VGA data when cirrus graphics mode was set to be VGA. A privileged user inside guest could use this flaw to crash the Qemu process instance on the host, resulting in DoS.
nvd
CVE-2017-5856P4MEDIUMCVSS 6.5v8.02017-03-16
CVE-2017-5856 [MEDIUM] CWE-401 CVE-2017-5856: Memory leak in the megasas_handle_dcmd function in hw/scsi/megasas.c in QEMU (aka Quick Emulator) al Memory leak in the megasas_handle_dcmd function in hw/scsi/megasas.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption) via MegaRAID Firmware Interface (MFI) commands with the sglist size set to a value over 2 Gb.
nvd
Debian Linux vulnerabilities | cvebase