cbcvebase.

Debian Linux vulnerabilities

9,955 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358

Vulnerabilities

Page 390 of 498
CVE-2020-16305P4MEDIUMCVSS 5.5v9.0v10.02020-08-13
CVE-2020-16305 [MEDIUM] CWE-787 CVE-2020-16305: A buffer overflow vulnerability in pcx_write_rle() in contrib/japanese/gdev10v.c of Artifex Software A buffer overflow vulnerability in pcx_write_rle() in contrib/japanese/gdev10v.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
nvd
CVE-2020-29571P4MEDIUMCVSS 6.2v10.02020-12-15
CVE-2020-29571 [MEDIUM] CWE-476 CVE-2020-29571: An issue was discovered in Xen through 4.14.x. A bounds check common to most operation time function An issue was discovered in Xen through 4.14.x. A bounds check common to most operation time functions specific to FIFO event channels depends on the CPU observing consistent state. While the producer side uses appropriately ordered writes, the consumer side isn't protected against re-ordered reads, and may hence end up de-referencing a NULL pointer.
nvd
CVE-2013-3557P4MEDIUMCVSS 5.0v7.02013-05-25
CVE-2013-3557 [MEDIUM] CWE-119 CVE-2013-3557: The dissect_ber_choice function in epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wiresh The dissect_ber_choice function in epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 1.6.x before 1.6.15 and 1.8.x before 1.8.7 does not properly initialize a certain variable, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.
nvd
CVE-2013-3559P4MEDIUMCVSS 5.0v8.02013-05-25
CVE-2013-3559 [MEDIUM] CWE-189 CVE-2013-3559: epan/dissectors/packet-dcp-etsi.c in the DCP ETSI dissector in Wireshark 1.8.x before 1.8.7 uses inc epan/dissectors/packet-dcp-etsi.c in the DCP ETSI dissector in Wireshark 1.8.x before 1.8.7 uses incorrect integer data types, which allows remote attackers to cause a denial of service (integer overflow, and heap memory corruption or NULL pointer dereference, and application crash) via a malformed packet.
nvd
CVE-2014-4617P4MEDIUMCVSS 5.0v7.02014-06-25
CVE-2014-4617 [MEDIUM] CWE-20 CVE-2014-4617: The do_uncompress function in g10/compress.c in GnuPG 1.x before 1.4.17 and 2.x before 2.0.24 allows The do_uncompress function in g10/compress.c in GnuPG 1.x before 1.4.17 and 2.x before 2.0.24 allows context-dependent attackers to cause a denial of service (infinite loop) via malformed compressed packets, as demonstrated by an a3 01 5b ff byte sequence.
nvd
CVE-2015-2317P4MEDIUMCVSS 4.3v7.02015-03-25
CVE-2015-2317 [MEDIUM] CWE-79 CVE-2015-2317: The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1.6.x before 1.6.11, 1.7.x befor The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1 does not properly validate URLs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a control character in a URL, as demonstrated by a \x08javascript: URL.
nvd
CVE-2020-16300P4MEDIUMCVSS 5.5v9.0v10.02020-08-13
CVE-2020-16300 [MEDIUM] CWE-787 CVE-2020-16300: A buffer overflow vulnerability in tiff12_print_page() in devices/gdevtfnx.c of Artifex Software Gho A buffer overflow vulnerability in tiff12_print_page() in devices/gdevtfnx.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
nvd
CVE-2020-16289P4MEDIUMCVSS 5.5v9.0v10.02020-08-13
CVE-2020-16289 [MEDIUM] CWE-787 CVE-2020-16289: A buffer overflow vulnerability in cif_print_page() in devices/gdevcif.c of Artifex Software GhostSc A buffer overflow vulnerability in cif_print_page() in devices/gdevcif.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
nvd
CVE-2020-16288P4MEDIUMCVSS 5.5v9.0v10.02020-08-13
CVE-2020-16288 [MEDIUM] CWE-120 CVE-2020-16288: A buffer overflow vulnerability in pj_common_print_page() in devices/gdevpjet.c of Artifex Software A buffer overflow vulnerability in pj_common_print_page() in devices/gdevpjet.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
nvd
CVE-2020-16298P4MEDIUMCVSS 5.5v9.0v10.02020-08-13
CVE-2020-16298 [MEDIUM] CWE-120 CVE-2020-16298: A buffer overflow vulnerability in mj_color_correct() in contrib/japanese/gdevmjc.c of Artifex Softw A buffer overflow vulnerability in mj_color_correct() in contrib/japanese/gdevmjc.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
nvd
CVE-2020-16292P4MEDIUMCVSS 5.5v9.0v10.02020-08-13
CVE-2020-16292 [MEDIUM] CWE-787 CVE-2020-16292: A buffer overflow vulnerability in mj_raster_cmd() in contrib/japanese/gdevmjc.c of Artifex Software A buffer overflow vulnerability in mj_raster_cmd() in contrib/japanese/gdevmjc.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
nvd
CVE-2020-16290P4MEDIUMCVSS 5.5v9.0v10.02020-08-13
CVE-2020-16290 [MEDIUM] CWE-787 CVE-2020-16290: A buffer overflow vulnerability in jetp3852_print_page() in devices/gdev3852.c of Artifex Software G A buffer overflow vulnerability in jetp3852_print_page() in devices/gdev3852.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
nvd
CVE-2013-4075P4MEDIUMCVSS 5.0v7.02013-06-09
CVE-2013-4075 [MEDIUM] CWE-399 CVE-2013-4075: epan/dissectors/packet-gmr1_bcch.c in the GMR-1 BCCH dissector in Wireshark 1.8.x before 1.8.8 does epan/dissectors/packet-gmr1_bcch.c in the GMR-1 BCCH dissector in Wireshark 1.8.x before 1.8.8 does not properly initialize memory, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
nvd
CVE-2020-16301P4MEDIUMCVSS 5.5v9.0v10.02020-08-13
CVE-2020-16301 [MEDIUM] CWE-120 CVE-2020-16301: A buffer overflow vulnerability in okiibm_print_page1() in devices/gdevokii.c of Artifex Software Gh A buffer overflow vulnerability in okiibm_print_page1() in devices/gdevokii.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
nvd
CVE-2018-16542P4MEDIUMCVSS 5.5v8.0v9.02018-09-05
CVE-2018-16542 [MEDIUM] CWE-787 CVE-2018-16542: In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use insu In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use insufficient interpreter stack-size checking during error handling to crash the interpreter.
nvd
CVE-2016-5315P4MEDIUMCVSS 5.5v8.02017-03-07
CVE-2016-5315 [MEDIUM] CWE-125 CVE-2016-5315: The setByteArray function in tif_dir.c in libtiff 4.0.6 and earlier allows remote attackers to cause The setByteArray function in tif_dir.c in libtiff 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tiff image.
nvd
CVE-2021-42528P4MEDIUMCVSS 5.5v10.02022-05-02
CVE-2021-42528 [MEDIUM] CWE-476 CVE-2021-42528: XMP Toolkit 2021.07 (and earlier) is affected by a Null pointer dereference vulnerability when parsi XMP Toolkit 2021.07 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open
nvd
CVE-2020-16294P4MEDIUMCVSS 5.5v9.0v10.02020-08-13
CVE-2020-16294 [MEDIUM] CWE-120 CVE-2020-16294: A buffer overflow vulnerability in epsc_print_page() in devices/gdevepsc.c of Artifex Software Ghost A buffer overflow vulnerability in epsc_print_page() in devices/gdevepsc.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
nvd
CVE-2020-16308P4MEDIUMCVSS 5.5v9.0v10.02020-08-13
CVE-2020-16308 [MEDIUM] CWE-787 CVE-2020-16308: A buffer overflow vulnerability in p_print_image() in devices/gdevcdj.c of Artifex Software GhostScr A buffer overflow vulnerability in p_print_image() in devices/gdevcdj.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
nvd
CVE-2020-16309P4MEDIUMCVSS 5.5v9.0v10.02020-08-13
CVE-2020-16309 [MEDIUM] CWE-787 CVE-2020-16309: A buffer overflow vulnerability in lxm5700m_print_page() in devices/gdevlxm.c of Artifex Software Gh A buffer overflow vulnerability in lxm5700m_print_page() in devices/gdevlxm.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted eps file. This is fixed in v9.51.
nvd
Debian Linux vulnerabilities | cvebase