cbcvebase.

Debian Linux vulnerabilities

9,955 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358

Vulnerabilities

Page 391 of 498
CVE-2020-16287P4MEDIUMCVSS 5.5v9.0v10.02020-08-13
CVE-2020-16287 [MEDIUM] CWE-787 CVE-2020-16287: A buffer overflow vulnerability in lprn_is_black() in contrib/lips4/gdevlprn.c of Artifex Software G A buffer overflow vulnerability in lprn_is_black() in contrib/lips4/gdevlprn.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
nvd
CVE-2020-11763P4MEDIUMCVSS 5.5v9.0v10.02020-04-14
CVE-2020-11763 [MEDIUM] CWE-125 CVE-2020-11763: An issue was discovered in OpenEXR before 2.4.1. There is an std::vector out-of-bounds read and writ An issue was discovered in OpenEXR before 2.4.1. There is an std::vector out-of-bounds read and write, as demonstrated by ImfTileOffsets.cpp.
nvd
CVE-2018-12495P4MEDIUMCVSS 5.5v8.0v9.02018-06-15
CVE-2018-12495 [MEDIUM] CWE-125 CVE-2018-12495: The quoteblock function in markdown.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to The quoteblock function in markdown.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file.
nvd
CVE-2021-3416P4MEDIUMCVSS 6.0v9.0v10.02021-03-18
CVE-2021-3416 [MEDIUM] CWE-835 CVE-2021-3416: A potential stack overflow via infinite loop issue was found in various NIC emulators of QEMU in ver A potential stack overflow via infinite loop issue was found in various NIC emulators of QEMU in versions up to and including 5.2.0. The issue occurs in loopback mode of a NIC wherein reentrant DMA checks get bypassed. A guest user/process may use this flaw to consume CPU cycles or crash the QEMU process on the host resulting in DoS scenario.
nvd
CVE-2016-4454P4MEDIUMCVSS 6.0v8.02016-06-01
CVE-2016-4454 [MEDIUM] CWE-119 CVE-2016-4454: The vmsvga_fifo_read_raw function in hw/display/vmware_vga.c in QEMU allows local guest OS administr The vmsvga_fifo_read_raw function in hw/display/vmware_vga.c in QEMU allows local guest OS administrators to obtain sensitive host memory information or cause a denial of service (QEMU process crash) by changing FIFO registers and issuing a VGA command, which triggers an out-of-bounds read.
nvd
CVE-2018-10539P4MEDIUMCVSS 5.5v8.0v9.02018-04-29
CVE-2018-10539 [MEDIUM] CWE-787 CVE-2018-10539: An issue was discovered in WavPack 5.1.0 and earlier for DSDiff input. Out-of-bounds writes can occu An issue was discovered in WavPack 5.1.0 and earlier for DSDiff input. Out-of-bounds writes can occur because ParseDsdiffHeaderConfig in dsdiff.c does not validate the sizes of unknown chunks before attempting memory allocation, related to a lack of integer-overflow protection within a bytes_to_copy calculation and subsequent malloc call, leading to
nvd
CVE-2018-10540P4MEDIUMCVSS 5.5v8.0v9.02018-04-29
CVE-2018-10540 [MEDIUM] CWE-787 CVE-2018-10540: An issue was discovered in WavPack 5.1.0 and earlier for W64 input. Out-of-bounds writes can occur b An issue was discovered in WavPack 5.1.0 and earlier for W64 input. Out-of-bounds writes can occur because ParseWave64HeaderConfig in wave64.c does not validate the sizes of unknown chunks before attempting memory allocation, related to a lack of integer-overflow protection within a bytes_to_copy calculation and subsequent malloc call, leading to in
nvd
CVE-2020-29486P4MEDIUMCVSS 6.0v10.02020-12-15
CVE-2020-29486 [MEDIUM] CWE-770 CVE-2020-29486: An issue was discovered in Xen through 4.14.x. Nodes in xenstore have an ownership. In oxenstored, a An issue was discovered in Xen through 4.14.x. Nodes in xenstore have an ownership. In oxenstored, a owner could give a node away. However, node ownership has quota implications. Any guest can run another guest out of quota, or create an unbounded number of nodes owned by dom0, thus running xenstored out of memory A malicious guest administrator can
nvd
CVE-2017-15372P4MEDIUMCVSS 5.5v7.0v8.02017-10-16
CVE-2017-15372 [MEDIUM] CWE-119 CVE-2017-15372: There is a stack-based buffer overflow in the lsx_ms_adpcm_block_expand_i function of adpcm.c in Sou There is a stack-based buffer overflow in the lsx_ms_adpcm_block_expand_i function of adpcm.c in Sound eXchange (SoX) 14.4.2. A Crafted input will lead to a denial of service attack during conversion of an audio file.
nvd
CVE-2014-9323P4MEDIUMCVSS 5.0v7.0v8.02014-12-16
CVE-2014-9323 [MEDIUM] CWE-476 CVE-2014-9323: The xdr_status_vector function in Firebird before 2.1.7 and 2.5.x before 2.5.3 SU1 allows remote att The xdr_status_vector function in Firebird before 2.1.7 and 2.5.x before 2.5.3 SU1 allows remote attackers to cause a denial of service (NULL pointer dereference, segmentation fault, and crash) via an op_response action with a non-empty status.
nvd
CVE-2015-0433P4MEDIUMCVSS 4.0v7.0v8.02015-04-16
CVE-2015-0433 [MEDIUM] CVE-2015-0433: Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows remote authenticated users to affect availability via vectors related to InnoDB : DML.
nvd
CVE-2021-3608P4MEDIUMCVSS 6.0v10.02022-02-24
CVE-2021-3608 [MEDIUM] CWE-824 CVE-2021-3608: A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0. The issue occurs while handling a "PVRDMA_REG_DSRHIGH" write from the guest and may result in a crash of QEMU or cause undefined behavior due to the access of an uninitialized pointer. The highest threat from this vulnerability is to system avai
nvd
CVE-2017-3265P4MEDIUMCVSS 5.6v8.02017-01-27
CVE-2017-3265 [MEDIUM] CVE-2017-3265: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Packaging). Suppo Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Packaging). Supported versions that are affected are 5.5.53 and earlier, 5.6.34 and earlier and 5.7.16 and earlier. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Succes
nvd
CVE-2018-20185P4MEDIUMCVSS 5.3v8.0v9.0+1 more2018-12-17
CVE-2018-20185 [MEDIUM] CWE-125 CVE-2018-20185: In GraphicsMagick 1.4 snapshot-20181209 Q8 on 32-bit platforms, there is a heap-based buffer over-re In GraphicsMagick 1.4 snapshot-20181209 Q8 on 32-bit platforms, there is a heap-based buffer over-read in the ReadBMPImage function of bmp.c, which allows attackers to cause a denial of service via a crafted bmp image file. This only affects GraphicsMagick installations with customized BMP limits.
nvd
CVE-2021-29458P4MEDIUMCVSS 5.5v10.02021-04-19
CVE-2021-29458 [MEDIUM] CWE-125 CVE-2021-29458: Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the me Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.3 and earlier. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafted image file. An attacker could potentially exploit the vulnerability t
nvd
CVE-2017-6010P4MEDIUMCVSS 5.5v8.0v9.02017-02-16
CVE-2017-6010 [MEDIUM] CWE-119 CVE-2017-6010: An issue was discovered in icoutils 0.31.1. A buffer overflow was observed in the "extract_icons" fu An issue was discovered in icoutils 0.31.1. A buffer overflow was observed in the "extract_icons" function in the "extract.c" source file. This issue can be triggered by processing a corrupted ico file and will result in an icotool crash.
nvd
CVE-2015-1382P4MEDIUMCVSS 5.0v7.02015-02-03
CVE-2015-1382 [MEDIUM] CWE-20 CVE-2015-1382: parsers.c in Privoxy before 3.0.23 allows remote attackers to cause a denial of service (invalid rea parsers.c in Privoxy before 3.0.23 allows remote attackers to cause a denial of service (invalid read and crash) via vectors related to an HTTP time header.
nvd
CVE-2024-26843P4MEDIUMCVSS 6.0v10.02024-04-17
CVE-2024-26843 [MEDIUM] CWE-787 CVE-2024-26843: In the Linux kernel, the following vulnerability has been resolved: efi: runtime: Fix potential ove In the Linux kernel, the following vulnerability has been resolved: efi: runtime: Fix potential overflow of soft-reserved region size md_size will have been narrowed if we have >= 4GB worth of pages in a soft-reserved region.
nvd
CVE-2020-10177P4MEDIUMCVSS 5.5v9.02020-06-25
CVE-2020-10177 [MEDIUM] CWE-125 CVE-2020-10177: Pillow before 7.1.0 has multiple out-of-bounds reads in libImaging/FliDecode.c. Pillow before 7.1.0 has multiple out-of-bounds reads in libImaging/FliDecode.c.
nvd
CVE-2015-2571P4MEDIUMCVSS 4.0v7.0v8.02015-04-16
CVE-2015-2571 [MEDIUM] CVE-2015-2571: Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier, and 5.6.23 and earlier, allows Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier, and 5.6.23 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Optimizer.
nvd
Debian Linux vulnerabilities | cvebase