cbcvebase.

Debian Linux vulnerabilities

9,955 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358

Vulnerabilities

Page 392 of 498
CVE-2020-27845P4MEDIUMCVSS 5.5v9.0v10.02021-01-05
CVE-2020-27845 [MEDIUM] CWE-125 CVE-2020-27845: There's a flaw in src/lib/openjp2/pi.c of openjpeg in versions prior to 2.4.0. If an attacker is abl There's a flaw in src/lib/openjp2/pi.c of openjpeg in versions prior to 2.4.0. If an attacker is able to provide untrusted input to openjpeg's conversion/encoding functionality, they could cause an out-of-bounds read. The highest impact of this flaw is to application availability.
nvd
CVE-2019-11459P4MEDIUMCVSS 5.5v8.0v9.0+1 more2019-04-22
CVE-2019-11459 [MEDIUM] CWE-754 CVE-2019-11459: The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3.32.0 did not handle errors from TIFFReadRGBAImageOriented(), leading to uninitialized memory use when processing certain TIFF image files.
nvd
CVE-2020-14812P4MEDIUMCVSS 4.9v9.02020-10-21
CVE-2020-14812 [MEDIUM] CVE-2020-14812: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Locking). Supported ve Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Locking). Supported versions that are affected are 5.6.49 and prior, 5.7.31 and prior and 8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerabil
nvd
CVE-2021-45949P4MEDIUMCVSS 5.5v9.0v10.0+1 more2022-01-01
CVE-2021-45949 [MEDIUM] CWE-787 CVE-2021-45949: Ghostscript GhostPDL 9.50 through 9.54.0 has a heap-based buffer overflow in sampled_data_finish (ca Ghostscript GhostPDL 9.50 through 9.54.0 has a heap-based buffer overflow in sampled_data_finish (called from sampled_data_continue and interp).
nvd
CVE-2019-9209P4MEDIUMCVSS 5.5v8.0v9.02019-02-28
CVE-2019-9209 [MEDIUM] CWE-193 CVE-2019-9209: In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the ASN.1 BER and related dissectors could crash. T In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the ASN.1 BER and related dissectors could crash. This was addressed in epan/dissectors/packet-ber.c by preventing a buffer overflow associated with excessive digits in time values.
nvd
CVE-2020-27841P4MEDIUMCVSS 5.5v9.0v10.02021-01-05
CVE-2020-27841 [MEDIUM] CWE-122 CVE-2020-27841: There's a flaw in openjpeg in versions prior to 2.4.0 in src/lib/openjp2/pi.c. When an attacker is a There's a flaw in openjpeg in versions prior to 2.4.0 in src/lib/openjp2/pi.c. When an attacker is able to provide crafted input to be processed by the openjpeg encoder, this could cause an out-of-bounds read. The greatest impact from this flaw is to application availability.
nvd
CVE-2017-8312P4MEDIUMCVSS 5.5v8.02017-05-23
CVE-2017-8312 [MEDIUM] CWE-125 CVE-2017-8312: Heap out-of-bound read in ParseJSS in VideoLAN VLC due to missing check of string length allows atta Heap out-of-bound read in ParseJSS in VideoLAN VLC due to missing check of string length allows attackers to read heap uninitialized data via a crafted subtitles file.
nvd
CVE-2017-3462P4MEDIUMCVSS 4.9v8.02017-04-24
CVE-2017-3462 [MEDIUM] CVE-2017-3462: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privile Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported versions that are affected are 5.5.54 and earlier, 5.6.35 and earlier and 5.7.17 and earlier. Easily "exploitable" vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful at
nvd
CVE-2015-2573P4MEDIUMCVSS 4.0v7.0v8.02015-04-16
CVE-2015-2573 [MEDIUM] CVE-2015-2573: Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows remote authenticated users to affect availability via vectors related to DDL.
nvd
CVE-2014-2270P4MEDIUMCVSS 4.3v6.0v7.0+1 more2014-03-14
CVE-2014-2270 [MEDIUM] CWE-119 CVE-2014-2270: softmagic.c in file before 5.17 and libmagic allows context-dependent attackers to cause a denial of softmagic.c in file before 5.17 and libmagic allows context-dependent attackers to cause a denial of service (out-of-bounds memory access and crash) via crafted offsets in the softmagic of a PE executable.
nvd
CVE-2018-1000199P4MEDIUMCVSS 5.5v7.0v8.0+1 more2018-05-24
CVE-2018-1000199 [MEDIUM] CWE-119 CVE-2018-1000199: The Linux Kernel version 3.18 contains a dangerous feature vulnerability in modify_user_hw_breakpoin The Linux Kernel version 3.18 contains a dangerous feature vulnerability in modify_user_hw_breakpoint() that can result in crash and possibly memory corruption. This attack appear to be exploitable via local code execution and the ability to use ptrace. This vulnerability appears to have been fixed in git commit f67b15037a7a50c57f72e69a6d59941ad
nvd
CVE-2010-0205P4MEDIUMCVSS 4.3v5.0v6.02010-03-03
CVE-2010-0205 [MEDIUM] CWE-400 CVE-2010-0205: The png_decompress_chunk function in pngrutil.c in libpng 1.0.x before 1.0.53, 1.2.x before 1.2.43, The png_decompress_chunk function in pngrutil.c in libpng 1.0.x before 1.0.53, 1.2.x before 1.2.43, and 1.4.x before 1.4.1 does not properly handle compressed ancillary-chunk data that has a disproportionately large uncompressed representation, which allows remote attackers to cause a denial of service (memory and CPU consumption, and application hang)
nvd
CVE-2021-20244P4MEDIUMCVSS 5.5v9.02021-03-09
CVE-2021-20244 [MEDIUM] CWE-369 CVE-2021-20244: A flaw was found in ImageMagick in MagickCore/visual-effects.c. An attacker who submits a crafted fi A flaw was found in ImageMagick in MagickCore/visual-effects.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat from this vulnerability is to system availability.
nvd
CVE-2014-4911P4MEDIUMCVSS 5.0v6.0v7.0+1 more2014-07-22
CVE-2014-4911 [MEDIUM] CWE-310 CVE-2014-4911: The ssl_decrypt_buf function in library/ssl_tls.c in PolarSSL before 1.2.11 and 1.3.x before 1.3.8 a The ssl_decrypt_buf function in library/ssl_tls.c in PolarSSL before 1.2.11 and 1.3.x before 1.3.8 allows remote attackers to cause a denial of service (crash) via vectors related to the GCM ciphersuites, as demonstrated using the Codenomicon Defensics toolkit.
nvd
CVE-2020-25676P4MEDIUMCVSS 5.5v9.02020-12-08
CVE-2020-25676 [MEDIUM] CWE-190 CVE-2020-25676: In CatromWeights(), MeshInterpolate(), InterpolatePixelChannel(), InterpolatePixelChannels(), and In In CatromWeights(), MeshInterpolate(), InterpolatePixelChannel(), InterpolatePixelChannels(), and InterpolatePixelInfo(), which are all functions in /MagickCore/pixel.c, there were multiple unconstrained pixel offset calculations which were being used with the floor() function. These calculations produced undefined behavior in the form of out-of-ran
nvd
CVE-2011-4360P4MEDIUMCVSS 5.0v5.0v6.02012-01-08
CVE-2011-4360 [MEDIUM] CWE-200 CVE-2011-4360: MediaWiki before 1.17.1 allows remote attackers to obtain the page titles of all restricted pages vi MediaWiki before 1.17.1 allows remote attackers to obtain the page titles of all restricted pages via a series of requests involving the (1) curid or (2) oldid parameter.
nvd
CVE-2025-38191P4MEDIUMCVSS 5.5v11.02025-07-04
CVE-2025-38191 [MEDIUM] CWE-476 CVE-2025-38191: In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix null pointer derefer In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix null pointer dereference in destroy_previous_session If client set ->PreviousSessionId on kerberos session setup stage, NULL pointer dereference error will happen. Since sess->user is not set yet, It can pass the user argument as NULL to destroy_previous_session. sess->u
nvd
CVE-2020-21529P4MEDIUMCVSS 5.5v9.0v10.02021-09-16
CVE-2020-21529 [MEDIUM] CWE-787 CVE-2020-21529: fig2dev 3.2.7b contains a stack buffer overflow in the bezier_spline function in genepic.c. fig2dev 3.2.7b contains a stack buffer overflow in the bezier_spline function in genepic.c.
nvd
CVE-2021-3630P4MEDIUMCVSS 5.5v9.0v10.0+1 more2021-06-30
CVE-2021-3630 [MEDIUM] CWE-787 CVE-2021-3630: An out-of-bounds write vulnerability was found in DjVuLibre in DJVU::DjVuTXT::decode() in DjVuText.c An out-of-bounds write vulnerability was found in DjVuLibre in DJVU::DjVuTXT::decode() in DjVuText.cpp via a crafted djvu file which may lead to crash and segmentation fault. This flaw affects DjVuLibre versions prior to 3.5.28.
nvd
CVE-2020-10001P4MEDIUMCVSS 5.5v9.02021-04-02
CVE-2020-10001 [MEDIUM] CWE-20 CVE-2020-10001: An input validation issue was addressed with improved memory handling. This issue is fixed in macOS An input validation issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave. A malicious application may be able to read restricted memory.
nvd
Debian Linux vulnerabilities | cvebase