cbcvebase.

Debian Linux vulnerabilities

9,955 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358

Vulnerabilities

Page 399 of 498
CVE-2017-16529P4MEDIUMCVSS 6.6v7.02017-11-04
CVE-2017-16529 [MEDIUM] CWE-125 CVE-2017-16529: The snd_usb_create_streams function in sound/usb/card.c in the Linux kernel before 4.13.6 allows loc The snd_usb_create_streams function in sound/usb/card.c in the Linux kernel before 4.13.6 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly have unspecified other impact via a crafted USB device.
nvd
CVE-2017-16533P4MEDIUMCVSS 6.6v7.02017-11-04
CVE-2017-16533 [MEDIUM] CWE-125 CVE-2017-16533: The usbhid_parse function in drivers/hid/usbhid/hid-core.c in the Linux kernel before 4.13.8 allows The usbhid_parse function in drivers/hid/usbhid/hid-core.c in the Linux kernel before 4.13.8 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly have unspecified other impact via a crafted USB device.
nvd
CVE-2014-7204P4MEDIUMCVSS 5.0v7.02014-10-07
CVE-2014-7204 [MEDIUM] CWE-399 CVE-2014-7204: jscript.c in Exuberant Ctags 5.8 allows remote attackers to cause a denial of service (infinite loop jscript.c in Exuberant Ctags 5.8 allows remote attackers to cause a denial of service (infinite loop and CPU and disk consumption) via a crafted JavaScript file.
nvd
CVE-2016-9916P4MEDIUMCVSS 6.5v8.02016-12-29
CVE-2016-9916 [MEDIUM] CWE-401 CVE-2016-9916: Memory leak in hw/9pfs/9p-proxy.c in QEMU (aka Quick Emulator) allows local privileged guest OS user Memory leak in hw/9pfs/9p-proxy.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of service (host memory consumption and possibly QEMU process crash) by leveraging a missing cleanup operation in the proxy backend.
nvd
CVE-2017-8086P4MEDIUMCVSS 6.5v8.02017-05-02
CVE-2017-8086 [MEDIUM] CWE-772 CVE-2017-8086: Memory leak in the v9fs_list_xattr function in hw/9pfs/9p-xattr.c in QEMU (aka Quick Emulator) allow Memory leak in the v9fs_list_xattr function in hw/9pfs/9p-xattr.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (memory consumption) via vectors involving the orig_value variable.
nvd
CVE-2017-8379P4MEDIUMCVSS 6.5v8.02017-05-23
CVE-2017-8379 [MEDIUM] CWE-772 CVE-2017-8379: Memory leak in the keyboard input event handlers support in QEMU (aka Quick Emulator) allows local g Memory leak in the keyboard input event handlers support in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption) by rapidly generating large keyboard events.
nvd
CVE-2015-2750P4MEDIUMCVSS 6.1v8.0v9.02017-09-13
CVE-2015-2750 [MEDIUM] CWE-601 CVE-2015-2750: Open redirect vulnerability in URL-related API functions in Drupal 6.x before 6.35 and 7.x before 7. Open redirect vulnerability in URL-related API functions in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the "//" initial sequence.
nvd
CVE-2019-12067P4MEDIUMCVSS 6.5v9.0v10.0+1 more2021-06-02
CVE-2019-12067 [MEDIUM] CWE-476 CVE-2019-12067: The ahci_commit_buf function in ide/ahci.c in QEMU allows attackers to cause a denial of service (NU The ahci_commit_buf function in ide/ahci.c in QEMU allows attackers to cause a denial of service (NULL dereference) when the command header 'ad->cur_cmd' is null.
nvd
CVE-2013-2486P4MEDIUMCVSS 6.1v7.02013-03-07
CVE-2013-2486 [MEDIUM] CWE-189 CVE-2013-2486: The dissect_diagnosticrequest function in epan/dissectors/packet-reload.c in the REsource LOcation A The dissect_diagnosticrequest function in epan/dissectors/packet-reload.c in the REsource LOcation And Discovery (aka RELOAD) dissector in Wireshark 1.8.x before 1.8.6 uses an incorrect integer data type, which allows remote attackers to cause a denial of service (infinite loop) via crafted integer values in a packet.
nvd
CVE-2012-0876P4MEDIUMCVSS 4.3v6.0v7.02012-07-03
CVE-2012-0876 [MEDIUM] CWE-400 CVE-2012-0876: The XML parser (xmlparse.c) in expat before 2.1.0 computes hash values without restricting the abili The XML parser (xmlparse.c) in expat before 2.1.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via an XML file with many identifiers with the same value.
nvd
CVE-2015-2559P4LOWCVSS 3.5v7.02015-03-25
CVE-2015-2559 [LOW] CWE-284 CVE-2015-2559: Drupal 6.x before 6.35 and 7.x before 7.35 allows remote authenticated users to reset the password o Drupal 6.x before 6.35 and 7.x before 7.35 allows remote authenticated users to reset the password of other accounts by leveraging an account with the same password hash as another account and a crafted password reset URL.
nvd
CVE-2017-8808P4MEDIUMCVSS 6.1v9.02017-11-15
CVE-2017-8808 [MEDIUM] CWE-79 CVE-2017-8808: MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 has XSS when the $wgShowExce MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 has XSS when the $wgShowExceptionDetails setting is false and the browser sends non-standard URL escaping.
nvd
CVE-2017-8811P4MEDIUMCVSS 6.1v9.02017-11-15
CVE-2017-8811 [MEDIUM] CWE-20 CVE-2017-8811: The implementation of raw message parameter expansion in MediaWiki before 1.27.4, 1.28.x before 1.28 The implementation of raw message parameter expansion in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows HTML mangling attacks.
nvd
CVE-2015-9261P4MEDIUMCVSS 5.5v8.0v9.02018-07-26
CVE-2015-9261 [MEDIUM] CWE-476 CVE-2015-9261: huft_build in archival/libarchive/decompress_gunzip.c in BusyBox before 1.27.2 misuses a pointer, ca huft_build in archival/libarchive/decompress_gunzip.c in BusyBox before 1.27.2 misuses a pointer, causing segfaults and an application crash during an unzip operation on a specially crafted ZIP file.
nvd
CVE-2018-18606P4MEDIUMCVSS 5.5v7.0v8.0+1 more2018-10-23
CVE-2018-18606 [MEDIUM] CWE-476 CVE-2018-18606: An issue was discovered in the merge_strings function in merge.c in the Binary File Descriptor (BFD) An issue was discovered in the merge_strings function in merge.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. There is a NULL pointer dereference in _bfd_add_merge_section when attempting to merge sections with large alignments. A specially crafted ELF allows remote attackers to cause a denial of ser
nvd
CVE-2018-18607P4MEDIUMCVSS 5.5v7.0v8.0+1 more2018-10-23
CVE-2018-18607 [MEDIUM] CWE-476 CVE-2018-18607: An issue was discovered in elf_link_input_bfd in elflink.c in the Binary File Descriptor (BFD) libra An issue was discovered in elf_link_input_bfd in elflink.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. There is a NULL pointer dereference in elf_link_input_bfd when used for finding STT_TLS symbols without any TLS section. A specially crafted ELF allows remote attackers to cause a denial of service
nvd
CVE-2016-9556P4MEDIUMCVSS 5.5v8.02017-03-23
CVE-2016-9556 [MEDIUM] CWE-119 CVE-2016-9556: The IsPixelGray function in MagickCore/pixel-accessor.h in ImageMagick 7.0.3-8 allows remote attacke The IsPixelGray function in MagickCore/pixel-accessor.h in ImageMagick 7.0.3-8 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted image file.
nvd
CVE-2013-4078P4MEDIUMCVSS 5.0v7.02013-06-09
CVE-2013-4078 [MEDIUM] CWE-20 CVE-2013-4078: epan/dissectors/packet-rdp.c in the RDP dissector in Wireshark 1.8.x before 1.8.8 does not validate epan/dissectors/packet-rdp.c in the RDP dissector in Wireshark 1.8.x before 1.8.8 does not validate return values during checks for data availability, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
nvd
CVE-2010-2531P4MEDIUMCVSS 4.3v5.0v6.02010-08-20
CVE-2010-2531 [MEDIUM] CWE-200 CVE-2010-2531: The var_export function in PHP 5.2 before 5.2.14 and 5.3 before 5.3.3 flushes the output buffer to t The var_export function in PHP 5.2 before 5.2.14 and 5.3 before 5.3.3 flushes the output buffer to the user when certain fatal errors occur, even if display_errors is off, which allows remote attackers to obtain sensitive information by causing the application to exceed limits for memory, execution time, or recursion.
nvd
CVE-2016-2317P4MEDIUMCVSS 5.5v8.02017-02-03
CVE-2016-2317 [MEDIUM] CWE-119 CVE-2016-2317: Multiple buffer overflows in GraphicsMagick 1.3.23 allow remote attackers to cause a denial of servi Multiple buffer overflows in GraphicsMagick 1.3.23 allow remote attackers to cause a denial of service (crash) via a crafted SVG file, related to the (1) TracePoint function in magick/render.c, (2) GetToken function in magick/utility.c, and (3) GetTransformTokens function in coders/svg.c.
nvd
Debian Linux vulnerabilities | cvebase