Debian Linux vulnerabilities
9,955 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358
Vulnerabilities
Page 400 of 498
CVE-2016-9532P4MEDIUMCVSS 5.5v8.02017-02-06
CVE-2016-9532 [MEDIUM] CWE-125 CVE-2016-9532: Integer overflow in the writeBufferToSeparateStrips function in tiffcrop.c in LibTIFF before 4.0.7 a
Integer overflow in the writeBufferToSeparateStrips function in tiffcrop.c in LibTIFF before 4.0.7 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tif file.
nvd
CVE-2021-36058P4MEDIUMCVSS 5.5v10.02021-09-01
CVE-2021-36058 [MEDIUM] CWE-190 CVE-2021-36058: XMP Toolkit SDK version 2020.1 (and earlier) is affected by an Integer Overflow vulnerability potent
XMP Toolkit SDK version 2020.1 (and earlier) is affected by an Integer Overflow vulnerability potentially resulting in application-level denial of service in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file.
nvd
CVE-2018-19478P4MEDIUMCVSS 5.5v8.02019-01-02
CVE-2018-19478 [MEDIUM] CWE-20 CVE-2018-19478: In Artifex Ghostscript before 9.26, a carefully crafted PDF file can trigger an extremely long runni
In Artifex Ghostscript before 9.26, a carefully crafted PDF file can trigger an extremely long running computation when parsing the file.
nvd
CVE-2016-2318P4MEDIUMCVSS 5.5v8.02017-02-03
CVE-2016-2318 [MEDIUM] CWE-476 CVE-2016-2318: GraphicsMagick 1.3.23 allows remote attackers to cause a denial of service (NULL pointer dereference
GraphicsMagick 1.3.23 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted SVG file, related to the (1) DrawImage function in magick/render.c, (2) SVGStartElement function in coders/svg.c, and (3) TraceArcPath function in magick/render.c.
nvd
CVE-2019-15142P4MEDIUMCVSS 5.5v8.0v9.0+2 more2019-08-18
CVE-2019-15142 [MEDIUM] CWE-125 CVE-2019-15142: In DjVuLibre 3.5.27, DjVmDir.cpp in the DJVU reader component allows attackers to cause a denial-of-
In DjVuLibre 3.5.27, DjVmDir.cpp in the DJVU reader component allows attackers to cause a denial-of-service (application crash in GStringRep::strdup in libdjvu/GString.cpp caused by a heap-based buffer over-read) by crafting a DJVU file.
nvd
CVE-2020-11760P4MEDIUMCVSS 5.5v9.0v10.02020-04-14
CVE-2020-11760 [MEDIUM] CWE-125 CVE-2020-11760: An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during RLE uncompres
An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during RLE uncompression in rleUncompress in ImfRle.cpp.
nvd
CVE-2020-11758P4MEDIUMCVSS 5.5v9.0v10.02020-04-14
CVE-2020-11758 [MEDIUM] CWE-125 CVE-2020-11758: An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read in ImfOptimizedPixel
An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read in ImfOptimizedPixelReading.h.
nvd
CVE-2013-7345P4MEDIUMCVSS 5.0v6.0v7.0+1 more2014-03-24
CVE-2013-7345 [MEDIUM] CVE-2013-7345: The BEGIN regular expression in the awk script detector in magic/Magdir/commands in file before 5.15
The BEGIN regular expression in the awk script detector in magic/Magdir/commands in file before 5.15 uses multiple wildcards with unlimited repetitions, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted ASCII file that triggers a large amount of backtracking, as demonstrated via a file with many newline char
nvd
CVE-2020-11761P4MEDIUMCVSS 5.5v9.0v10.02020-04-14
CVE-2020-11761 [MEDIUM] CWE-125 CVE-2020-11761: An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during Huffman uncom
An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during Huffman uncompression, as demonstrated by FastHufDecoder::refill in ImfFastHuf.cpp.
nvd
CVE-2020-16306P4MEDIUMCVSS 5.5v9.0v10.02020-08-13
CVE-2020-16306 [MEDIUM] CWE-476 CVE-2020-16306: A null pointer dereference vulnerability in devices/gdevtsep.c of Artifex Software GhostScript v9.50
A null pointer dereference vulnerability in devices/gdevtsep.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted postscript file. This is fixed in v9.51.
nvd
CVE-2021-22924P4LOWCVSS 3.7v9.0v10.0+1 more2021-08-05
CVE-2021-22924 [LOW] CWE-20 CVE-2021-22924: libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if
libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup.Due to errors in the logic, the config matching function did not take 'issuercert' into account and it compared the involved paths *case insensitively*,which could lead to libcurl reusing wrong connections.File paths are, or c
nvd
CVE-2018-0360P4MEDIUMCVSS 5.5v8.02018-07-16
CVE-2018-0360 [MEDIUM] CWE-190 CVE-2018-0360: ClamAV before 0.100.1 has an HWP integer overflow with a resultant infinite loop via a crafted Hangu
ClamAV before 0.100.1 has an HWP integer overflow with a resultant infinite loop via a crafted Hangul Word Processor file. This is in parsehwp3_paragraph() in libclamav/hwp.c.
nvd
CVE-2014-7155P4MEDIUMCVSS 5.8v7.02014-10-02
CVE-2014-7155 [MEDIUM] CWE-264 CVE-2014-7155: The x86_emulate function in arch/x86/x86_emulate/x86_emulate.c in Xen 4.4.x and earlier does not pro
The x86_emulate function in arch/x86/x86_emulate/x86_emulate.c in Xen 4.4.x and earlier does not properly check supervisor mode permissions, which allows local HVM users to cause a denial of service (guest crash) or gain guest kernel mode privileges via vectors involving an (1) HLT, (2) LGDT, (3) LIDT, or (4) LMSW instruction.
nvd
CVE-2016-7906P4MEDIUMCVSS 5.5v8.02017-01-18
CVE-2016-7906 [MEDIUM] CWE-416 CVE-2016-7906: magick/attribute.c in ImageMagick 7.0.3-2 allows remote attackers to cause a denial of service (use-
magick/attribute.c in ImageMagick 7.0.3-2 allows remote attackers to cause a denial of service (use-after-free) via a crafted file.
nvd
CVE-2016-0647P4MEDIUMCVSS 5.5v8.02016-04-21
CVE-2016-0647 [MEDIUM] CVE-2016-0647: Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and ear
Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows local users to affect availability via vectors related to FTS.
nvd
CVE-2016-0648P4MEDIUMCVSS 5.5v8.02016-04-21
CVE-2016-0648 [MEDIUM] CVE-2016-0648: Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and ear
Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows local users to affect availability via vectors related to PS.
nvd
CVE-2017-7613P4MEDIUMCVSS 5.5v8.02017-04-09
CVE-2017-7613 [MEDIUM] CWE-20 CVE-2017-7613: elflint.c in elfutils 0.168 does not validate the number of sections and the number of segments, whi
elflint.c in elfutils 0.168 does not validate the number of sections and the number of segments, which allows remote attackers to cause a denial of service (memory consumption) via a crafted ELF file.
nvd
CVE-2017-9865P4MEDIUMCVSS 5.5v8.0v9.02017-06-25
CVE-2017-9865 [MEDIUM] CWE-125 CVE-2017-9865: The function GfxImageColorMap::getGray in GfxState.cc in Poppler 0.54.0 allows remote attackers to c
The function GfxImageColorMap::getGray in GfxState.cc in Poppler 0.54.0 allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted PDF document, related to missing color-map validation in ImageOutputDev.cc.
nvd
CVE-2013-2879P4MEDIUMCVSS 5.8v7.02013-07-10
CVE-2013-2879 [MEDIUM] CWE-200 CVE-2013-2879: Google Chrome before 28.0.1500.71 does not properly determine the circumstances in which a renderer
Google Chrome before 28.0.1500.71 does not properly determine the circumstances in which a renderer process can be considered a trusted process for sign-in and subsequent sync operations, which makes it easier for remote attackers to conduct phishing attacks via a crafted web site.
nvd
CVE-2018-1000085P4MEDIUMCVSS 5.5v7.02018-03-13
CVE-2018-1000085 [MEDIUM] CWE-125 CVE-2018-1000085: ClamAV version version 0.99.3 contains a Out of bounds heap memory read vulnerability in XAR parser,
ClamAV version version 0.99.3 contains a Out of bounds heap memory read vulnerability in XAR parser, function xar_hash_check() that can result in Leaking of memory, may help in developing exploit chains.. This attack appear to be exploitable via The victim must scan a crafted XAR file. This vulnerability appears to have been fixed in after commi
nvd