cbcvebase.

Debian Linux vulnerabilities

9,955 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358

Vulnerabilities

Page 402 of 498
CVE-2019-19797P4MEDIUMCVSS 5.5v9.02019-12-15
CVE-2019-19797 [MEDIUM] CWE-787 CVE-2019-19797: read_colordef in read.c in Xfig fig2dev 3.2.7b has an out-of-bounds write. read_colordef in read.c in Xfig fig2dev 3.2.7b has an out-of-bounds write.
nvd
CVE-2019-1010301P4MEDIUMCVSS 5.5v8.02019-07-15
CVE-2019-1010301 [MEDIUM] CWE-787 CVE-2019-1010301: jhead 3.03 is affected by: Buffer Overflow. The impact is: Denial of service. The component is: gpsi jhead 3.03 is affected by: Buffer Overflow. The impact is: Denial of service. The component is: gpsinfo.c Line 151 ProcessGpsInfo(). The attack vector is: Open a specially crafted JPEG file.
nvd
CVE-2021-20245P4MEDIUMCVSS 5.5v9.02021-03-09
CVE-2021-20245 [MEDIUM] CWE-369 CVE-2021-20245: A flaw was found in ImageMagick in coders/webp.c. An attacker who submits a crafted file that is pro A flaw was found in ImageMagick in coders/webp.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat from this vulnerability is to system availability.
nvd
CVE-2001-0755P4HIGHCVSS 7.5v6.22001-10-18
CVE-2001-0755 [HIGH] CVE-2001-0755: Buffer overflow in ftp daemon (ftpd) 6.2 in Debian GNU/Linux allows attackers to cause a denial of s Buffer overflow in ftp daemon (ftpd) 6.2 in Debian GNU/Linux allows attackers to cause a denial of service and possibly execute arbitrary code via a long SITE command.
nvd
CVE-2020-27770P4MEDIUMCVSS 5.5v9.02020-12-04
CVE-2020-27770 [MEDIUM] CWE-190 CVE-2020-27770: Due to a missing check for 0 value of `replace_extent`, it is possible for offset `p` to overflow in Due to a missing check for 0 value of `replace_extent`, it is possible for offset `p` to overflow in SubstituteString(), causing potential impact to application availability. This could be triggered by a crafted input file that is processed by ImageMagick. This flaw affects ImageMagick versions prior to 7.0.8-68.
nvd
CVE-2020-15989P4MEDIUMCVSS 5.5v10.02020-11-03
CVE-2020-15989 [MEDIUM] CWE-908 CVE-2020-15989: Uninitialized data in PDFium in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to obt Uninitialized data in PDFium in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted PDF file.
nvd
CVE-2020-27762P4MEDIUMCVSS 5.5v9.02020-12-03
CVE-2020-27762 [MEDIUM] CWE-190 CVE-2020-27762: A flaw was found in ImageMagick in coders/hdr.c. An attacker who submits a crafted file that is proc A flaw was found in ImageMagick in coders/hdr.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type `unsigned char`. This would most likely lead to an impact to application availability, but could potentially cause other problems related to undefine
nvd
CVE-2020-25674P4MEDIUMCVSS 5.5v9.02020-12-08
CVE-2020-25674 [MEDIUM] CWE-122 CVE-2020-25674: WriteOnePNGImage() from coders/png.c (the PNG coder) has a for loop with an improper exit condition WriteOnePNGImage() from coders/png.c (the PNG coder) has a for loop with an improper exit condition that can allow an out-of-bounds READ via heap-buffer-overflow. This occurs because it is possible for the colormap to have less than 256 valid values but the loop condition will loop 256 times, attempting to pass invalid colormap data to the event logg
nvd
CVE-2020-25665P4MEDIUMCVSS 5.5v9.02020-12-08
CVE-2020-25665 [MEDIUM] CWE-122 CVE-2020-25665: The PALM image coder at coders/palm.c makes an improper call to AcquireQuantumMemory() in routine Wr The PALM image coder at coders/palm.c makes an improper call to AcquireQuantumMemory() in routine WritePALMImage() because it needs to be offset by 256. This can cause a out-of-bounds read later on in the routine. The patch adds 256 to bytes_per_row in the call to AcquireQuantumMemory(). This could cause impact to reliability. This flaw affects Imag
nvd
CVE-2020-13434P4MEDIUMCVSS 5.5v8.0v9.02020-05-24
CVE-2020-13434 [MEDIUM] CWE-190 CVE-2020-13434: SQLite through 3.32.0 has an integer overflow in sqlite3_str_vappendf in printf.c. SQLite through 3.32.0 has an integer overflow in sqlite3_str_vappendf in printf.c.
nvd
CVE-2020-27750P4MEDIUMCVSS 5.5v9.02020-12-08
CVE-2020-27750 [MEDIUM] CWE-369 CVE-2020-27750: A flaw was found in ImageMagick in MagickCore/colorspace-private.h and MagickCore/quantum.h. An atta A flaw was found in ImageMagick in MagickCore/colorspace-private.h and MagickCore/quantum.h. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type `unsigned char` and math division by zero. This would most likely lead to an impact to application availa
nvd
CVE-2022-47929P4MEDIUMCVSS 5.5v11.02023-01-17
CVE-2022-47929 [MEDIUM] CWE-476 CVE-2022-47929: In the Linux kernel before 6.1.6, a NULL pointer dereference bug in the traffic control subsystem al In the Linux kernel before 6.1.6, a NULL pointer dereference bug in the traffic control subsystem allows an unprivileged user to trigger a denial of service (system crash) via a crafted traffic control configuration that is set up with "tc qdisc" and "tc class" commands. This affects qdisc_graft in net/sched/sch_api.c.
nvd
CVE-2021-3478P4MEDIUMCVSS 5.5v9.0v10.02021-03-31
CVE-2021-3478 [MEDIUM] CWE-400 CVE-2021-3478: There's a flaw in OpenEXR's scanline input file functionality in versions before 3.0.0-beta. An atta There's a flaw in OpenEXR's scanline input file functionality in versions before 3.0.0-beta. An attacker able to submit a crafted file to be processed by OpenEXR could consume excessive system memory. The greatest impact of this flaw is to system availability.
nvd
CVE-2021-3477P4MEDIUMCVSS 5.5v9.0v10.02021-03-31
CVE-2021-3477 [MEDIUM] CWE-190 CVE-2021-3477: There's a flaw in OpenEXR's deep tile sample size calculations in versions before 3.0.0-beta. An att There's a flaw in OpenEXR's deep tile sample size calculations in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to be processed by OpenEXR could trigger an integer overflow, subsequently leading to an out-of-bounds read. The greatest risk of this flaw is to application availability.
nvd
CVE-2019-19922P4MEDIUMCVSS 5.5v8.02019-12-22
CVE-2019-19922 [MEDIUM] CWE-400 CVE-2019-19922: kernel/sched/fair.c in the Linux kernel before 5.3.9, when cpu.cfs_quota_us is used (e.g., with Kube kernel/sched/fair.c in the Linux kernel before 5.3.9, when cpu.cfs_quota_us is used (e.g., with Kubernetes), allows attackers to cause a denial of service against non-cpu-bound applications by generating a workload that triggers unwanted slice expiration, aka CID-de53fd7aedb1. (In other words, although this slice expiration would typically be seen w
nvd
CVE-2018-18358P4MEDIUMCVSS 5.7v9.02018-12-11
CVE-2018-18358 [MEDIUM] CWE-20 CVE-2018-18358: Lack of special casing of localhost in WPAD files in Google Chrome prior to 71.0.3578.80 allowed an Lack of special casing of localhost in WPAD files in Google Chrome prior to 71.0.3578.80 allowed an attacker on the local network segment to proxy resources on localhost via a crafted WPAD file.
nvd
CVE-2021-20176P4MEDIUMCVSS 5.5v9.02021-02-06
CVE-2021-20176 [MEDIUM] CWE-369 CVE-2021-20176: A divide-by-zero flaw was found in ImageMagick 6.9.11-57 and 7.0.10-57 in gem.c. This flaw allows an A divide-by-zero flaw was found in ImageMagick 6.9.11-57 and 7.0.10-57 in gem.c. This flaw allows an attacker who submits a crafted file that is processed by ImageMagick to trigger undefined behavior through a division by zero. The highest threat from this vulnerability is to system availability.
nvd
CVE-2021-20300P4MEDIUMCVSS 5.5v10.02022-03-04
CVE-2021-20300 [MEDIUM] CWE-190 CVE-2021-20300: A flaw was found in OpenEXR's hufUncompress functionality in OpenEXR/IlmImf/ImfHuf.cpp. This flaw al A flaw was found in OpenEXR's hufUncompress functionality in OpenEXR/IlmImf/ImfHuf.cpp. This flaw allows an attacker who can submit a crafted file that is processed by OpenEXR, to trigger an integer overflow. The highest threat from this vulnerability is to system availability.
nvd
CVE-2020-27618P4MEDIUMCVSS 5.5v10.02021-02-26
CVE-2020-27618 [MEDIUM] CVE-2020-27618: The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing inval The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid multi-byte input sequences in IBM1364, IBM1371, IBM1388, IBM1390, and IBM1399 encodings, fails to advance the input state, which could lead to an infinite loop in applications, resulting in a denial of service, a different vulnerability from CVE-2016-10228
nvd
CVE-2020-21533P4MEDIUMCVSS 5.5v9.02021-09-16
CVE-2020-21533 [MEDIUM] CWE-787 CVE-2020-21533: fig2dev 3.2.7b contains a stack buffer overflow in the read_textobject function in read.c. fig2dev 3.2.7b contains a stack buffer overflow in the read_textobject function in read.c.
nvd
Debian Linux vulnerabilities | cvebase