cbcvebase.

Debian Linux vulnerabilities

9,955 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358

Vulnerabilities

Page 414 of 498
CVE-2016-9915P4MEDIUMCVSS 6.5v8.02016-12-29
CVE-2016-9915 [MEDIUM] CWE-401 CVE-2016-9915: Memory leak in hw/9pfs/9p-handle.c in QEMU (aka Quick Emulator) allows local privileged guest OS use Memory leak in hw/9pfs/9p-handle.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of service (host memory consumption and possibly QEMU process crash) by leveraging a missing cleanup operation in the handle backend.
nvd
CVE-2016-9914P4MEDIUMCVSS 6.5v8.02016-12-29
CVE-2016-9914 [MEDIUM] CWE-401 CVE-2016-9914: Memory leak in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to c Memory leak in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of service (host memory consumption and possibly QEMU process crash) by leveraging a missing cleanup operation in FileOperations.
nvd
CVE-2017-8112P4MEDIUMCVSS 6.5v8.02017-05-02
CVE-2017-8112 [MEDIUM] CWE-835 CVE-2017-8112: hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (infinite loop and CPU consumption) via the message ring page count.
nvd
CVE-2017-5525P4MEDIUMCVSS 6.5v8.02017-03-15
CVE-2017-5525 [MEDIUM] CWE-401 CVE-2017-5525: Memory leak in hw/audio/ac97.c in QEMU (aka Quick Emulator) allows local guest OS privileged users t Memory leak in hw/audio/ac97.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption and QEMU process crash) via a large number of device unplug operations.
nvd
CVE-2017-5579P4MEDIUMCVSS 6.5v8.02017-03-15
CVE-2017-5579 [MEDIUM] CWE-401 CVE-2017-5579: Memory leak in the serial_exit_core function in hw/char/serial.c in QEMU (aka Quick Emulator) allows Memory leak in the serial_exit_core function in hw/char/serial.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption and QEMU process crash) via a large number of device unplug operations.
nvd
CVE-2017-5526P4MEDIUMCVSS 6.5v8.02017-03-15
CVE-2017-5526 [MEDIUM] CWE-401 CVE-2017-5526: Memory leak in hw/audio/es1370.c in QEMU (aka Quick Emulator) allows local guest OS privileged users Memory leak in hw/audio/es1370.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption and QEMU process crash) via a large number of device unplug operations.
nvd
CVE-2017-12809P4MEDIUMCVSS 6.5v9.02017-08-23
CVE-2017-12809 [MEDIUM] CWE-476 CVE-2017-12809: QEMU (aka Quick Emulator), when built with the IDE disk and CD/DVD-ROM Emulator support, allows loca QEMU (aka Quick Emulator), when built with the IDE disk and CD/DVD-ROM Emulator support, allows local guest OS privileged users to cause a denial of service (NULL pointer dereference and QEMU process crash) by flushing an empty CDROM device drive.
nvd
CVE-2018-7542P4MEDIUMCVSS 6.5v9.02018-02-27
CVE-2018-7542 [MEDIUM] CWE-476 CVE-2018-7542: An issue was discovered in Xen 4.8.x through 4.10.x allowing x86 PVH guest OS users to cause a denia An issue was discovered in Xen 4.8.x through 4.10.x allowing x86 PVH guest OS users to cause a denial of service (NULL pointer dereference and hypervisor crash) by leveraging the mishandling of configurations that lack a Local APIC.
nvd
CVE-2007-0778P4MEDIUMCVSS 5.4v3.12007-02-26
CVE-2007-0778 [MEDIUM] CWE-200 CVE-2007-0778: The page cache feature in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey befo The page cache feature in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 can generate hash collisions that cause page data to be appended to the wrong page cache, which allows remote attackers to obtain sensitive information or enable further attack vectors when the target page is reloaded from the cache.
nvd
CVE-2019-12973P4MEDIUMCVSS 5.5v9.02019-06-26
CVE-2019-12973 [MEDIUM] CVE-2019-12973: In OpenJPEG 2.3.1, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. In OpenJPEG 2.3.1, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file. This issue is similar to CVE-2018-6616.
nvd
CVE-2015-8932P4MEDIUMCVSS 5.5v7.0v8.02016-09-20
CVE-2015-8932 [MEDIUM] CWE-20 CVE-2015-8932: The compress_bidder_init function in archive_read_support_filter_compress.c in libarchive before 3.2 The compress_bidder_init function in archive_read_support_filter_compress.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted tar file, which triggers an invalid left shift.
nvd
CVE-2015-8767P4MEDIUMCVSS 6.2v7.0v8.02016-02-08
CVE-2015-8767 [MEDIUM] CWE-362 CVE-2015-8767: net/sctp/sm_sideeffect.c in the Linux kernel before 4.3 does not properly manage the relationship be net/sctp/sm_sideeffect.c in the Linux kernel before 4.3 does not properly manage the relationship between a lock and a socket, which allows local users to cause a denial of service (deadlock) via a crafted sctp_accept call.
nvd
CVE-2014-6568P4LOWCVSS 3.5v7.02015-01-21
CVE-2014-6568 [LOW] CVE-2014-6568: Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier, and 5.6.21 and earlier, allows Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier, and 5.6.21 and earlier, allows remote authenticated users to affect availability via vectors related to Server : InnoDB : DML.
nvd
CVE-2017-7608P4MEDIUMCVSS 5.5v8.02017-04-09
CVE-2017-7608 [MEDIUM] CWE-125 CVE-2017-7608: The ebl_object_note_type_name function in eblobjnotetypename.c in elfutils 0.168 allows remote attac The ebl_object_note_type_name function in eblobjnotetypename.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.
nvd
CVE-2020-29570P4MEDIUMCVSS 6.2v10.02020-12-15
CVE-2020-29570 [MEDIUM] CWE-770 CVE-2020-29570: An issue was discovered in Xen through 4.14.x. Recording of the per-vCPU control block mapping maint An issue was discovered in Xen through 4.14.x. Recording of the per-vCPU control block mapping maintained by Xen and that of pointers into the control block is reversed. The consumer assumes, seeing the former initialized, that the latter are also ready for use. Malicious or buggy guest kernels can mount a Denial of Service (DoS) attack affecting th
nvd
CVE-2021-30002P4MEDIUMCVSS 6.2v9.02021-04-02
CVE-2021-30002 [MEDIUM] CWE-401 CVE-2021-30002: An issue was discovered in the Linux kernel before 5.11.3 when a webcam device exists. video_usercop An issue was discovered in the Linux kernel before 5.11.3 when a webcam device exists. video_usercopy in drivers/media/v4l2-core/v4l2-ioctl.c has a memory leak for large arguments, aka CID-fb18802a338b.
nvd
CVE-2015-1606P4MEDIUMCVSS 5.5v7.0v8.02019-11-20
CVE-2015-1606 [MEDIUM] CWE-416 CVE-2015-1606: The keyring DB in GnuPG before 2.1.2 does not properly handle invalid packets, which allows remote a The keyring DB in GnuPG before 2.1.2 does not properly handle invalid packets, which allows remote attackers to cause a denial of service (invalid read and use-after-free) via a crafted keyring file.
nvd
CVE-2020-16299P4MEDIUMCVSS 5.5v9.0v10.02020-08-13
CVE-2020-16299 [MEDIUM] CWE-369 CVE-2020-16299: A Division by Zero vulnerability in bj10v_print_page() in contrib/japanese/gdev10v.c of Artifex Soft A Division by Zero vulnerability in bj10v_print_page() in contrib/japanese/gdev10v.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
nvd
CVE-2020-16310P4MEDIUMCVSS 5.5v9.0v10.02020-08-13
CVE-2020-16310 [MEDIUM] CWE-369 CVE-2020-16310: A division by zero vulnerability in dot24_print_page() in devices/gdevdm24.c of Artifex Software Gho A division by zero vulnerability in dot24_print_page() in devices/gdevdm24.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
nvd
CVE-2020-16293P4MEDIUMCVSS 5.5v9.0v10.02020-08-13
CVE-2020-16293 [MEDIUM] CWE-476 CVE-2020-16293: A null pointer dereference vulnerability in compose_group_nonknockout_nonblend_isolated_allmask_comm A null pointer dereference vulnerability in compose_group_nonknockout_nonblend_isolated_allmask_common() in base/gxblend.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
nvd
Debian Linux vulnerabilities | cvebase