cbcvebase.

Debian Linux vulnerabilities

9,955 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358

Vulnerabilities

Page 415 of 498
CVE-2020-16295P4MEDIUMCVSS 5.5v9.0v10.02020-08-13
CVE-2020-16295 [MEDIUM] CWE-476 CVE-2020-16295: A null pointer dereference vulnerability in clj_media_size() in devices/gdevclj.c of Artifex Softwar A null pointer dereference vulnerability in clj_media_size() in devices/gdevclj.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
nvd
CVE-2020-16307P4MEDIUMCVSS 5.5v9.0v10.02020-08-13
CVE-2020-16307 [MEDIUM] CWE-476 CVE-2020-16307: A null pointer dereference vulnerability in devices/vector/gdevtxtw.c and psi/zbfont.c of Artifex So A null pointer dereference vulnerability in devices/vector/gdevtxtw.c and psi/zbfont.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted postscript file. This is fixed in v9.51.
nvd
CVE-2017-7611P4MEDIUMCVSS 5.5v8.02017-04-09
CVE-2017-7611 [MEDIUM] CWE-125 CVE-2017-7611: The check_symtab_shndx function in elflint.c in elfutils 0.168 allows remote attackers to cause a de The check_symtab_shndx function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.
nvd
CVE-2017-7610P4MEDIUMCVSS 5.5v8.02017-04-09
CVE-2017-7610 [MEDIUM] CWE-125 CVE-2017-7610: The check_group function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of The check_group function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.
nvd
CVE-2017-7612P4MEDIUMCVSS 5.5v8.02017-04-09
CVE-2017-7612 [MEDIUM] CWE-125 CVE-2017-7612: The check_sysv_hash function in elflint.c in elfutils 0.168 allows remote attackers to cause a denia The check_sysv_hash function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.
nvd
CVE-2016-9830P4MEDIUMCVSS 5.5v8.02017-03-01
CVE-2016-9830 [MEDIUM] CWE-20 CVE-2016-9830: The MagickRealloc function in memory.c in Graphicsmagick 1.3.25 allows remote attackers to cause a d The MagickRealloc function in memory.c in Graphicsmagick 1.3.25 allows remote attackers to cause a denial of service (crash) via large dimensions in a jpeg image.
nvd
CVE-2019-15143P4MEDIUMCVSS 5.5v8.0v9.0+2 more2019-08-18
CVE-2019-15143 [MEDIUM] CWE-835 CVE-2019-15143: In DjVuLibre 3.5.27, the bitmap reader component allows attackers to cause a denial-of-service error In DjVuLibre 3.5.27, the bitmap reader component allows attackers to cause a denial-of-service error (resource exhaustion caused by a GBitmap::read_rle_raw infinite loop) by crafting a corrupted image file, related to libdjvu/DjVmDir.cpp and libdjvu/GBitmap.cpp.
nvd
CVE-2020-11765P4MEDIUMCVSS 5.5v9.0v10.02020-04-14
CVE-2020-11765 [MEDIUM] CWE-125 CVE-2020-11765: An issue was discovered in OpenEXR before 2.4.1. There is an off-by-one error in use of the ImfXdr.h An issue was discovered in OpenEXR before 2.4.1. There is an off-by-one error in use of the ImfXdr.h read function by DwaCompressor::Classifier::Classifier, leading to an out-of-bounds read.
nvd
CVE-2015-8551P4MEDIUMCVSS 6.0v7.0v8.02016-04-13
CVE-2015-8551 [MEDIUM] CWE-476 CVE-2015-8551: The PCI backend driver in Xen, when running on an x86 system and using Linux 3.1.x through 4.3.x as The PCI backend driver in Xen, when running on an x86 system and using Linux 3.1.x through 4.3.x as the driver domain, allows local guest administrators to hit BUG conditions and cause a denial of service (NULL pointer dereference and host OS crash) by leveraging a system with access to a passed-through MSI or MSI-X capable physical PCI device and a cr
nvd
CVE-2017-18236P4MEDIUMCVSS 5.5v7.02018-03-15
CVE-2017-18236 [MEDIUM] CWE-835 CVE-2017-18236: An issue was discovered in Exempi before 2.4.4. The ASF_Support::ReadHeaderObject function in XMPFil An issue was discovered in Exempi before 2.4.4. The ASF_Support::ReadHeaderObject function in XMPFiles/source/FormatSupport/ASF_Support.cpp allows remote attackers to cause a denial of service (infinite loop) via a crafted .asf file.
nvd
CVE-2016-6836P4MEDIUMCVSS 6.0v8.02016-12-10
CVE-2016-6836 [MEDIUM] CWE-665 CVE-2016-6836: The vmxnet3_complete_packet function in hw/net/vmxnet3.c in QEMU (aka Quick Emulator) allows local g The vmxnet3_complete_packet function in hw/net/vmxnet3.c in QEMU (aka Quick Emulator) allows local guest OS administrators to obtain sensitive host memory information by leveraging failure to initialize the txcq_descr object.
nvd
CVE-2016-9103P4MEDIUMCVSS 6.0v8.02016-12-09
CVE-2016-9103 [MEDIUM] CWE-200 CVE-2016-9103: The v9fs_xattrcreate function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS adm The v9fs_xattrcreate function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to obtain sensitive host heap memory information by reading xattribute values before writing to them.
nvd
CVE-2013-6425P4MEDIUMCVSS 5.0v6.0v7.02014-01-18
CVE-2013-6425 [MEDIUM] CWE-191 CVE-2013-6425: Integer underflow in the pixman_trapezoid_valid macro in pixman.h in Pixman before 0.32.0, as used i Integer underflow in the pixman_trapezoid_valid macro in pixman.h in Pixman before 0.32.0, as used in X.Org server and cairo, allows context-dependent attackers to cause a denial of service (crash) via a negative bottom value.
nvd
CVE-2017-15371P4MEDIUMCVSS 5.5v7.0v8.02017-10-16
CVE-2017-15371 [MEDIUM] CWE-617 CVE-2017-15371: There is a reachable assertion abort in the function sox_append_comment() in formats.c in Sound eXch There is a reachable assertion abort in the function sox_append_comment() in formats.c in Sound eXchange (SoX) 14.4.2. A Crafted input will lead to a denial of service attack during conversion of an audio file.
nvd
CVE-2018-11503P4MEDIUMCVSS 5.5v8.0v9.02018-05-26
CVE-2018-11503 [MEDIUM] CWE-125 CVE-2018-11503: The isfootnote function in markdown.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to The isfootnote function in markdown.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file, as demonstrated by mkd2html.
nvd
CVE-2017-3243P4MEDIUMCVSS 4.4v8.02017-01-27
CVE-2017-3243 [MEDIUM] CVE-2017-3243: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Charsets). Suppor Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Charsets). Supported versions that are affected are 5.5.53 and earlier. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized
nvd
CVE-2016-4570P4MEDIUMCVSS 5.5v8.02017-02-03
CVE-2016-4570 [MEDIUM] CWE-400 CVE-2016-4570: The mxmlDelete function in mxml-node.c in mxml 2.9, 2.7, and possibly earlier allows remote attacker The mxmlDelete function in mxml-node.c in mxml 2.9, 2.7, and possibly earlier allows remote attackers to cause a denial of service (stack consumption) via crafted xml file.
nvd
CVE-2013-2488P4MEDIUMCVSS 5.0v7.02013-03-07
CVE-2013-2488 [MEDIUM] CWE-20 CVE-2013-2488: The DTLS dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 does not validate the fra The DTLS dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 does not validate the fragment offset before invoking the reassembly state machine, which allows remote attackers to cause a denial of service (application crash) via a large offset value that triggers write access to an invalid memory location.
nvd
CVE-2018-1000037P4MEDIUMCVSS 5.5v9.02018-05-24
CVE-2018-1000037 [MEDIUM] CWE-20 CVE-2018-1000037: In Artifex MuPDF 1.12.0 and earlier, multiple reachable assertions in the PDF parser allow an attack In Artifex MuPDF 1.12.0 and earlier, multiple reachable assertions in the PDF parser allow an attacker to cause a denial of service (assert crash) via a crafted file.
nvd
CVE-2016-7424P4MEDIUMCVSS 5.5v8.02016-10-07
CVE-2016-7424 [MEDIUM] CWE-476 CVE-2016-7424: The put_no_rnd_pixels8_xy2_mmx function in x86/rnd_template.c in libav 11.7 and earlier allows remot The put_no_rnd_pixels8_xy2_mmx function in x86/rnd_template.c in libav 11.7 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted MP3 file.
nvd
Debian Linux vulnerabilities | cvebase