cbcvebase.

Debian Linux vulnerabilities

9,955 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358

Vulnerabilities

Page 416 of 498
CVE-2015-1381P4MEDIUMCVSS 5.0v7.02015-02-03
CVE-2015-1381 [MEDIUM] CWE-399 CVE-2015-1381: Multiple unspecified vulnerabilities in pcrs.c in Privoxy before 3.0.23 allow remote attackers to ca Multiple unspecified vulnerabilities in pcrs.c in Privoxy before 3.0.23 allow remote attackers to cause a denial of service (segmentation fault or memory consumption) via unspecified vectors.
nvd
CVE-2019-1010319P4MEDIUMCVSS 5.5v9.02019-07-11
CVE-2019-1010319 [MEDIUM] CWE-457 CVE-2019-1010319: WavPack 5.1.0 and earlier is affected by: CWE-457: Use of Uninitialized Variable. The impact is: Une WavPack 5.1.0 and earlier is affected by: CWE-457: Use of Uninitialized Variable. The impact is: Unexpected control flow, crashes, and segfaults. The component is: ParseWave64HeaderConfig (wave64.c:211). The attack vector is: Maliciously crafted .wav file. The fixed version is: After commit https://github.com/dbry/WavPack/commit/33a0025d1d63ccd0
nvd
CVE-2019-1010317P4MEDIUMCVSS 5.5v9.02019-07-11
CVE-2019-1010317 [MEDIUM] CWE-457 CVE-2019-1010317: WavPack 5.1.0 and earlier is affected by: CWE-457: Use of Uninitialized Variable. The impact is: Une WavPack 5.1.0 and earlier is affected by: CWE-457: Use of Uninitialized Variable. The impact is: Unexpected control flow, crashes, and segfaults. The component is: ParseCaffHeaderConfig (caff.c:486). The attack vector is: Maliciously crafted .wav file. The fixed version is: After commit https://github.com/dbry/WavPack/commit/f68a9555b548306c5b1e
nvd
CVE-2018-16541P4MEDIUMCVSS 5.5v8.0v9.02018-09-05
CVE-2018-16541 [MEDIUM] CWE-416 CVE-2018-16541: In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use inco In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use incorrect free logic in pagedevice replacement to crash the interpreter.
nvd
CVE-2019-7150P4MEDIUMCVSS 5.5v8.0v9.02019-01-29
CVE-2019-7150 [MEDIUM] CWE-125 CVE-2019-7150: An issue was discovered in elfutils 0.175. A segmentation fault can occur in the function elf64_xlat An issue was discovered in elfutils 0.175. A segmentation fault can occur in the function elf64_xlatetom in libelf/elf32_xlatetom.c, due to dwfl_segment_report_module not checking whether the dyn data read from a core file is truncated. A crafted input can cause a program crash, leading to denial-of-service, as demonstrated by eu-stack.
nvd
CVE-2009-2687P4MEDIUMCVSS 4.3v4.0v5.0+1 more2009-08-05
CVE-2009-2687 [MEDIUM] CVE-2009-2687: The exif_read_data function in the Exif module in PHP before 5.2.10 allows remote attackers to cause The exif_read_data function in the Exif module in PHP before 5.2.10 allows remote attackers to cause a denial of service (crash) via a malformed JPEG image with invalid offset fields, a different issue than CVE-2005-3353.
nvd
CVE-2006-6503P4MEDIUMCVSS 6.8v3.1v4.02006-12-20
CVE-2006-6503 [MEDIUM] CWE-254 CVE-2006-6503: Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to bypass cross-site scripting (XSS) protection by changing the src attribute of an IMG element to a javascript: URI.
nvd
CVE-2017-15873P4MEDIUMCVSS 5.5v8.0v9.02017-10-24
CVE-2017-15873 [MEDIUM] CWE-190 CVE-2017-15873: The get_next_block function in archival/libarchive/decompress_bunzip2.c in BusyBox 1.27.2 has an Int The get_next_block function in archival/libarchive/decompress_bunzip2.c in BusyBox 1.27.2 has an Integer Overflow that may lead to a write access violation.
nvd
CVE-2018-15378P4MEDIUMCVSS 5.5v8.02018-10-15
CVE-2018-15378 [MEDIUM] CWE-125 CVE-2018-15378: A vulnerability in ClamAV versions prior to 0.100.2 could allow an attacker to cause a denial of ser A vulnerability in ClamAV versions prior to 0.100.2 could allow an attacker to cause a denial of service (DoS) condition. The vulnerability is due to an error related to the MEW unpacker within the "unmew11()" function (libclamav/mew.c), which can be exploited to trigger an invalid read memory access via a specially crafted EXE file.
nvd
CVE-2020-3810P4MEDIUMCVSS 5.5v9.0v10.02020-05-15
CVE-2020-3810 [MEDIUM] CWE-20 CVE-2020-3810: Missing input validation in the ar/tar implementations of APT before version 2.1.2 could result in d Missing input validation in the ar/tar implementations of APT before version 2.1.2 could result in denial of service when processing specially crafted deb files.
nvd
CVE-2019-20171P4MEDIUMCVSS 5.5v8.02019-12-31
CVE-2019-20171 [MEDIUM] CWE-401 CVE-2019-20171: An issue was discovered in GPAC version 0.5.2 and 0.9.0-development-20191109. There are memory leaks An issue was discovered in GPAC version 0.5.2 and 0.9.0-development-20191109. There are memory leaks in metx_New in isomedia/box_code_base.c and abst_Read in isomedia/box_code_adobe.c.
nvd
CVE-2019-14558P4MEDIUMCVSS 5.7v9.02020-10-05
CVE-2019-14558 [MEDIUM] CVE-2019-14558: Insufficient control flow management in BIOS firmware for 8th, 9th, 10th Generation Intel(R) Core(TM Insufficient control flow management in BIOS firmware for 8th, 9th, 10th Generation Intel(R) Core(TM), Intel(R) Celeron(R) Processor 4000 & 5000 Series Processors may allow an authenticated user to potentially enable denial of service via adjacent access.
nvd
CVE-2021-42715P4MEDIUMCVSS 5.5v10.02021-10-21
CVE-2021-42715 [MEDIUM] CWE-835 CVE-2021-42715: An issue was discovered in stb stb_image.h 1.33 through 2.27. The HDR loader parsed truncated end-of An issue was discovered in stb stb_image.h 1.33 through 2.27. The HDR loader parsed truncated end-of-file RLE scanlines as an infinite sequence of zero-length runs. An attacker could potentially have caused denial of service in applications using stb_image by submitting crafted HDR files.
nvd
CVE-2019-18849P4MEDIUMCVSS 5.5v8.02019-11-11
CVE-2019-18849 [MEDIUM] CWE-125 CVE-2019-18849: In tnef before 1.4.18, an attacker may be able to write to the victim's .ssh/authorized_keys file vi In tnef before 1.4.18, an attacker may be able to write to the victim's .ssh/authorized_keys file via an e-mail message with a crafted winmail.dat application/ms-tnef attachment, because of a heap-based buffer over-read involving strdup.
nvd
CVE-2021-23215P4MEDIUMCVSS 5.5v9.0v10.0+1 more2021-06-08
CVE-2021-23215 [MEDIUM] CWE-400 CVE-2021-23215: An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in v An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR.
nvd
CVE-2021-20241P4MEDIUMCVSS 5.5v9.02021-03-09
CVE-2021-20241 [MEDIUM] CWE-369 CVE-2021-20241: A flaw was found in ImageMagick in coders/jp2.c. An attacker who submits a crafted file that is proc A flaw was found in ImageMagick in coders/jp2.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat from this vulnerability is to system availability.
nvd
CVE-2021-37622P4MEDIUMCVSS 5.5v10.02021-08-09
CVE-2021-37622 [MEDIUM] CWE-835 CVE-2021-37622: Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the me Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop was found in Exiv2 versions v0.27.4 and earlier. The infinite loop is triggered when Exiv2 is used to modify the metadata of a crafted image file. An attacker could potentially exploit the vulnerability to cause
nvd
CVE-2022-1122P4MEDIUMCVSS 5.5v9.02022-03-29
CVE-2022-1122 [MEDIUM] CWE-665 CVE-2022-1122: A flaw was found in the opj2_decompress program in openjpeg2 2.4.0 in the way it handles an input di A flaw was found in the opj2_decompress program in openjpeg2 2.4.0 in the way it handles an input directory with a large number of files. When it fails to allocate a buffer to store the filenames of the input directory, it calls free() on an uninitialized pointer, leading to a segmentation fault and a denial of service.
nvd
CVE-2021-26260P4MEDIUMCVSS 5.5v9.0v10.0+1 more2021-06-08
CVE-2021-26260 [MEDIUM] CVE-2021-26260: An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in v An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR. This is a different flaw from CVE-2021-23215.
nvd
CVE-2021-20243P4MEDIUMCVSS 5.5v9.02021-03-09
CVE-2021-20243 [MEDIUM] CWE-369 CVE-2021-20243: A flaw was found in ImageMagick in MagickCore/resize.c. An attacker who submits a crafted file that A flaw was found in ImageMagick in MagickCore/resize.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat from this vulnerability is to system availability.
nvd
Debian Linux vulnerabilities | cvebase