Debian Linux vulnerabilities
9,955 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358
Vulnerabilities
Page 417 of 498
CVE-2022-2598P4MEDIUMCVSS 5.5v10.02022-08-01
CVE-2022-2598 [MEDIUM] CWE-787 CVE-2022-2598: Out-of-bounds Write to API in GitHub repository vim/vim prior to 9.0.0100.
Out-of-bounds Write to API in GitHub repository vim/vim prior to 9.0.0100.
nvd
CVE-2022-38750P4MEDIUMCVSS 5.5v10.02022-09-05
CVE-2022-38750 [MEDIUM] CWE-121 CVE-2022-38750: Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS).
Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow.
nvd
CVE-2021-3605P4MEDIUMCVSS 5.5v10.0v11.02021-08-25
CVE-2021-3605 [MEDIUM] CWE-119 CVE-2021-3605: There's a flaw in OpenEXR's rleUncompress functionality in versions prior to 3.0.5. An attacker who
There's a flaw in OpenEXR's rleUncompress functionality in versions prior to 3.0.5. An attacker who is able to submit a crafted file to an application linked with OpenEXR could cause an out-of-bounds read. The greatest risk from this flaw is to application availability.
nvd
CVE-2022-27114P4MEDIUMCVSS 5.5v9.02022-05-09
CVE-2022-27114 [MEDIUM] CWE-190 CVE-2022-27114: There is a vulnerability in htmldoc 1.9.16. In image_load_jpeg function image.cxx when it calls mall
There is a vulnerability in htmldoc 1.9.16. In image_load_jpeg function image.cxx when it calls malloc,'img->width' and 'img->height' they are large enough to cause an integer overflow. So, the malloc function may return a heap blosmaller than the expected size, and it will cause a buffer overflow/Address boundary error in the jpeg_read_scanlines fu
nvd
CVE-2022-0534P4MEDIUMCVSS 5.5v9.02022-02-09
CVE-2022-0534 [MEDIUM] CWE-125 CVE-2022-0534: A vulnerability was found in htmldoc version 1.9.15 where the stack out-of-bounds read takes place i
A vulnerability was found in htmldoc version 1.9.15 where the stack out-of-bounds read takes place in gif_get_code() and occurs when opening a malicious GIF file, which can result in a crash (segmentation fault).
nvd
CVE-2021-20302P4MEDIUMCVSS 5.5v10.02022-03-04
CVE-2021-20302 [MEDIUM] CWE-20 CVE-2021-20302: A flaw was found in OpenEXR's TiledInputFile functionality. This flaw allows an attacker who can sub
A flaw was found in OpenEXR's TiledInputFile functionality. This flaw allows an attacker who can submit a crafted single-part non-image to be processed by OpenEXR, to trigger a floating-point exception error. The highest threat from this vulnerability is to system availability.
nvd
CVE-2021-36410P4MEDIUMCVSS 5.5v10.0v11.02022-01-10
CVE-2021-36410 [MEDIUM] CWE-787 CVE-2021-36410: A stack-buffer-overflow exists in libde265 v1.0.8 via fallback-motion.cc in function put_epel_hv_fal
A stack-buffer-overflow exists in libde265 v1.0.8 via fallback-motion.cc in function put_epel_hv_fallback when running program dec265.
nvd
CVE-2018-2771P4MEDIUMCVSS 4.4v7.0v8.0+1 more2018-04-19
CVE-2018-2771 [MEDIUM] CVE-2018-2771: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Locking). Support
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Locking). Supported versions that are affected are 5.5.59 and prior, 5.6.39 and prior and 5.7.21 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulne
nvd
CVE-2015-3429P4MEDIUMCVSS 4.3v8.02015-06-17
CVE-2015-3429 [MEDIUM] CWE-79 CVE-2015-3429: Cross-site scripting (XSS) vulnerability in example.html in Genericons before 3.3.1, as used in Word
Cross-site scripting (XSS) vulnerability in example.html in Genericons before 3.3.1, as used in WordPress before 4.2.2, allows remote attackers to inject arbitrary web script or HTML via a fragment identifier.
nvd
CVE-2024-26817P4MEDIUMCVSS 5.5v10.02024-04-13
CVE-2024-26817 [MEDIUM] CWE-190 CVE-2024-26817: In the Linux kernel, the following vulnerability has been resolved: amdkfd: use calloc instead of k
In the Linux kernel, the following vulnerability has been resolved:
amdkfd: use calloc instead of kzalloc to avoid integer overflow
This uses calloc instead of doing the multiplication which might
overflow.
nvd
CVE-2024-26845P4MEDIUMCVSS 5.5v10.02024-04-17
CVE-2024-26845 [MEDIUM] CVE-2024-26845: In the Linux kernel, the following vulnerability has been resolved: scsi: target: core: Add TMF to
In the Linux kernel, the following vulnerability has been resolved:
scsi: target: core: Add TMF to tmr_list handling
An abort that is responded to by iSCSI itself is added to tmr_list but does
not go to target core. A LUN_RESET that goes through tmr_list takes a
refcounter on the abort and waits for completion. However, the abort will
be never complete beca
nvd
CVE-2018-10882P4MEDIUMCVSS 5.5v8.02018-07-27
CVE-2018-10882 [MEDIUM] CWE-787 CVE-2018-10882: A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bound write
A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bound write in in fs/jbd2/transaction.c code, a denial of service, and a system crash by unmounting a crafted ext4 filesystem image.
nvd
CVE-2018-18690P4MEDIUMCVSS 5.5v8.02018-10-26
CVE-2018-18690 [MEDIUM] CWE-754 CVE-2018-18690: In the Linux kernel before 4.17, a local attacker able to set attributes on an xfs filesystem could
In the Linux kernel before 4.17, a local attacker able to set attributes on an xfs filesystem could make this filesystem non-operational until the next mount by triggering an unchecked error condition during an xfs attribute change, because xfs_attr_shortform_addname in fs/xfs/libxfs/xfs_attr.c mishandles ATTR_REPLACE operations with conversion of an
nvd
CVE-2018-19965P4MEDIUMCVSS 5.6v9.02018-12-08
CVE-2018-19965 [MEDIUM] CVE-2018-19965: An issue was discovered in Xen through 4.11.x allowing 64-bit PV guest OS users to cause a denial of
An issue was discovered in Xen through 4.11.x allowing 64-bit PV guest OS users to cause a denial of service (host OS crash) because #GP[0] can occur after a non-canonical address is passed to the TLB flushing code. NOTE: this issue exists because of an incorrect CVE-2017-5754 (aka Meltdown) mitigation.
nvd
CVE-2020-12769P4MEDIUMCVSS 5.5v8.02020-05-09
CVE-2020-12769 [MEDIUM] CWE-662 CVE-2020-12769: An issue was discovered in the Linux kernel before 5.4.17. drivers/spi/spi-dw.c allows attackers to
An issue was discovered in the Linux kernel before 5.4.17. drivers/spi/spi-dw.c allows attackers to cause a panic via concurrent calls to dw_spi_irq and dw_spi_transfer_one, aka CID-19b61392c5a8.
nvd
CVE-2024-27436P4MEDIUMCVSS 5.5v10.02024-05-17
CVE-2024-27436 [MEDIUM] CWE-787 CVE-2024-27436: In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Stop parsing c
In the Linux kernel, the following vulnerability has been resolved:
ALSA: usb-audio: Stop parsing channels bits when all channels are found.
If a usb audio device sets more bits than the amount of channels
it could write outside of the map array.
nvd
CVE-2020-14323P4MEDIUMCVSS 5.5v9.02020-10-29
CVE-2020-14323 [MEDIUM] CWE-170 CVE-2020-14323: A null pointer dereference flaw was found in samba's Winbind service in versions before 4.11.15, bef
A null pointer dereference flaw was found in samba's Winbind service in versions before 4.11.15, before 4.12.9 and before 4.13.1. A local user could use this flaw to crash the winbind service causing denial of service.
nvd
CVE-2015-2582P4MEDIUMCVSS 4.0v8.02015-07-16
CVE-2015-2582 [MEDIUM] CVE-2015-2582: Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.24 and earlier allows re
Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.24 and earlier allows remote authenticated users to affect availability via vectors related to GIS.
nvd
CVE-2015-2648P4MEDIUMCVSS 4.0v7.0v8.02015-07-16
CVE-2015-2648 [MEDIUM] CVE-2015-2648: Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.24 and earlier allows re
Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.24 and earlier allows remote authenticated users to affect availability via vectors related to DML.
nvd
CVE-2022-42722P4MEDIUMCVSS 5.5v10.0v11.02022-10-14
CVE-2022-42722 [MEDIUM] CWE-476 CVE-2022-42722: In the Linux kernel 5.8 through 5.19.x before 5.19.16, local attackers able to inject WLAN frames in
In the Linux kernel 5.8 through 5.19.x before 5.19.16, local attackers able to inject WLAN frames into the mac80211 stack could cause a NULL pointer dereference denial-of-service attack against the beacon protection of P2P devices.
nvd