cbcvebase.

Debian Linux vulnerabilities

9,955 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358

Vulnerabilities

Page 432 of 498
CVE-2013-4077P4MEDIUMCVSS 5.0v7.02013-06-09
CVE-2013-4077 [MEDIUM] CWE-119 CVE-2013-4077: Array index error in the NBAP dissector in Wireshark 1.8.x before 1.8.8 allows remote attackers to c Array index error in the NBAP dissector in Wireshark 1.8.x before 1.8.8 allows remote attackers to cause a denial of service (application crash) via a crafted packet, related to nbap.cnf and packet-nbap.c.
nvd
CVE-2016-4037P4MEDIUMCVSS 6.0v8.02016-05-23
CVE-2016-4037 [MEDIUM] CVE-2016-4037: The ehci_advance_state function in hw/usb/hcd-ehci.c in QEMU allows local guest OS administrators to The ehci_advance_state function in hw/usb/hcd-ehci.c in QEMU allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) via a circular split isochronous transfer descriptor (siTD) list, a related issue to CVE-2015-8558.
nvd
CVE-2016-8910P4MEDIUMCVSS 6.0v8.02016-11-04
CVE-2016-8910 [MEDIUM] CWE-835 CVE-2016-8910: The rtl8139_cplus_transmit function in hw/net/rtl8139.c in QEMU (aka Quick Emulator) allows local gu The rtl8139_cplus_transmit function in hw/net/rtl8139.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) by leveraging failure to limit the ring descriptor count.
nvd
CVE-2016-8576P4MEDIUMCVSS 6.0v8.02016-11-04
CVE-2016-8576 [MEDIUM] CWE-770 CVE-2016-8576: The xhci_ring_fetch function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator) allows local guest OS The xhci_ring_fetch function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by leveraging failure to limit the number of link Transfer Request Blocks (TRB) to process.
nvd
CVE-2020-29484P4MEDIUMCVSS 6.0v10.02020-12-15
CVE-2020-29484 [MEDIUM] CWE-476 CVE-2020-29484: An issue was discovered in Xen through 4.14.x. When a Xenstore watch fires, the xenstore client that An issue was discovered in Xen through 4.14.x. When a Xenstore watch fires, the xenstore client that registered the watch will receive a Xenstore message containing the path of the modified Xenstore entry that triggered the watch, and the tag that was specified when registering the watch. Any communication with xenstored is done via Xenstore message
nvd
CVE-2016-5106P4MEDIUMCVSS 6.0v8.02016-09-02
CVE-2016-5106 [MEDIUM] CWE-787 CVE-2016-5106: The megasas_dcmd_set_properties function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS The megasas_dcmd_set_properties function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest administrators to cause a denial of service (out-of-bounds write access) via vectors involving a MegaRAID Firmware Interface (MFI) command.
nvd
CVE-2013-6424P4MEDIUMCVSS 5.0v6.0v7.02014-01-18
CVE-2013-6424 [MEDIUM] CWE-191 CVE-2013-6424: Integer underflow in the xTrapezoidValid macro in render/picture.h in X.Org allows context-dependent Integer underflow in the xTrapezoidValid macro in render/picture.h in X.Org allows context-dependent attackers to cause a denial of service (crash) via a negative bottom value.
nvd
CVE-2017-17669P4MEDIUMCVSS 5.5v10.02017-12-13
CVE-2017-17669 [MEDIUM] CWE-125 CVE-2017-17669: There is a heap-based buffer over-read in the Exiv2::Internal::PngChunk::keyTXTChunk function of png There is a heap-based buffer over-read in the Exiv2::Internal::PngChunk::keyTXTChunk function of pngchunk_int.cpp in Exiv2 0.26. A crafted PNG file will lead to a remote denial of service attack.
nvd
CVE-2016-4571P4MEDIUMCVSS 5.5v8.02017-02-03
CVE-2016-4571 [MEDIUM] CWE-400 CVE-2016-4571: The mxml_write_node function in mxml-file.c in mxml 2.9, 2.7, and possibly earlier allows remote att The mxml_write_node function in mxml-file.c in mxml 2.9, 2.7, and possibly earlier allows remote attackers to cause a denial of service (stack consumption) via crafted xml file.
nvd
CVE-2020-35504P4MEDIUMCVSS 6.0v10.02021-05-28
CVE-2020-35504 [MEDIUM] CWE-476 CVE-2020-35504: A NULL pointer dereference flaw was found in the SCSI emulation support of QEMU in versions before 6 A NULL pointer dereference flaw was found in the SCSI emulation support of QEMU in versions before 6.0.0. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.
nvd
CVE-2019-15145P4MEDIUMCVSS 5.5v8.0v9.0+2 more2019-08-18
CVE-2019-15145 [MEDIUM] CWE-125 CVE-2019-15145: DjVuLibre 3.5.27 allows attackers to cause a denial-of-service attack (application crash via an out- DjVuLibre 3.5.27 allows attackers to cause a denial-of-service attack (application crash via an out-of-bounds read) by crafting a corrupted JB2 image file that is mishandled in JB2Dict::JB2Codec::get_direct_context in libdjvu/JB2Image.h because of a missing zero-bytes check in libdjvu/GBitmap.h.
nvd
CVE-2018-6544P4MEDIUMCVSS 5.5v8.0v9.02018-02-02
CVE-2018-6544 [MEDIUM] CWE-674 CVE-2018-6544: pdf_load_obj_stm in pdf/pdf-xref.c in Artifex MuPDF 1.12.0 could reference the object stream recursi pdf_load_obj_stm in pdf/pdf-xref.c in Artifex MuPDF 1.12.0 could reference the object stream recursively and therefore run out of error stack, which allows remote attackers to cause a denial of service via a crafted PDF document.
nvd
CVE-2022-0696P4MEDIUMCVSS 5.5v10.02022-02-21
CVE-2022-0696 [MEDIUM] CWE-476 CVE-2022-0696: NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.4428. NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.4428.
nvd
CVE-2018-11504P4MEDIUMCVSS 5.5v8.0v9.02018-05-26
CVE-2018-11504 [MEDIUM] CWE-125 CVE-2018-11504: The islist function in markdown.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cau The islist function in markdown.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file, as demonstrated by mkd2html.
nvd
CVE-2018-11468P4MEDIUMCVSS 5.5v8.0v9.02018-05-25
CVE-2018-11468 [MEDIUM] CWE-125 CVE-2018-11468: The __mkd_trim_line function in mkdio.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers The __mkd_trim_line function in mkdio.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file, as demonstrated by mkd2html.
nvd
CVE-2017-18233P4MEDIUMCVSS 5.5v7.02018-03-15
CVE-2017-18233 [MEDIUM] CWE-190 CVE-2017-18233: An issue was discovered in Exempi before 2.4.4. Integer overflow in the Chunk class in XMPFiles/sour An issue was discovered in Exempi before 2.4.4. Integer overflow in the Chunk class in XMPFiles/source/FormatSupport/RIFF.cpp allows remote attackers to cause a denial of service (infinite loop) via crafted XMP data in a .avi file.
nvd
CVE-2017-15642P4MEDIUMCVSS 5.5v7.0v8.02017-10-19
CVE-2017-15642 [MEDIUM] CWE-416 CVE-2017-15642: In lsx_aiffstartread in aiff.c in Sound eXchange (SoX) 14.4.2, there is a Use-After-Free vulnerabili In lsx_aiffstartread in aiff.c in Sound eXchange (SoX) 14.4.2, there is a Use-After-Free vulnerability triggered by supplying a malformed AIFF file.
nvd
CVE-2018-1000040P4MEDIUMCVSS 5.5v9.02018-05-24
CVE-2018-1000040 [MEDIUM] CWE-20 CVE-2018-1000040: In Artifex MuPDF 1.12.0 and earlier, multiple use of uninitialized value bugs in the PDF parser coul In Artifex MuPDF 1.12.0 and earlier, multiple use of uninitialized value bugs in the PDF parser could allow an attacker to cause a denial of service (crash) or influence program flow via a crafted file.
nvd
CVE-2017-18238P4MEDIUMCVSS 5.5v7.02018-03-15
CVE-2017-18238 [MEDIUM] CWE-835 CVE-2017-18238: An issue was discovered in Exempi before 2.4.4. The TradQT_Manager::ParseCachedBoxes function in XMP An issue was discovered in Exempi before 2.4.4. The TradQT_Manager::ParseCachedBoxes function in XMPFiles/source/FormatSupport/QuickTime_Support.cpp allows remote attackers to cause a denial of service (infinite loop) via crafted XMP data in a .qt file.
nvd
CVE-2016-9591P4MEDIUMCVSS 5.5v8.02018-03-09
CVE-2016-9591 [MEDIUM] CWE-416 CVE-2016-9591: JasPer before version 2.0.12 is vulnerable to a use-after-free in the way it decodes certain JPEG 20 JasPer before version 2.0.12 is vulnerable to a use-after-free in the way it decodes certain JPEG 2000 image files resulting in a crash on the application using JasPer.
nvd
Debian Linux vulnerabilities | cvebase