cbcvebase.

Debian Linux vulnerabilities

9,955 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358

Vulnerabilities

Page 433 of 498
CVE-2000-0289P4MEDIUMCVSS 5.0v2.1v2.22000-03-27
CVE-2000-0289 [MEDIUM] CVE-2000-0289: IP masquerading in Linux 2.2.x allows remote attackers to route UDP packets through the internal int IP masquerading in Linux 2.2.x allows remote attackers to route UDP packets through the internal interface by modifying the external source IP address and port number to match those of an established connection.
nvd
CVE-2019-7665P4MEDIUMCVSS 5.5v8.0v9.02019-02-09
CVE-2019-7665 [MEDIUM] CWE-125 CVE-2019-7665: In elfutils 0.175, a heap-based buffer over-read was discovered in the function elf32_xlatetom in el In elfutils 0.175, a heap-based buffer over-read was discovered in the function elf32_xlatetom in elf32_xlatetom.c in libelf. A crafted ELF input can cause a segmentation fault leading to denial of service (program crash) because ebl_core_note does not reject malformed core file notes.
nvd
CVE-2021-45944P4MEDIUMCVSS 5.5v9.0v10.0+1 more2022-01-01
CVE-2021-45944 [MEDIUM] CWE-416 CVE-2021-45944: Ghostscript GhostPDL 9.50 through 9.53.3 has a use-after-free in sampled_data_sample (called from sa Ghostscript GhostPDL 9.50 through 9.53.3 has a use-after-free in sampled_data_sample (called from sampled_data_continue and interp).
nvd
CVE-2022-22844P4MEDIUMCVSS 5.5v9.0v10.0+1 more2022-01-10
CVE-2022-22844 [MEDIUM] CWE-125 CVE-2022-22844: LibTIFF 4.3.0 has an out-of-bounds read in _TIFFmemcpy in tif_unix.c in certain situations involving LibTIFF 4.3.0 has an out-of-bounds read in _TIFFmemcpy in tif_unix.c in certain situations involving a custom tag and 0x0200 as the second word of the DE field.
nvd
CVE-2013-4394P4MEDIUMCVSS 5.9v7.02013-10-28
CVE-2013-4394 [MEDIUM] CWE-276 CVE-2013-4394: The SetX11Keyboard function in systemd, when PolicyKit Local Authority (PKLA) is used to change the The SetX11Keyboard function in systemd, when PolicyKit Local Authority (PKLA) is used to change the group permissions on the X Keyboard Extension (XKB) layouts description, allows local users in the group to modify the Xorg X11 Server configuration file and possibly gain privileges via vectors involving "special and control characters."
nvd
CVE-2017-6499P4MEDIUMCVSS 5.5v8.0v9.02017-03-06
CVE-2017-6499 [MEDIUM] CWE-772 CVE-2017-6499: An issue was discovered in Magick++ in ImageMagick 6.9.7. A specially crafted file creating a nested An issue was discovered in Magick++ in ImageMagick 6.9.7. A specially crafted file creating a nested exception could lead to a memory leak (thus, a DoS).
nvd
CVE-2017-6498P4MEDIUMCVSS 5.5v8.0v9.02017-03-06
CVE-2017-6498 [MEDIUM] CWE-20 CVE-2017-6498: An issue was discovered in ImageMagick 6.9.7. Incorrect TGA files could trigger assertion failures, An issue was discovered in ImageMagick 6.9.7. Incorrect TGA files could trigger assertion failures, thus leading to DoS.
nvd
CVE-2017-6500P4MEDIUMCVSS 5.5v8.0v9.02017-03-06
CVE-2017-6500 [MEDIUM] CWE-125 CVE-2017-6500: An issue was discovered in ImageMagick 6.9.7. A specially crafted sun file triggers a heap-based buf An issue was discovered in ImageMagick 6.9.7. A specially crafted sun file triggers a heap-based buffer over-read.
nvd
CVE-2019-20485P4MEDIUMCVSS 5.7v8.0v9.0+1 more2020-03-19
CVE-2019-20485 [MEDIUM] CWE-20 CVE-2019-20485: qemu/qemu_driver.c in libvirt before 6.0.0 mishandles the holding of a monitor job during a query to qemu/qemu_driver.c in libvirt before 6.0.0 mishandles the holding of a monitor job during a query to a guest agent, which allows attackers to cause a denial of service (API blockage).
nvd
CVE-2020-13904P4MEDIUMCVSS 5.5v9.0v10.02020-06-07
CVE-2020-13904 [MEDIUM] CWE-416 CVE-2020-13904: FFmpeg 2.8 and 4.2.3 has a use-after-free via a crafted EXTINF duration in an m3u8 file because pars FFmpeg 2.8 and 4.2.3 has a use-after-free via a crafted EXTINF duration in an m3u8 file because parse_playlist in libavformat/hls.c frees a pointer, and later that pointer is accessed in av_probe_input_format3 in libavformat/format.c.
nvd
CVE-2018-5747P4MEDIUMCVSS 5.5v9.02018-01-17
CVE-2018-5747 [MEDIUM] CWE-416 CVE-2018-5747: In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in the ucompthread function (stream.c In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in the ucompthread function (stream.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted lrz file.
nvd
CVE-2022-0908P4MEDIUMCVSS 5.5v10.0v11.02022-03-11
CVE-2022-0908 [MEDIUM] CWE-476 CVE-2022-0908: Null source pointer passed as an argument to memcpy() function within TIFFFetchNormalTag () in tif_d Null source pointer passed as an argument to memcpy() function within TIFFFetchNormalTag () in tif_dirread.c in libtiff versions up to 4.3.0 could lead to Denial of Service via crafted TIFF file.
nvd
CVE-2022-0561P4MEDIUMCVSS 5.5v9.0v10.0+1 more2022-02-11
CVE-2022-0561 [MEDIUM] CWE-476 CVE-2022-0561: Null source pointer passed as an argument to memcpy() function within TIFFFetchStripThing() in tif_d Null source pointer passed as an argument to memcpy() function within TIFFFetchStripThing() in tif_dirread.c in libtiff versions from 3.9.0 to 4.3.0 could lead to Denial of Service via crafted TIFF file. For users that compile libtiff from sources, the fix is available with commit eecb0712.
nvd
CVE-2022-0562P4MEDIUMCVSS 5.5v9.0v10.0+1 more2022-02-11
CVE-2022-0562 [MEDIUM] CWE-476 CVE-2022-0562: Null source pointer passed as an argument to memcpy() function within TIFFReadDirectory() in tif_dir Null source pointer passed as an argument to memcpy() function within TIFFReadDirectory() in tif_dirread.c in libtiff versions from 4.0 to 4.3.0 could lead to Denial of Service via crafted TIFF file. For users that compile libtiff from sources, a fix is available with commit 561599c.
nvd
CVE-2020-21913P4MEDIUMCVSS 5.5v9.0v10.02021-09-20
CVE-2020-21913 [MEDIUM] CWE-416 CVE-2020-21913: International Components for Unicode (ICU-20850) v66.1 was discovered to contain a use after free bu International Components for Unicode (ICU-20850) v66.1 was discovered to contain a use after free bug in the pkg_createWithAssemblyCode function in the file tools/pkgdata/pkgdata.cpp.
nvd
CVE-2013-3555P4MEDIUMCVSS 5.0v7.02013-05-25
CVE-2013-3555 [MEDIUM] CWE-20 CVE-2013-3555: epan/dissectors/packet-gtpv2.c in the GTPv2 dissector in Wireshark 1.8.x before 1.8.7 calls incorrec epan/dissectors/packet-gtpv2.c in the GTPv2 dissector in Wireshark 1.8.x before 1.8.7 calls incorrect functions in certain contexts related to ciphers, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.
nvd
CVE-2020-16589P4MEDIUMCVSS 5.5v10.02020-12-09
CVE-2020-16589 [MEDIUM] CWE-787 CVE-2020-16589: A head-based buffer overflow exists in Academy Software Foundation OpenEXR 2.3.0 in writeTileData in A head-based buffer overflow exists in Academy Software Foundation OpenEXR 2.3.0 in writeTileData in ImfTiledOutputFile.cpp that can cause a denial of service via a crafted EXR file.
nvd
CVE-2022-30974P4MEDIUMCVSS 5.5v11.02022-05-18
CVE-2022-30974 [MEDIUM] CVE-2022-30974: compile in regexp.c in Artifex MuJS through 1.2.0 results in stack consumption because of unlimited compile in regexp.c in Artifex MuJS through 1.2.0 results in stack consumption because of unlimited recursion, a different issue than CVE-2019-11413.
nvd
CVE-2021-46141P4MEDIUMCVSS 5.5v9.0v10.0+1 more2022-01-06
CVE-2021-46141 [MEDIUM] CWE-416 CVE-2021-46141: An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUri An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner.
nvd
CVE-2021-32815P4MEDIUMCVSS 5.5v10.02021-08-09
CVE-2021-32815 [MEDIUM] CWE-617 CVE-2021-32815: Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the me Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. The assertion failure is triggered when Exiv2 is used to modify the metadata of a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service, if they can trick the victim into runnin
nvd
Debian Linux vulnerabilities | cvebase