cbcvebase.

Debian Linux vulnerabilities

9,955 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358

Vulnerabilities

Page 434 of 498
CVE-2021-37621P4MEDIUMCVSS 5.5v10.02021-08-09
CVE-2021-37621 [MEDIUM] CWE-835 CVE-2021-37621: Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the me Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop was found in Exiv2 versions v0.27.4 and earlier. The infinite loop is triggered when Exiv2 is used to print the metadata of a crafted image file. An attacker could potentially exploit the vulnerability to cause
nvd
CVE-2021-46142P4MEDIUMCVSS 5.5v9.0v10.0+1 more2022-01-06
CVE-2021-46142 [MEDIUM] CWE-416 CVE-2021-46142: An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormali An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormalizeSyntax.
nvd
CVE-2017-11732P4MEDIUMCVSS 5.5v7.02017-07-29
CVE-2017-11732 [MEDIUM] CWE-119 CVE-2017-11732: A heap-based buffer overflow vulnerability was found in the function dcputs (called from decompileIM A heap-based buffer overflow vulnerability was found in the function dcputs (called from decompileIMPLEMENTS) in util/decompile.c in Ming 0.4.8, which allows attackers to cause a denial of service via a crafted file.
nvd
CVE-2020-21676P4MEDIUMCVSS 5.5v9.0v10.02021-08-10
CVE-2020-21676 [MEDIUM] CWE-787 CVE-2020-21676: A stack-based buffer overflow in the genpstrx_text() component in genpstricks.c of fig2dev 3.2.7b al A stack-based buffer overflow in the genpstrx_text() component in genpstricks.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into pstricks format.
nvd
CVE-2020-21675P4MEDIUMCVSS 5.5v9.02021-08-10
CVE-2020-21675 [MEDIUM] CWE-787 CVE-2020-21675: A stack-based buffer overflow in the genptk_text component in genptk.c of fig2dev 3.2.7b allows atta A stack-based buffer overflow in the genptk_text component in genptk.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into ptk format.
nvd
CVE-2020-0569P4MEDIUMCVSS 5.7v8.0v9.0+1 more2020-11-23
CVE-2020-0569 [MEDIUM] CWE-787 CVE-2020-0569: Out of bounds write in Intel(R) PROSet/Wireless WiFi products on Windows 10 may allow an authenticat Out of bounds write in Intel(R) PROSet/Wireless WiFi products on Windows 10 may allow an authenticated user to potentially enable denial of service via local access.
nvd
CVE-2021-37620P4MEDIUMCVSS 5.5v10.02021-08-09
CVE-2021-37620 [MEDIUM] CWE-125 CVE-2021-37620: Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the me Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.4 and earlier. The out-of-bounds read is triggered when Exiv2 is used to read the metadata of a crafted image file. An attacker could potentially exploit the vulnerability
nvd
CVE-2023-34151P4MEDIUMCVSS 5.5v10.02023-05-30
CVE-2023-34151 [MEDIUM] CVE-2023-34151: A vulnerability was found in ImageMagick. This security flaw ouccers as an undefined behaviors of ca A vulnerability was found in ImageMagick. This security flaw ouccers as an undefined behaviors of casting double to size_t in svg, mvg and other coders (recurring bugs of CVE-2022-32546).
nvd
CVE-2021-32434P4MEDIUMCVSS 5.5v9.02022-03-10
CVE-2021-32434 [MEDIUM] CWE-125 CVE-2021-32434: abcm2ps v8.14.11 was discovered to contain an out-of-bounds read in the function calculate_beam at d abcm2ps v8.14.11 was discovered to contain an out-of-bounds read in the function calculate_beam at draw.c.
nvd
CVE-2024-27388P4MEDIUMCVSS 5.5v10.02024-05-01
CVE-2024-27388 [MEDIUM] CWE-401 CVE-2024-27388: In the Linux kernel, the following vulnerability has been resolved: SUNRPC: fix some memleaks in gs In the Linux kernel, the following vulnerability has been resolved: SUNRPC: fix some memleaks in gssx_dec_option_array The creds and oa->data need to be freed in the error-handling paths after their allocation. So this patch add these deallocations in the corresponding paths.
nvd
CVE-2017-13672P4MEDIUMCVSS 5.5v9.02017-09-01
CVE-2017-13672 [MEDIUM] CWE-125 CVE-2017-13672: QEMU (aka Quick Emulator), when built with the VGA display emulator support, allows local guest OS p QEMU (aka Quick Emulator), when built with the VGA display emulator support, allows local guest OS privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) via vectors involving display update.
nvd
CVE-2021-21417P4MEDIUMCVSS 5.5v9.02021-04-29
CVE-2021-21417 [MEDIUM] CWE-416 CVE-2021-21417: fluidsynth is a software synthesizer based on the SoundFont 2 specifications. A use after free viola fluidsynth is a software synthesizer based on the SoundFont 2 specifications. A use after free violation was discovered in fluidsynth, that can be triggered when loading an invalid SoundFont file.
nvd
CVE-2024-36929P4MEDIUMCVSS 5.5v10.02024-05-30
CVE-2024-36929 [MEDIUM] CWE-476 CVE-2024-36929: In the Linux kernel, the following vulnerability has been resolved: net: core: reject skb_copy(_exp In the Linux kernel, the following vulnerability has been resolved: net: core: reject skb_copy(_expand) for fraglist GSO skbs SKB_GSO_FRAGLIST skbs must not be linearized, otherwise they become invalid. Return NULL if such an skb is passed to skb_copy or skb_copy_expand, in order to prevent a crash on a potential later call to skb_gso_segment.
nvd
CVE-2022-26291P4MEDIUMCVSS 5.5v9.0v10.0+1 more2022-03-28
CVE-2022-26291 [MEDIUM] CWE-416 CVE-2022-26291: lrzip v0.641 was discovered to contain a multiple concurrency use-after-free between the functions z lrzip v0.641 was discovered to contain a multiple concurrency use-after-free between the functions zpaq_decompress_buf() and clear_rulist(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted Irz file.
nvd
CVE-2005-4347P4MEDIUMCVSS 5.0v3.0v3.12005-12-31
CVE-2005-4347 [MEDIUM] CVE-2005-4347: The Linux 2.4 kernel patch in kernel-patch-vserver before 1.9.5.5 and 2.x before 2.3 for Debian GNU/ The Linux 2.4 kernel patch in kernel-patch-vserver before 1.9.5.5 and 2.x before 2.3 for Debian GNU/Linux does not correctly set the "chroot barrier" with util-vserver, which allows attackers to access files on the host system that are outside of the vserver.
nvd
CVE-2021-36408P4MEDIUMCVSS 5.5v10.0v11.02022-01-10
CVE-2021-36408 [MEDIUM] CWE-416 CVE-2021-36408: An issue was discovered in libde265 v1.0.8.There is a Heap-use-after-free in intrapred.h when decodi An issue was discovered in libde265 v1.0.8.There is a Heap-use-after-free in intrapred.h when decoding file using dec265.
nvd
CVE-2018-10881P4MEDIUMCVSS 5.5v8.02018-07-26
CVE-2018-10881 [MEDIUM] CWE-787 CVE-2018-10881: A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bound acces A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bound access in ext4_get_group_info function, a denial of service, and a system crash by mounting and operating on a crafted ext4 filesystem image.
nvd
CVE-2022-48554P4MEDIUMCVSS 5.5v11.02023-08-22
CVE-2022-48554 [MEDIUM] CWE-125 CVE-2022-48554: File before 5.43 has an stack-based buffer over-read in file_copystr in funcs.c. NOTE: "File" is the File before 5.43 has an stack-based buffer over-read in file_copystr in funcs.c. NOTE: "File" is the name of an Open Source project.
nvd
CVE-2018-7492P4MEDIUMCVSS 5.5v7.0v8.02018-02-26
CVE-2018-7492 [MEDIUM] CWE-476 CVE-2018-7492: A NULL pointer dereference was found in the net/rds/rdma.c __rds_rdma_map() function in the Linux ke A NULL pointer dereference was found in the net/rds/rdma.c __rds_rdma_map() function in the Linux kernel before 4.14.7 allowing local attackers to cause a system panic and a denial-of-service, related to RDS_GET_MR and RDS_GET_MR_FOR_DEST.
nvd
CVE-2018-12896P4MEDIUMCVSS 5.5v8.02018-07-02
CVE-2018-12896 [MEDIUM] CWE-190 CVE-2018-12896: An issue was discovered in the Linux kernel through 4.17.3. An Integer Overflow in kernel/time/posix An issue was discovered in the Linux kernel through 4.17.3. An Integer Overflow in kernel/time/posix-timers.c in the POSIX timer code is caused by the way the overrun accounting works. Depending on interval and expiry time values, the overrun can be larger than INT_MAX, but the accounting is int based. This basically makes the accounting values, whi
nvd
Debian Linux vulnerabilities | cvebase