cbcvebase.

Debian Linux vulnerabilities

9,955 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358

Vulnerabilities

Page 449 of 498
CVE-2016-9101P4MEDIUMCVSS 6.0v8.02016-12-09
CVE-2016-9101 [MEDIUM] CWE-772 CVE-2016-9101: Memory leak in hw/net/eepro100.c in QEMU (aka Quick Emulator) allows local guest OS administrators t Memory leak in hw/net/eepro100.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by repeatedly unplugging an i8255x (PRO100) NIC device.
nvd
CVE-2016-8577P4MEDIUMCVSS 6.0v8.02016-11-04
CVE-2016-8577 [MEDIUM] CWE-772 CVE-2016-8577: Memory leak in the v9fs_read function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local gues Memory leak in the v9fs_read function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption) via vectors related to an I/O read operation.
nvd
CVE-2016-6835P4MEDIUMCVSS 6.0v8.02016-12-10
CVE-2016-6835 [MEDIUM] CVE-2016-6835: The vmxnet_tx_pkt_parse_headers function in hw/net/vmxnet_tx_pkt.c in QEMU (aka Quick Emulator) allo The vmxnet_tx_pkt_parse_headers function in hw/net/vmxnet_tx_pkt.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (buffer over-read) by leveraging failure to check IP header length.
nvd
CVE-2017-7377P4MEDIUMCVSS 6.0v8.02017-04-10
CVE-2017-7377 [MEDIUM] CWE-772 CVE-2017-7377: The (1) v9fs_create and (2) v9fs_lcreate functions in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allo The (1) v9fs_create and (2) v9fs_lcreate functions in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allow local guest OS privileged users to cause a denial of service (file descriptor or memory consumption) via vectors related to an already in-use fid.
nvd
CVE-2016-9102P4MEDIUMCVSS 6.0v8.02016-12-09
CVE-2016-9102 [MEDIUM] CWE-772 CVE-2016-9102: Memory leak in the v9fs_xattrcreate function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows loc Memory leak in the v9fs_xattrcreate function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) via a large number of Txattrcreate messages with the same fid number.
nvd
CVE-2016-4952P4MEDIUMCVSS 6.0v8.02016-09-02
CVE-2016-4952 [MEDIUM] CWE-787 CVE-2016-4952: QEMU (aka Quick Emulator), when built with VMWARE PVSCSI paravirtual SCSI bus emulation support, all QEMU (aka Quick Emulator), when built with VMWARE PVSCSI paravirtual SCSI bus emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds array access) via vectors related to the (1) PVSCSI_CMD_SETUP_RINGS or (2) PVSCSI_CMD_SETUP_MSG_RING SCSI command.
nvd
CVE-2013-3556P4MEDIUMCVSS 5.0v7.02013-05-25
CVE-2013-3556 [MEDIUM] CWE-20 CVE-2013-3556: The fragment_add_seq_common function in epan/reassemble.c in the ASN.1 BER dissector in Wireshark be The fragment_add_seq_common function in epan/reassemble.c in the ASN.1 BER dissector in Wireshark before r48943 has an incorrect pointer dereference during a comparison, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.
nvd
CVE-2017-8846P4MEDIUMCVSS 5.5v9.02017-05-08
CVE-2017-8846 [MEDIUM] CWE-416 CVE-2017-8846: The read_stream function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause The read_stream function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted archive.
nvd
CVE-2002-0912P4MEDIUMCVSS 5.0v2.22002-10-04
CVE-2002-0912 [MEDIUM] CVE-2002-0912: in.uucpd UUCP server in Debian GNU/Linux 2.2, and possibly other operating systems, does not properl in.uucpd UUCP server in Debian GNU/Linux 2.2, and possibly other operating systems, does not properly terminate long strings, which allows remote attackers to cause a denial of service, possibly due to a buffer overflow.
nvd
CVE-2018-19626P4MEDIUMCVSS 5.5v8.0v9.02018-11-29
CVE-2018-19626 [MEDIUM] CWE-125 CVE-2018-19626: In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the DCOM dissector could crash. This was addressed In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the DCOM dissector could crash. This was addressed in epan/dissectors/packet-dcom.c by adding '\0' termination.
nvd
CVE-2019-14534P4MEDIUMCVSS 5.5v9.0v10.02019-08-29
CVE-2019-14534 [MEDIUM] CWE-476 CVE-2019-14534: In VideoLAN VLC media player 3.0.7.1, there is a NULL pointer dereference at the function SeekPercen In VideoLAN VLC media player 3.0.7.1, there is a NULL pointer dereference at the function SeekPercent of demux/asf/asf.c that will lead to a denial of service attack.
nvd
CVE-2019-5718P4MEDIUMCVSS 5.5v9.02019-01-08
CVE-2019-5718 [MEDIUM] CWE-125 CVE-2019-5718: In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the RTSE dissector and other ASN.1 dissectors could In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the RTSE dissector and other ASN.1 dissectors could crash. This was addressed in epan/charsets.c by adding a get_t61_string length check.
nvd
CVE-2018-18873P4MEDIUMCVSS 5.5v8.02018-10-31
CVE-2018-18873 [MEDIUM] CWE-476 CVE-2018-18873: An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function ras_pu An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function ras_putdatastd in ras/ras_enc.c.
nvd
CVE-2018-7728P4MEDIUMCVSS 5.5v7.02018-03-06
CVE-2018-7728 [MEDIUM] CWE-125 CVE-2018-7728: An issue was discovered in Exempi through 2.4.4. XMPFiles/source/FileHandlers/TIFF_Handler.cpp misha An issue was discovered in Exempi through 2.4.4. XMPFiles/source/FileHandlers/TIFF_Handler.cpp mishandles a case of a zero length, leading to a heap-based buffer over-read in the MD5Update() function in third-party/zuid/interfaces/MD5.cpp.
nvd
CVE-2009-3094P4LOWCVSS 2.6v4.0v5.02009-09-08
CVE-2009-3094 [LOW] CWE-476 CVE-2009-3094: The ap_proxy_ftp_handler function in modules/proxy/proxy_ftp.c in the mod_proxy_ftp module in the Ap The ap_proxy_ftp_handler function in modules/proxy/proxy_ftp.c in the mod_proxy_ftp module in the Apache HTTP Server 2.0.63 and 2.2.13 allows remote FTP servers to cause a denial of service (NULL pointer dereference and child process crash) via a malformed reply to an EPSV command.
nvd
CVE-2022-1623P4MEDIUMCVSS 5.5v11.02022-05-11
CVE-2022-1623 [MEDIUM] CWE-125 CVE-2022-1623: LibTIFF master branch has an out-of-bounds read in LZWDecode in libtiff/tif_lzw.c:624, allowing atta LibTIFF master branch has an out-of-bounds read in LZWDecode in libtiff/tif_lzw.c:624, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit b4e79bfa.
nvd
CVE-2014-9670P4MEDIUMCVSS 4.3v7.02015-02-08
CVE-2014-9670 [MEDIUM] CWE-189 CVE-2014-9670: Multiple integer signedness errors in the pcf_get_encodings function in pcf/pcfread.c in FreeType be Multiple integer signedness errors in the pcf_get_encodings function in pcf/pcfread.c in FreeType before 2.5.4 allow remote attackers to cause a denial of service (integer overflow, NULL pointer dereference, and application crash) via a crafted PCF file that specifies negative values for the first column and first row.
nvd
CVE-2017-6299P4MEDIUMCVSS 5.5v8.0v9.02017-02-24
CVE-2017-6299 [MEDIUM] CWE-835 CVE-2017-6299: An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "2 of 9. Infi An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "2 of 9. Infinite Loop / DoS in the TNEFFillMapi function in lib/ytnef.c."
nvd
CVE-2021-36411P4MEDIUMCVSS 5.5v10.0v11.02022-01-10
CVE-2021-36411 [MEDIUM] CWE-125 CVE-2021-36411: An issue has been found in libde265 v1.0.8 due to incorrect access control. A SEGV caused by a READ An issue has been found in libde265 v1.0.8 due to incorrect access control. A SEGV caused by a READ memory access in function derive_boundaryStrength of deblock.cc has occurred. The vulnerability causes a segmentation fault and application crash, which leads to remote denial of service.
nvd
CVE-2013-3560P4MEDIUMCVSS 5.0v7.02013-05-25
CVE-2013-3560 [MEDIUM] CWE-134 CVE-2013-3560: The dissect_dsmcc_un_download function in epan/dissectors/packet-mpeg-dsmcc.c in the MPEG DSM-CC dis The dissect_dsmcc_un_download function in epan/dissectors/packet-mpeg-dsmcc.c in the MPEG DSM-CC dissector in Wireshark 1.8.x before 1.8.7 uses an incorrect format string, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.
nvd
Debian Linux vulnerabilities | cvebase