cbcvebase.

Debian Linux vulnerabilities

9,955 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358

Vulnerabilities

Page 450 of 498
CVE-2013-3718P4MEDIUMCVSS 5.5v8.0v9.0+1 more2019-11-01
CVE-2013-3718 [MEDIUM] CWE-20 CVE-2013-3718: evince is missing a check on number of pages which can lead to a segmentation fault evince is missing a check on number of pages which can lead to a segmentation fault
nvd
CVE-2004-1014P4MEDIUMCVSS 5.0v3.02005-01-10
CVE-2004-1014 [MEDIUM] CVE-2004-1014: statd in nfs-utils 1.257 and earlier does not ignore the SIGPIPE signal, which allows remote attacke statd in nfs-utils 1.257 and earlier does not ignore the SIGPIPE signal, which allows remote attackers to cause a denial of service (server process crash) via a TCP connection that is prematurely terminated.
nvd
CVE-2017-17788P4MEDIUMCVSS 5.5v7.0v8.0+1 more2017-12-20
CVE-2017-17788 [MEDIUM] CWE-125 CVE-2017-17788: In GIMP 2.8.22, there is a stack-based buffer over-read in xcf_load_stream in app/xcf/xcf.c when the In GIMP 2.8.22, there is a stack-based buffer over-read in xcf_load_stream in app/xcf/xcf.c when there is no '\0' character after the version string.
nvd
CVE-2008-4065P4MEDIUMCVSS 4.3v4.02008-09-24
CVE-2008-4065 [MEDIUM] CWE-79 CVE-2008-4065: Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey bef Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to bypass cross-site scripting (XSS) protection mechanisms and conduct XSS attacks via byte order mark (BOM) characters that are removed from JavaScript code before execution, aka "Stripped BOM characters bug."
nvd
CVE-2021-34334P4MEDIUMCVSS 5.5v10.02021-08-09
CVE-2021-34334 [MEDIUM] CWE-835 CVE-2021-34334: Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the me Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop is triggered when Exiv2 is used to read the metadata of a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service, if they can trick the victim into running Exiv2
nvd
CVE-2020-21532P4MEDIUMCVSS 5.5v9.0v10.02021-09-16
CVE-2020-21532 [MEDIUM] CWE-120 CVE-2020-21532: fig2dev 3.2.7b contains a global buffer overflow in the setfigfont function in genepic.c. fig2dev 3.2.7b contains a global buffer overflow in the setfigfont function in genepic.c.
nvd
CVE-2020-21531P4MEDIUMCVSS 5.5v9.0v10.02021-09-16
CVE-2020-21531 [MEDIUM] CWE-120 CVE-2020-21531: fig2dev 3.2.7b contains a global buffer overflow in the conv_pattern_index function in gencgm.c. fig2dev 3.2.7b contains a global buffer overflow in the conv_pattern_index function in gencgm.c.
nvd
CVE-2017-9929P4MEDIUMCVSS 5.5v9.02017-06-26
CVE-2017-9929 [MEDIUM] CWE-119 CVE-2017-9929: In lrzip 0.631, a stack buffer overflow was found in the function get_fileinfo in lrzip.c:1074, whic In lrzip 0.631, a stack buffer overflow was found in the function get_fileinfo in lrzip.c:1074, which allows attackers to cause a denial of service via a crafted file.
nvd
CVE-2019-13218P4MEDIUMCVSS 5.5v10.02019-08-15
CVE-2019-13218 [MEDIUM] CWE-369 CVE-2019-13218: Division by zero in the predict_point function in stb_vorbis through 2019-03-04 allows an attacker t Division by zero in the predict_point function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service by opening a crafted Ogg Vorbis file.
nvd
CVE-2021-38114P4MEDIUMCVSS 5.5v9.0v10.0+1 more2021-08-04
CVE-2021-38114 [MEDIUM] CVE-2021-38114: libavcodec/dnxhddec.c in FFmpeg 4.4 does not check the return value of the init_vlc function, a simi libavcodec/dnxhddec.c in FFmpeg 4.4 does not check the return value of the init_vlc function, a similar issue to CVE-2013-0868.
nvd
CVE-2017-9928P4MEDIUMCVSS 5.5v9.02017-06-26
CVE-2017-9928 [MEDIUM] CWE-119 CVE-2017-9928: In lrzip 0.631, a stack buffer overflow was found in the function get_fileinfo in lrzip.c:979, which In lrzip 0.631, a stack buffer overflow was found in the function get_fileinfo in lrzip.c:979, which allows attackers to cause a denial of service via a crafted file.
nvd
CVE-2017-15954P4MEDIUMCVSS 5.5v8.02017-10-28
CVE-2017-15954 [MEDIUM] CWE-119 CVE-2017-15954: bchunk (related to BinChunker) 1.2.0 and 1.2.1 is vulnerable to a heap-based buffer overflow (with a bchunk (related to BinChunker) 1.2.0 and 1.2.1 is vulnerable to a heap-based buffer overflow (with a resultant invalid free) and crash when processing a malformed CUE (.cue) file.
nvd
CVE-2019-20096P4MEDIUMCVSS 5.5v8.02019-12-30
CVE-2019-20096 [MEDIUM] CWE-401 CVE-2019-20096: In the Linux kernel before 5.1, there is a memory leak in __feat_register_sp() in net/dccp/feat.c, w In the Linux kernel before 5.1, there is a memory leak in __feat_register_sp() in net/dccp/feat.c, which may cause denial of service, aka CID-1d3ff0950e2b.
nvd
CVE-2019-1010302P4MEDIUMCVSS 5.5v8.02019-07-15
CVE-2019-1010302 [MEDIUM] CWE-119 CVE-2019-1010302: jhead 3.03 is affected by: Incorrect Access Control. The impact is: Denial of service. The component jhead 3.03 is affected by: Incorrect Access Control. The impact is: Denial of service. The component is: iptc.c Line 122 show_IPTC(). The attack vector is: the victim must open a specially crafted JPEG file.
nvd
CVE-2019-13223P4MEDIUMCVSS 5.5v10.02019-08-15
CVE-2019-13223 [MEDIUM] CWE-617 CVE-2019-13223: A reachable assertion in the lookup1_values function in stb_vorbis through 2019-03-04 allows an atta A reachable assertion in the lookup1_values function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service by opening a crafted Ogg Vorbis file.
nvd
CVE-2009-1073P4MEDIUMCVSS 5.5v5.02009-03-31
CVE-2009-1073 [MEDIUM] CWE-732 CVE-2009-1073: nss-ldapd before 0.6.8 uses world-readable permissions for the /etc/nss-ldapd.conf file, which allow nss-ldapd before 0.6.8 uses world-readable permissions for the /etc/nss-ldapd.conf file, which allows local users to obtain a cleartext password for the LDAP server by reading the bindpw field.
nvd
CVE-2017-15955P4MEDIUMCVSS 5.5v8.02017-10-28
CVE-2017-15955 [MEDIUM] CWE-476 CVE-2017-15955: bchunk (related to BinChunker) 1.2.0 and 1.2.1 is vulnerable to an "Access violation near NULL on de bchunk (related to BinChunker) 1.2.0 and 1.2.1 is vulnerable to an "Access violation near NULL on destination operand" and crash when processing a malformed CUE (.cue) file.
nvd
CVE-2021-45343P4MEDIUMCVSS 5.5v10.0v11.02022-01-25
CVE-2021-45343 [MEDIUM] CWE-476 CVE-2021-45343: In LibreCAD 2.2.0, a NULL pointer dereference in the HATCH handling of libdxfrw allows an attacker t In LibreCAD 2.2.0, a NULL pointer dereference in the HATCH handling of libdxfrw allows an attacker to crash the application using a crafted DXF document.
nvd
CVE-2021-40985P4MEDIUMCVSS 5.5v9.02021-11-03
CVE-2021-40985 [MEDIUM] CWE-125 CVE-2021-40985: A stack-based buffer under-read in htmldoc before 1.9.12, allows attackers to cause a denial of serv A stack-based buffer under-read in htmldoc before 1.9.12, allows attackers to cause a denial of service via a crafted BMP image to image_load_bmp.
nvd
CVE-2021-3933P4MEDIUMCVSS 5.5v10.0v11.02022-03-25
CVE-2021-3933 [MEDIUM] CWE-190 CVE-2021-3933: An integer overflow could occur when OpenEXR processes a crafted file on systems where size_t < 64 b An integer overflow could occur when OpenEXR processes a crafted file on systems where size_t < 64 bits. This could cause an invalid bytesPerLine and maxBytesPerLine value, which could lead to problems with application stability or lead to other attack paths.
nvd
Debian Linux vulnerabilities | cvebase