Debian Linux vulnerabilities
9,955 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358
Vulnerabilities
Page 451 of 498
CVE-2020-21534P4MEDIUMCVSS 5.5v9.02021-09-16
CVE-2020-21534 [MEDIUM] CWE-120 CVE-2020-21534: fig2dev 3.2.7b contains a global buffer overflow in the get_line function in read.c.
fig2dev 3.2.7b contains a global buffer overflow in the get_line function in read.c.
nvd
CVE-2019-20170P4MEDIUMCVSS 5.5v8.02019-12-31
CVE-2019-20170 [MEDIUM] CWE-763 CVE-2019-20170: An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is an invalid po
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is an invalid pointer dereference in the function GF_IPMPX_AUTH_Delete() in odf/ipmpx_code.c.
nvd
CVE-2013-3558P4MEDIUMCVSS 5.0v7.02013-05-25
CVE-2013-3558 [MEDIUM] CWE-189 CVE-2013-3558: The dissect_ccp_bsdcomp_opt function in epan/dissectors/packet-ppp.c in the PPP CCP dissector in Wir
The dissect_ccp_bsdcomp_opt function in epan/dissectors/packet-ppp.c in the PPP CCP dissector in Wireshark 1.8.x before 1.8.7 does not terminate a bit-field list, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.
nvd
CVE-2015-4171P4LOWCVSS 2.6v8.02015-06-10
CVE-2015-4171 [LOW] CWE-200 CVE-2015-4171: strongSwan 4.3.0 through 5.x before 5.3.2 and strongSwan VPN Client before 1.4.6, when using EAP or
strongSwan 4.3.0 through 5.x before 5.3.2 and strongSwan VPN Client before 1.4.6, when using EAP or pre-shared keys for authenticating an IKEv2 connection, does not enforce server authentication restrictions until the entire authentication process is complete, which allows remote servers to obtain credentials by using a valid certificate and then reading
nvd
CVE-2019-5719P4MEDIUMCVSS 5.5v8.0v9.02019-01-08
CVE-2019-5719 [MEDIUM] CWE-327 CVE-2019-5719: In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the ISAKMP dissector could crash. This was addresse
In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the ISAKMP dissector could crash. This was addressed in epan/dissectors/packet-isakmp.c by properly handling the case of a missing decryption data block.
nvd
CVE-2021-37530P4MEDIUMCVSS 5.5v9.0v10.0+1 more2022-01-12
CVE-2021-37530 [MEDIUM] CWE-787 CVE-2021-37530: A denial of service vulnerabiity exists in fig2dev through 3.28a due to a segfault in the open_strea
A denial of service vulnerabiity exists in fig2dev through 3.28a due to a segfault in the open_stream function in readpics.c.
nvd
CVE-2021-27347P4MEDIUMCVSS 5.5v9.02021-06-10
CVE-2021-27347 [MEDIUM] CWE-416 CVE-2021-27347: Use after free in lzma_decompress_buf function in stream.c in Irzip 0.631 allows attackers to cause
Use after free in lzma_decompress_buf function in stream.c in Irzip 0.631 allows attackers to cause Denial of Service (DoS) via a crafted compressed file.
nvd
CVE-2019-19221P4MEDIUMCVSS 5.5v9.0v10.02019-11-21
CVE-2019-19221 [MEDIUM] CWE-125 CVE-2019-19221: In Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c has an out-of-bounds read b
In Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c has an out-of-bounds read because of an incorrect mbrtowc or mbtowc call. For example, bsdtar crashes via a crafted archive.
nvd
CVE-2020-28916P4MEDIUMCVSS 5.5v9.0v10.02020-12-04
CVE-2020-28916 [MEDIUM] CWE-835 CVE-2020-28916: hw/net/e1000e_core.c in QEMU 5.0.0 has an infinite loop via an RX descriptor with a NULL buffer addr
hw/net/e1000e_core.c in QEMU 5.0.0 has an infinite loop via an RX descriptor with a NULL buffer address.
nvd
CVE-2017-9310P4MEDIUMCVSS 5.6v8.0v9.02017-06-08
CVE-2017-9310 [MEDIUM] CWE-835 CVE-2017-9310: QEMU (aka Quick Emulator), when built with the e1000e NIC emulation support, allows local guest OS p
QEMU (aka Quick Emulator), when built with the e1000e NIC emulation support, allows local guest OS privileged users to cause a denial of service (infinite loop) via vectors related to setting the initial receive / transmit descriptor head (TDH/RDH) outside the allocated descriptor buffer.
nvd
CVE-2019-19051P4MEDIUMCVSS 5.5v8.02019-11-18
CVE-2019-19051 [MEDIUM] CWE-401 CVE-2019-19051: A memory leak in the i2400m_op_rfkill_sw_toggle() function in drivers/net/wimax/i2400m/op-rfkill.c i
A memory leak in the i2400m_op_rfkill_sw_toggle() function in drivers/net/wimax/i2400m/op-rfkill.c in the Linux kernel before 5.3.11 allows attackers to cause a denial of service (memory consumption), aka CID-6f3ef5c25cc7.
nvd
CVE-2022-28356P4MEDIUMCVSS 5.5v9.0v10.0+1 more2022-04-02
CVE-2022-28356 [MEDIUM] CVE-2022-28356: In the Linux kernel before 5.17.1, a refcount leak bug was found in net/llc/af_llc.c.
In the Linux kernel before 5.17.1, a refcount leak bug was found in net/llc/af_llc.c.
nvd
CVE-2024-30203P4MEDIUMCVSS 5.5v10.02024-03-25
CVE-2024-30203 [MEDIUM] CVE-2024-30203: In Emacs before 29.3, Gnus treats inline MIME contents as trusted.
In Emacs before 29.3, Gnus treats inline MIME contents as trusted.
nvd
CVE-2018-10323P4MEDIUMCVSS 5.5v9.02018-04-24
CVE-2018-10323 [MEDIUM] CWE-476 CVE-2018-10323: The xfs_bmap_extents_to_btree function in fs/xfs/libxfs/xfs_bmap.c in the Linux kernel through 4.16.
The xfs_bmap_extents_to_btree function in fs/xfs/libxfs/xfs_bmap.c in the Linux kernel through 4.16.3 allows local users to cause a denial of service (xfs_bmapi_write NULL pointer dereference) via a crafted xfs image.
nvd
CVE-2016-3712P4MEDIUMCVSS 5.5v8.02016-05-11
CVE-2016-3712 [MEDIUM] CWE-190 CVE-2016-3712: Integer overflow in the VGA module in QEMU allows local guest OS users to cause a denial of service
Integer overflow in the VGA module in QEMU allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) by editing VGA registers in VBE mode.
nvd
CVE-2021-4214P4MEDIUMCVSS 5.5v10.0v11.02022-08-24
CVE-2021-4214 [MEDIUM] CWE-120 CVE-2021-4214: A heap overflow flaw was found in libpngs' pngimage.c program. This flaw allows an attacker with loc
A heap overflow flaw was found in libpngs' pngimage.c program. This flaw allows an attacker with local network access to pass a specially crafted PNG file to the pngimage utility, causing an application to crash, leading to a denial of service.
nvd
CVE-2018-6554P4MEDIUMCVSS 5.5v8.0v9.02018-09-04
CVE-2018-6554 [MEDIUM] CWE-400 CVE-2018-6554: Memory leak in the irda_bind function in net/irda/af_irda.c and later in drivers/staging/irda/net/af
Memory leak in the irda_bind function in net/irda/af_irda.c and later in drivers/staging/irda/net/af_irda.c in the Linux kernel before 4.17 allows local users to cause a denial of service (memory consumption) by repeatedly binding an AF_IRDA socket.
nvd
CVE-2024-36964P4MEDIUMCVSS 5.5v10.02024-06-03
CVE-2024-36964 [MEDIUM] CVE-2024-36964: In the Linux kernel, the following vulnerability has been resolved: fs/9p: only translate RWX permi
In the Linux kernel, the following vulnerability has been resolved:
fs/9p: only translate RWX permissions for plain 9P2000
Garbage in plain 9P2000's perm bits is allowed through, which causes it
to be able to set (among others) the suid bit. This was presumably not
the intent since the unix extended bits are handled explicitly and
conditionally on .u.
nvd
CVE-2022-3570P4MEDIUMCVSS 5.5v10.0v11.02022-10-21
CVE-2022-3570 [MEDIUM] CWE-787 CVE-2022-3570: Multiple heap buffer overflows in tiffcrop.c utility in libtiff library Version 4.4.0 allows attacke
Multiple heap buffer overflows in tiffcrop.c utility in libtiff library Version 4.4.0 allows attacker to trigger unsafe or out of bounds memory access via crafted TIFF image file which could result into application crash, potential information disclosure or any other context-dependent impact
nvd
CVE-2020-12867P4MEDIUMCVSS 5.5v9.02020-06-01
CVE-2020-12867 [MEDIUM] CWE-476 CVE-2020-12867: A NULL pointer dereference in sanei_epson_net_read in SANE Backends before 1.0.30 allows a malicious
A NULL pointer dereference in sanei_epson_net_read in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to cause a denial of service, aka GHSL-2020-075.
nvd