cbcvebase.

Debian Linux vulnerabilities

9,955 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358

Vulnerabilities

Page 463 of 498
CVE-2019-12975P4MEDIUMCVSS 5.5v10.02019-06-26
CVE-2019-12975 [MEDIUM] CWE-401 CVE-2019-12975: ImageMagick 7.0.8-34 has a memory leak vulnerability in the WriteDPXImage function in coders/dpx.c. ImageMagick 7.0.8-34 has a memory leak vulnerability in the WriteDPXImage function in coders/dpx.c.
nvd
CVE-2015-8035P4LOWCVSS 2.6v7.0v8.02015-11-18
CVE-2015-8035 [LOW] CWE-399 CVE-2015-8035: The xz_decomp function in xzlib.c in libxml2 2.9.1 does not properly detect compression errors, whic The xz_decomp function in xzlib.c in libxml2 2.9.1 does not properly detect compression errors, which allows context-dependent attackers to cause a denial of service (process hang) via crafted XML data.
nvd
CVE-2018-6192P4MEDIUMCVSS 5.5v9.02018-01-24
CVE-2018-6192 [MEDIUM] CWE-119 CVE-2018-6192: In Artifex MuPDF 1.12.0, the pdf_read_new_xref function in pdf/pdf-xref.c allows remote attackers to In Artifex MuPDF 1.12.0, the pdf_read_new_xref function in pdf/pdf-xref.c allows remote attackers to cause a denial of service (segmentation violation and application crash) via a crafted pdf file.
nvd
CVE-2016-8909P4MEDIUMCVSS 6.0v8.02016-11-04
CVE-2016-8909 [MEDIUM] CWE-835 CVE-2016-8909: The intel_hda_xfer function in hw/audio/intel-hda.c in QEMU (aka Quick Emulator) allows local guest The intel_hda_xfer function in hw/audio/intel-hda.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) via an entry with the same value for buffer length and pointer position.
nvd
CVE-2018-19139P4MEDIUMCVSS 5.5v8.02018-11-09
CVE-2018-19139 [MEDIUM] CWE-772 CVE-2018-19139: An issue has been found in JasPer 2.0.14. There is a memory leak in jas_malloc.c when called from jp An issue has been found in JasPer 2.0.14. There is a memory leak in jas_malloc.c when called from jpc_unk_getparms in jpc_cs.c.
nvd
CVE-2016-8578P4MEDIUMCVSS 6.0v8.02016-11-04
CVE-2016-8578 [MEDIUM] CVE-2016-8578: The v9fs_iov_vunmarshal function in fsdev/9p-iov-marshal.c in QEMU (aka Quick Emulator) allows local The v9fs_iov_vunmarshal function in fsdev/9p-iov-marshal.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) by sending an empty string parameter to a 9P operation.
nvd
CVE-2016-8667P4MEDIUMCVSS 6.0v8.02016-11-04
CVE-2016-8667 [MEDIUM] CWE-369 CVE-2016-8667: The rc4030_write function in hw/dma/rc4030.c in QEMU (aka Quick Emulator) allows local guest OS admi The rc4030_write function in hw/dma/rc4030.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (divide-by-zero error and QEMU process crash) via a large interval timer reload value.
nvd
CVE-2016-9105P4MEDIUMCVSS 6.0v8.02016-12-09
CVE-2016-9105 [MEDIUM] CWE-772 CVE-2016-9105: Memory leak in the v9fs_link function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local gues Memory leak in the v9fs_link function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption) via vectors involving a reference to the source fid object.
nvd
CVE-2016-8669P4MEDIUMCVSS 6.0v8.02016-11-04
CVE-2016-8669 [MEDIUM] CWE-369 CVE-2016-8669: The serial_update_parameters function in hw/char/serial.c in QEMU (aka Quick Emulator) allows local The serial_update_parameters function in hw/char/serial.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (divide-by-zero error and QEMU process crash) via vectors involving a value of divider greater than baud base.
nvd
CVE-2018-5686P4MEDIUMCVSS 5.5v8.0v9.02018-01-14
CVE-2018-5686 [MEDIUM] CWE-835 CVE-2018-5686: In MuPDF 1.12.0, there is an infinite loop vulnerability and application hang in the pdf_parse_array In MuPDF 1.12.0, there is an infinite loop vulnerability and application hang in the pdf_parse_array function (pdf/pdf-parse.c) because EOF is not considered. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted pdf file.
nvd
CVE-2003-0615P4MEDIUMCVSS 4.3v3.02003-08-27
CVE-2003-0615 [MEDIUM] CVE-2003-0615: Cross-site scripting (XSS) vulnerability in start_form() of CGI.pm allows remote attackers to insert Cross-site scripting (XSS) vulnerability in start_form() of CGI.pm allows remote attackers to insert web script via a URL that is fed into the form's action parameter.
nvd
CVE-2018-19624P4MEDIUMCVSS 5.5v8.0v9.02018-11-29
CVE-2018-19624 [MEDIUM] CWE-476 CVE-2018-19624: In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the PVFS dissector could crash. This was addressed In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the PVFS dissector could crash. This was addressed in epan/dissectors/packet-pvfs2.c by preventing a NULL pointer dereference.
nvd
CVE-2019-5717P4MEDIUMCVSS 5.5v8.0v9.02019-01-08
CVE-2019-5717 [MEDIUM] CWE-20 CVE-2019-5717: In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the P_MUL dissector could crash. This was addressed In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the P_MUL dissector could crash. This was addressed in epan/dissectors/packet-p_mul.c by rejecting the invalid sequence number of zero.
nvd
CVE-2018-7730P4MEDIUMCVSS 5.5v7.02018-03-06
CVE-2018-7730 [MEDIUM] CWE-125 CVE-2018-7730: An issue was discovered in Exempi through 2.4.4. A certain case of a 0xffffffff length is mishandled An issue was discovered in Exempi through 2.4.4. A certain case of a 0xffffffff length is mishandled in XMPFiles/source/FormatSupport/PSIR_FileWriter.cpp, leading to a heap-based buffer over-read in the PSD_MetaHandler::CacheFileData() function.
nvd
CVE-2019-5716P4MEDIUMCVSS 5.5v8.0v9.02019-01-08
CVE-2019-5716 [MEDIUM] CWE-20 CVE-2019-5716: In Wireshark 2.6.0 to 2.6.5, the 6LoWPAN dissector could crash. This was addressed in epan/dissector In Wireshark 2.6.0 to 2.6.5, the 6LoWPAN dissector could crash. This was addressed in epan/dissectors/packet-6lowpan.c by avoiding use of a TVB before its creation.
nvd
CVE-2018-19625P4MEDIUMCVSS 5.5v8.0v9.02018-11-29
CVE-2018-19625 [MEDIUM] CWE-125 CVE-2018-19625: In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the dissection engine could crash. This was address In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the dissection engine could crash. This was addressed in epan/tvbuff_composite.c by preventing a heap-based buffer over-read.
nvd
CVE-2017-6888P4MEDIUMCVSS 5.5v9.02018-04-25
CVE-2017-6888 [MEDIUM] CWE-772 CVE-2017-6888: An error in the "read_metadata_vorbiscomment_()" function (src/libFLAC/stream_decoder.c) in FLAC ver An error in the "read_metadata_vorbiscomment_()" function (src/libFLAC/stream_decoder.c) in FLAC version 1.3.2 can be exploited to cause a memory leak via a specially crafted FLAC file.
nvd
CVE-2018-5269P4MEDIUMCVSS 5.5v7.0v8.0+1 more2018-01-08
CVE-2018-5269 [MEDIUM] CWE-617 CVE-2018-5269: In OpenCV 3.3.1, an assertion failure happens in cv::RBaseStream::setPos in modules/imgcodecs/src/bi In OpenCV 3.3.1, an assertion failure happens in cv::RBaseStream::setPos in modules/imgcodecs/src/bitstrm.cpp because of an incorrect integer cast.
nvd
CVE-2022-0909P4MEDIUMCVSS 5.5v10.0v11.02022-03-11
CVE-2022-0909 [MEDIUM] CWE-369 CVE-2022-0909: Divide By Zero error in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via Divide By Zero error in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit f8d0f9aa.
nvd
CVE-2022-0924P4MEDIUMCVSS 5.5v10.0v11.02022-03-11
CVE-2022-0924 [MEDIUM] CWE-125 CVE-2022-0924: Out-of-bounds Read error in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service vi Out-of-bounds Read error in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 408976c4.
nvd
Debian Linux vulnerabilities | cvebase