Debian Linux vulnerabilities
9,955 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358
Vulnerabilities
Page 464 of 498
CVE-2018-5786P4MEDIUMCVSS 5.5v9.0v10.0+1 more2018-01-19
CVE-2018-5786 [MEDIUM] CWE-835 CVE-2018-5786: In Long Range Zip (aka lrzip) 0.631, there is an infinite loop and application hang in the get_filei
In Long Range Zip (aka lrzip) 0.631, there is an infinite loop and application hang in the get_fileinfo function (lrzip.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted lrz file.
nvd
CVE-2007-6284P4MEDIUMCVSS 5.0v3.1v4.02008-01-12
CVE-2007-6284 [MEDIUM] CWE-399 CVE-2007-6284: The xmlCurrentChar function in libxml2 before 2.6.31 allows context-dependent attackers to cause a d
The xmlCurrentChar function in libxml2 before 2.6.31 allows context-dependent attackers to cause a denial of service (infinite loop) via XML containing invalid UTF-8 sequences.
nvd
CVE-2004-1009P4MEDIUMCVSS 5.0v3.02005-04-14
CVE-2004-1009 [MEDIUM] CVE-2004-1009: Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service (inf
Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service (infinite loop) via unknown attack vectors.
nvd
CVE-2013-3562P4MEDIUMCVSS 5.0v7.02013-05-25
CVE-2013-3562 [MEDIUM] CWE-189 CVE-2013-3562: Multiple integer signedness errors in the tvb_unmasked function in epan/dissectors/packet-websocket.
Multiple integer signedness errors in the tvb_unmasked function in epan/dissectors/packet-websocket.c in the Websocket dissector in Wireshark 1.8.x before 1.8.7 allow remote attackers to cause a denial of service (application crash) via a malformed packet.
nvd
CVE-2022-0907P4MEDIUMCVSS 5.5v10.0v11.02022-03-11
CVE-2022-0907 [MEDIUM] CWE-252 CVE-2022-0907: Unchecked Return Value to NULL Pointer Dereference in tiffcrop in libtiff 4.3.0 allows attackers to
Unchecked Return Value to NULL Pointer Dereference in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit f2b656e2.
nvd
CVE-2020-16588P4MEDIUMCVSS 5.5v10.02020-12-09
CVE-2020-16588 [MEDIUM] CWE-476 CVE-2020-16588: A Null Pointer Deference issue exists in Academy Software Foundation OpenEXR 2.3.0 in generatePrevie
A Null Pointer Deference issue exists in Academy Software Foundation OpenEXR 2.3.0 in generatePreview in makePreview.cpp that can cause a denial of service via a crafted EXR file.
nvd
CVE-2017-14121P4MEDIUMCVSS 5.5v9.02017-09-03
CVE-2017-14121 [MEDIUM] CVE-2017-14121: The DecodeNumber function in unrarlib.c in unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a
The DecodeNumber function in unrarlib.c in unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a NULL pointer dereference flaw triggered by a crafted RAR archive. NOTE: this may be the same as one of the several test cases in the CVE-2017-11189 references.
nvd
CVE-2019-10018P4MEDIUMCVSS 5.5v9.02019-03-25
CVE-2019-10018 [MEDIUM] CWE-369 CVE-2019-10018: An issue was discovered in Xpdf 4.01.01. There is an FPE in the function PostScriptFunction::exec at
An issue was discovered in Xpdf 4.01.01. There is an FPE in the function PostScriptFunction::exec at Function.cc for the psOpIdiv case.
nvd
CVE-2005-3624P4MEDIUMCVSS 5.0v3.0v3.12005-12-31
CVE-2005-3624 [MEDIUM] CWE-189 CVE-2005-3624: The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, t
The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via negative or large integers in a CCITTFaxDecode stream, which lead to integer overflows and integer underflows.
nvd
CVE-2017-15953P4MEDIUMCVSS 5.5v8.02017-10-28
CVE-2017-15953 [MEDIUM] CWE-119 CVE-2017-15953: bchunk (related to BinChunker) 1.2.0 and 1.2.1 is vulnerable to a heap-based buffer overflow and cra
bchunk (related to BinChunker) 1.2.0 and 1.2.1 is vulnerable to a heap-based buffer overflow and crash when processing a malformed CUE (.cue) file.
nvd
CVE-2019-1010069P4MEDIUMCVSS 5.5v9.02019-07-18
CVE-2019-1010069 [MEDIUM] CWE-119 CVE-2019-1010069: moinejf abcm2ps 8.13.20 is affected by: Incorrect Access Control. The impact is: Allows attackers to
moinejf abcm2ps 8.13.20 is affected by: Incorrect Access Control. The impact is: Allows attackers to cause a denial of service attack via a crafted file. The component is: front.c, function txt_add. The fixed version is: after commit commit 08aef597656d065e86075f3d53fda89765845eae.
nvd
CVE-2019-20161P4MEDIUMCVSS 5.5v8.02019-12-31
CVE-2019-20161 [MEDIUM] CWE-787 CVE-2019-20161: An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is heap-based bu
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is heap-based buffer overflow in the function ReadGF_IPMPX_WatermarkingInit() in odf/ipmpx_code.c.
nvd
CVE-2019-20162P4MEDIUMCVSS 5.5v8.02019-12-31
CVE-2019-20162 [MEDIUM] CWE-787 CVE-2019-20162: An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is heap-based bu
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is heap-based buffer overflow in the function gf_isom_box_parse_ex() in isomedia/box_funcs.c.
nvd
CVE-2019-20163P4MEDIUMCVSS 5.5v8.02019-12-31
CVE-2019-20163 [MEDIUM] CWE-476 CVE-2019-20163: An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a NULL pointe
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a NULL pointer dereference in the function gf_odf_avc_cfg_write_bs() in odf/descriptors.c.
nvd
CVE-2019-20165P4MEDIUMCVSS 5.5v8.02019-12-31
CVE-2019-20165 [MEDIUM] CWE-476 CVE-2019-20165: An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a NULL pointe
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a NULL pointer dereference in the function ilst_item_Read() in isomedia/box_code_apple.c.
nvd
CVE-2024-12425P4LOWCVSS 3.3v11.02025-01-07
CVE-2024-12425 [LOW] CWE-22 CVE-2024-12425: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The Document Foundation LibreOffice allows Absolute Path Traversal.
An attacker can write to arbitrary locations, albeit suffixed with ".ttf", by supplying a file in a format that supports embedded font files.
This issue affects LibreOffice: from 24.8 befo
nvd
CVE-2021-37529P4MEDIUMCVSS 5.5v9.0v10.0+1 more2022-01-12
CVE-2021-37529 [MEDIUM] CWE-415 CVE-2021-37529: A double-free vulnerability exists in fig2dev through 3.28a is affected by: via the free_stream func
A double-free vulnerability exists in fig2dev through 3.28a is affected by: via the free_stream function in readpics.c, which could cause a denial of service (context-dependent).
nvd
CVE-2017-13755P4MEDIUMCVSS 5.5v9.02017-08-29
CVE-2017-13755 [MEDIUM] CWE-125 CVE-2017-13755: In The Sleuth Kit (TSK) 4.4.2, opening a crafted ISO 9660 image triggers an out-of-bounds read in is
In The Sleuth Kit (TSK) 4.4.2, opening a crafted ISO 9660 image triggers an out-of-bounds read in iso9660_proc_dir() in tsk/fs/iso9660_dent.c in libtskfs.a, as demonstrated by fls.
nvd
CVE-2017-13760P4MEDIUMCVSS 5.5v9.02017-08-29
CVE-2017-13760 [MEDIUM] CWE-119 CVE-2017-13760: In The Sleuth Kit (TSK) 4.4.2, fls hangs on a corrupt exfat image in tsk_img_read() in tsk/img/img_i
In The Sleuth Kit (TSK) 4.4.2, fls hangs on a corrupt exfat image in tsk_img_read() in tsk/img/img_io.c in libtskimg.a.
nvd
CVE-2017-13756P4MEDIUMCVSS 5.5v9.02017-08-29
CVE-2017-13756 [MEDIUM] CWE-835 CVE-2017-13756: In The Sleuth Kit (TSK) 4.4.2, opening a crafted disk image triggers infinite recursion in dos_load_
In The Sleuth Kit (TSK) 4.4.2, opening a crafted disk image triggers infinite recursion in dos_load_ext_table() in tsk/vs/dos.c in libtskvs.a, as demonstrated by mmls.
nvd