cbcvebase.

Debian Linux vulnerabilities

9,956 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,956
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4169MEDIUM4296LOW358

Vulnerabilities

Page 465 of 498
CVE-2017-13756P4MEDIUMCVSS 5.5v9.02017-08-29
CVE-2017-13756 [MEDIUM] CWE-835 CVE-2017-13756: In The Sleuth Kit (TSK) 4.4.2, opening a crafted disk image triggers infinite recursion in dos_load_ In The Sleuth Kit (TSK) 4.4.2, opening a crafted disk image triggers infinite recursion in dos_load_ext_table() in tsk/vs/dos.c in libtskvs.a, as demonstrated by mmls.
nvd
CVE-2022-2953P4MEDIUMCVSS 5.5v11.02022-08-29
CVE-2022-2953 [MEDIUM] CWE-125 CVE-2022-2953: LibTIFF 4.4.0 has an out-of-bounds read in extractImageSection in tools/tiffcrop.c:6905, allowing at LibTIFF 4.4.0 has an out-of-bounds read in extractImageSection in tools/tiffcrop.c:6905, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 48d6ece8.
nvd
CVE-2020-12767P4MEDIUMCVSS 5.5v8.02020-05-09
CVE-2020-12767 [MEDIUM] CWE-369 CVE-2020-12767: exif_entry_get_value in exif-entry.c in libexif 0.6.21 has a divide-by-zero error. exif_entry_get_value in exif-entry.c in libexif 0.6.21 has a divide-by-zero error.
nvd
CVE-2008-3275P4MEDIUMCVSS 5.5v4.02008-08-12
CVE-2008-3275 [MEDIUM] CWE-120 CVE-2008-3275: The (1) real_lookup and (2) __lookup_hash functions in fs/namei.c in the vfs implementation in the L The (1) real_lookup and (2) __lookup_hash functions in fs/namei.c in the vfs implementation in the Linux kernel before 2.6.25.15 do not prevent creation of a child dentry for a deleted (aka S_DEAD) directory, which allows local users to cause a denial of service ("overflow" of the UBIFS orphan area) via a series of attempted file creations within dele
nvd
CVE-2011-1489P4MEDIUMCVSS 5.5v8.0v9.0+1 more2019-11-14
CVE-2011-1489 [MEDIUM] CWE-772 CVE-2011-1489: A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages were logged A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages were logged when multiple rulesets were used and some output batches contained messages belonging to more than one ruleset. A local attacker could cause denial of the rsyslogd daemon service via a log message belonging to more than one ruleset.
nvd
CVE-2018-8087P4MEDIUMCVSS 5.5v9.02018-03-13
CVE-2018-8087 [MEDIUM] CWE-772 CVE-2018-8087: Memory leak in the hwsim_new_radio_nl function in drivers/net/wireless/mac80211_hwsim.c in the Linux Memory leak in the hwsim_new_radio_nl function in drivers/net/wireless/mac80211_hwsim.c in the Linux kernel through 4.15.9 allows local users to cause a denial of service (memory consumption) by triggering an out-of-array error case.
nvd
CVE-2019-9706P4MEDIUMCVSS 5.5v8.0v9.02019-03-12
CVE-2019-9706 [MEDIUM] CWE-416 CVE-2019-9706: Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (use Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (use-after-free and daemon crash) because of a force_rescan_user error.
nvd
CVE-2022-24959P4MEDIUMCVSS 5.5v9.0v10.0+1 more2022-02-11
CVE-2022-24959 [MEDIUM] CWE-401 CVE-2022-24959: An issue was discovered in the Linux kernel before 5.16.5. There is a memory leak in yam_siocdevpriv An issue was discovered in the Linux kernel before 5.16.5. There is a memory leak in yam_siocdevprivate in drivers/net/hamradio/yam.c.
nvd
CVE-2000-0511P4MEDIUMCVSS 5.0v2.2v2.32000-06-21
CVE-2000-0511 [MEDIUM] CVE-2000-0511: CUPS (Common Unix Printing System) 1.04 and earlier allows remote attackers to cause a denial of ser CUPS (Common Unix Printing System) 1.04 and earlier allows remote attackers to cause a denial of service via a CGI POST request.
nvd
CVE-2000-0513P4MEDIUMCVSS 5.0v2.2v2.32000-06-21
CVE-2000-0513 [MEDIUM] CVE-2000-0513: CUPS (Common Unix Printing System) 1.04 and earlier allows remote attackers to cause a denial of ser CUPS (Common Unix Printing System) 1.04 and earlier allows remote attackers to cause a denial of service by authenticating with a user name that does not exist or does not have a shadow password.
nvd
CVE-2000-0512P4MEDIUMCVSS 5.0v2.2v2.32000-06-16
CVE-2000-0512 [MEDIUM] CVE-2000-0512: CUPS (Common Unix Printing System) 1.04 and earlier does not properly delete request files, which al CUPS (Common Unix Printing System) 1.04 and earlier does not properly delete request files, which allows a remote attacker to cause a denial of service.
nvd
CVE-2004-1091P4MEDIUMCVSS 5.0v3.02005-04-14
CVE-2004-1091 [MEDIUM] CVE-2004-1091: Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service by t Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service by triggering a null dereference.
nvd
CVE-2017-5987P4MEDIUMCVSS 5.5v8.02017-03-20
CVE-2017-5987 [MEDIUM] CWE-835 CVE-2017-5987: The sdhci_sdma_transfer_multi_blocks function in hw/sd/sdhci.c in QEMU (aka Quick Emulator) allows l The sdhci_sdma_transfer_multi_blocks function in hw/sd/sdhci.c in QEMU (aka Quick Emulator) allows local OS guest privileged users to cause a denial of service (infinite loop and QEMU process crash) via vectors involving the transfer mode register during multi block transfer.
nvd
CVE-2025-37757P4MEDIUMCVSS 5.5v11.02025-05-01
CVE-2025-37757 [MEDIUM] CWE-401 CVE-2025-37757: In the Linux kernel, the following vulnerability has been resolved: tipc: fix memory leak in tipc_l In the Linux kernel, the following vulnerability has been resolved: tipc: fix memory leak in tipc_link_xmit In case the backlog transmit queue for system-importance messages is overloaded, tipc_link_xmit() returns -ENOBUFS but the skb list is not purged. This leads to memory leak and failure when a skb is allocated. This commit fixes this issue by
nvd
CVE-2017-9503P4MEDIUMCVSS 5.5v8.0v9.02017-06-16
CVE-2017-9503 [MEDIUM] CWE-476 CVE-2017-9503: QEMU (aka Quick Emulator), when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, QEMU (aka Quick Emulator), when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest OS privileged users to cause a denial of service (NULL pointer dereference and QEMU process crash) via vectors involving megasas command processing.
nvd
CVE-2020-12768P4MEDIUMCVSS 5.5v10.02020-05-09
CVE-2020-12768 [MEDIUM] CWE-401 CVE-2020-12768: An issue was discovered in the Linux kernel before 5.6. svm_cpu_uninit in arch/x86/kvm/svm.c has a m An issue was discovered in the Linux kernel before 5.6. svm_cpu_uninit in arch/x86/kvm/svm.c has a memory leak, aka CID-d80b64ff297e. NOTE: third parties dispute this issue because it's a one-time leak at the boot, the size is negligible, and it can't be triggered at will
nvd
CVE-2011-1490P4MEDIUMCVSS 5.5v8.0v9.0+1 more2019-11-14
CVE-2011-1490 [MEDIUM] CWE-772 CVE-2011-1490: A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when multiple rulesets were used and some output batches contained messages belonging to more than one ruleset. A local attacker could cause denial of the rsyslogd daemon service via a log message belonging to more than one ruleset
nvd
CVE-2020-35532P4MEDIUMCVSS 5.5v10.02022-09-01
CVE-2020-35532 [MEDIUM] CWE-125 CVE-2020-35532: In LibRaw, an out-of-bounds read vulnerability exists within the "simple_decode_row()" function (lib In LibRaw, an out-of-bounds read vulnerability exists within the "simple_decode_row()" function (libraw\src\x3f\x3f_utils_patched.cpp) which can be triggered via an image with a large row_stride field.
nvd
CVE-2021-1093P4MEDIUMCVSS 5.5v9.02021-07-22
CVE-2021-1093 [MEDIUM] CWE-404 CVE-2021-1093: NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in firmware where the drive NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in firmware where the driver contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary, and may lead to denial of service or system crash.
nvd
CVE-2019-17350P4MEDIUMCVSS 5.5v9.0v10.02019-10-08
CVE-2019-17350 [MEDIUM] CWE-835 CVE-2019-17350: An issue was discovered in Xen through 4.12.x allowing Arm domU attackers to cause a denial of servi An issue was discovered in Xen through 4.12.x allowing Arm domU attackers to cause a denial of service (infinite loop) involving a compare-and-exchange operation.
nvd
Debian Linux vulnerabilities | cvebase