cbcvebase.

Debian Linux vulnerabilities

9,956 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,956
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4169MEDIUM4296LOW358

Vulnerabilities

Page 472 of 498
CVE-2024-0749P4MEDIUMCVSS 4.3v10.02024-01-23
CVE-2024-0749 [MEDIUM] CWE-346 CVE-2024-0749: A phishing site could have repurposed an `about:` dialog to show phishing content with an incorrect A phishing site could have repurposed an `about:` dialog to show phishing content with an incorrect origin in the address bar. This vulnerability affects Firefox < 122 and Thunderbird < 115.7.
nvd
CVE-2023-23920P4MEDIUMCVSS 4.2v10.02023-02-23
CVE-2023-23920 [MEDIUM] CWE-426 CVE-2023-23920: An untrusted search path vulnerability exists in Node.js. <19.6.1, <18.14.1, <16.19.1, and <14.21.3 An untrusted search path vulnerability exists in Node.js. <19.6.1, <18.14.1, <16.19.1, and <14.21.3 that could allow an attacker to search and potentially load ICU data when running with elevated privileges.
nvd
CVE-2024-28085P4LOWCVSS 3.3v10.02024-03-27
CVE-2024-28085 [LOW] CWE-150 CVE-2024-28085: wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequence wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals through argv. (Specifically, escape sequences received from stdin are blocked, but escape sequences received from argv are not blocked.) There may be plausible scenarios where this leads to account takeover.
nvd
CVE-2016-8691P4MEDIUMCVSS 5.5v8.02017-02-15
CVE-2016-8691 [MEDIUM] CWE-369 CVE-2016-8691: The jpc_dec_process_siz function in libjasper/jpc/jpc_dec.c in JasPer before 1.900.4 allows remote a The jpc_dec_process_siz function in libjasper/jpc/jpc_dec.c in JasPer before 1.900.4 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted XRsiz value in a BMP image to the imginfo command.
nvd
CVE-2016-8692P4MEDIUMCVSS 5.5v8.02017-02-15
CVE-2016-8692 [MEDIUM] CWE-369 CVE-2016-8692: The jpc_dec_process_siz function in libjasper/jpc/jpc_dec.c in JasPer before 1.900.4 allows remote a The jpc_dec_process_siz function in libjasper/jpc/jpc_dec.c in JasPer before 1.900.4 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted YRsiz value in a BMP image to the imginfo command.
nvd
CVE-2005-3626P4MEDIUMCVSS 5.0v3.0v3.12005-12-31
CVE-2005-3626 [MEDIUM] CWE-399 CVE-2005-3626: Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and oth Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null dereference.
nvd
CVE-2002-1232P4MEDIUMCVSS 5.0v2.2v3.02002-11-04
CVE-2002-1232 [MEDIUM] CVE-2002-1232: Memory leak in ypdb_open in yp_db.c for ypserv before 2.5 in the NIS package 3.9 and earlier allows Memory leak in ypdb_open in yp_db.c for ypserv before 2.5 in the NIS package 3.9 and earlier allows remote attackers to cause a denial of service (memory consumption) via a large number of requests for a map that does not exist.
nvd
CVE-2008-3912P4MEDIUMCVSS 5.0v4.02008-09-11
CVE-2008-3912 [MEDIUM] CWE-399 CVE-2008-3912: libclamav in ClamAV before 0.94 allows attackers to cause a denial of service (NULL pointer derefere libclamav in ClamAV before 0.94 allows attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors related to an out-of-memory condition.
nvd
CVE-2018-18521P4MEDIUMCVSS 5.5v8.0v9.02018-10-19
CVE-2018-18521 [MEDIUM] CWE-369 CVE-2018-18521: Divide-by-zero vulnerabilities in the function arlib_add_symbols() in arlib.c in elfutils 0.174 allo Divide-by-zero vulnerabilities in the function arlib_add_symbols() in arlib.c in elfutils 0.174 allow remote attackers to cause a denial of service (application crash) with a crafted ELF file, as demonstrated by eu-ranlib, because a zero sh_entsize is mishandled.
nvd
CVE-2019-11139P4MEDIUMCVSS 6.0v8.02019-11-14
CVE-2019-11139 [MEDIUM] CWE-754 CVE-2019-11139: Improper conditions check in the voltage modulation interface for some Intel(R) Xeon(R) Scalable Pro Improper conditions check in the voltage modulation interface for some Intel(R) Xeon(R) Scalable Processors may allow a privileged user to potentially enable denial of service via local access.
nvd
CVE-2016-5241P4MEDIUMCVSS 5.5v8.02017-02-03
CVE-2016-5241 [MEDIUM] CWE-189 CVE-2016-5241: magick/render.c in GraphicsMagick before 1.3.24 allows remote attackers to cause a denial of service magick/render.c in GraphicsMagick before 1.3.24 allows remote attackers to cause a denial of service (arithmetic exception and application crash) via a crafted svg file.
nvd
CVE-2004-1142P4MEDIUMCVSS 5.0v3.02004-12-15
CVE-2004-1142 [MEDIUM] CVE-2004-1142: Ethereal 0.9.0 through 0.10.7 allows remote attackers to cause a denial of service (CPU consumption) Ethereal 0.9.0 through 0.10.7 allows remote attackers to cause a denial of service (CPU consumption) via a certain malformed SMB packet.
nvd
CVE-2018-19777P4MEDIUMCVSS 5.5v8.0v9.02018-11-30
CVE-2018-19777 [MEDIUM] CWE-835 CVE-2018-19777: In Artifex MuPDF 1.14.0, there is an infinite loop in the function svg_dev_end_tile in fitz/svg-devi In Artifex MuPDF 1.14.0, there is an infinite loop in the function svg_dev_end_tile in fitz/svg-device.c, as demonstrated by mutool.
nvd
CVE-2022-30975P4MEDIUMCVSS 5.5v11.02022-05-18
CVE-2022-30975 [MEDIUM] CWE-476 CVE-2022-30975: In Artifex MuJS through 1.2.0, jsP_dumpsyntax in jsdump.c has a NULL pointer dereference, as demonst In Artifex MuJS through 1.2.0, jsP_dumpsyntax in jsdump.c has a NULL pointer dereference, as demonstrated by mujs-pp.
nvd
CVE-2018-10289P4MEDIUMCVSS 5.5v9.02018-04-22
CVE-2018-10289 [MEDIUM] CWE-835 CVE-2018-10289: In MuPDF 1.13.0, there is an infinite loop in the fz_skip_space function of the pdf/pdf-xref.c file. In MuPDF 1.13.0, there is an infinite loop in the fz_skip_space function of the pdf/pdf-xref.c file. A remote adversary could leverage this vulnerability to cause a denial of service via a crafted pdf file.
nvd
CVE-2021-32280P4MEDIUMCVSS 5.5v9.0v10.02021-09-20
CVE-2021-32280 [MEDIUM] CWE-476 CVE-2021-32280: An issue was discovered in fig2dev before 3.2.8.. A NULL pointer dereference exists in the function An issue was discovered in fig2dev before 3.2.8.. A NULL pointer dereference exists in the function compute_closed_spline() located in trans_spline.c. It allows an attacker to cause Denial of Service. The fixed version of fig2dev is 3.2.8.
nvd
CVE-2018-1000036P4MEDIUMCVSS 5.5v9.02018-05-24
CVE-2018-1000036 [MEDIUM] CWE-772 CVE-2018-1000036: In Artifex MuPDF 1.12.0 and earlier, multiple memory leaks in the PDF parser allow an attacker to ca In Artifex MuPDF 1.12.0 and earlier, multiple memory leaks in the PDF parser allow an attacker to cause a denial of service (memory leak) via a crafted file.
nvd
CVE-2019-13219P4MEDIUMCVSS 5.5v10.02019-08-15
CVE-2019-13219 [MEDIUM] CWE-476 CVE-2019-13219: A NULL pointer dereference in the get_window function in stb_vorbis through 2019-03-04 allows an att A NULL pointer dereference in the get_window function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service by opening a crafted Ogg Vorbis file.
nvd
CVE-2021-32276P4MEDIUMCVSS 5.5v9.0v10.02021-09-20
CVE-2021-32276 [MEDIUM] CWE-476 CVE-2021-32276: An issue was discovered in faad2 through 2.10.0. A NULL pointer dereference exists in the function g An issue was discovered in faad2 through 2.10.0. A NULL pointer dereference exists in the function get_sample() located in output.c. It allows an attacker to cause Denial of Service.
nvd
CVE-2019-12481P4MEDIUMCVSS 5.5v8.02019-05-30
CVE-2019-12481 [MEDIUM] CWE-476 CVE-2019-12481: An issue was discovered in GPAC 0.7.1. There is a NULL pointer dereference in the function GetESD at An issue was discovered in GPAC 0.7.1. There is a NULL pointer dereference in the function GetESD at isomedia/track.c in libgpac.a, as demonstrated by MP4Box.
nvd
Debian Linux vulnerabilities | cvebase