cbcvebase.

Debian Linux vulnerabilities

9,956 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,956
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4169MEDIUM4296LOW358

Vulnerabilities

Page 473 of 498
CVE-2020-25467P4MEDIUMCVSS 5.5v9.02021-06-10
CVE-2020-25467 [MEDIUM] CWE-476 CVE-2020-25467: A null pointer dereference was discovered lzo_decompress_buf in stream.c in Irzip 0.621 which allows A null pointer dereference was discovered lzo_decompress_buf in stream.c in Irzip 0.621 which allows an attacker to cause a denial of service (DOS) via a crafted compressed file.
nvd
CVE-2017-7697P4MEDIUMCVSS 5.5v9.02017-04-11
CVE-2017-7697 [MEDIUM] CWE-125 CVE-2017-7697: In libsamplerate before 0.1.9, a buffer over-read occurs in the calc_output_single function in src_s In libsamplerate before 0.1.9, a buffer over-read occurs in the calc_output_single function in src_sinc.c via a crafted audio file.
nvd
CVE-2020-21535P4MEDIUMCVSS 5.5v9.02021-09-16
CVE-2020-21535 [MEDIUM] CWE-125 CVE-2020-21535: fig2dev 3.2.7b contains a segmentation fault in the gencgm_start function in gencgm.c. fig2dev 3.2.7b contains a segmentation fault in the gencgm_start function in gencgm.c.
nvd
CVE-2017-18005P4MEDIUMCVSS 5.5v10.02017-12-31
CVE-2017-18005 [MEDIUM] CWE-476 CVE-2017-18005: Exiv2 0.26 has a Null Pointer Dereference in the Exiv2::DataValue::toLong function in value.cpp, rel Exiv2 0.26 has a Null Pointer Dereference in the Exiv2::DataValue::toLong function in value.cpp, related to crafted metadata in a TIFF file.
nvd
CVE-2020-15569P4MEDIUMCVSS 5.5v9.02020-07-06
CVE-2020-15569 [MEDIUM] CWE-416 CVE-2020-15569: PlayerGeneric.cpp in MilkyTracker through 1.02.00 has a use-after-free in the PlayerGeneric destruct PlayerGeneric.cpp in MilkyTracker through 1.02.00 has a use-after-free in the PlayerGeneric destructor.
nvd
CVE-2017-14926P4MEDIUMCVSS 5.5v9.02017-09-30
CVE-2017-14926 [MEDIUM] CWE-476 CVE-2017-14926: In Poppler 0.59.0, a NULL Pointer Dereference exists in AnnotRichMedia::Content::Content in Annot.cc In Poppler 0.59.0, a NULL Pointer Dereference exists in AnnotRichMedia::Content::Content in Annot.cc via a crafted PDF document.
nvd
CVE-2017-14928P4MEDIUMCVSS 5.5v9.02017-09-30
CVE-2017-14928 [MEDIUM] CWE-476 CVE-2017-14928: In Poppler 0.59.0, a NULL Pointer Dereference exists in AnnotRichMedia::Configuration::Configuration In Poppler 0.59.0, a NULL Pointer Dereference exists in AnnotRichMedia::Configuration::Configuration in Annot.cc via a crafted PDF document.
nvd
CVE-2007-6716P4MEDIUMCVSS 5.5v4.02008-09-04
CVE-2007-6716 [MEDIUM] CVE-2007-6716: fs/direct-io.c in the dio subsystem in the Linux kernel before 2.6.23 does not properly zero out the fs/direct-io.c in the dio subsystem in the Linux kernel before 2.6.23 does not properly zero out the dio struct, which allows local users to cause a denial of service (OOPS), as demonstrated by a certain fio test.
nvd
CVE-2019-3832P4MEDIUMCVSS 5.5v9.02019-03-21
CVE-2019-3832 [MEDIUM] CVE-2019-3832: It was discovered the fix for CVE-2018-19758 (libsndfile) was not complete and still allows a read b It was discovered the fix for CVE-2018-19758 (libsndfile) was not complete and still allows a read beyond the limits of a buffer in wav_write_header() function in wav.c. A local attacker may use this flaw to make the application crash.
nvd
CVE-2000-0314P4MEDIUMCVSS 5.0v2.0.342001-03-12
CVE-2000-0314 [MEDIUM] CVE-2000-0314: traceroute in NetBSD 1.3.3 and Linux systems allows local users to flood other systems by providing traceroute in NetBSD 1.3.3 and Linux systems allows local users to flood other systems by providing traceroute with a large waittime (-w) option, which is not parsed properly and sets the time delay for sending packets to zero.
nvd
CVE-2017-18043P4MEDIUMCVSS 5.5v9.02018-01-31
CVE-2017-18043 [MEDIUM] CWE-190 CVE-2017-18043: Integer overflow in the macro ROUND_UP (n, d) in Quick Emulator (Qemu) allows a user to cause a deni Integer overflow in the macro ROUND_UP (n, d) in Quick Emulator (Qemu) allows a user to cause a denial of service (Qemu process crash).
nvd
CVE-2016-0609P4LOWCVSS 1.7v8.02016-01-21
CVE-2016-0609 [LOW] CVE-2016-0609: Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and Mari Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via unknown vectors related to privileges.
nvd
CVE-2004-1090P4MEDIUMCVSS 5.0v3.02005-04-14
CVE-2004-1090 [MEDIUM] CVE-2004-1090: Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service via Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service via "a corrupt section header."
nvd
CVE-2001-0457P4MEDIUMCVSS 5.0v2.22001-06-27
CVE-2001-0457 [MEDIUM] CVE-2001-0457: man2html before 1.5-22 allows remote attackers to cause a denial of service (memory exhaustion). man2html before 1.5-22 allows remote attackers to cause a denial of service (memory exhaustion).
nvd
CVE-2022-38850P4MEDIUMCVSS 5.5v10.02022-09-15
CVE-2022-38850 [MEDIUM] CWE-369 CVE-2022-38850: The MPlayer Project mencoder SVN-r38374-13.0.1 is vulnerable to Divide By Zero via the function conf The MPlayer Project mencoder SVN-r38374-13.0.1 is vulnerable to Divide By Zero via the function config () of llibmpcodecs/vf_scale.c.
nvd
CVE-2019-14562P4MEDIUMCVSS 5.5v9.02020-11-23
CVE-2019-14562 [MEDIUM] CWE-190 CVE-2019-14562: Integer overflow in DxeImageVerificationHandler() EDK II may allow an authenticated user to potentia Integer overflow in DxeImageVerificationHandler() EDK II may allow an authenticated user to potentially enable denial of service via local access.
nvd
CVE-2008-1567P4MEDIUMCVSS 5.5v4.02008-03-31
CVE-2008-1567 [MEDIUM] CWE-312 CVE-2008-1567: phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secr phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secret key, in cleartext in a Session file under /tmp, which allows local users to obtain sensitive information.
nvd
CVE-2024-27076P4MEDIUMCVSS 5.5v10.02024-05-01
CVE-2024-27076 [MEDIUM] CWE-401 CVE-2024-27076: In the Linux kernel, the following vulnerability has been resolved: media: imx: csc/scaler: fix v4l In the Linux kernel, the following vulnerability has been resolved: media: imx: csc/scaler: fix v4l2_ctrl_handler memory leak Free the memory allocated in v4l2_ctrl_handler_init on release.
nvd
CVE-2025-37788P4MEDIUMCVSS 5.5v11.02025-05-01
CVE-2025-37788 [MEDIUM] CWE-401 CVE-2025-37788: In the Linux kernel, the following vulnerability has been resolved: cxgb4: fix memory leak in cxgb4 In the Linux kernel, the following vulnerability has been resolved: cxgb4: fix memory leak in cxgb4_init_ethtool_filters() error path In the for loop used to allocate the loc_array and bmap for each port, a memory leak is possible when the allocation for loc_array succeeds, but the allocation for bmap fails. This is because when the control flow go
nvd
CVE-2025-38612P4MEDIUMCVSS 5.5v11.02025-08-19
CVE-2025-38612 [MEDIUM] CWE-401 CVE-2025-38612: In the Linux kernel, the following vulnerability has been resolved: staging: fbtft: fix potential m In the Linux kernel, the following vulnerability has been resolved: staging: fbtft: fix potential memory leak in fbtft_framebuffer_alloc() In the error paths after fb_info structure is successfully allocated, the memory allocated in fb_deferred_io_init() for info->pagerefs is not freed. Fix that by adding the cleanup function on the error path.
nvd
Debian Linux vulnerabilities | cvebase