cbcvebase.

Debian Linux vulnerabilities

9,956 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,956
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4169MEDIUM4296LOW358

Vulnerabilities

Page 478 of 498
CVE-2021-36053P4LOWCVSS 3.3v10.02021-09-01
CVE-2021-36053 [LOW] CWE-125 CVE-2021-36053: XMP Toolkit SDK versions 2020.1 (and earlier) are affected by an out-of-bounds read vulnerability th XMP Toolkit SDK versions 2020.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of arbitrary memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2021-36045P4LOWCVSS 3.3v10.02021-09-01
CVE-2021-36045 [LOW] CWE-125 CVE-2021-36045: XMP Toolkit SDK versions 2020.1 (and earlier) are affected by an out-of-bounds read vulnerability th XMP Toolkit SDK versions 2020.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of arbitrary memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2020-16116P4LOWCVSS 3.3v9.0v10.02020-08-03
CVE-2020-16116 [LOW] CWE-22 CVE-2020-16116: In kerfuffle/jobs.cpp in KDE Ark before 20.08.0, a crafted archive can install files outside the ext In kerfuffle/jobs.cpp in KDE Ark before 20.08.0, a crafted archive can install files outside the extraction directory via ../ directory traversal.
nvd
CVE-2018-20199P4MEDIUMCVSS 5.5v8.0v9.0+1 more2018-12-18
CVE-2018-20199 [MEDIUM] CWE-476 CVE-2018-20199: A NULL pointer dereference was discovered in ifilter_bank of libfaad/filtbank.c in Freeware Advanced A NULL pointer dereference was discovered in ifilter_bank of libfaad/filtbank.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash, which leads to denial of service because adding to windowed output is mishandled in the ONLY_LONG_SEQUENCE case.
nvd
CVE-2017-14862P4MEDIUMCVSS 5.5v10.02017-09-29
CVE-2017-14862 [MEDIUM] CWE-119 CVE-2017-14862: An Invalid memory address dereference was discovered in Exiv2::DataValue::read in value.cpp in Exiv2 An Invalid memory address dereference was discovered in Exiv2::DataValue::read in value.cpp in Exiv2 0.26. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.
nvd
CVE-2017-14864P4MEDIUMCVSS 5.5v10.02017-09-29
CVE-2017-14864 [MEDIUM] CWE-119 CVE-2017-14864: An Invalid memory address dereference was discovered in Exiv2::getULong in types.cpp in Exiv2 0.26. An Invalid memory address dereference was discovered in Exiv2::getULong in types.cpp in Exiv2 0.26. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.
nvd
CVE-2017-14859P4MEDIUMCVSS 5.5v10.02017-09-29
CVE-2017-14859 [MEDIUM] CWE-119 CVE-2017-14859: An Invalid memory address dereference was discovered in Exiv2::StringValueBase::read in value.cpp in An Invalid memory address dereference was discovered in Exiv2::StringValueBase::read in value.cpp in Exiv2 0.26. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.
nvd
CVE-2017-11733P4MEDIUMCVSS 5.5v7.02017-07-29
CVE-2017-11733 [MEDIUM] CWE-476 CVE-2017-11733: A null pointer dereference vulnerability was found in the function stackswap (called from decompileS A null pointer dereference vulnerability was found in the function stackswap (called from decompileSTACKSWAP) in util/decompile.c in Ming 0.4.8, which allows attackers to cause a denial of service via a crafted file.
nvd
CVE-2006-6499P4MEDIUMCVSS 4.3v3.1v4.02006-12-20
CVE-2006-6499 [MEDIUM] CWE-835 CVE-2006-6499: The js_dtoa function in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before The js_dtoa function in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 overwrites memory instead of exiting when the floating point precision is reduced, which allows remote attackers to cause a denial of service via any plugins that reduce the precision.
nvd
CVE-2021-27345P4MEDIUMCVSS 5.5v9.02021-06-10
CVE-2021-27345 [MEDIUM] CWE-476 CVE-2021-27345: A null pointer dereference was discovered in ucompthread in stream.c in Irzip 0.631 which allows att A null pointer dereference was discovered in ucompthread in stream.c in Irzip 0.631 which allows attackers to cause a denial of service (DOS) via a crafted compressed file.
nvd
CVE-2015-4792P4LOWCVSS 1.7v7.0v8.02015-10-21
CVE-2015-4792 [LOW] CVE-2015-4792: Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows re Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Partition, a different vulnerability than CVE-2015-4802.
nvd
CVE-2019-9704P4MEDIUMCVSS 5.5v8.0v9.02019-03-12
CVE-2019-9704 [MEDIUM] CWE-252 CVE-2019-9704: Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (dae Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (daemon crash) via a large crontab file because the calloc return value is not checked.
nvd
CVE-2011-0779P4MEDIUMCVSS 5.0v6.0v7.02011-02-04
CVE-2011-0779 [MEDIUM] CWE-20 CVE-2011-0779: Google Chrome before 9.0.597.84 does not properly handle a missing key in an extension, which allows Google Chrome before 9.0.597.84 does not properly handle a missing key in an extension, which allows remote attackers to cause a denial of service (application crash) via a crafted extension.
nvd
CVE-2025-37982P4MEDIUMCVSS 5.5v11.02025-05-20
CVE-2025-37982 [MEDIUM] CWE-401 CVE-2025-37982: In the Linux kernel, the following vulnerability has been resolved: wifi: wl1251: fix memory leak i In the Linux kernel, the following vulnerability has been resolved: wifi: wl1251: fix memory leak in wl1251_tx_work The skb dequeued from tx_queue is lost when wl1251_ps_elp_wakeup fails with a -ETIMEDOUT error. Fix that by queueing the skb back to tx_queue.
nvd
CVE-2025-38015P4MEDIUMCVSS 5.5v11.02025-06-18
CVE-2025-38015 [MEDIUM] CWE-401 CVE-2025-38015: In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix memory lea In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix memory leak in error handling path of idxd_alloc Memory allocated for idxd is not freed if an error occurs during idxd_alloc(). To fix it, free the allocated memory in the reverse order of allocation before exiting the function in case of an error.
nvd
CVE-2010-4008P4MEDIUMCVSS 4.3v5.0v6.02010-11-17
CVE-2010-4008 [MEDIUM] CWE-119 CVE-2010-4008: libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, an libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows context-dependent attackers to cause a denial of service (application crash) via a crafted XML document.
nvd
CVE-2008-5019P4MEDIUMCVSS 4.3v4.02008-11-13
CVE-2008-5019 [MEDIUM] CWE-79 CVE-2008-5019: The session restore feature in Mozilla Firefox 3.x before 3.0.4 and 2.x before 2.0.0.18 allows remot The session restore feature in Mozilla Firefox 3.x before 3.0.4 and 2.x before 2.0.0.18 allows remote attackers to violate the same origin policy to conduct cross-site scripting (XSS) attacks and execute arbitrary JavaScript with chrome privileges via unknown vectors.
nvd
CVE-2019-2983P4LOWCVSS 3.7v8.0v9.0+1 more2019-10-16
CVE-2019-2983 [LOW] CVE-2019-2983: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successf
nvd
CVE-2019-2981P4LOWCVSS 3.7v8.0v9.0+1 more2019-10-16
CVE-2019-2981 [LOW] CVE-2019-2981: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JAXP). Supporte Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JAXP). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attack
nvd
CVE-2018-3139P4LOWCVSS 3.1v8.0v9.02018-10-17
CVE-2018-3139 [LOW] CVE-2018-3139: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u201, 7u191, 8u182 and 11; Java SE Embedded: 8u181. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Success
nvd
Debian Linux vulnerabilities | cvebase