cbcvebase.

Debian Linux vulnerabilities

9,956 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,956
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4169MEDIUM4296LOW358

Vulnerabilities

Page 483 of 498
CVE-2023-24756P4MEDIUMCVSS 5.5v10.02023-03-01
CVE-2023-24756 [MEDIUM] CWE-476 CVE-2023-24756: libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_unweighted_ libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_unweighted_pred_8_sse function at sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.
nvd
CVE-2007-2650P4MEDIUMCVSS 4.3v3.1v4.02007-05-14
CVE-2007-2650 [MEDIUM] CWE-400 CVE-2007-2650: The OLE2 parser in Clam AntiVirus (ClamAV) allows remote attackers to cause a denial of service (res The OLE2 parser in Clam AntiVirus (ClamAV) allows remote attackers to cause a denial of service (resource consumption) via an OLE2 file with (1) a large property size or (2) a loop in the FAT file block chain that triggers an infinite loop, as demonstrated via a crafted DOC file.
nvd
CVE-2016-2391P4MEDIUMCVSS 5.0v8.02016-06-16
CVE-2016-2391 [MEDIUM] CWE-476 CVE-2016-2391: The ohci_bus_start function in the USB OHCI emulation support (hw/usb/hcd-ohci.c) in QEMU allows loc The ohci_bus_start function in the USB OHCI emulation support (hw/usb/hcd-ohci.c) in QEMU allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via vectors related to multiple eof_timers.
nvd
CVE-2018-2790P4LOWCVSS 3.1v8.0v9.02018-04-19
CVE-2018-2790 [LOW] CVE-2018-2790: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u181, 7u171, 8u162 and 10; Java SE Embedded: 8u161. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successfu
nvd
CVE-2014-3122P4MEDIUMCVSS 4.9v7.02014-05-11
CVE-2014-3122 [MEDIUM] CWE-400 CVE-2014-3122: The try_to_unmap_cluster function in mm/rmap.c in the Linux kernel before 3.14.3 does not properly c The try_to_unmap_cluster function in mm/rmap.c in the Linux kernel before 3.14.3 does not properly consider which pages must be locked, which allows local users to cause a denial of service (system crash) by triggering a memory-usage pattern that requires removal of page-table mappings.
nvd
CVE-2009-0322P4MEDIUMCVSS 4.9v4.0v5.02009-01-28
CVE-2009-0322 [MEDIUM] CWE-189 CVE-2009-0322: drivers/firmware/dell_rbu.c in the Linux kernel before 2.6.27.13, and 2.6.28.x before 2.6.28.2, allo drivers/firmware/dell_rbu.c in the Linux kernel before 2.6.27.13, and 2.6.28.x before 2.6.28.2, allows local users to cause a denial of service (system crash) via a read system call that specifies zero bytes from the (1) image_type or (2) packet_size file in /sys/devices/platform/dell_rbu/.
nvd
CVE-2010-0410P4MEDIUMCVSS 4.9v4.0v5.02010-02-22
CVE-2010-0410 [MEDIUM] CWE-399 CVE-2010-0410: drivers/connector/connector.c in the Linux kernel before 2.6.32.8 allows local users to cause a deni drivers/connector/connector.c in the Linux kernel before 2.6.32.8 allows local users to cause a denial of service (memory consumption and system crash) by sending the kernel many NETLINK_CONNECTOR messages.
nvd
CVE-2010-3880P4MEDIUMCVSS 4.9v5.02010-12-10
CVE-2010-3880 [MEDIUM] CWE-835 CVE-2010-3880: net/ipv4/inet_diag.c in the Linux kernel before 2.6.37-rc2 does not properly audit INET_DIAG bytecod net/ipv4/inet_diag.c in the Linux kernel before 2.6.37-rc2 does not properly audit INET_DIAG bytecode, which allows local users to cause a denial of service (kernel infinite loop) via crafted INET_DIAG_REQ_BYTECODE instructions in a netlink message that contains multiple attribute elements, as demonstrated by INET_DIAG_BC_JMP instructions.
nvd
CVE-2008-2826P4MEDIUMCVSS 4.9v4.02008-07-02
CVE-2008-2826 [MEDIUM] CWE-190 CVE-2008-2826: Integer overflow in the sctp_getsockopt_local_addrs_old function in net/sctp/socket.c in the Stream Integer overflow in the sctp_getsockopt_local_addrs_old function in net/sctp/socket.c in the Stream Control Transmission Protocol (sctp) functionality in the Linux kernel before 2.6.25.9 allows local users to cause a denial of service (resource consumption and system outage) via vectors involving a large addr_num field in an sctp_getaddrs_old data stru
nvd
CVE-2010-1187P4MEDIUMCVSS 4.9v5.02010-03-31
CVE-2010-1187 [MEDIUM] CWE-476 CVE-2010-1187: The Transparent Inter-Process Communication (TIPC) functionality in Linux kernel 2.6.16-rc1 through The Transparent Inter-Process Communication (TIPC) functionality in Linux kernel 2.6.16-rc1 through 2.6.33, and possibly other versions, allows local users to cause a denial of service (kernel OOPS) by sending datagrams through AF_TIPC before entering network mode, which triggers a NULL pointer dereference.
nvd
CVE-2009-2287P4MEDIUMCVSS 4.9v4.0v5.02009-07-01
CVE-2009-2287 [MEDIUM] CWE-476 CVE-2009-2287: The kvm_arch_vcpu_ioctl_set_sregs function in the KVM in Linux kernel 2.6 before 2.6.30, when runnin The kvm_arch_vcpu_ioctl_set_sregs function in the KVM in Linux kernel 2.6 before 2.6.30, when running on x86 systems, does not validate the page table root in a KVM_SET_SREGS call, which allows local users to cause a denial of service (crash or hang) via a crafted cr3 value, which triggers a NULL pointer dereference in the gfn_to_rmap function.
nvd
CVE-2019-2988P4LOWCVSS 3.7v8.0v9.0+1 more2019-10-16
CVE-2019-2988 [LOW] CVE-2019-2988: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks o
nvd
CVE-2019-2978P4LOWCVSS 3.7v8.0v9.0+1 more2019-10-16
CVE-2019-2978 [LOW] CVE-2019-2978: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Su Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful
nvd
CVE-2019-15807P4MEDIUMCVSS 4.7v8.02019-08-29
CVE-2019-15807 [MEDIUM] CWE-401 CVE-2019-15807: In the Linux kernel before 5.1.13, there is a memory leak in drivers/scsi/libsas/sas_expander.c when In the Linux kernel before 5.1.13, there is a memory leak in drivers/scsi/libsas/sas_expander.c when SAS expander discovery fails. This will cause a BUG and denial of service.
nvd
CVE-2019-19056P4MEDIUMCVSS 4.7v8.02019-11-18
CVE-2019-19056 [MEDIUM] CWE-401 CVE-2019-19056: A memory leak in the mwifiex_pcie_alloc_cmdrsp_buf() function in drivers/net/wireless/marvell/mwifie A memory leak in the mwifiex_pcie_alloc_cmdrsp_buf() function in drivers/net/wireless/marvell/mwifiex/pcie.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering mwifiex_map_pci_memory() failures, aka CID-db8fd2cde932.
nvd
CVE-2001-0886P4MEDIUMCVSS 4.6v2.12001-12-21
CVE-2001-0886 [MEDIUM] CVE-2001-0886: Buffer overflow in glob function of glibc allows attackers to cause a denial of service (crash) and Buffer overflow in glob function of glibc allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a glob pattern that ends in a brace "{" character.
nvd
CVE-2005-1111P4MEDIUMCVSS 4.7v3.0v3.12005-05-02
CVE-2005-1111 [MEDIUM] CWE-59 CVE-2005-1111: Race condition in cpio 2.6 and earlier allows local users to modify permissions of arbitrary files v Race condition in cpio 2.6 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by cpio after the decompression is complete.
nvd
CVE-2016-10741P4MEDIUMCVSS 4.7v8.02019-02-01
CVE-2016-10741 [MEDIUM] CWE-362 CVE-2016-10741: In the Linux kernel before 4.9.3, fs/xfs/xfs_aops.c allows local users to cause a denial of service In the Linux kernel before 4.9.3, fs/xfs/xfs_aops.c allows local users to cause a denial of service (system crash) because there is a race condition between direct and memory-mapped I/O (associated with a hole) that is handled with BUG_ON instead of an I/O failure.
nvd
CVE-1999-1048P4MEDIUMCVSS 4.6v1.3.11998-09-05
CVE-1999-1048 [MEDIUM] CVE-1999-1048: Buffer overflow in bash 2.0.0, 1.4.17, and other versions allows local attackers to gain privileges Buffer overflow in bash 2.0.0, 1.4.17, and other versions allows local attackers to gain privileges by creating an extremely large directory name, which is inserted into the password prompt via the \w option in the PS1 environmental variable when another user changes into that directory.
nvd
CVE-2021-29265P4MEDIUMCVSS 4.7v9.02021-03-26
CVE-2021-29265 [MEDIUM] CWE-362 CVE-2021-29265: An issue was discovered in the Linux kernel before 5.11.7. usbip_sockfd_store in drivers/usb/usbip/s An issue was discovered in the Linux kernel before 5.11.7. usbip_sockfd_store in drivers/usb/usbip/stub_dev.c allows attackers to cause a denial of service (GPF) because the stub-up sequence has race conditions during an update of the local and shared status, aka CID-9380afd6df70.
nvd
Debian Linux vulnerabilities | cvebase