cbcvebase.

Debian Linux vulnerabilities

9,953 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358

Vulnerabilities

Page 71 of 498
CVE-2017-5121P3HIGHCVSS 8.8v9.0v10.02017-10-27
CVE-2017-5121 [HIGH] CWE-20 CVE-2017-5121: Inappropriate use of JIT optimisation in V8 in Google Chrome prior to 61.0.3163.100 for Linux, Windo Inappropriate use of JIT optimisation in V8 in Google Chrome prior to 61.0.3163.100 for Linux, Windows, and Mac allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page, related to the escape analysis phase.
nvd
CVE-2020-17353P3CRITICALCVSS 9.8v10.02020-08-05
CVE-2020-17353 [CRITICAL] CVE-2020-17353: scm/define-stencil-commands.scm in LilyPond through 2.20.0, and 2.21.x through 2.21.4, when -dsafe i scm/define-stencil-commands.scm in LilyPond through 2.20.0, and 2.21.x through 2.21.4, when -dsafe is used, lacks restrictions on embedded-ps and embedded-svg, as demonstrated by including dangerous PostScript code.
nvd
CVE-2021-21215P3MEDIUMCVSS 6.5v10.02021-04-26
CVE-2021-21215 [MEDIUM] CWE-290 CVE-2021-21215: Inappropriate implementation in Autofill in Google Chrome prior to 90.0.4430.72 allowed a remote att Inappropriate implementation in Autofill in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to spoof security UI via a crafted HTML page.
nvd
CVE-2013-6435P3HIGHCVSS 7.6v7.02014-12-16
CVE-2013-6435 [HIGH] CWE-74 CVE-2013-6435: Race condition in RPM 4.11.1 and earlier allows remote attackers to execute arbitrary code via a cra Race condition in RPM 4.11.1 and earlier allows remote attackers to execute arbitrary code via a crafted RPM file whose installation extracts the contents to temporary files before validating the signature, as demonstrated by installing a file in the /etc/cron.d directory.
nvd
CVE-2012-6094P3CRITICALCVSS 9.8v8.0v9.0+1 more2019-12-20
CVE-2012-6094 [CRITICAL] CWE-863 CVE-2012-6094: cups (Common Unix Printing System) 'Listen localhost:631' option not honored correctly which could p cups (Common Unix Printing System) 'Listen localhost:631' option not honored correctly which could provide unauthorized access to the system
nvd
CVE-2019-25034P3CRITICALCVSS 9.8v9.02021-04-27
CVE-2019-25034 [CRITICAL] CWE-190 CVE-2019-25034: Unbound before 1.9.5 allows an integer overflow in sldns_str2wire_dname_buf_origin, leading to an ou Unbound before 1.9.5 allows an integer overflow in sldns_str2wire_dname_buf_origin, leading to an out-of-bounds write. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
nvd
CVE-2019-25042P3CRITICALCVSS 9.8v9.02021-04-27
CVE-2019-25042 [CRITICAL] CWE-787 CVE-2019-25042: Unbound before 1.9.5 allows an out-of-bounds write via a compressed name in rdata_copy. NOTE: The ve Unbound before 1.9.5 allows an out-of-bounds write via a compressed name in rdata_copy. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
nvd
CVE-2019-25035P3CRITICALCVSS 9.8v9.02021-04-27
CVE-2019-25035 [CRITICAL] CWE-787 CVE-2019-25035: Unbound before 1.9.5 allows an out-of-bounds write in sldns_bget_token_par. NOTE: The vendor dispute Unbound before 1.9.5 allows an out-of-bounds write in sldns_bget_token_par. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
nvd
CVE-2001-0136P4MEDIUMCVSS 5.0PoCv2.22001-03-12
CVE-2001-0136 [MEDIUM] CWE-401 CVE-2001-0136: Memory leak in ProFTPd 1.2.0rc2 allows remote attackers to cause a denial of service via a series of Memory leak in ProFTPd 1.2.0rc2 allows remote attackers to cause a denial of service via a series of USER commands, and possibly SIZE commands if the server has been improperly installed.
nvd
CVE-2021-44538P3CRITICALCVSS 9.8v9.0v10.0+1 more2021-12-14
CVE-2021-44538 [CRITICAL] CWE-119 CVE-2021-44538: The olm_session_describe function in Matrix libolm before 3.2.7 is vulnerable to a buffer overflow. The olm_session_describe function in Matrix libolm before 3.2.7 is vulnerable to a buffer overflow. The Olm session object represents a cryptographic channel between two parties. Therefore, its state is partially controllable by the remote party of the channel. Attackers can construct a crafted sequence of messages to manipulate the state of the re
nvd
CVE-2018-2633P3HIGHCVSS 8.3v7.0v8.0+1 more2018-01-18
CVE-2018-2633 [HIGH] CVE-2018-2633: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: J Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JNDI). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE,
nvd
CVE-2022-24786P3CRITICALCVSS 9.8v9.0v10.02022-04-06
CVE-2022-24786 [CRITICAL] CWE-125 CVE-2022-24786: PJSIP is a free and open source multimedia communication library written in C. PJSIP versions 2.12 a PJSIP is a free and open source multimedia communication library written in C. PJSIP versions 2.12 and prior do not parse incoming RTCP feedback RPSI (Reference Picture Selection Indication) packet, but any app that directly uses pjmedia_rtcp_fb_parse_rpsi() will be affected. A patch is available in the `master` branch of the `pjsip/pjproject` Git
nvd
CVE-2022-41794P3CRITICALCVSS 9.8v11.02022-12-22
CVE-2022-41794 [CRITICAL] CWE-122 CVE-2022-41794: A heap based buffer overflow vulnerability exists in the PSD thumbnail resource parsing code of Open A heap based buffer overflow vulnerability exists in the PSD thumbnail resource parsing code of OpenImageIO 2.3.19.0. A specially-crafted PSD file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
nvd
CVE-2018-19409P3CRITICALCVSS 9.8v8.0v9.02018-11-21
CVE-2018-19409 [CRITICAL] CVE-2018-19409: An issue was discovered in Artifex Ghostscript before 9.26. LockSafetyParams is not checked correctl An issue was discovered in Artifex Ghostscript before 9.26. LockSafetyParams is not checked correctly if another device is used.
nvd
CVE-2022-41838P3CRITICALCVSS 9.8v11.02022-12-22
CVE-2022-41838 [CRITICAL] CWE-122 CVE-2022-41838: A code execution vulnerability exists in the DDS scanline parsing functionality of OpenImageIO Proje A code execution vulnerability exists in the DDS scanline parsing functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially-crafted .dds can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
nvd
CVE-2018-1000222P3HIGHCVSS 8.8v8.02018-08-20
CVE-2018-1000222 [HIGH] CWE-415 CVE-2018-1000222: Libgd version 2.2.5 contains a Double Free Vulnerability vulnerability in gdImageBmpPtr Function tha Libgd version 2.2.5 contains a Double Free Vulnerability vulnerability in gdImageBmpPtr Function that can result in Remote Code Execution . This attack appear to be exploitable via Specially Crafted Jpeg Image can trigger double free. This vulnerability appears to have been fixed in after commit ac16bdf2d41724b5a65255d4c28fb0ec46bc42f5.
nvd
CVE-2022-24300P3CRITICALCVSS 9.8v10.0v11.02022-02-02
CVE-2022-24300 [CRITICAL] CVE-2022-24300: Minetest before 5.4.0 allows attackers to add or modify arbitrary meta fields of the same item stack Minetest before 5.4.0 allows attackers to add or modify arbitrary meta fields of the same item stack as saved user input, aka ItemStack meta injection.
nvd
CVE-2017-10111P3CRITICALCVSS 9.6v9.02017-08-08
CVE-2017-10111 [CRITICAL] CVE-2017-10111: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries) Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). The supported version that is affected is Java SE: 8u131; Java SE Embedded: 8u131. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks requ
nvd
CVE-2019-15505P3CRITICALCVSS 9.8v8.02019-08-23
CVE-2019-15505 [CRITICAL] CWE-125 CVE-2019-15505: drivers/media/usb/dvb-usb/technisat-usb2.c in the Linux kernel through 5.2.9 has an out-of-bounds re drivers/media/usb/dvb-usb/technisat-usb2.c in the Linux kernel through 5.2.9 has an out-of-bounds read via crafted USB device traffic (which may be remote via usbip or usbredir).
nvd
CVE-2019-9637P3HIGHCVSS 7.5v8.0v9.02019-03-09
CVE-2019-9637 [HIGH] CWE-264 CVE-2019-9637: An issue was discovered in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. Due to th An issue was discovered in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. Due to the way rename() across filesystems is implemented, it is possible that file being renamed is briefly available with wrong permissions while the rename is ongoing, thus enabling unauthorized users to access the data.
nvd
Debian Linux vulnerabilities | cvebase