cbcvebase.

Debian Linux vulnerabilities

9,953 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358

Vulnerabilities

Page 85 of 498
CVE-2022-22825P3HIGHCVSS 8.8v10.0v11.02022-01-10
CVE-2022-22825 [HIGH] CWE-190 CVE-2022-22825: lookup in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. lookup in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
nvd
CVE-2022-35255P3CRITICALCVSS 9.1v11.02022-12-05
CVE-2022-35255 [CRITICAL] CWE-338 CVE-2022-35255: A weak randomness in WebCrypto keygen vulnerability exists in Node.js 18 due to a change with Entrop A weak randomness in WebCrypto keygen vulnerability exists in Node.js 18 due to a change with EntropySource() in SecretKeyGenTraits::DoKeyGen() in src/crypto/crypto_keygen.cc. There are two problems with this: 1) It does not check the return value, it assumes EntropySource() always succeeds, but it can (and sometimes will) fail. 2) The random data
nvd
CVE-2021-41182P3MEDIUMCVSS 6.1v9.02021-10-26
CVE-2021-41182 [MEDIUM] CWE-79 CVE-2021-41182: jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the valu jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `altField` option is now treated as a CSS selector. A workaround is to not acc
nvd
CVE-2014-9906P3CRITICALCVSS 9.8v8.02016-08-19
CVE-2014-9906 [CRITICAL] CWE-416 CVE-2014-9906: Use-after-free vulnerability in DBD::mysql before 4.029 allows attackers to cause a denial of servic Use-after-free vulnerability in DBD::mysql before 4.029 allows attackers to cause a denial of service (program crash) or possibly execute arbitrary code via vectors related to a lost server connection.
nvd
CVE-2018-6120P3HIGHCVSS 8.8v9.02019-01-09
CVE-2018-6120 [HIGH] CWE-190 CVE-2018-6120: An integer overflow that could lead to an attacker-controlled heap out-of-bounds write in PDFium in An integer overflow that could lead to an attacker-controlled heap out-of-bounds write in PDFium in Google Chrome prior to 66.0.3359.170 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file.
nvd
CVE-2018-6088P3HIGHCVSS 8.8v8.0v9.02018-12-04
CVE-2018-6088 [HIGH] CWE-20 CVE-2018-6088: An iterator-invalidation bug in PDFium in Google Chrome prior to 66.0.3359.117 allowed a remote atta An iterator-invalidation bug in PDFium in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file.
nvd
CVE-2021-21772P3HIGHCVSS 8.1v10.02021-03-10
CVE-2021-21772 [HIGH] CWE-416 CVE-2021-21772: A use-after-free vulnerability exists in the NMR::COpcPackageReader::releaseZIP() functionality of 3 A use-after-free vulnerability exists in the NMR::COpcPackageReader::releaseZIP() functionality of 3MF Consortium lib3mf 2.0.0. A specially crafted 3MF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
nvd
CVE-2020-26116P3HIGHCVSS 7.2v9.02020-09-27
CVE-2020-26116 [HIGH] CWE-74 CVE-2020-26116: http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3 http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of HTTPConnection.request.
nvd
CVE-2017-12375P3HIGHCVSS 7.5v7.02018-01-26
CVE-2017-12375 [HIGH] CWE-119 CVE-2017-12375: The ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an The ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a lack of input validation checking mechanisms during certain mail parsing functions (the rfc2047 function in mbox.c). An una
nvd
CVE-2020-28623P3HIGHCVSS 8.8v10.02022-04-18
CVE-2020-28623 [HIGH] CWE-129 CVE-2020-28623: Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libc Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lead to code execution. An attacker can provide malicious input to trigger any of these vulnerabilities. An oob read vulnerability exist
nvd
CVE-2020-28617P3HIGHCVSS 8.8v10.02022-04-18
CVE-2020-28617 [HIGH] CWE-129 CVE-2020-28617: Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libc Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lead to code execution. An attacker can provide malicious input to trigger any of these vulnerabilities. An oob read vulnerability exist
nvd
CVE-2020-28622P3HIGHCVSS 8.8v10.02022-04-18
CVE-2020-28622 [HIGH] CWE-129 CVE-2020-28622: Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libc Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lead to code execution. An attacker can provide malicious input to trigger any of these vulnerabilities. An oob read vulnerability exist
nvd
CVE-2020-28605P3HIGHCVSS 8.8v10.02022-04-18
CVE-2020-28605 [HIGH] CWE-129 CVE-2020-28605: Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libc Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lead to code execution. An attacker can provide malicious input to trigger any of these vulnerabilities. An oob read exists in Nef_2/PM_
nvd
CVE-2020-28628P3HIGHCVSS 8.8v10.02022-04-18
CVE-2020-28628 [HIGH] CWE-129 CVE-2020-28628: Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libc Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lead to code execution. An attacker can provide malicious input to trigger any of these vulnerabilities. An oob read vulnerability exist
nvd
CVE-2020-28613P3HIGHCVSS 8.8v10.02022-04-18
CVE-2020-28613 [HIGH] CWE-129 CVE-2020-28613: Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libc Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lead to code execution. An attacker can provide malicious input to trigger any of these vulnerabilities. An oob read vulnerability exist
nvd
CVE-2020-28616P3HIGHCVSS 8.8v10.02022-04-18
CVE-2020-28616 [HIGH] CWE-129 CVE-2020-28616: Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libc Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lead to code execution. An attacker can provide malicious input to trigger any of these vulnerabilities. An oob read vulnerability exist
nvd
CVE-2020-28615P3HIGHCVSS 8.8v10.02022-04-18
CVE-2020-28615 [HIGH] CWE-129 CVE-2020-28615: Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libc Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lead to code execution. An attacker can provide malicious input to trigger any of these vulnerabilities. An oob read vulnerability exist
nvd
CVE-2020-28620P3HIGHCVSS 8.8v10.02022-04-18
CVE-2020-28620 [HIGH] CWE-129 CVE-2020-28620: Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libc Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lead to code execution. An attacker can provide malicious input to trigger any of these vulnerabilities. An oob read vulnerability exist
nvd
CVE-2020-28619P3HIGHCVSS 8.8v10.02022-04-18
CVE-2020-28619 [HIGH] CWE-129 CVE-2020-28619: Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libc Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lead to code execution. An attacker can provide malicious input to trigger any of these vulnerabilities. An oob read vulnerability exist
nvd
CVE-2020-28621P3HIGHCVSS 8.8v10.02022-04-18
CVE-2020-28621 [HIGH] CWE-129 CVE-2020-28621: Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libc Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lead to code execution. An attacker can provide malicious input to trigger any of these vulnerabilities. An oob read vulnerability exist
nvd
Debian Linux vulnerabilities | cvebase