Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 87 of 498
CVE-2020-35630P3HIGHCVSS 8.8v10.02022-04-18
CVE-2020-35630 [HIGH] CWE-129 CVE-2020-35630: Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libc
Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lead to code execution. An attacker can provide malicious input to trigger any of these vulnerabilities. An oob read vulnerability exist
nvd
CVE-2020-28602P3HIGHCVSS 8.8v10.02022-04-18
CVE-2020-28602 [HIGH] CWE-129 CVE-2020-28602: Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libc
Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lead to code execution. An attacker can provide malicious input to trigger any of these vulnerabilities. An oob read vulnerability exist
nvd
CVE-2020-28603P3HIGHCVSS 8.8v10.02022-04-18
CVE-2020-28603 [HIGH] CWE-129 CVE-2020-28603: Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libc
Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lead to code execution. An attacker can provide malicious input to trigger any of these vulnerabilities. An oob read vulnerability exist
nvd
CVE-2021-4057P3HIGHCVSS 8.8v10.0v11.02021-12-23
CVE-2021-4057 [HIGH] CWE-416 CVE-2021-4057: Use after free in file API in Google Chrome prior to 96.0.4664.93 allowed a remote attacker who had
Use after free in file API in Google Chrome prior to 96.0.4664.93 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-10673P3HIGHCVSS 8.8v8.02020-03-18
CVE-2020-10673 [HIGH] CWE-502 CVE-2020-10673: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadg
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).
nvd
CVE-2021-21843P3HIGHCVSS 8.8v10.0v11.02021-08-18
CVE-2021-21843 [HIGH] CWE-680 CVE-2021-21843: Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality
Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. After validating the number of r
nvd
CVE-2007-2798P3CRITICALCVSS 9.0v3.1v4.02007-06-26
CVE-2007-2798 [CRITICAL] CWE-787 CVE-2007-2798: Stack-based buffer overflow in the rename_principal_2_svc function in kadmind for MIT Kerberos 1.5.3
Stack-based buffer overflow in the rename_principal_2_svc function in kadmind for MIT Kerberos 1.5.3, 1.6.1, and other versions allows remote authenticated users to execute arbitrary code via a crafted request to rename a principal.
nvd
CVE-2021-21837P3HIGHCVSS 8.8v11.02021-08-18
CVE-2021-21837 [HIGH] CWE-680 CVE-2021-21837: Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality
Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user
nvd
CVE-2021-21845P3HIGHCVSS 8.8v10.0v11.02021-08-18
CVE-2021-21845 [HIGH] CWE-680 CVE-2021-21845: Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality
Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input in “stsc” decoder can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker ca
nvd
CVE-2021-21838P3HIGHCVSS 8.8v10.0v11.02021-08-18
CVE-2021-21838 [HIGH] CWE-680 CVE-2021-21838: Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality
Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user
nvd
CVE-2021-21846P3HIGHCVSS 8.8v10.0v11.02021-08-18
CVE-2021-21846 [HIGH] CWE-680 CVE-2021-21846: Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality
Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input in “stsz” decoder can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker ca
nvd
CVE-2021-21839P3HIGHCVSS 8.8v10.0v11.02021-08-18
CVE-2021-21839 [HIGH] CWE-680 CVE-2021-21839: Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality
Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user
nvd
CVE-2021-21847P3HIGHCVSS 8.8v10.0v11.02021-08-18
CVE-2021-21847 [HIGH] CWE-680 CVE-2021-21847: Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality
Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input in “stts” decoder can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker ca
nvd
CVE-2021-21844P3HIGHCVSS 8.8v10.0v11.02021-08-18
CVE-2021-21844 [HIGH] CWE-680 CVE-2021-21844: Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality
Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input when encountering an atom using the “stco” FOURCC code, can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that ca
nvd
CVE-2009-0385P3CRITICALCVSS 9.3v4.0v5.0+1 more2009-02-02
CVE-2009-0385 [CRITICAL] CVE-2009-0385: Integer signedness error in the fourxm_read_header function in libavformat/4xm.c in FFmpeg before re
Integer signedness error in the fourxm_read_header function in libavformat/4xm.c in FFmpeg before revision 16846 allows remote attackers to execute arbitrary code via a malformed 4X movie file with a large current_track value, which triggers a NULL pointer dereference.
nvd
CVE-2020-15962P3HIGHCVSS 8.8v10.02020-09-21
CVE-2020-15962 [HIGH] CVE-2020-15962: Insufficient policy validation in serial in Google Chrome prior to 85.0.4183.121 allowed a remote at
Insufficient policy validation in serial in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
nvd
CVE-2020-28609P3HIGHCVSS 8.8v10.02022-04-18
CVE-2020-28609 [HIGH] CWE-129 CVE-2020-28609: Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libc
Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lead to code execution. An attacker can provide malicious input to trigger any of these vulnerabilities. An oob read vulnerability exist
nvd
CVE-2001-0279P4HIGHCVSS 7.2PoCv2.22001-05-03
CVE-2001-0279 [HIGH] CVE-2001-0279: Buffer overflow in sudo earlier than 1.6.3p6 allows local users to gain root privileges.
Buffer overflow in sudo earlier than 1.6.3p6 allows local users to gain root privileges.
nvd
CVE-2019-18422P3HIGHCVSS 8.8v9.0v10.02019-10-31
CVE-2019-18422 [HIGH] CWE-732 CVE-2019-18422: An issue was discovered in Xen through 4.12.x allowing ARM guest OS users to cause a denial of servi
An issue was discovered in Xen through 4.12.x allowing ARM guest OS users to cause a denial of service or gain privileges by leveraging the erroneous enabling of interrupts. Interrupts are unconditionally unmasked in exception handlers. When an exception occurs on an ARM system which is handled without changing processor level, some interrupts are unc
nvd
CVE-2014-0458P3HIGHCVSS 7.5v6.0v7.0+1 more2014-04-16
CVE-2014-0458 [HIGH] CVE-2014-0458: Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows rem
Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JAX-WS, a different vulnerability than CVE-2014-0452 and CVE-2014-2423.
nvd