Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 88 of 498
CVE-2014-0452P3HIGHCVSS 7.5v6.0v7.0+1 more2014-04-16
CVE-2014-0452 [HIGH] CVE-2014-0452: Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows rem
Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JAX-WS, a different vulnerability than CVE-2014-0458 and CVE-2014-2423.
nvd
CVE-2014-2423P3HIGHCVSS 7.5v6.0v7.0+1 more2014-04-16
CVE-2014-2423 [HIGH] CVE-2014-2423: Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows rem
Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JAX-WS, a different vulnerability than CVE-2014-0452 and CVE-2014-0458.
nvd
CVE-2020-15969P3HIGHCVSS 8.8v10.02020-11-03
CVE-2020-15969 [HIGH] CWE-416 CVE-2020-15969: Use after free in WebRTC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potenti
Use after free in WebRTC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-21848P3HIGHCVSS 8.8v10.0v11.02021-08-25
CVE-2021-21848 [HIGH] CWE-680 CVE-2021-21848: An exploitable integer overflow vulnerability exists within the MPEG-4 decoding functionality of the
An exploitable integer overflow vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. The library will actually reuse the parser for atoms with the “stsz” FOURCC code when parsing atoms that use the “stz2” FOURCC code and can cause an integer overflow due to unchecked arithmetic resulting
nvd
CVE-2021-21858P3HIGHCVSS 8.8v10.0v11.02021-08-18
CVE-2021-21858 [HIGH] CWE-680 CVE-2021-21858: Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality
Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow due to unchecked addition arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convinc
nvd
CVE-2021-21853P3HIGHCVSS 8.8v10.0v11.02021-08-18
CVE-2021-21853 [HIGH] CWE-680 CVE-2021-21853: Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality
Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow due to unchecked addition arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convinc
nvd
CVE-2018-15688P3HIGHCVSS 8.8v8.02018-10-26
CVE-2018-15688 [HIGH] CWE-120 CVE-2018-15688: A buffer overflow vulnerability in the dhcp6 client of systemd allows a malicious dhcp6 server to ov
A buffer overflow vulnerability in the dhcp6 client of systemd allows a malicious dhcp6 server to overwrite heap memory in systemd-networkd. Affected releases are systemd: versions up to and including 239.
nvd
CVE-2021-21855P3HIGHCVSS 8.8v10.0v11.02021-08-18
CVE-2021-21855 [HIGH] CWE-680 CVE-2021-21855: Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality
Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow due to unchecked addition arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convinc
nvd
CVE-2021-21857P3HIGHCVSS 8.8v10.0v11.02021-08-18
CVE-2021-21857 [HIGH] CWE-680 CVE-2021-21857: Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality
Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow due to unchecked addition arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convinc
nvd
CVE-2021-21854P3HIGHCVSS 8.8v10.0v11.02021-08-18
CVE-2021-21854 [HIGH] CWE-680 CVE-2021-21854: Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality
Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow due to unchecked addition arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convinc
nvd
CVE-2016-7568P3CRITICALCVSS 9.8v8.02016-09-28
CVE-2016-7568 [CRITICAL] CWE-190 CVE-2016-7568: Integer overflow in the gdImageWebpCtx function in gd_webp.c in the GD Graphics Library (aka libgd)
Integer overflow in the gdImageWebpCtx function in gd_webp.c in the GD Graphics Library (aka libgd) through 2.2.3, as used in PHP through 7.0.11, allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted imagewebp and imagedestroy calls.
nvd
CVE-2022-23483P3CRITICALCVSS 9.1v11.02022-12-09
CVE-2022-23483 [CRITICAL] CWE-125 CVE-2022-23483: xrdp is an open source project which provides a graphical login to remote machines using Microsoft R
xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP).
xrdp < v0.9.21 contain a Out of Bound Read in libxrdp_send_to_channel() function. There are no known workarounds for this issue. Users are advised to upgrade.
nvd
CVE-2024-5197P3CRITICALCVSS 9.1v10.02024-06-03
CVE-2024-5197 [CRITICAL] CWE-190 CVE-2024-5197: There exists interger overflows in libvpx in versions prior to 1.14.1. Calling vpx_img_alloc() with
There exists interger overflows in libvpx in versions prior to 1.14.1. Calling vpx_img_alloc() with a large value of the d_w, d_h, or align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. Calling vpx_img_wrap() with a large value of the d_w, d
nvd
CVE-2020-6537P3HIGHCVSS 8.8v10.02020-09-21
CVE-2020-6537 [HIGH] CWE-843 CVE-2020-6537: Type confusion in V8 in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to execute ar
Type confusion in V8 in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
nvd
CVE-2022-23481P3CRITICALCVSS 9.1v11.02022-12-09
CVE-2022-23481 [CRITICAL] CWE-125 CVE-2022-23481: xrdp is an open source project which provides a graphical login to remote machines using Microsoft R
xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP).
xrdp < v0.9.21 contain a Out of Bound Read in xrdp_caps_process_confirm_active() function. There are no known workarounds for this issue. Users are advised to upgrade.
nvd
CVE-2022-23482P3CRITICALCVSS 9.1v11.02022-12-09
CVE-2022-23482 [CRITICAL] CWE-125 CVE-2022-23482: xrdp is an open source project which provides a graphical login to remote machines using Microsoft R
xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP).
xrdp < v0.9.21 contain a Out of Bound Read in xrdp_sec_process_mcs_data_CS_CORE() function. There are no known workarounds for this issue. Users are advised to upgrade.
nvd
CVE-2016-2374P3HIGHCVSS 8.1v8.02017-01-06
CVE-2016-2374 [HIGH] CWE-125 CVE-2016-2374: An exploitable memory corruption vulnerability exists in the handling of the MXIT protocol in Pidgin
An exploitable memory corruption vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT MultiMX message sent via the server can result in an out-of-bounds write leading to memory disclosure and code execution.
nvd
CVE-2019-8922P3HIGHCVSS 8.8v10.02021-11-29
CVE-2019-8922 [HIGH] CWE-787 CVE-2019-8922: A heap-based buffer overflow was discovered in bluetoothd in BlueZ through 5.48. There isn't any che
A heap-based buffer overflow was discovered in bluetoothd in BlueZ through 5.48. There isn't any check on whether there is enough space in the destination buffer. The function simply appends all data passed to it. The values of all attributes that are requested are appended to the output buffer. There are no size checks whatsoever, resulting in a simple
nvd
CVE-2016-2371P3HIGHCVSS 8.1v8.02017-01-06
CVE-2016-2371 [HIGH] CWE-787 CVE-2016-2371: An out-of-bounds write vulnerability exists in the handling of the MXIT protocol in Pidgin. Speciall
An out-of-bounds write vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could cause memory corruption resulting in code execution.
nvd
CVE-2022-26110P3HIGHCVSS 8.8v9.0v10.02022-04-06
CVE-2022-26110 [HIGH] CVE-2022-26110: An issue was discovered in HTCondor 8.8.x before 8.8.16, 9.0.x before 9.0.10, and 9.1.x before 9.6.0
An issue was discovered in HTCondor 8.8.x before 8.8.16, 9.0.x before 9.0.10, and 9.1.x before 9.6.0. When a user authenticates to an HTCondor daemon via the CLAIMTOBE method, the user can then impersonate any entity when issuing additional commands to that daemon.
nvd