cbcvebase.

Debian Linux vulnerabilities

9,953 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358

Vulnerabilities

Page 95 of 498
CVE-2021-21779P3HIGHCVSS 8.8v10.02021-07-08
CVE-2021-21779 [HIGH] CWE-416 CVE-2021-21779: A use-after-free vulnerability exists in the way Webkit’s GraphicsContext handles certain events in A use-after-free vulnerability exists in the way Webkit’s GraphicsContext handles certain events in WebKitGTK 2.30.4. A specially crafted web page can lead to a potential information leak and further memory corruption. A victim must be tricked into visiting a malicious web page to trigger this vulnerability.
nvd
CVE-2015-7974P3HIGHCVSS 7.7v8.0v9.02016-01-26
CVE-2015-7974 [HIGH] CWE-287 CVE-2015-7974: NTP 4.x before 4.2.8p6 and 4.3.x before 4.3.90 do not verify peer associations of symmetric keys whe NTP 4.x before 4.2.8p6 and 4.3.x before 4.3.90 do not verify peer associations of symmetric keys when authenticating packets, which might allow remote attackers to conduct impersonation attacks via an arbitrary trusted key, aka a "skeleton key."
nvd
CVE-2021-21897P3HIGHCVSS 8.8v9.02021-09-08
CVE-2021-21897 [HIGH] CWE-191 CVE-2021-21897: A code execution vulnerability exists in the DL_Dxf::handleLWPolylineData functionality of Ribbonsof A code execution vulnerability exists in the DL_Dxf::handleLWPolylineData functionality of Ribbonsoft dxflib 3.17.0. A specially-crafted .dxf file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
nvd
CVE-2017-13082P3HIGHCVSS 8.1v8.0v9.02017-10-17
CVE-2017-13082 [HIGH] CWE-323 CVE-2017-13082: Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11r allows reinstallation of the Pairwi Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11r allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during the fast BSS transmission (FT) handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames.
nvd
CVE-2022-3890P3CRITICALCVSS 9.6v11.02022-11-09
CVE-2022-3890 [CRITICAL] CWE-787 CVE-2022-3890: Heap buffer overflow in Crashpad in Google Chrome on Android prior to 107.0.5304.106 allowed a remot Heap buffer overflow in Crashpad in Google Chrome on Android prior to 107.0.5304.106 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2018-19541P3HIGHCVSS 8.8v8.02018-11-26
CVE-2018-19541 [HIGH] CWE-125 CVE-2018-19541: An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14 An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20, 1.900.21, 1.900.22, 1.900.23, 1.900.24, 1.900.25, 1.900.26, 1.900.27, 1.900.28, 1.900.29, 1.900.30, 1.900.31, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, 2.0.6, 2.0.7, 2.0.8, 2.0.9, 2.0.10, 2.0
nvd
CVE-2020-6517P3HIGHCVSS 8.8v10.02020-07-22
CVE-2020-6517 [HIGH] CWE-787 CVE-2020-6517: Heap buffer overflow in history in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to Heap buffer overflow in history in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2018-3169P3HIGHCVSS 8.3v8.0v9.02018-10-17
CVE-2018-3169 [HIGH] CVE-2018-3169: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are affected are Java SE: 7u191, 8u182 and 11; Java SE Embedded: 8u181. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attack
nvd
CVE-2020-6523P3HIGHCVSS 8.8v10.02020-07-22
CVE-2020-6523 [HIGH] CWE-190 CVE-2020-6523: Out of bounds write in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to pote Out of bounds write in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6520P3HIGHCVSS 8.8v10.02020-07-22
CVE-2020-6520 [HIGH] CWE-787 CVE-2020-6520: Buffer overflow in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentia Buffer overflow in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2017-14441P3HIGHCVSS 8.8v7.0v8.0+1 more2018-04-24
CVE-2017-14441 [HIGH] CWE-190 CVE-2017-14441: An exploitable code execution vulnerability exists in the ICO image rendering functionality of SDL2_ An exploitable code execution vulnerability exists in the ICO image rendering functionality of SDL2_image-2.0.2. A specially crafted ICO image can cause an integer overflow, cascading to a heap overflow resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability.
nvd
CVE-2017-2887P3HIGHCVSS 8.8v8.0v9.02017-10-11
CVE-2017-2887 [HIGH] CWE-787 CVE-2017-2887: An exploitable buffer overflow vulnerability exists in the XCF property handling functionality of SD An exploitable buffer overflow vulnerability exists in the XCF property handling functionality of SDL_image 2.0.1. A specially crafted xcf file can cause a stack-based buffer overflow resulting in potential code execution. An attacker can provide a specially crafted XCF file to trigger this vulnerability.
nvd
CVE-2016-3105P3HIGHCVSS 8.8v8.02016-05-09
CVE-2016-3105 [HIGH] CWE-284 CVE-2016-3105: The convert extension in Mercurial before 3.8 might allow context-dependent attackers to execute arb The convert extension in Mercurial before 3.8 might allow context-dependent attackers to execute arbitrary code via a crafted git repository name.
nvd
CVE-2018-6111P3HIGHCVSS 8.8v9.02019-01-09
CVE-2018-6111 [HIGH] CWE-20 CVE-2018-6111: An object lifetime issue in the developer tools network handler in Google Chrome prior to 66.0.3359. An object lifetime issue in the developer tools network handler in Google Chrome prior to 66.0.3359.117 allowed a local attacker to execute arbitrary code via a crafted HTML page.
nvd
CVE-2020-6548P3HIGHCVSS 8.8v10.02020-09-21
CVE-2020-6548 [HIGH] CWE-787 CVE-2020-6548: Heap buffer overflow in Skia in Google Chrome prior to 84.0.4147.125 allowed a remote attacker who h Heap buffer overflow in Skia in Google Chrome prior to 84.0.4147.125 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2014-1514P3CRITICALCVSS 9.8v7.0v8.02014-03-19
CVE-2014-1514 [CRITICAL] CWE-787 CVE-2014-1514: vmtypedarrayobject.cpp in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird bef vmtypedarrayobject.cpp in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 does not validate the length of the destination array before a copy operation, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write and application crash) by trig
nvd
CVE-2022-20771P3HIGHCVSS 7.5v9.02022-05-04
CVE-2022-20771 [HIGH] CWE-399 CVE-2022-20771: On April 20, 2022, the following vulnerability in the ClamAV scanning library versions 0.103.5 and e On April 20, 2022, the following vulnerability in the ClamAV scanning library versions 0.103.5 and earlier and 0.104.2 and earlier was disclosed: A vulnerability in the TIFF file parser of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104.2 and LTS version 0.103.5 and prior versions could allow an unauthenticated, remote attacker to cause a denia
nvd
CVE-2021-21898P3HIGHCVSS 8.8v9.0v10.0+1 more2021-11-19
CVE-2021-21898 [HIGH] CWE-119 CVE-2021-21898: A code execution vulnerability exists in the dwgCompressor::decompress18() functionality of LibreCad A code execution vulnerability exists in the dwgCompressor::decompress18() functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-crafted .dwg file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.
nvd
CVE-2020-6515P3HIGHCVSS 8.8v10.02020-07-22
CVE-2020-6515 [HIGH] CWE-416 CVE-2020-6515: Use after free in tab strip in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to pote Use after free in tab strip in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2017-5204P3CRITICALCVSS 9.8v8.0v9.02017-01-28
CVE-2017-5204 [CRITICAL] CWE-119 CVE-2017-5204: The IPv6 parser in tcpdump before 4.9.0 has a buffer overflow in print-ip6.c:ip6_print(). The IPv6 parser in tcpdump before 4.9.0 has a buffer overflow in print-ip6.c:ip6_print().
nvd
Debian Linux vulnerabilities | cvebase