cbcvebase.

Debian Linux vulnerabilities

9,953 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358

Vulnerabilities

Page 98 of 498
CVE-2021-21840P3HIGHCVSS 8.8v10.0v11.02021-08-25
CVE-2021-21840 [HIGH] CWE-680 CVE-2021-21840: An exploitable integer overflow vulnerability exists within the MPEG-4 decoding functionality of the An exploitable integer overflow vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input used to process an atom using the “saio” FOURCC code cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory co
nvd
CVE-2021-21842P3HIGHCVSS 8.8v10.0v11.02021-08-25
CVE-2021-21842 [HIGH] CWE-680 CVE-2021-21842: An exploitable integer overflow vulnerability exists within the MPEG-4 decoding functionality of the An exploitable integer overflow vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow when processing an atom using the 'ssix' FOURCC code, due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memo
nvd
CVE-2021-21834P3HIGHCVSS 8.8v10.0v11.02021-08-25
CVE-2021-21834 [HIGH] CWE-680 CVE-2021-21834: An exploitable integer overflow vulnerability exists within the MPEG-4 decoding functionality of the An exploitable integer overflow vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input when decoding the atom for the “co64” FOURCC can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corrup
nvd
CVE-2021-21836P3HIGHCVSS 8.8v10.0v11.02021-08-25
CVE-2021-21836 [HIGH] CWE-680 CVE-2021-21836: An exploitable integer overflow vulnerability exists within the MPEG-4 decoding functionality of the An exploitable integer overflow vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input using the “ctts” FOURCC code can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacke
nvd
CVE-2022-31625P3HIGHCVSS 8.1v10.0v11.02022-06-16
CVE-2022-31625 [HIGH] CWE-590 CVE-2022-31625: In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when using Postgres d In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when using Postgres database extension, supplying invalid parameters to the parametrized query may lead to PHP attempting to free memory using uninitialized data as pointers. This could lead to RCE vulnerability or denial of service.
nvd
CVE-2017-8817P3CRITICALCVSS 9.8v8.0v9.02017-11-29
CVE-2017-8817 [CRITICAL] CWE-125 CVE-2017-8817: The FTP wildcard function in curl and libcurl before 7.57.0 allows remote attackers to cause a denia The FTP wildcard function in curl and libcurl before 7.57.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) or possibly have unspecified other impact via a string that ends with an '[' character.
nvd
CVE-2020-16005P3HIGHCVSS 8.8v10.02020-11-03
CVE-2020-16005 [HIGH] CWE-755 CVE-2020-16005: Insufficient policy enforcement in ANGLE in Google Chrome prior to 86.0.4240.183 allowed a remote at Insufficient policy enforcement in ANGLE in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-16006P3HIGHCVSS 8.8v10.02020-11-03
CVE-2020-16006 [HIGH] CWE-787 CVE-2020-16006: Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-16002P3HIGHCVSS 8.8v10.02020-11-03
CVE-2020-16002 [HIGH] CWE-416 CVE-2020-16002: Use after free in PDFium in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potent Use after free in PDFium in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
nvd
CVE-2021-21861P3HIGHCVSS 8.8v11.02021-08-16
CVE-2021-21861 [HIGH] CWE-680 CVE-2021-21861: An exploitable integer truncation vulnerability exists within the MPEG-4 decoding functionality of t An exploitable integer truncation vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. When processing the 'hdlr' FOURCC code, a specially crafted MPEG-4 input can cause an improper memory allocation resulting in a heap-based buffer overflow that causes memory corruption. An attacker can
nvd
CVE-2021-21860P3HIGHCVSS 8.8v11.02021-08-16
CVE-2021-21860 [HIGH] CWE-680 CVE-2021-21860: An exploitable integer truncation vulnerability exists within the MPEG-4 decoding functionality of t An exploitable integer truncation vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an improper memory allocation resulting in a heap-based buffer overflow that causes memory corruption. The FOURCC code, 'trik', is parsed by the function with
nvd
CVE-2021-21230P3HIGHCVSS 8.8v10.02021-04-30
CVE-2021-21230 [HIGH] CWE-843 CVE-2021-21230: Type confusion in V8 in Google Chrome prior to 90.0.4430.93 allowed a remote attacker to potentially Type confusion in V8 in Google Chrome prior to 90.0.4430.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2016-5766P3HIGHCVSS 8.8v8.02016-08-07
CVE-2016-5766 [HIGH] CWE-190 CVE-2016-5766: Integer overflow in the _gd2GetHeader function in gd_gd2.c in the GD Graphics Library (aka libgd) be Integer overflow in the _gd2GetHeader function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8, allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via crafted chunk dimens
nvd
CVE-2020-15991P3HIGHCVSS 8.8v10.02020-11-03
CVE-2020-15991 [HIGH] CWE-416 CVE-2020-15991: Use after free in password manager in Google Chrome prior to 86.0.4240.75 allowed a remote attacker Use after free in password manager in Google Chrome prior to 86.0.4240.75 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2017-0926P3HIGHCVSS 8.8v9.02018-03-21
CVE-2017-0926 [HIGH] CWE-285 CVE-2017-0926: Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the Oauth Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the Oauth sign-in component resulting in unauthorized user login.
nvd
CVE-2023-39928P3HIGHCVSS 8.8v11.0v12.02023-10-06
CVE-2023-39928 [HIGH] CWE-416 CVE-2023-39928: A use-after-free vulnerability exists in the MediaRecorder API of Webkit WebKitGTK 2.40.5. A special A use-after-free vulnerability exists in the MediaRecorder API of Webkit WebKitGTK 2.40.5. A specially crafted web page can abuse this vulnerability to cause memory corruption and potentially arbitrary code execution. A user would need to to visit a malicious webpage to trigger this vulnerability.
nvd
CVE-2021-37712P3HIGHCVSS 8.6v10.0v11.02021-08-31
CVE-2021-37712 [HIGH] CWE-22 CVE-2021-37712: The npm package "tar" (aka node-tar) before versions 4.4.18, 5.0.10, and 6.1.9 has an arbitrary file The npm package "tar" (aka node-tar) before versions 4.4.18, 5.0.10, and 6.1.9 has an arbitrary file creation/overwrite and arbitrary code execution vulnerability. node-tar aims to guarantee that any file whose location would be modified by a symbolic link is not extracted. This is, in part, achieved by ensuring that extracted directories are not symli
nvd
CVE-2018-1000026P3HIGHCVSS 7.7v8.02018-02-09
CVE-2018-1000026 [HIGH] CWE-20 CVE-2018-1000026: Linux Linux kernel version at least v4.8 onwards, probably well before contains a Insufficient input Linux Linux kernel version at least v4.8 onwards, probably well before contains a Insufficient input validation vulnerability in bnx2x network card driver that can result in DoS: Network card firmware assertion takes card off-line. This attack appear to be exploitable via An attacker on a must pass a very large, specially crafted packet to the bnx2
nvd
CVE-2013-6632P3CRITICALCVSS 9.3v7.0v8.02013-11-18
CVE-2013-6632 [CRITICAL] CWE-189 CVE-2013-6632: Integer overflow in Google Chrome before 31.0.1650.57 allows remote attackers to execute arbitrary c Integer overflow in Google Chrome before 31.0.1650.57 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, as demonstrated during a Mobile Pwn2Own competition at PacSec 2013.
nvd
CVE-2021-37962P3HIGHCVSS 8.8v10.0v11.02021-10-08
CVE-2021-37962 [HIGH] CWE-416 CVE-2021-37962: Use after free in Performance Manager in Google Chrome prior to 94.0.4606.54 allowed a remote attack Use after free in Performance Manager in Google Chrome prior to 94.0.4606.54 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
nvd
Debian Linux vulnerabilities | cvebase