VendorsDebiandebian_linux11.0
Vulnerabilities

Debian Debian Linux 11.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2060CVEs
CVE-2023-31248
Linux Kernel nftables Use-After-Free Local Privilege Escalation Vulnerability
Published 2023-07-05 · Modified
7.8EPSS 0.021
CVE-2021-45444
In zsh before 5.8.1, an attacker can achieve code execution if they control a command output inside the prompt, as demonstrated by a %F argument. This occurs because of recursive PROMPT_SUBST expansion.
Published 2022-02-13 · Modified
7.8EPSS 0.020
CVE-2021-45342
A buffer overflow vulnerability in CDataList of the jwwlib component of LibreCAD 2.2.0-rc3 and older allows an attacker to achieve Remote Code Execution using a crafted JWW document.
Published 2022-01-25 · Modified
7.8EPSS 0.019
CVE-2021-4019
Heap-based Buffer Overflow in vim/vim
Published 2021-12-01 · Analyzed
7.8EPSS 0.019
CVE-2021-45845
The Path Sanity Check script of FreeCAD 0.19 is vulnerable to OS command injection, allowing an attacker to execute arbitrary commands via a crafted FCStd document.
Published 2022-01-25 · Modified
7.8EPSS 0.019
CVE-2022-23222
kernel/bpf/verifier.c in the Linux kernel through 5.15.14 allows local users to gain privileges because of the availability of pointer arithmetic via certain *_OR_NULL pointer types.
Published 2022-01-14 · Modified
7.8EPSS 0.019
CVE-2022-23946
A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon GCodeNumber parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or excellon file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
Published 2022-02-04 · Modified
7.8EPSS 0.017
CVE-2022-23804
A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon ReadIJCoord coordinate parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or excellon file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
Published 2022-02-16 · Modified
7.8EPSS 0.016
CVE-2022-23803
A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon ReadXYCoord coordinate parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or excellon file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
Published 2022-02-16 · Modified
7.8EPSS 0.016
CVE-2023-6377
Xorg-x11-server: out-of-bounds memory reads/writes in xkb button actions
Published 2023-12-13 · Modified
7.8EPSS 0.016
CVE-2023-35001
Linux Kernel nftables Out-Of-Bounds Read/Write Vulnerability
Published 2023-07-05 · Modified
7.8EPSS 0.015
CVE-2022-20001
Injection in fish
Published 2022-03-14 · Modified
7.8EPSS 0.015
CVE-2022-23947
A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon DCodeNumber parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or excellon file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
Published 2022-02-04 · Modified
7.8EPSS 0.015
CVE-2021-21703
PHP-FPM memory access in root process leading to privilege escalation
Published 2021-10-25 · Modified
7.8EPSS 0.014
CVE-2021-30846
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, Safari 15, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing maliciously crafted web content may lead to arbitrary code execution.
Published 2021-10-19 · Modified
7.8EPSS 0.014
CVE-2021-45078
stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write. NOTE: this issue exists because of an incorrect fix for CVE-2018-12699.
Published 2021-12-15 · Modified
7.8EPSS 0.013
CVE-2025-38352
posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()
Published 2025-07-22 · Analyzed
7.8KEVEPSS 0.013
CVE-2022-0546
A missing bounds check in the image loader used in Blender 3.x and 2.93.8 leads to out-of-bounds heap access, allowing an attacker to cause denial of service, memory corruption or potentially code execution.
Published 2022-02-24 · Modified
7.8EPSS 0.012
CVE-2022-0545
An integer overflow in the processing of loaded 2D images leads to a write-what-where vulnerability and an out-of-bounds read vulnerability, allowing an attacker to leak sensitive information or achieve code execution in the context of the Blender process when a specially crafted image file is loaded. This flaw affects Blender versions prior to 2.83.19, 2.93.8 and 3.1.
Published 2022-02-24 · Modified
7.8EPSS 0.012
CVE-2021-45844
Improper sanitization in the invocation of ODA File Converter from FreeCAD 0.19 allows an attacker to inject OS commands via a crafted filename.
Published 2022-01-25 · Modified
7.8EPSS 0.011
CVE-2025-63261
AWStats 8.0 is vulnerable to Command Injection via the open function
Published 2026-03-20 · Analyzed
7.8EPSS 0.010
CVE-2021-32493
A flaw was found in djvulibre-3.5.28 and earlier. A heap buffer overflow in function DJVU::GBitmap::decode() via crafted djvu file may lead to application crash and other consequences.
Published 2021-06-24 · Modified
7.8EPSS 0.010
CVE-2024-32465
Git's protections for cloning untrusted repositories can be bypassed
Published 2024-05-14 · Analyzed
7.8EPSS 0.010
CVE-2022-4283
A vulnerability was found in X.Org. This security flaw occurs because the XkbCopyNames function left a dangling pointer to freed memory, resulting in out-of-bounds memory access on subsequent XkbGetKbdByName requests.. This issue can lead to local privileges elevation on systems where the X server is running privileged and remote code execution for ssh X forwarding sessions.
Published 2022-12-14 · Modified
7.8EPSS 0.010
CVE-2022-1441
MP4Box is a component of GPAC-2.0.0, which is a widely-used third-party package on RPM Fusion. When MP4Box tries to parse a MP4 file, it calls the function `diST_box_read()` to read from video. In this function, it allocates a buffer `str` with fixed length. However, content read from `bs` is controllable by user, so is the length, which causes a buffer overflow.
Published 2022-04-25 · Modified
7.8EPSS 0.010
CVE-2021-32492
A flaw was found in djvulibre-3.5.28 and earlier. An out of bounds read in function DJVU::DataPool::has_data() via crafted djvu file may lead to application crash and other consequences.
Published 2021-06-24 · Modified
7.8EPSS 0.010
CVE-2021-44731
snapd could be made to escalate privileges and run programs as administrator
Published 2022-02-17 · Modified
7.8EPSS 0.010
CVE-2021-37969
Inappropriate implementation in Google Updater in Google Chrome on Windows prior to 94.0.4606.54 allowed a remote attacker to perform local privilege escalation via a crafted file.
Published 2021-10-08 · Modified
7.8EPSS 0.009
CVE-2021-3500
A flaw was found in djvulibre-3.5.28 and earlier. A Stack overflow in function DJVU::DjVuDocument::get_djvu_file() via crafted djvu file may lead to application crash and other consequences.
Published 2021-06-24 · Modified
7.8EPSS 0.009
CVE-2023-4004
Kernel: netfilter: use-after-free due to improper element removal in nft_pipapo_remove()
Published 2023-07-31 · Modified
7.8EPSS 0.009
CVE-2021-32490
A flaw was found in djvulibre-3.5.28 and earlier. An out of bounds write in function DJVU::filter_bv() via crafted djvu file may lead to application crash and other consequences.
Published 2021-06-24 · Modified
7.8EPSS 0.009
CVE-2021-32491
A flaw was found in djvulibre-3.5.28 and earlier. An integer overflow in function render() in tools/ddjvu via crafted djvu file may lead to application crash and other consequences.
Published 2021-06-24 · Modified
7.8EPSS 0.009
CVE-2021-36409
There is an Assertion `scaling_list_pred_matrix_id_delta==1' failed at sps.cc:925 in libde265 v1.0.8 when decoding file, which allows attackers to cause a Denial of Service (DoS) by running the application with a crafted file or possibly have unspecified other impact.
Published 2022-01-10 · Modified
7.8EPSS 0.009
CVE-2022-42720
Various refcounting bugs in the multi-BSS handling in the mac80211 stack in the Linux kernel 5.1 through 5.19.x before 5.19.16 could be used by local attackers (able to inject WLAN frames) to trigger use-after-free conditions to potentially execute code.
Published 2022-10-13 · Modified
7.8EPSS 0.009
CVE-2021-46829
GNOME GdkPixbuf (aka GDK-PixBuf) before 2.42.8 allows a heap-based buffer overflow when compositing or clearing frames in GIF files, as demonstrated by io-gif-animation.c composite_frame. This overflow is controllable and could be abused for code execution, especially on 32-bit systems.
Published 2022-07-24 · Modified
7.8EPSS 0.008
CVE-2022-41741
NGINX ngx_http_mp4_module vulnerability CVE-2022-41741
Published 2022-10-19 · Modified
7.8EPSS 0.008
CVE-2022-45934
An issue was discovered in the Linux kernel through 6.0.10. l2cap_config_req in net/bluetooth/l2cap_core.c has an integer wraparound via L2CAP_CONF_REQ packets.
Published 2022-11-27 · Modified
7.8EPSS 0.008
CVE-2025-10922
GIMP DCM File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2025-10-29 · Analyzed
7.8EPSS 0.008
CVE-2024-44940
fou: remove warn in gue_gro_receive on unsupported protocol
Published 2024-08-26 · Modified
7.8EPSS 0.008
CVE-2021-3999
A flaw was found in glibc. An off-by-one buffer overflow and underflow in getcwd() may lead to memory corruption when the size of the buffer is exactly 1. A local attacker who can control the input buffer and size passed to getcwd() in a setuid program could use this flaw to potentially execute arbitrary code and escalate their privileges on the system.
Published 2022-08-24 · Modified
7.8EPSS 0.007
← Prev15 / 52Next →