VendorsDebiandebian_linux11.0
Vulnerabilities

Debian Debian Linux 11.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2060CVEs
CVE-2021-35269
NTFS-3G versions < 2021.8.22, when a specially crafted NTFS attribute from the MFT is setup in the function ntfs_attr_setup_flag, a heap buffer overflow can occur allowing for code execution and escalation of privileges.
Published 2021-09-07 · Modified
7.8EPSS 0.005
CVE-2021-35268
In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS inode is loaded in the function ntfs_inode_real_open, a heap buffer overflow can occur allowing for code execution and escalation of privileges.
Published 2021-09-07 · Modified
7.8EPSS 0.005
CVE-2022-41751
Jhead 3.06.0.1 allows attackers to execute arbitrary OS commands by placing them in a JPEG filename and then using the regeneration -rgt50 option.
Published 2022-10-17 · Modified
7.8EPSS 0.005
CVE-2022-1925
DOS / potential heap overwrite in mkv demuxing using HEADERSTRIP decompression. Integer overflow in matroskaparse element in gst_matroska_decompress_data function which causes a heap overflow. Due to restrictions on chunk sizes in the matroskademux element, the overflow can't be triggered, however the matroskaparse element has no size checks.
Published 2022-07-19 · Modified
7.8EPSS 0.005
CVE-2022-1270
In GraphicsMagick, a heap buffer overflow was found when parsing MIFF.
Published 2022-09-28 · Modified
7.8EPSS 0.005
CVE-2021-33286
In NTFS-3G versions < 2021.8.22, when a specially crafted unicode string is supplied in an NTFS image a heap buffer overflow can occur and allow for code execution.
Published 2021-09-07 · Modified
7.8EPSS 0.005
CVE-2022-2122
DOS / potential heap overwrite in qtdemux using zlib decompression. Integer overflow in qtdemux element in qtdemux_inflate function which causes a segfault, or could cause a heap overwrite, depending on libc and OS. Depending on the libc used, and the underlying OS capabilities, it could be just a segfault or a heap overwrite.
Published 2022-07-19 · Modified
7.8EPSS 0.005
CVE-2021-39256
A crafted NTFS image can cause a heap-based buffer overflow in ntfs_inode_lookup_by_name in NTFS-3G < 2021.8.22.
Published 2021-09-07 · Modified
7.8EPSS 0.005
CVE-2022-1922
DOS / potential heap overwrite in mkv demuxing using zlib decompression. Integer overflow in matroskademux element in gst_matroska_decompress_data function which causes a segfault, or could cause a heap overwrite, depending on libc and OS. Depending on the libc used, and the underlying OS capabilities, it could be just a segfault or a heap overwrite. If the libc uses mmap for large chunks, and the OS supports mmap, then it is just a segfault (because the realloc before the integer overflow will use mremap to reduce the size of the chunk, and it will start to write to unmapped memory). However, if using a libc implementation that does not use mmap, or if the OS does not support mmap while using libc, then this could result in a heap overwrite.
Published 2022-07-19 · Modified
7.8EPSS 0.005
CVE-2023-3609
Use-after-free in Linux kernel's net/sched: cls_u32 component
Published 2023-07-21 · Analyzed
7.8EPSS 0.005
CVE-2021-39261
A crafted NTFS image can cause a heap-based buffer overflow in ntfs_compressed_pwrite in NTFS-3G < 2021.8.22.
Published 2021-09-07 · Modified
7.8EPSS 0.005
CVE-2021-39263
A crafted NTFS image can trigger a heap-based buffer overflow, caused by an unsanitized attribute in ntfs_get_attribute_value, in NTFS-3G < 2021.8.22.
Published 2021-09-07 · Modified
7.8EPSS 0.005
CVE-2022-30788
A crafted NTFS image can cause a heap-based buffer overflow in ntfs_mft_rec_alloc in NTFS-3G through 2021.8.22.
Published 2022-05-26 · Modified
7.8EPSS 0.004
CVE-2022-30786
A crafted NTFS image can cause a heap-based buffer overflow in ntfs_names_full_collate in NTFS-3G through 2021.8.22.
Published 2022-05-26 · Modified
7.8EPSS 0.004
CVE-2022-30789
A crafted NTFS image can cause a heap-based buffer overflow in ntfs_check_log_client_array in NTFS-3G through 2021.8.22.
Published 2022-05-26 · Modified
7.8EPSS 0.004
CVE-2022-4141
Heap-based Buffer Overflow in vim/vim
Published 2022-11-25 · Analyzed
7.8EPSS 0.004
CVE-2022-31087
Incorrect Default Permissions in ldap-account-manager
Published 2022-06-27 · Modified
7.8EPSS 0.004
CVE-2023-3111
A use after free vulnerability was found in prepare_to_relocate in fs/btrfs/relocation.c in btrfs in the Linux Kernel. This possible flaw can be triggered by calling btrfs_ioctl_balance() before calling btrfs_ioctl_defrag().
Published 2023-06-05 · Modified
7.8EPSS 0.004
CVE-2021-39254
A crafted NTFS image can cause an integer overflow in memmove, leading to a heap-based buffer overflow in the function ntfs_attr_record_resize, in NTFS-3G < 2021.8.22.
Published 2021-09-07 · Modified
7.8EPSS 0.004
CVE-2021-34055
jhead 3.06 is vulnerable to Buffer Overflow via exif.c in function Put16u.
Published 2022-11-04 · Modified
7.8EPSS 0.004
CVE-2022-21546
scsi: target: Fix WRITE_SAME No Data Buffer crash
Published 2025-05-02 · Modified
7.8EPSS 0.004
CVE-2022-3545
Linux Kernel IPsec nfp_cppcore.c area_cache_get use after free
Published 2022-10-17 · Modified
7.8EPSS 0.004
CVE-2022-1923
DOS / potential heap overwrite in mkv demuxing using bzip decompression. Integer overflow in matroskademux element in bzip decompression function which causes a segfault, or could cause a heap overwrite, depending on libc and OS. Depending on the libc used, and the underlying OS capabilities, it could be just a segfault or a heap overwrite. If the libc uses mmap for large chunks, and the OS supports mmap, then it is just a segfault (because the realloc before the integer overflow will use mremap to reduce the size of the chunk, and it will start to write to unmapped memory). However, if using a libc implementation that does not use mmap, or if the OS does not support mmap while using libc, then this could result in a heap overwrite.
Published 2022-07-19 · Modified
7.8EPSS 0.004
CVE-2022-1924
DOS / potential heap overwrite in mkv demuxing using lzo decompression. Integer overflow in matroskademux element in lzo decompression function which causes a segfault, or could cause a heap overwrite, depending on libc and OS. Depending on the libc used, and the underlying OS capabilities, it could be just a segfault or a heap overwrite. If the libc uses mmap for large chunks, and the OS supports mmap, then it is just a segfault (because the realloc before the integer overflow will use mremap to reduce the size of the chunk, and it will start to write to unmapped memory). However, if using a libc implementation that does not use mmap, or if the OS does not support mmap while using libc, then this could result in a heap overwrite.
Published 2022-07-19 · Modified
7.8EPSS 0.004
CVE-2021-39252
A crafted NTFS image can cause an out-of-bounds read in ntfs_ie_lookup in NTFS-3G < 2021.8.22.
Published 2021-09-07 · Modified
7.8EPSS 0.004
CVE-2021-39253
A crafted NTFS image can cause an out-of-bounds read in ntfs_runlists_merge_i in NTFS-3G < 2021.8.22.
Published 2021-09-07 · Modified
7.8EPSS 0.004
CVE-2020-16119
DCCP CCID structure use-after-free
Published 2021-01-14 · Modified
7.8EPSS 0.004
CVE-2021-39255
A crafted NTFS image can trigger an out-of-bounds read, caused by an invalid attribute in ntfs_attr_find_in_attrdef, in NTFS-3G < 2021.8.22.
Published 2021-09-07 · Modified
7.8EPSS 0.004
CVE-2021-39258
A crafted NTFS image can cause out-of-bounds reads in ntfs_attr_find and ntfs_external_attr_find in NTFS-3G < 2021.8.22.
Published 2021-09-07 · Modified
7.8EPSS 0.004
CVE-2021-39259
A crafted NTFS image can trigger an out-of-bounds access, caused by an unsanitized attribute length in ntfs_inode_lookup_by_name, in NTFS-3G < 2021.8.22.
Published 2021-09-07 · Modified
7.8EPSS 0.004
CVE-2021-39260
A crafted NTFS image can cause an out-of-bounds access in ntfs_inode_sync_standard_information in NTFS-3G < 2021.8.22.
Published 2021-09-07 · Modified
7.8EPSS 0.004
CVE-2021-39262
A crafted NTFS image can cause an out-of-bounds access in ntfs_decompress in NTFS-3G < 2021.8.22.
Published 2021-09-07 · Modified
7.8EPSS 0.004
CVE-2021-39251
A crafted NTFS image can cause a NULL pointer dereference in ntfs_extent_inode_open in NTFS-3G < 2021.8.22.
Published 2021-09-07 · Modified
7.8EPSS 0.004
CVE-2021-33285
In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS attribute is supplied to the function ntfs_get_attribute_value, a heap buffer overflow can occur allowing for memory disclosure or denial of service. The vulnerability is caused by an out-of-bound buffer access which can be triggered by mounting a crafted ntfs partition. The root cause is a missing consistency check after reading an MFT record : the "bytes_in_use" field should be less than the "bytes_allocated" field. When it is not, the parsing of the records proceeds into the wild.
Published 2021-09-07 · Modified
7.8EPSS 0.004
CVE-2021-33287
In NTFS-3G versions < 2021.8.22, when specially crafted NTFS attributes are read in the function ntfs_attr_pread_i, a heap buffer overflow can occur and allow for writing to arbitrary memory or denial of service of the application.
Published 2021-09-07 · Modified
7.8EPSS 0.004
CVE-2022-30784
A crafted NTFS image can cause heap exhaustion in ntfs_get_attribute_value in NTFS-3G through 2021.8.22.
Published 2022-05-26 · Modified
7.8EPSS 0.004
CVE-2022-30688
needrestart 0.8 through 3.5 before 3.6 is prone to local privilege escalation. Regexes to detect the Perl, Python, and Ruby interpreters are not anchored, allowing a local user to escalate privileges when needrestart tries to detect if interpreters are using old source files.
Published 2022-05-17 · Modified
7.8EPSS 0.004
CVE-2022-28893
The SUNRPC subsystem in the Linux kernel through 5.17.2 can call xs_xprt_free before ensuring that sockets are in the intended state.
Published 2022-04-11 · Modified
7.8EPSS 0.004
CVE-2025-38676
iommu/amd: Avoid stack buffer overflow from kernel cmdline
Published 2025-08-26 · Modified
7.8EPSS 0.004
CVE-2025-38617
net/packet: fix a race in packet_set_ring() and packet_notifier()
Published 2025-08-22 · Modified
7.8EPSS 0.004
← Prev17 / 52Next →