VendorsDebiandebian_linux11.0
Vulnerabilities

Debian Debian Linux 11.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2060CVEs
CVE-2021-43299
Stack overflow in PJSUA API when calling pjsua_player_create. An attacker-controlled 'filename' argument may cause a buffer overflow since it is copied to a fixed-size stack buffer without any size validation.
Published 2022-02-16 · Modified
9.8EPSS 0.025
CVE-2021-38171
adts_decode_extradata in libavformat/adtsenc.c in FFmpeg 4.4 does not check the init_get_bits return value, which is a necessary step because the second argument to init_get_bits can be crafted.
Published 2021-08-21 · Modified
9.8EPSS 0.024
CVE-2021-43300
Stack overflow in PJSUA API when calling pjsua_recorder_create. An attacker-controlled 'filename' argument may cause a buffer overflow since it is copied to a fixed-size stack buffer without any size validation.
Published 2022-02-16 · Modified
9.8EPSS 0.024
CVE-2021-43303
Buffer overflow in PJSUA API when calling pjsua_call_dump. An attacker-controlled 'buffer' argument may cause a buffer overflow, since supplying an output buffer smaller than 128 characters may overflow the output buffer, regardless of the 'maxlen' argument supplied
Published 2022-02-16 · Modified
9.8EPSS 0.024
CVE-2023-42464
A Type Confusion vulnerability was found in the Spotlight RPC functions in afpd in Netatalk 3.1.x before 3.1.17. When parsing Spotlight RPC packets, one encoded data structure is a key-value style dictionary where the keys are character strings, and the values can be any of the supported types in the underlying protocol. Due to a lack of type checking in callers of the dalloc_value_for_key() function, which returns the object associated with a key, a malicious actor may be able to fully control the value of the pointer and theoretically achieve Remote Code Execution on the host. This issue is similar to CVE-2023-34967.
Published 2023-09-20 · Modified
9.8EPSS 0.021
CVE-2022-31799
Bottle before 0.12.20 mishandles errors during early request binding.
Published 2022-05-29 · Modified
9.8EPSS 0.021
CVE-2022-31031
Potential stack buffer overflow when parsing message as a STUN client
Published 2022-06-07 · Modified
9.8EPSS 0.020
CVE-2022-28044
Irzip v0.640 was discovered to contain a heap memory corruption via the component lrzip.c:initialise_control.
Published 2022-04-15 · Modified
9.8EPSS 0.019
CVE-2021-44538
The olm_session_describe function in Matrix libolm before 3.2.7 is vulnerable to a buffer overflow. The Olm session object represents a cryptographic channel between two parties. Therefore, its state is partially controllable by the remote party of the channel. Attackers can construct a crafted sequence of messages to manipulate the state of the receiver's session in such a way that, for some buffer sizes, a buffer overflow happens on a call to olm_session_describe. Furthermore, safe buffer sizes were undocumented. The overflow content is partially controllable by the attacker and limited to ASCII spaces and digits. The known affected products are Element Web And SchildiChat Web.
Published 2021-12-14 · Modified
9.8EPSS 0.019
CVE-2022-41794
A heap based buffer overflow vulnerability exists in the PSD thumbnail resource parsing code of OpenImageIO 2.3.19.0. A specially-crafted PSD file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
Published 2022-12-23 · Modified
9.8EPSS 0.019
CVE-2022-41639
A heap based buffer overflow vulnerability exists in tile decoding code of TIFF image parser in OpenImageIO master-branch-9aeece7a and v2.3.19.0. A specially-crafted TIFF file can lead to an out of bounds memory corruption, which can result in arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
Published 2022-12-23 · Modified
9.8EPSS 0.018
CVE-2022-41838
A code execution vulnerability exists in the DDS scanline parsing functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially-crafted .dds can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
Published 2022-12-23 · Modified
9.8EPSS 0.018
CVE-2022-24300
Minetest before 5.4.0 allows attackers to add or modify arbitrary meta fields of the same item stack as saved user input, aka ItemStack meta injection.
Published 2022-02-02 · Modified
9.8EPSS 0.017
CVE-2022-48337
GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses the system C library function in its implementation of the etags program. For example, a victim may use the "etags -u *" command (suggested in the etags documentation) in a situation where the current working directory has contents that depend on untrusted input.
Published 2023-02-20 · Modified
9.8EPSS 0.016
CVE-2021-20001
It was discovered, that debian-edu-config, a set of configuration files used for the Debian Edu blend, before 2.12.16 configured insecure permissions for the user web shares (~/public_html), which could result in privilege escalation.
Published 2022-02-11 · Modified
9.8EPSS 0.016
CVE-2022-41837
An out-of-bounds write vulnerability exists in the OpenImageIO::add_exif_item_to_spec functionality of OpenImageIO Project OpenImageIO v2.4.4.2. Specially-crafted exif metadata can lead to stack-based memory corruption. An attacker can provide a malicious file to trigger this vulnerability.
Published 2022-12-23 · Modified
9.8EPSS 0.016
CVE-2022-47629
Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL signature parser.
Published 2022-12-20 · Modified
9.8EPSS 0.016
CVE-2022-45062
In Xfce xfce4-settings before 4.16.4 and 4.17.x before 4.17.1, there is an argument injection vulnerability in xfce4-mime-helper.
Published 2022-11-09 · Modified
9.8EPSS 0.015
CVE-2023-5730
Memory safety bugs present in Firefox 118, Firefox ESR 115.3, and Thunderbird 115.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
Published 2023-10-24 · Modified
9.8EPSS 0.015
CVE-2025-68670
xrdp improperly checks bounds of domain string length, which leads to Stack-based Buffer Overflow
Published 2026-01-27 · Analyzed
9.8EPSS 0.014
CVE-2024-47606
GHSL-2024-166: GStreamer Integer overflows in MP4/MOV demuxer and memory allocator that can lead to out-of-bounds writes
Published 2024-12-11 · Modified
9.8EPSS 0.014
CVE-2022-4338
An integer underflow in Organization Specific TLV was found in various versions of OpenvSwitch.
Published 2023-01-10 · Modified
9.8EPSS 0.013
CVE-2022-4337
An out-of-bounds read in Organization Specific TLV was found in various versions of OpenvSwitch.
Published 2023-01-10 · Modified
9.8EPSS 0.013
CVE-2024-52533
gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CONN_MSG_LEN is not sufficient for a trailing '\0' character.
Published 2024-11-11 · Analyzed
9.8EPSS 0.013
CVE-2023-5176
Memory safety bugs present in Firefox 117, Firefox ESR 115.2, and Thunderbird 115.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.
Published 2023-09-27 · Modified
9.8EPSS 0.012
CVE-2025-37778
ksmbd: Fix dangling pointer in krb_authenticate
Published 2025-05-01 · Modified
9.8EPSS 0.011
CVE-2023-4056
Memory safety bugs present in Firefox 115, Firefox ESR 115.0, Firefox ESR 102.13, Thunderbird 115.0, and Thunderbird 102.13. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.
Published 2023-08-01 · Modified
9.8EPSS 0.009
CVE-2022-23477
Buffer Overflow in xrdp
Published 2022-12-09 · Modified
9.8EPSS 0.009
CVE-2022-23479
Buffer Overflow occurs in xrdp
Published 2022-12-09 · Modified
9.8EPSS 0.009
CVE-2022-23480
Buffer Overflow in xrdp
Published 2022-12-09 · Modified
9.8EPSS 0.009
CVE-2022-23478
Out of Bound Write in xrdp
Published 2022-12-09 · Modified
9.8EPSS 0.008
CVE-2024-25714
In Rhonabwy through 1.1.13, HMAC signature verification uses a strcmp function that is vulnerable to side-channel attacks, because it stops the comparison when the first difference is spotted in the two signatures. (The fix uses gnutls_memcmp, which has constant-time execution.)
Published 2024-02-11 · Modified
9.8EPSS 0.008
CVE-2022-23468
Buffer Overflow in xrdp
Published 2022-12-09 · Modified
9.8EPSS 0.008
CVE-2022-23484
Integer Overflow in xrdp
Published 2022-12-09 · Modified
9.8EPSS 0.008
CVE-2025-37879
9p/net: fix improper handling of bogus negative read/write replies
Published 2025-05-09 · Modified
9.8EPSS 0.007
CVE-2024-41073
nvme: avoid double free special payload
Published 2024-07-29 · Modified
9.8EPSS 0.007
CVE-2025-38488
smb: client: fix use-after-free in crypt_message when using async crypto
Published 2025-07-28 · Modified
9.8EPSS 0.006
CVE-2025-0838
Heap Buffer overflow in Abseil
Published 2025-02-21 · Analyzed
9.8EPSS 0.006
CVE-2024-0808
Integer underflow in WebUI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via a malicious file. (Chromium security severity: High)
Published 2024-01-23 · Modified
9.8EPSS 0.005
CVE-2025-38430
nfsd: nfsd4_spo_must_allow() must check this is a v4 compound request
Published 2025-07-25 · Modified
9.8EPSS 0.005
← Prev3 / 52Next →