VendorsDebiandebian_linuxall versions
Vulnerabilities

Debian Debian Linux

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10063CVEs
CVE-2020-6524
Heap buffer overflow in WebAudio in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published 2020-07-22 · Modified
9.3EPSS 0.029
CVE-2016-1649
The Program::getUniformInternal function in Program.cpp in libANGLE, as used in Google Chrome before 49.0.2623.108, does not properly handle a certain data-type mismatch, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via crafted shader stages.
Published 2016-03-29 · Modified
9.3EPSS 0.029
CVE-2020-7040
storeBackup.pl in storeBackup through 3.5 relies on the /tmp/storeBackup.lock pathname, which allows symlink attacks that possibly lead to privilege escalation. (Local users can also create a plain file named /tmp/storeBackup.lock to block use of storeBackup until an admin manually deletes that file.)
Published 2020-01-21 · Modified
9.3EPSS 0.029
CVE-2021-38714
In Plib through 1.85, there is an integer overflow vulnerability that could result in arbitrary code execution. The vulnerability is found in ssgLoadTGA() function in src/ssg/ssgLoadTGA.cxx file.
Published 2021-08-24 · Modified
9.3EPSS 0.028
CVE-2020-6517
Heap buffer overflow in history in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published 2020-07-22 · Modified
9.3EPSS 0.028
CVE-2021-36055
XMP Toolkit SDK Use After Free Vulnerability In ReadingXMPNewDOM Could Lead To Arbitrary Code Execution
Published 2021-09-01 · Modified
9.3EPSS 0.027
CVE-2006-5868
Multiple buffer overflows in Imagemagick 6.0 before 6.0.6.2, and 6.2 before 6.2.4.5, has unknown impact and user-assisted attack vectors via a crafted SGI image.
Published 2006-11-22 · Modified
9.3EPSS 0.027
CVE-2020-6523
Out of bounds write in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published 2020-07-22 · Modified
9.3EPSS 0.027
CVE-2021-36064
XMP Toolkit SDK SVG_Adapter ParseFullNS Buffer Underflow
Published 2021-09-01 · Modified
9.3EPSS 0.027
CVE-2021-36047
XMP Toolkit SDK Improper Input Validation Could Lead To Arbitrary Code Execution
Published 2021-09-01 · Modified
9.3EPSS 0.027
CVE-2021-36048
XMP Toolkit SDK Improper Input Validation Could Lead To Arbitrary Code Execution
Published 2021-09-01 · Modified
9.3EPSS 0.027
CVE-2020-6520
Buffer overflow in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published 2020-07-22 · Modified
9.3EPSS 0.027
CVE-2018-6140
Allowing the chrome.debugger API to attach to Web UI pages in DevTools in Google Chrome prior to 67.0.3396.62 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension.
Published 2019-01-09 · Modified
9.3EPSS 0.026
CVE-2021-30934
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted web content may lead to arbitrary code execution.
Published 2021-08-24 · Modified
9.3EPSS 0.026
CVE-2020-6548
Heap buffer overflow in Skia in Google Chrome prior to 84.0.4147.125 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
Published 2020-09-21 · Modified
9.3EPSS 0.026
CVE-2017-18123
The call parameter of /lib/exe/ajax.php in DokuWiki through 2017-02-19e does not properly encode user input, which leads to a reflected file download vulnerability, and allows remote attackers to run arbitrary programs.
Published 2018-02-03 · Modified
9.3EPSS 0.026
CVE-2016-1653
The LoadBuffer implementation in Google V8, as used in Google Chrome before 50.0.2661.75, mishandles data types, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that triggers an out-of-bounds write operation, related to compiler/pipeline.cc and compiler/simplified-lowering.cc.
Published 2016-04-18 · Modified
9.3EPSS 0.026
CVE-2020-6518
Use after free in developer tools in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had convinced the user to use developer tools to potentially exploit heap corruption via a crafted HTML page.
Published 2020-07-22 · Modified
9.3EPSS 0.026
CVE-2014-5439
Multiple Stack-based Buffer Overflow vulnerabilities exists in Sniffit prior to 0.3.7 via a crafted configuration file that will bypass Non-eXecutable bit NX, stack smashing protector SSP, and address space layout randomization ASLR protection mechanisms, which could let a malicious user execute arbitrary code.
Published 2019-11-19 · Modified
9.3EPSS 0.025
CVE-2020-6515
Use after free in tab strip in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published 2020-07-22 · Modified
9.3EPSS 0.025
CVE-2021-36046
XMP Toolkit SDK TIFF_MemoryReader::SortIFD function Memory Corruption
Published 2021-09-01 · Modified
9.3EPSS 0.025
CVE-2012-2248
An issue was discovered in dhclient 4.3.1-6 due to an embedded path variable.
Published 2019-11-27 · Modified
9.3EPSS 0.024
CVE-2013-0773
The Chrome Object Wrapper (COW) and System Only Wrapper (SOW) implementations in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 do not prevent modifications to a prototype, which allows remote attackers to obtain sensitive information from chrome objects or possibly execute arbitrary JavaScript code with chrome privileges via a crafted web site.
Published 2013-02-19 · Modified
9.3EPSS 0.024
CVE-2013-2870
Use-after-free vulnerability in Google Chrome before 28.0.1500.71 allows remote servers to execute arbitrary code via crafted response traffic after a URL request.
Published 2013-07-10 · Modified
9.3EPSS 0.023
CVE-2011-0480
Multiple buffer overflows in vorbis_dec.c in the Vorbis decoder in FFmpeg, as used in Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344, allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a crafted WebM file, related to buffers for (1) the channel floor and (2) the channel residue.
Published 2011-01-14 · Modified
9.3EPSS 0.023
CVE-2020-6559
Use after free in presentation API in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published 2020-09-21 · Modified
9.3EPSS 0.023
CVE-2019-18345
A reflected XSS issue was discovered in DAViCal through 1.1.8. It echoes the action parameter without encoding. If a user visits an attacker-supplied link, the attacker can view all data the attacked user can view, as well as perform all actions in the name of the user. If the user is an administrator, the attacker can for example add a new admin user to gain full access to the application.
Published 2019-12-12 · Modified
9.3EPSS 0.022
CVE-2016-1647
Use-after-free vulnerability in the RenderWidgetHostImpl::Destroy function in content/browser/renderer_host/render_widget_host_impl.cc in the Navigation implementation in Google Chrome before 49.0.2623.108 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
Published 2016-03-29 · Modified
9.3EPSS 0.021
CVE-2016-1645
Multiple integer signedness errors in the opj_j2k_update_image_data function in j2k.c in OpenJPEG, as used in PDFium in Google Chrome before 49.0.2623.87, allow remote attackers to cause a denial of service (incorrect cast and out-of-bounds write) or possibly have unspecified other impact via crafted JPEG 2000 data.
Published 2016-03-13 · Modified
9.3EPSS 0.020
CVE-2016-1648
Use-after-free vulnerability in the GetLoadTimes function in renderer/loadtimes_extension_bindings.cc in the Extensions implementation in Google Chrome before 49.0.2623.108 allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code.
Published 2016-03-29 · Modified
9.3EPSS 0.019
CVE-2022-1650
Improper Removal of Sensitive Information Before Storage or Transfer in eventsource/eventsource
Published 2022-05-12 · Modified
9.3EPSS 0.019
CVE-2021-3973
Heap-based Buffer Overflow in vim/vim
Published 2021-11-19 · Modified
9.3EPSS 0.018
CVE-2015-9268
Nullsoft Scriptable Install System (NSIS) before 2.49 has unsafe implicit linking against Version.dll. In other words, there is no protection mechanism in which a wrapper function resolves the dependency at an appropriate time during runtime.
Published 2018-10-01 · Modified
9.3EPSS 0.015
CVE-2020-6552
Use after free in Blink in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published 2020-09-21 · Modified
9.3EPSS 0.015
CVE-2020-6553
Use after free in offline mode in Google Chrome on iOS prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published 2020-09-21 · Modified
9.3EPSS 0.015
CVE-2021-30954
A type confusion issue was addressed with improved memory handling. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted web content may lead to arbitrary code execution.
Published 2021-08-24 · Modified
9.3EPSS 0.015
CVE-2016-1650
The PageCaptureSaveAsMHTMLFunction::ReturnFailure function in browser/extensions/api/page_capture/page_capture_api.cc in Google Chrome before 49.0.2623.108 allows attackers to cause a denial of service or possibly have unspecified other impact by triggering an error in creating an MHTML document.
Published 2016-03-29 · Modified
9.3EPSS 0.012
CVE-2010-4654
poppler before 0.16.3 has malformed commands that may cause corruption of the internal stack.
Published 2019-11-13 · Modified
9.3EPSS 0.012
CVE-2021-3624
There is an integer overflow vulnerability in dcraw. When the victim runs dcraw with a maliciously crafted X3F input image, arbitrary code may be executed in the victim's system.
Published 2022-04-18 · Modified
9.3EPSS 0.009
CVE-2024-36913
Drivers: hv: vmbus: Leak pages if set_memory_encrypted() fails
Published 2024-05-30 · Modified
9.3EPSS 0.007
← Prev30 / 252Next →