VendorsDebiandebian_linux9.0
Vulnerabilities

Debian Debian Linux 9.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3996CVEs
CVE-2018-15908
In Artifex Ghostscript 9.23 before 2018-08-23, attackers are able to supply malicious PostScript files to bypass .tempfile restrictions and write files.
Published 2018-08-27 · Modified
7.8EPSS 0.019
CVE-2018-10119
sot/source/sdstor/stgstrms.cxx in LibreOffice before 5.4.5.1 and 6.x before 6.0.1.1 uses an incorrect integer data type in the StgSmallStrm class, which allows remote attackers to cause a denial of service (use-after-free with write access) or possibly have unspecified other impact via a crafted document that uses the structured storage ole2 wrapper file format.
Published 2018-04-15 · Modified
7.8EPSS 0.019
CVE-2020-12762
json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend.
Published 2020-05-09 · Modified
7.8EPSS 0.019
CVE-2019-1000018
rssh version 2.3.4 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in allowscp permission that can result in Local command execution. This attack appear to be exploitable via An authorized SSH user with the allowscp permission.
Published 2019-02-04 · Modified
7.8EPSS 0.019
CVE-2020-35524
A heap-based buffer overflow flaw was found in libtiff in the handling of TIFF images in libtiff's TIFF2PDF tool. A specially crafted TIFF file can lead to arbitrary code execution. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Published 2021-03-09 · Modified
7.8EPSS 0.019
CVE-2019-18218
cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a heap-based buffer overflow (4-byte out-of-bounds write).
Published 2019-10-21 · Modified
7.8EPSS 0.019
CVE-2017-2908
An exploitable integer overflow exists in the thumbnail functionality of the Blender open-source 3d creation suite version 2.78c. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to render the thumbnail for the file while in the File->Open dialog.
Published 2018-04-24 · Modified
7.8EPSS 0.018
CVE-2019-14438
A heap-based buffer over-read in xiph_PackHeaders() in modules/demux/xiph.h in VideoLAN VLC media player 3.0.7.1 allows remote attackers to trigger a heap-based buffer over-read via a crafted .ogg file.
Published 2019-08-29 · Modified
7.8EPSS 0.018
CVE-2020-16303
A use-after-free vulnerability in xps_finish_image_path() in devices/vector/gdevxps.c of Artifex Software GhostScript v9.50 allows a remote attacker to escalate privileges via a crafted PDF file. This is fixed in v9.51.
Published 2020-08-13 · Modified
7.8EPSS 0.018
CVE-2017-13194
A vulnerability in the Android media framework (libvpx) related to odd frame width. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-64710201.
Published 2018-01-12 · Modified
7.8EPSS 0.018
CVE-2019-7548
SQLAlchemy 1.2.17 has SQL Injection when the group_by parameter can be controlled.
Published 2019-02-06 · Modified
7.8EPSS 0.018
CVE-2019-3839
It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER. Ghostscript versions before 9.27 are vulnerable.
Published 2019-05-16 · Modified
7.8EPSS 0.018
CVE-2019-9854
Unsafe URL assembly flaw in allowed script location check
Published 2019-09-06 · Modified
7.8EPSS 0.018
CVE-2019-9852
Insufficient URL encoding flaw in allowed script location check
Published 2019-08-15 · Modified
7.8EPSS 0.018
CVE-2022-23946
A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon GCodeNumber parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or excellon file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
Published 2022-02-04 · Modified
7.8EPSS 0.017
CVE-2021-3778
Heap-based Buffer Overflow in vim/vim
Published 2021-09-15 · Modified
7.8EPSS 0.017
CVE-2018-16585
An issue was discovered in Artifex Ghostscript before 9.24. The .setdistillerkeys PostScript command is accepted even though it is not intended for use during document processing (e.g., after the startup phase). This leads to memory corruption, allowing remote attackers able to supply crafted PostScript to crash the interpreter or possibly have unspecified other impact. Note: A reputable source believes that the CVE is potentially a duplicate of CVE-2018-15910 as explained in Red Hat bugzilla (https://bugzilla.redhat.com/show_bug.cgi?id=1626193)
Published 2018-09-06 · Modified
7.8EPSS 0.017
CVE-2021-4192
Use After Free in vim/vim
Published 2021-12-31 · Modified
7.8EPSS 0.017
CVE-2021-3927
Heap-based Buffer Overflow in vim/vim
Published 2021-11-05 · Modified
7.8EPSS 0.017
CVE-2018-1000051
Artifex Mupdf version 1.12.0 contains a Use After Free vulnerability in fz_keep_key_storable that can result in DOS / Possible code execution. This attack appear to be exploitable via Victim opens a specially crafted PDF.
Published 2018-02-09 · Modified
7.8EPSS 0.017
CVE-2022-0261
Heap-based Buffer Overflow in vim/vim
Published 2022-01-18 · Modified
7.8EPSS 0.017
CVE-2019-1010057
nfdump 1.6.16 and earlier is affected by: Buffer Overflow. The impact is: The impact could range from a denial of service to local code execution. The component is: nfx.c:546, nffile_inline.c:83, minilzo.c (redistributed). The attack vector is: nfdump must read and process a specially crafted file. The fixed version is: after commit 9f0fe9563366f62a71d34c92229da3432ec5cf0e.
Published 2019-07-16 · Modified
7.8EPSS 0.017
CVE-2020-19667
Stack-based buffer overflow and unconditional jump in ReadXPMImage in coders/xpm.c in ImageMagick 7.0.10-7.
Published 2020-11-20 · Modified
7.8EPSS 0.017
CVE-2022-23803
A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon ReadXYCoord coordinate parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or excellon file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
Published 2022-02-16 · Modified
7.8EPSS 0.016
CVE-2022-23804
A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon ReadIJCoord coordinate parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or excellon file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
Published 2022-02-16 · Modified
7.8EPSS 0.016
CVE-2022-1851
Out-of-bounds Read in vim/vim
Published 2022-05-25 · Modified
7.8EPSS 0.016
CVE-2017-8844
The read_1g function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted archive.
Published 2017-05-08 · Modified
7.8EPSS 0.016
CVE-2022-28463
ImageMagick 7.1.0-27 is vulnerable to Buffer Overflow.
Published 2022-05-08 · Analyzed
7.8EPSS 0.016
CVE-2017-17866
pdf/pdf-write.c in Artifex MuPDF before 1.12.0 mishandles certain length changes when a repair operation occurs during a clean operation, which allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted PDF document.
Published 2017-12-23 · Modified
7.8EPSS 0.016
CVE-2021-3984
Heap-based Buffer Overflow in vim/vim
Published 2021-12-01 · Modified
7.8EPSS 0.016
CVE-2022-2126
Out-of-bounds Read in vim/vim
Published 2022-06-19 · Modified
7.8EPSS 0.016
CVE-2022-2124
Buffer Over-read in vim/vim
Published 2022-06-19 · Modified
7.8EPSS 0.016
CVE-2018-16540
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files to the builtin PDF14 converter could use a use-after-free in copydevice handling to crash the interpreter or possibly have unspecified other impact.
Published 2018-09-05 · Modified
7.8EPSS 0.016
CVE-2021-42008
The decode_data function in drivers/net/hamradio/6pack.c in the Linux kernel before 5.13.13 has a slab out-of-bounds write. Input from a process that has the CAP_NET_ADMIN capability can lead to root access.
Published 2021-10-04 · Modified
7.8EPSS 0.016
CVE-2022-0368
Out-of-bounds Read in vim/vim
Published 2022-01-26 · Modified
7.8EPSS 0.015
CVE-2019-14498
A divide-by-zero error exists in the Control function of demux/caf.c in VideoLAN VLC media player 3.0.7.1. As a result, an FPE can be triggered via a crafted CAF file.
Published 2019-08-29 · Modified
7.8EPSS 0.015
CVE-2019-14437
The xiph_SplitHeaders function in modules/demux/xiph.h in VideoLAN VLC media player 3.0.7.1 does not check array bounds properly. As a result, a heap-based buffer over-read can be triggered via a crafted .ogg file.
Published 2019-08-29 · Modified
7.8EPSS 0.015
CVE-2018-16513
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use a type confusion in the setcolor function to crash the interpreter or possibly have unspecified other impact.
Published 2018-09-05 · Modified
7.8EPSS 0.015
CVE-2021-3872
Heap-based Buffer Overflow in vim/vim
Published 2021-10-19 · Modified
7.8EPSS 0.015
CVE-2019-14535
A divide-by-zero error exists in the SeekIndex function of demux/asf/asf.c in VideoLAN VLC media player 3.0.7.1. As a result, an FPE can be triggered via a crafted WMV file.
Published 2019-08-29 · Modified
7.8EPSS 0.015
← Prev35 / 100Next →