VulnSea

debian_linux vulnerabilities

CVEs whose affected-version data names the debian_linux package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

181 CVEsRSS

CVE-2023-6377High· 7.8
2y ago

A flaw was found in xorg-server

A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory reads and writes. This may allow local privilege escalation or possible remote code exe…

Twilightx.org · x_serverEPSS 1.6%via NVD
CVE-2023-46850Critical· 9.8
2y ago

Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending network buffers to a remote peer.

Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending network buffers to a remote peer.

Midnightopenvpn · openvpnEPSS 2.0%via NVD
CVE-2023-46734Medium· 6.1
2y ago

Symfony is a PHP framework for web and console applications and a set of reusable PHP components

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 2.0.0, 5.0.0, and 6.0.0 and prior to versions 4.4.51, 5.4.31, and 6.3.8, some Twig filters in CodeExtension use `is_sa…

Sunlitsensiolabs · symfonyEPSS 0.68%via NVD
CVE-2023-5380Medium· 4.7
2y ago

A use-after-free flaw was found in the xorg-x11-server

A use-after-free flaw was found in the xorg-x11-server. An X server crash may occur in a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode) if the pointer is warped fro…

Sunlitx.org · x_serverEPSS 0.71%via NVD
CVE-2023-5367High· 7.8
2y ago

A out-of-bounds write flaw was found in the xorg-x11-server

A out-of-bounds write flaw was found in the xorg-x11-server. This issue occurs due to an incorrect calculation of a buffer offset when copying data stored in the heap in the XIChangeDeviceProperty function in Xi/xiproperty.c and in RRCha…

Twilightx.org · x_serverEPSS 0.62%via NVD
CVE-2023-42753High· 7.0
2y ago

An array indexing vulnerability was found in the netfilter subsystem of the Linux kernel

An array indexing vulnerability was found in the netfilter subsystem of the Linux kernel. A missing macro could lead to a miscalculation of the `h->nets` array offset, providing attackers with the primitive to arbitrarily increment/decre…

Twilightlinux · linux_kernelEPSS 0.51%via NVD
CVE-2023-4622High· 7.8PoC
3y ago

A use-after-free vulnerability in the Linux kernel's af_unix component can be exploited to achieve local privilege escalation. The unix_stream_sendpage() function tries to add data to the last skb in the peer's recv queue without lock…

A use-after-free vulnerability in the Linux kernel's af_unix component can be exploited to achieve local privilege escalation. The unix_stream_sendpage() function tries to add data to the last skb in the peer's recv queue without lock…

Midnightlinux · linux_kernelEPSS 0.61%via NVD
CVE-2023-4244High· 7.8
3y ago

A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. Due to a race condition between nf_tables netlink control plane transaction and nft_set elemen…

A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. Due to a race condition between nf_tables netlink control plane transaction and nft_set elemen…

Twilightlinux · linux_kernelEPSS 0.24%via NVD
CVE-2023-4781High· 7.8
3y ago

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1873.

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1873.

Twilightneovim · neovimEPSS 0.61%via NVD
CVE-2023-4752High· 7.8
3y ago

Use After Free in GitHub repository vim/vim prior to 9.0.1858.

Use After Free in GitHub repository vim/vim prior to 9.0.1858.

Twilightneovim · neovimEPSS 0.56%via NVD
CVE-2023-4738High· 7.8
3y ago

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1848.

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1848.

Twilightneovim · neovimEPSS 0.60%via NVD
CVE-2020-19189Medium· 6.5
3y ago

Buffer Overflow vulnerability in postprocess_terminfo function in tinfo/parse_entry.c:997 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.

Buffer Overflow vulnerability in postprocess_terminfo function in tinfo/parse_entry.c:997 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.

Sunlitinvisible-island · ncursesEPSS 2.2%via NVD
CVE-2022-48174Critical· 9.8
3y ago

There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35

There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be executed from command to arbitrary code execution.

Midnightbusybox · busyboxEPSS 3.2%via NVD
CVE-2023-38559Medium· 5.5
3y ago

A buffer overflow flaw was found in base/gdevdevn.c:1973 in devn_pcx_write_rle() in ghostscript

A buffer overflow flaw was found in base/gdevdevn.c:1973 in devn_pcx_write_rle() in ghostscript. This issue may allow a local attacker to cause a denial of service via outputting a crafted PDF file for a DEVN device with gs.

Sunlitartifex · ghostscriptEPSS 0.43%via NVD
CVE-2023-3609High· 7.8PoC
3y ago

A use-after-free vulnerability in the Linux kernel's net/sched: cls_u32 component can be exploited to achieve local privilege escalation. If tcf_change_indev() fails, u32_set_parms() will immediately return an error after incrementing…

A use-after-free vulnerability in the Linux kernel's net/sched: cls_u32 component can be exploited to achieve local privilege escalation. If tcf_change_indev() fails, u32_set_parms() will immediately return an error after incrementing…

Midnightlinux · linux_kernelEPSS 0.45%via NVD
CVE-2023-36664High· 7.8PoC
3y ago

Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).

Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).

Midnightartifex · ghostscriptEPSS 4.2%via NVD
CVE-2023-35823High· 7.0
3y ago

An issue was discovered in the Linux kernel before 6.3.2

An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in saa7134_finidev in drivers/media/pci/saa7134/saa7134-core.c.

Twilightlinux · linux_kernelEPSS 0.20%via NVD
CVE-2023-3268High· 7.1
3y ago

An out of bounds (OOB) memory access flaw was found in the Linux kernel in relay_file_read_start_pos in kernel/relay.c in the relayfs

An out of bounds (OOB) memory access flaw was found in the Linux kernel in relay_file_read_start_pos in kernel/relay.c in the relayfs. This flaw could allow a local attacker to crash the system or leak kernel internal information.

Twilightlinux · linux_kernelEPSS 0.48%via NVD
CVE-2023-1380High· 7.1
3y ago

A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux Kernel

A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux Kernel. This issue could occur when assoc_info->req_len data is bigger than the size of the buf…

Twilightredhat · enterprise_linuxEPSS 17%via NVD
CVE-2023-1175Medium· 6.6
3y ago

Incorrect Calculation of Buffer Size in GitHub repository vim/vim prior to 9.0.1378.

Incorrect Calculation of Buffer Size in GitHub repository vim/vim prior to 9.0.1378.

Sunlitneovim · neovimEPSS 0.45%via NVD
CVE-2022-2196Medium· 5.8
3y ago

A regression exists in the Linux Kernel within KVM: nVMX that allowed for speculative execution attacks. L2 can carry out Spectre v2 attacks on L1 due to L1 thinking it doesn't need retpolines or IBPB after running L2 due to KVM (L0) adv…

A regression exists in the Linux Kernel within KVM: nVMX that allowed for speculative execution attacks. L2 can carry out Spectre v2 attacks on L1 due to L1 thinking it doesn't need retpolines or IBPB after running L2 due to KVM (L0) adv…

Sunlitlinux · linux_kernelEPSS 0.29%via NVD
CVE-2022-3636Medium· 5.5
3y ago

A vulnerability was identified in Linux Kernel 33fc42de33278b2b3ec6f3390512987bc29a62b7

A vulnerability was identified in Linux Kernel 33fc42de33278b2b3ec6f3390512987bc29a62b7. This affects the function __mtk_ppe_check_skb of the file drivers/net/ethernet/mediatek/mtk_ppe.c of the component Ethernet Handler. Such manipulati…

Sunlitlinux · linux_kernelEPSS 0.34%via NVD
CVE-2022-38178High· 7.5
4y ago

By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small memory leak

By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.

Twilightisc · bindEPSS 3.0%via NVD
CVE-2022-38177High· 7.5
4y ago

By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak

By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.

Twilightisc · bindEPSS 3.2%via NVD
CVE-2022-2795Medium· 5.3
4y ago

By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver's performance, effectively denying legitimate clients access to the DNS resolution service.

By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver's performance, effectively denying legitimate clients access to the DNS resolution service.

Sunlitisc · bindEPSS 2.2%via NVD
CVE-2022-38266Medium· 6.5
4y ago

An issue in the Leptonica linked library (v1.79.0) allows attackers to cause an arithmetic exception leading to a Denial of Service (DoS) via a crafted JPEG file.

An issue in the Leptonica linked library (v1.79.0) allows attackers to cause an arithmetic exception leading to a Denial of Service (DoS) via a crafted JPEG file.

Sunlittesseract-ocr · tesseract_ocrEPSS 1.4%via NVD
CVE-2021-4037Medium· 4.4
4y ago

A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create files for the XFS file-system with an unintended group ownership and with group execution and SGID permis…

A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create files for the XFS file-system with an unintended group ownership and with group execution and SGID permis…

Sunlitlinux · linux_kernelEPSS 0.31%via NVD
CVE-2022-37434Critical· 9.8PoC⚖ disputed
4y ago

zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field

zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the af…

Abyssalzlib · zlibEPSS 18%via NVD
CVE-2022-1734High· 7.0
4y ago

A flaw in Linux Kernel found in nfcmrvl_nci_unregister_dev() in drivers/nfc/nfcmrvl/main.c can lead to use after free both read or write when non synchronized between cleanup routine and firmware download routine.

A flaw in Linux Kernel found in nfcmrvl_nci_unregister_dev() in drivers/nfc/nfcmrvl/main.c can lead to use after free both read or write when non synchronized between cleanup routine and firmware download routine.

Twilightlinux · linux_kernelEPSS 0.53%via NVD
CVE-2022-30333High· 7.5CISA KEVPoC
4y ago

RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file

RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected.

Abyssalrarlab · unrarEPSS 99%via NVD
debian_linux vulnerabilities (CVEs) — page 3 · VulnSea