Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 103 of 498
CVE-2023-4147P3HIGHCVSS 7.8v10.0v11.0+1 more2023-08-07
CVE-2023-4147 [HIGH] CWE-416 CVE-2023-4147: A use-after-free flaw was found in the Linux kernel’s Netfilter functionality when adding a rule wit
A use-after-free flaw was found in the Linux kernel’s Netfilter functionality when adding a rule with NFTA_RULE_CHAIN_ID. This flaw allows a local user to crash or escalate their privileges on the system.
nvd
CVE-2022-47629P3CRITICALCVSS 9.8v10.0v11.02022-12-20
CVE-2022-47629 [CRITICAL] CWE-190 CVE-2022-47629: Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL signature parser.
Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL signature parser.
nvd
CVE-2021-21216P3MEDIUMCVSS 6.5v10.02021-04-26
CVE-2021-21216 [MEDIUM] CWE-290 CVE-2021-21216: Inappropriate implementation in Autofill in Google Chrome prior to 90.0.4430.72 allowed a remote att
Inappropriate implementation in Autofill in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to spoof security UI via a crafted HTML page.
nvd
CVE-2023-5730P3CRITICALCVSS 9.8v10.0v11.02023-10-25
CVE-2023-5730 [CRITICAL] CWE-787 CVE-2023-5730: Memory safety bugs present in Firefox 118, Firefox ESR 115.3, and Thunderbird 115.3. Some of these b
Memory safety bugs present in Firefox 118, Firefox ESR 115.3, and Thunderbird 115.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
nvd
CVE-2020-11620P3HIGHCVSS 8.1v8.02020-04-07
CVE-2020-11620 [HIGH] CWE-502 CVE-2020-11620: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadg
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.jelly.impl.Embedded (aka commons-jelly).
nvd
CVE-2019-9024P3HIGHCVSS 7.5v9.02019-02-22
CVE-2019-9024 [HIGH] CWE-125 CVE-2019-9024: An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x befo
An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. xmlrpc_decode() can allow a hostile XMLRPC server to cause PHP to read memory outside of allocated areas in base64_decode_xmlrpc in ext/xmlrpc/libxmlrpc/base64.c.
nvd
CVE-2018-5104P3CRITICALCVSS 9.8v7.0v8.0+1 more2018-06-11
CVE-2018-5104 [CRITICAL] CWE-416 CVE-2018-5104: A use-after-free vulnerability can occur during font face manipulation when a font face is freed whi
A use-after-free vulnerability can occur during font face manipulation when a font face is freed while still in use, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.
nvd
CVE-2022-26306P3HIGHCVSS 7.5v10.02022-07-25
CVE-2022-26306 [HIGH] CWE-326 CVE-2022-26306: LibreOffice supports the storage of passwords for web connections in the user’s configuration databa
LibreOffice supports the storage of passwords for web connections in the user’s configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in LibreOffice existed where the required initialization vector for encryption was always the same which weakens the security of the encryption making them vuln
nvd
CVE-2020-27153P3HIGHCVSS 8.6v9.0v10.02020-10-15
CVE-2020-27153 [HIGH] CWE-415 CVE-2020-27153: In BlueZ before 5.55, a double free was found in the gatttool disconnect_cb() routine from shared/at
In BlueZ before 5.55, a double free was found in the gatttool disconnect_cb() routine from shared/att.c. A remote attacker could potentially cause a denial of service or code execution, during service discovery, due to a redundant disconnect MGMT event.
nvd
CVE-2018-1000027P3HIGHCVSS 7.5v7.0v8.0+1 more2018-02-09
CVE-2018-1000027 [HIGH] CWE-476 CVE-2018-1000027: The Squid Software Foundation Squid HTTP Caching Proxy version prior to version 4.0.23 contains a NU
The Squid Software Foundation Squid HTTP Caching Proxy version prior to version 4.0.23 contains a NULL Pointer Dereference vulnerability in HTTP Response X-Forwarded-For header processing that can result in Denial of Service to all clients of the proxy. This attack appear to be exploitable via Remote HTTP server responding with an X-Forwarded-For
nvd
CVE-2018-5102P3CRITICALCVSS 9.8v7.0v8.0+1 more2018-06-11
CVE-2018-5102 [CRITICAL] CWE-416 CVE-2018-5102: A use-after-free vulnerability can occur when manipulating HTML media elements with media streams, r
A use-after-free vulnerability can occur when manipulating HTML media elements with media streams, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.
nvd
CVE-2020-6522P3CRITICALCVSS 9.6v10.02020-07-22
CVE-2020-6522 [CRITICAL] CVE-2020-6522: Inappropriate implementation in external protocol handlers in Google Chrome prior to 84.0.4147.89 al
Inappropriate implementation in external protocol handlers in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2020-8112P3HIGHCVSS 8.8v8.02020-01-28
CVE-2020-8112 [HIGH] CVE-2020-8112: opj_t1_clbl_decode_processor in openjp2/t1.c in OpenJPEG 2.3.1 through 2020-01-28 has a heap-based b
opj_t1_clbl_decode_processor in openjp2/t1.c in OpenJPEG 2.3.1 through 2020-01-28 has a heap-based buffer overflow in the qmfbid==1 case, a different issue than CVE-2020-6851.
nvd
CVE-2020-6465P3CRITICALCVSS 9.6v9.0v10.02020-05-21
CVE-2020-6465 [CRITICAL] CWE-416 CVE-2020-6465: Use after free in reader mode in Google Chrome on Android prior to 83.0.4103.61 allowed a remote att
Use after free in reader mode in Google Chrome on Android prior to 83.0.4103.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2013-2870P3CRITICALCVSS 9.3v7.02013-07-10
CVE-2013-2870 [CRITICAL] CWE-399 CVE-2013-2870: Use-after-free vulnerability in Google Chrome before 28.0.1500.71 allows remote servers to execute a
Use-after-free vulnerability in Google Chrome before 28.0.1500.71 allows remote servers to execute arbitrary code via crafted response traffic after a URL request.
nvd
CVE-2017-16227P3HIGHCVSS 7.5v8.0v9.02017-10-29
CVE-2017-16227 [HIGH] CWE-20 CVE-2017-16227: The aspath_put function in bgpd/bgp_aspath.c in Quagga before 1.2.2 allows remote attackers to cause
The aspath_put function in bgpd/bgp_aspath.c in Quagga before 1.2.2 allows remote attackers to cause a denial of service (session drop) via BGP UPDATE messages, because AS_PATH size calculation for long paths counts certain bytes twice and consequently constructs an invalid message.
nvd
CVE-2019-18345P3CRITICALCVSS 9.3v8.0v9.0+1 more2019-12-12
CVE-2019-18345 [CRITICAL] CWE-79 CVE-2019-18345: A reflected XSS issue was discovered in DAViCal through 1.1.8. It echoes the action parameter withou
A reflected XSS issue was discovered in DAViCal through 1.1.8. It echoes the action parameter without encoding. If a user visits an attacker-supplied link, the attacker can view all data the attacked user can view, as well as perform all actions in the name of the user. If the user is an administrator, the attacker can for example add a new admin u
nvd
CVE-2020-15961P3CRITICALCVSS 9.6v10.02020-09-21
CVE-2020-15961 [CRITICAL] CVE-2020-15961: Insufficient policy validation in extensions in Google Chrome prior to 85.0.4183.121 allowed an atta
Insufficient policy validation in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
nvd
CVE-2012-1096P4MEDIUMCVSS 5.5PoCv8.0v9.0+1 more2020-03-10
CVE-2012-1096 [MEDIUM] CWE-295 CVE-2012-1096: NetworkManager 0.9 and earlier allows local users to use other users' certificates or private keys w
NetworkManager 0.9 and earlier allows local users to use other users' certificates or private keys when making a connection via the file path when adding a new connection.
nvd
CVE-2014-8158P3MEDIUMCVSS 6.8v7.02015-01-26
CVE-2014-8158 [MEDIUM] CWE-119 CVE-2014-8158: Multiple stack-based buffer overflows in jpc_qmfb.c in JasPer 1.900.1 and earlier allow remote attac
Multiple stack-based buffer overflows in jpc_qmfb.c in JasPer 1.900.1 and earlier allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted JPEG 2000 image.
nvd