Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 108 of 498
CVE-2020-15968P3HIGHCVSS 8.8v10.02020-11-03
CVE-2020-15968 [HIGH] CWE-416 CVE-2020-15968: Use after free in Blink in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentia
Use after free in Blink in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-21161P3HIGHCVSS 8.8v9.02021-03-09
CVE-2021-21161 [HIGH] CWE-787 CVE-2021-21161: Heap buffer overflow in TabStrip in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to
Heap buffer overflow in TabStrip in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-21213P3HIGHCVSS 8.8v10.02021-04-26
CVE-2021-21213 [HIGH] CWE-416 CVE-2021-21213: Use after free in WebMIDI in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to potent
Use after free in WebMIDI in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-32278P3HIGHCVSS 8.8v9.0v10.0+1 more2022-06-13
CVE-2022-32278 [HIGH] CVE-2022-32278: XFCE 4.16 allows attackers to execute arbitrary code because xdg-open can execute a .desktop file on
XFCE 4.16 allows attackers to execute arbitrary code because xdg-open can execute a .desktop file on an attacker-controlled FTP server.
nvd
CVE-2018-18493P3CRITICALCVSS 9.8v8.0v9.02019-02-28
CVE-2018-18493 [CRITICAL] CWE-119 CVE-2018-18493: A buffer overflow can occur in the Skia library during buffer offset calculations with hardware acce
A buffer overflow can occur in the Skia library during buffer offset calculations with hardware accelerated canvas 2D actions due to the use of 32-bit calculations instead of 64-bit. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64.
nvd
CVE-2018-10861P3HIGHCVSS 8.1v9.02018-07-10
CVE-2018-10861 [HIGH] CWE-285 CVE-2018-10861: A flaw was found in the way ceph mon handles user requests. Any authenticated ceph user having read
A flaw was found in the way ceph mon handles user requests. Any authenticated ceph user having read access to ceph can delete, create ceph storage pools and corrupt snapshot images. Ceph branches master, mimic, luminous and jewel are believed to be affected.
nvd
CVE-2022-44638P3HIGHCVSS 8.8v10.0v11.02022-11-03
CVE-2022-44638 [HIGH] CWE-190 CVE-2022-44638: In libpixman in Pixman before 0.42.2, there is an out-of-bounds write (aka heap-based buffer overflo
In libpixman in Pixman before 0.42.2, there is an out-of-bounds write (aka heap-based buffer overflow) in rasterize_edges_8 due to an integer overflow in pixman_sample_floor_y.
nvd
CVE-2021-23434P3HIGHCVSS 8.6v10.02021-08-27
CVE-2021-23434 [HIGH] CVE-2021-23434: This affects the package object-path before 0.11.6. A type confusion vulnerability can lead to a byp
This affects the package object-path before 0.11.6. A type confusion vulnerability can lead to a bypass of CVE-2020-15256 when the path components used in the path parameter are arrays. In particular, the condition currentPath === '__proto__' returns false if currentPath is ['__proto__']. This is because the === operator returns always false when the type of
nvd
CVE-2020-15967P3HIGHCVSS 8.8v10.02020-11-03
CVE-2020-15967 [HIGH] CWE-416 CVE-2020-15967: Use after free in payments in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to poten
Use after free in payments in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2021-4061P3HIGHCVSS 8.8v10.0v11.02021-12-23
CVE-2021-4061 [HIGH] CWE-843 CVE-2021-4061: Type confusion in V8 in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially
Type confusion in V8 in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-4056P3HIGHCVSS 8.8v10.0v11.02021-12-23
CVE-2021-4056 [HIGH] CWE-843 CVE-2021-4056: Type confusion in loader in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potenti
Type confusion in loader in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-37974P3HIGHCVSS 8.8v10.0v11.02021-10-08
CVE-2021-37974 [HIGH] CWE-416 CVE-2021-37974: Use after free in Safebrowsing in Google Chrome prior to 94.0.4606.71 allowed a remote attacker who
Use after free in Safebrowsing in Google Chrome prior to 94.0.4606.71 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-13692P3HIGHCVSS 7.7v10.0v11.02020-06-04
CVE-2020-13692 [HIGH] CWE-611 CVE-2020-13692: PostgreSQL JDBC Driver (aka PgJDBC) before 42.2.13 allows XXE.
PostgreSQL JDBC Driver (aka PgJDBC) before 42.2.13 allows XXE.
nvd
CVE-2021-28660P3HIGHCVSS 8.8v9.02021-03-17
CVE-2021-28660 [HIGH] CWE-787 CVE-2021-28660: rtw_wx_set_scan in drivers/staging/rtl8188eu/os_dep/ioctl_linux.c in the Linux kernel through 5.11.6
rtw_wx_set_scan in drivers/staging/rtl8188eu/os_dep/ioctl_linux.c in the Linux kernel through 5.11.6 allows writing beyond the end of the ->ssid[] array. NOTE: from the perspective of kernel.org releases, CVE IDs are not normally used for drivers/staging/* (unfinished work); however, system integrators may have situations in which a drivers/staging is
nvd
CVE-2019-14811P3HIGHCVSS 7.8v8.0v9.0+1 more2019-09-03
CVE-2019-14811 [HIGH] CWE-648 CVE-2019-14811: A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure wher
A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.
nvd
CVE-2014-2851P4MEDIUMCVSS 6.9PoCv7.02014-04-14
CVE-2014-2851 [MEDIUM] CWE-416 CVE-2014-2851: Integer overflow in the ping_init_sock function in net/ipv4/ping.c in the Linux kernel through 3.14.
Integer overflow in the ping_init_sock function in net/ipv4/ping.c in the Linux kernel through 3.14.1 allows local users to cause a denial of service (use-after-free and system crash) or possibly gain privileges via a crafted application that leverages an improperly managed reference counter.
nvd
CVE-2015-7560P3MEDIUMCVSS 6.5v7.0v8.02016-03-13
CVE-2015-7560 [MEDIUM] CWE-284 CVE-2015-7560: The SMB1 implementation in smbd in Samba 3.x and 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before
The SMB1 implementation in smbd in Samba 3.x and 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4 allows remote authenticated users to modify arbitrary ACLs by using a UNIX SMB1 call to create a symlink, and then using a non-UNIX SMB1 call to write to the ACL content.
nvd
CVE-2023-5854P3HIGHCVSS 8.8v11.0v12.02023-11-01
CVE-2023-5854 [HIGH] CWE-416 CVE-2023-5854: Use after free in Profiles in Google Chrome prior to 119.0.6045.105 allowed a remote attacker who co
Use after free in Profiles in Google Chrome prior to 119.0.6045.105 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via specific UI gestures. (Chromium security severity: Medium)
nvd
CVE-2023-2137P3HIGHCVSS 8.8v11.02023-04-19
CVE-2023-2137 [HIGH] CWE-787 CVE-2023-2137: Heap buffer overflow in sqlite in Google Chrome prior to 112.0.5615.137 allowed a remote attacker to
Heap buffer overflow in sqlite in Google Chrome prior to 112.0.5615.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2015-2808P3LOWCVSS 3.7v7.0v8.02015-04-01
CVE-2015-2808 [LOW] CWE-327 CVE-2015-2808: The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state dat
The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recovery attacks against the initial bytes of a stream by sniffing network traffic that occasionally relies on keys affected by the Invariance
nvd