Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 109 of 498
CVE-2018-20433P3CRITICALCVSS 9.8v8.02018-12-24
CVE-2018-20433 [CRITICAL] CWE-611 CVE-2018-20433: c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p0/cfg/C3P0ConfigXmlU
c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java during initialization.
nvd
CVE-2023-1810P3HIGHCVSS 8.8v11.02023-04-04
CVE-2023-1810 [HIGH] CWE-787 CVE-2023-1810: Heap buffer overflow in Visuals in Google Chrome prior to 112.0.5615.49 allowed a remote attacker wh
Heap buffer overflow in Visuals in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2020-7067P3HIGHCVSS 7.5v9.0v10.02020-04-27
CVE-2020-7067 [HIGH] CWE-125 CVE-2020-7067: In PHP versions 7.2.x below 7.2.30, 7.3.x below 7.3.17 and 7.4.x below 7.4.5, if PHP is compiled wit
In PHP versions 7.2.x below 7.2.30, 7.3.x below 7.3.17 and 7.4.x below 7.4.5, if PHP is compiled with EBCDIC support (uncommon), urldecode() function can be made to access locations past the allocated memory, due to erroneously using signed numbers as array indexes.
nvd
CVE-2023-2134P3HIGHCVSS 8.8v11.02023-04-19
CVE-2023-2134 [HIGH] CWE-787 CVE-2023-2134: Out of bounds memory access in Service Worker API in Google Chrome prior to 112.0.5615.137 allowed a
Out of bounds memory access in Service Worker API in Google Chrome prior to 112.0.5615.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-2133P3HIGHCVSS 8.8v11.02023-04-19
CVE-2023-2133 [HIGH] CWE-787 CVE-2023-2133: Out of bounds memory access in Service Worker API in Google Chrome prior to 112.0.5615.137 allowed a
Out of bounds memory access in Service Worker API in Google Chrome prior to 112.0.5615.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-5852P3HIGHCVSS 8.8v11.0v12.02023-11-01
CVE-2023-5852 [HIGH] CWE-416 CVE-2023-5852: Use after free in Printing in Google Chrome prior to 119.0.6045.105 allowed a remote attacker who co
Use after free in Printing in Google Chrome prior to 119.0.6045.105 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via specific UI gestures. (Chromium security severity: Medium)
nvd
CVE-2023-5855P3HIGHCVSS 8.8v11.0v12.02023-11-01
CVE-2023-5855 [HIGH] CWE-416 CVE-2023-5855: Use after free in Reading Mode in Google Chrome prior to 119.0.6045.105 allowed a remote attacker wh
Use after free in Reading Mode in Google Chrome prior to 119.0.6045.105 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via specific UI gestures. (Chromium security severity: Medium)
nvd
CVE-2023-6509P3HIGHCVSS 8.8v11.0v12.02023-12-06
CVE-2023-6509 [HIGH] CWE-416 CVE-2023-6509: Use after free in Side Panel Search in Google Chrome prior to 120.0.6099.62 allowed a remote attacke
Use after free in Side Panel Search in Google Chrome prior to 120.0.6099.62 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via specific UI interaction. (Chromium security severity: High)
nvd
CVE-2023-3214P3HIGHCVSS 8.8v11.0v12.02023-06-13
CVE-2023-3214 [HIGH] CWE-416 CVE-2023-3214: Use after free in Autofill payments in Google Chrome prior to 114.0.5735.133 allowed a remote attack
Use after free in Autofill payments in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2019-9506P3HIGHCVSS 8.1v8.02019-08-14
CVE-2019-9506 [HIGH] CWE-310 CVE-2019-9506: The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encrypti
The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka "KNOB") that can decrypt traffic and inject arbitrary ciphertext without the victim noticing.
nvd
CVE-2023-1812P3HIGHCVSS 8.8v11.02023-04-04
CVE-2023-1812 [HIGH] CWE-787 CVE-2023-1812: Out of bounds memory access in DOM Bindings in Google Chrome prior to 112.0.5615.49 allowed a remote
Out of bounds memory access in DOM Bindings in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-4353P3HIGHCVSS 8.8v11.0v12.02023-08-15
CVE-2023-4353 [HIGH] CWE-787 CVE-2023-4353: Heap buffer overflow in ANGLE in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to p
Heap buffer overflow in ANGLE in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2016-2377P3HIGHCVSS 8.1v8.02017-01-06
CVE-2016-2377 [HIGH] CWE-119 CVE-2016-2377: A buffer overflow vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially cra
A buffer overflow vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent by the server could potentially result in an out-of-bounds write of one byte. A malicious server can send a negative content-length in response to a HTTP request triggering the vulnerability.
nvd
CVE-2019-6978P3CRITICALCVSS 9.8v8.0v9.02019-01-28
CVE-2019-6978 [CRITICAL] CWE-415 CVE-2019-6978: The GD Graphics Library (aka LibGD) 2.2.5 has a double free in the gdImage*Ptr() functions in gd_gif
The GD Graphics Library (aka LibGD) 2.2.5 has a double free in the gdImage*Ptr() functions in gd_gif_out.c, gd_jpeg.c, and gd_wbmp.c. NOTE: PHP is unaffected.
nvd
CVE-2016-3710P3HIGHCVSS 8.8v8.02016-05-11
CVE-2016-3710 [HIGH] CWE-119 CVE-2016-3710: The VGA module in QEMU improperly performs bounds checking on banked access to video memory, which a
The VGA module in QEMU improperly performs bounds checking on banked access to video memory, which allows local guest OS administrators to execute arbitrary code on the host by changing access modes after setting the bank register, aka the "Dark Portal" issue.
nvd
CVE-2023-1818P3HIGHCVSS 8.8v11.02023-04-04
CVE-2023-1818 [HIGH] CWE-416 CVE-2023-1818: Use after free in Vulkan in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to potent
Use after free in Vulkan in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-2721P3HIGHCVSS 8.8v11.02023-05-16
CVE-2023-2721 [HIGH] CWE-416 CVE-2023-2721: Use after free in Navigation in Google Chrome prior to 113.0.5672.126 allowed a remote attacker to p
Use after free in Navigation in Google Chrome prior to 113.0.5672.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2023-2722P3HIGHCVSS 8.8v11.02023-05-16
CVE-2023-2722 [HIGH] CWE-416 CVE-2023-2722: Use after free in Autofill UI in Google Chrome on Android prior to 113.0.5672.126 allowed a remote a
Use after free in Autofill UI in Google Chrome on Android prior to 113.0.5672.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-0750P3HIGHCVSS 8.8v10.02024-01-23
CVE-2024-0750 [HIGH] CWE-451 CVE-2024-0750: A bug in popup notifications delay calculation could have made it possible for an attacker to trick
A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
nvd
CVE-2023-6207P3HIGHCVSS 8.8v10.0v11.0+1 more2023-11-21
CVE-2023-6207 [HIGH] CWE-416 CVE-2023-6207: Ownership mismanagement led to a use-after-free in ReadableByteStreams This vulnerability affects Fi
Ownership mismanagement led to a use-after-free in ReadableByteStreams This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
nvd