Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 118 of 498
CVE-2023-6858P3HIGHCVSS 8.8v10.0v11.0+1 more2023-12-19
CVE-2023-6858 [HIGH] CWE-787 CVE-2023-6858: Firefox was susceptible to a heap buffer overflow in `nsTextFragment` due to insufficient OOM handli
Firefox was susceptible to a heap buffer overflow in `nsTextFragment` due to insufficient OOM handling. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
nvd
CVE-2019-5809P3HIGHCVSS 8.8v10.02019-06-27
CVE-2019-5809 [HIGH] CWE-416 CVE-2019-5809: Use after free in file chooser in Google Chrome prior to 74.0.3729.108 allowed a remote attacker who
Use after free in file chooser in Google Chrome prior to 74.0.3729.108 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page.
nvd
CVE-2018-16515P3HIGHCVSS 8.8v8.02018-09-18
CVE-2018-16515 [HIGH] CWE-347 CVE-2018-16515: Matrix Synapse before 0.33.3.1 allows remote attackers to spoof events and possibly have unspecified
Matrix Synapse before 0.33.3.1 allows remote attackers to spoof events and possibly have unspecified other impacts by leveraging improper transaction and event signature validation.
nvd
CVE-2020-6553P3HIGHCVSS 8.8v10.02020-09-21
CVE-2020-6553 [HIGH] CWE-416 CVE-2020-6553: Use after free in offline mode in Google Chrome on iOS prior to 84.0.4147.125 allowed a remote attac
Use after free in offline mode in Google Chrome on iOS prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6552P3HIGHCVSS 8.8v10.02020-09-21
CVE-2020-6552 [HIGH] CWE-416 CVE-2020-6552: Use after free in Blink in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potenti
Use after free in Blink in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-16004P3HIGHCVSS 8.8v10.02020-11-03
CVE-2020-16004 [HIGH] CWE-416 CVE-2020-16004: Use after free in user interface in Google Chrome prior to 86.0.4240.183 allowed a remote attacker t
Use after free in user interface in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-15978P3HIGHCVSS 8.8v10.02020-11-03
CVE-2020-15978 [HIGH] CWE-20 CVE-2020-15978: Insufficient data validation in navigation in Google Chrome on Android prior to 86.0.4240.75 allowed
Insufficient data validation in navigation in Google Chrome on Android prior to 86.0.4240.75 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2019-5774P3HIGHCVSS 8.8v9.02019-02-19
CVE-2019-5774 [HIGH] CWE-862 CVE-2019-5774: Omission of the .desktop filetype from the Safe Browsing checklist in SafeBrowsing in Google Chrome
Omission of the .desktop filetype from the Safe Browsing checklist in SafeBrowsing in Google Chrome on Linux prior to 72.0.3626.81 allowed an attacker who convinced a user to download a .desktop file to execute arbitrary code via a downloaded .desktop file.
nvd
CVE-2020-6540P3HIGHCVSS 8.8v10.02020-09-21
CVE-2020-6540 [HIGH] CWE-787 CVE-2020-6540: Buffer overflow in Skia in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potenti
Buffer overflow in Skia in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-22029P3HIGHCVSS 8.8v10.02021-05-27
CVE-2020-22029 [HIGH] CWE-787 CVE-2020-22029: A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 at libavfilter/vf_colorconstancy.c:
A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 at libavfilter/vf_colorconstancy.c: in slice_get_derivative, which crossfade_samples_fltp, which might lead to memory corruption and other potential consequences.
nvd
CVE-2020-16003P3HIGHCVSS 8.8v10.02020-11-03
CVE-2020-16003 [HIGH] CWE-416 CVE-2020-16003: Use after free in printing in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to pote
Use after free in printing in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-21192P3HIGHCVSS 8.8v10.02021-03-16
CVE-2021-21192 [HIGH] CWE-787 CVE-2021-21192: Heap buffer overflow in tab groups in Google Chrome prior to 89.0.4389.90 allowed a remote attacker
Heap buffer overflow in tab groups in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-21113P3HIGHCVSS 8.8v10.02021-01-08
CVE-2021-21113 [HIGH] CWE-787 CVE-2021-21113: Heap buffer overflow in Skia in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to po
Heap buffer overflow in Skia in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2018-6033P3HIGHCVSS 8.8v8.0v9.02018-09-25
CVE-2018-6033 [HIGH] CWE-20 CVE-2018-6033: Insufficient data validation in Downloads in Google Chrome prior to 64.0.3282.119 allowed a remote a
Insufficient data validation in Downloads in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially run arbitrary code outside sandbox via a crafted Chrome Extension.
nvd
CVE-2017-5660P3HIGHCVSS 8.6v9.02018-02-27
CVE-2017-5660 [HIGH] CWE-20 CVE-2017-5660: There is a vulnerability in Apache Traffic Server (ATS) 6.2.0 and prior and 7.0.0 and prior with the
There is a vulnerability in Apache Traffic Server (ATS) 6.2.0 and prior and 7.0.0 and prior with the Host header and line folding. This can have issues when interacting with upstream proxies and the wrong host being used.
nvd
CVE-2021-37970P3HIGHCVSS 8.8v10.0v11.02021-10-08
CVE-2021-37970 [HIGH] CWE-416 CVE-2021-37970: Use after free in File System API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker t
Use after free in File System API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-25314P3HIGHCVSS 7.5v10.0v11.02022-02-18
CVE-2022-25314 [HIGH] CWE-190 CVE-2022-25314: In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.
nvd
CVE-2021-21116P3HIGHCVSS 8.8v10.02021-01-08
CVE-2021-21116 [HIGH] CWE-787 CVE-2021-21116: Heap buffer overflow in audio in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to p
Heap buffer overflow in audio in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-4062P3HIGHCVSS 8.8v10.0v11.02021-12-23
CVE-2021-4062 [HIGH] CWE-787 CVE-2021-4062: Heap buffer overflow in BFCache in Google Chrome prior to 96.0.4664.93 allowed a remote attacker who
Heap buffer overflow in BFCache in Google Chrome prior to 96.0.4664.93 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-21169P3HIGHCVSS 8.8v10.02021-03-09
CVE-2021-21169 [HIGH] CWE-787 CVE-2021-21169: Out of bounds memory access in V8 in Google Chrome prior to 89.0.4389.72 allowed a remote attacker t
Out of bounds memory access in V8 in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
nvd