cbcvebase.

Debian Linux vulnerabilities

9,953 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358

Vulnerabilities

Page 128 of 498
CVE-2021-41991P3HIGHCVSS 7.5v9.0v10.0+1 more2021-10-18
CVE-2021-41991 [HIGH] CWE-190 CVE-2021-41991: The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiv The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to fill the cache and later trigger the replacement of cache entries. The code attempts to select a less-often-used cache entry by means of a random number generator, but this is not done correctly. Remote c
nvd
CVE-2016-1673P3HIGHCVSS 8.8v8.02016-06-05
CVE-2016-1673 [HIGH] CVE-2016-1673: Blink, as used in Google Chrome before 51.0.2704.63, allows remote attackers to bypass the Same Orig Blink, as used in Google Chrome before 51.0.2704.63, allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
nvd
CVE-2017-1000115P3HIGHCVSS 7.5v8.0v9.02017-10-05
CVE-2017-1000115 [HIGH] CWE-59 CVE-2017-1000115: Mercurial prior to version 4.3 is vulnerable to a missing symlink check that can malicious repositor Mercurial prior to version 4.3 is vulnerable to a missing symlink check that can malicious repositories to modify files outside the repository
nvd
CVE-2021-28706P3HIGHCVSS 8.6v11.02021-11-24
CVE-2021-28706 [HIGH] CWE-770 CVE-2021-28706: guests may exceed their designated memory limit When a guest is permitted to have close to 16TiB of guests may exceed their designated memory limit When a guest is permitted to have close to 16TiB of memory, it may be able to issue hypercalls to increase its memory allocation beyond the administrator established limit. This is a result of a calculation done with 32-bit precision, which may overflow. It would then only be the overflowed (and hence sma
nvd
CVE-2018-6083P3HIGHCVSS 8.8v9.02018-11-14
CVE-2018-6083 [HIGH] CVE-2018-6083: Failure to disallow PWA installation from CSP sandboxed pages in AppManifest in Google Chrome prior Failure to disallow PWA installation from CSP sandboxed pages in AppManifest in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to access privileged APIs via a crafted HTML page.
nvd
CVE-2018-0739P3MEDIUMCVSS 6.5v7.0v8.0+1 more2018-03-27
CVE-2018-0739 [MEDIUM] CWE-674 CVE-2018-0739: Constructed ASN.1 types with a recursive definition (such as can be found in PKCS7) could eventually Constructed ASN.1 types with a recursive definition (such as can be found in PKCS7) could eventually exceed the stack given malicious input with excessive recursion. This could result in a Denial Of Service attack. There are no such structures used within SSL/TLS that come from untrusted sources so this is considered safe. Fixed in OpenSSL 1.1.0h (Aff
nvd
CVE-2008-1887P3CRITICALCVSS 9.3v4.02008-04-18
CVE-2008-1887 [CRITICAL] CWE-120 CVE-2008-1887: Python 2.5.2 and earlier allows context-dependent attackers to execute arbitrary code via multiple v Python 2.5.2 and earlier allows context-dependent attackers to execute arbitrary code via multiple vectors that cause a negative size value to be provided to the PyString_FromStringAndSize function, which allocates less memory than expected when assert() is disabled and triggers a buffer overflow.
nvd
CVE-2018-6067P3HIGHCVSS 8.8v9.02018-11-14
CVE-2018-6067 [HIGH] CWE-125 CVE-2018-6067: Incorrect IPC serialization in Skia in Google Chrome prior to 65.0.3325.146 allowed a remote attacke Incorrect IPC serialization in Skia in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2018-6063P3HIGHCVSS 8.8v9.02018-11-14
CVE-2018-6063 [HIGH] CWE-787 CVE-2018-6063: Incorrect use of mojo::WrapSharedMemoryHandle in Mojo in Google Chrome prior to 65.0.3325.146 allowe Incorrect use of mojo::WrapSharedMemoryHandle in Mojo in Google Chrome prior to 65.0.3325.146 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted HTML page.
nvd
CVE-2020-22027P3HIGHCVSS 8.8v10.02021-05-27
CVE-2020-22027 [HIGH] CWE-787 CVE-2020-22027: A heap-based Buffer Overflow vulnerability exits in FFmpeg 4.2 in deflate16 at libavfilter/vf_neighb A heap-based Buffer Overflow vulnerability exits in FFmpeg 4.2 in deflate16 at libavfilter/vf_neighbor.c, which might lead to memory corruption and other potential consequences.
nvd
CVE-2021-21174P3HIGHCVSS 8.8v10.02021-03-09
CVE-2021-21174 [HIGH] CVE-2021-21174: Inappropriate implementation in Referrer in Google Chrome prior to 89.0.4389.72 allowed a remote att Inappropriate implementation in Referrer in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2020-15976P3HIGHCVSS 8.8v10.02020-11-03
CVE-2020-15976 [HIGH] CWE-416 CVE-2020-15976: Use after free in WebXR in Google Chrome on Android prior to 86.0.4240.75 allowed a remote attacker Use after free in WebXR in Google Chrome on Android prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-22023P3HIGHCVSS 8.8v9.0v10.02021-05-27
CVE-2020-22023 [HIGH] CWE-787 CVE-2020-22023: A heap-based Buffer Overflow vulnerabililty exists in FFmpeg 4.2 in filter_frame at libavfilter/vf_b A heap-based Buffer Overflow vulnerabililty exists in FFmpeg 4.2 in filter_frame at libavfilter/vf_bitplanenoise.c, which might lead to memory corruption and other potential consequences.
nvd
CVE-2019-17596P3HIGHCVSS 7.5v9.0v10.02019-10-24
CVE-2019-17596 [HIGH] CWE-436 CVE-2019-17596: Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic conta Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that verifies client certificates.
nvd
CVE-2020-15992P3HIGHCVSS 8.8v10.02020-11-03
CVE-2020-15992 [HIGH] CVE-2020-15992: Insufficient policy enforcement in networking in Google Chrome prior to 86.0.4240.75 allowed a remot Insufficient policy enforcement in networking in Google Chrome prior to 86.0.4240.75 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page.
nvd
CVE-2020-22017P3HIGHCVSS 8.8v10.02021-05-27
CVE-2020-22017 [HIGH] CWE-787 CVE-2020-22017: A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 at ff_fill_rectangle in libavfilter/ A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 at ff_fill_rectangle in libavfilter/drawutils.c, which might lead to memory corruption and other potential consequences.
nvd
CVE-2020-6544P3HIGHCVSS 8.8v10.02020-09-21
CVE-2020-6544 [HIGH] CWE-416 CVE-2020-6544: Use after free in media in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potenti Use after free in media in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6543P3HIGHCVSS 8.8v10.02020-09-21
CVE-2020-6543 [HIGH] CWE-416 CVE-2020-6543: Use after free in task scheduling in Google Chrome prior to 84.0.4147.125 allowed a remote attacker Use after free in task scheduling in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6545P3HIGHCVSS 8.8v10.02020-09-21
CVE-2020-6545 [HIGH] CWE-416 CVE-2020-6545: Use after free in audio in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potenti Use after free in audio in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6496P3HIGHCVSS 8.8v9.0v10.02020-06-03
CVE-2020-6496 [HIGH] CWE-416 CVE-2020-6496: Use after free in payments in Google Chrome on MacOS prior to 83.0.4103.97 allowed a remote attacker Use after free in payments in Google Chrome on MacOS prior to 83.0.4103.97 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
nvd
Debian Linux vulnerabilities | cvebase