cbcvebase.

Debian Linux vulnerabilities

9,953 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358

Vulnerabilities

Page 129 of 498
CVE-2021-21233P3HIGHCVSS 8.8v10.02021-04-30
CVE-2021-21233 [HIGH] CWE-787 CVE-2021-21233: Heap buffer overflow in ANGLE in Google Chrome on Windows prior to 90.0.4430.93 allowed a remote att Heap buffer overflow in ANGLE in Google Chrome on Windows prior to 90.0.4430.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2014-2324P3MEDIUMCVSS 5.0v6.0v7.0+1 more2014-03-14
CVE-2014-2324 [MEDIUM] CWE-22 CVE-2014-2324: Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simple_vhost in lighttpd Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simple_vhost in lighttpd before 1.4.35 allow remote attackers to read arbitrary files via a .. (dot dot) in the host name, related to request_check_hostname.
nvd
CVE-2020-6532P3HIGHCVSS 8.8v10.02020-09-21
CVE-2020-6532 [HIGH] CWE-416 CVE-2020-6532: Use after free in SCTP in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentia Use after free in SCTP in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2017-9062P3HIGHCVSS 8.6v8.0v9.02017-05-18
CVE-2017-9062 [HIGH] CWE-79 CVE-2017-9062: In WordPress before 4.7.5, there is improper handling of post meta data values in the XML-RPC API. In WordPress before 4.7.5, there is improper handling of post meta data values in the XML-RPC API.
nvd
CVE-2021-37956P3HIGHCVSS 8.8v10.0v11.02021-10-08
CVE-2021-37956 [HIGH] CWE-416 CVE-2021-37956: Use after free in Offline use in Google Chrome on Android prior to 94.0.4606.54 allowed a remote att Use after free in Offline use in Google Chrome on Android prior to 94.0.4606.54 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-22030P3HIGHCVSS 8.8v10.02021-05-27
CVE-2020-22030 [HIGH] CWE-787 CVE-2020-22030: A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 at libavfilter/af_afade.c in crossfa A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 at libavfilter/af_afade.c in crossfade_samples_fltp, which might lead to memory corruption and other potential consequences.
nvd
CVE-2017-5469P3CRITICALCVSS 9.8v8.02018-06-11
CVE-2017-5469 [CRITICAL] CVE-2017-5469: Fixed potential buffer overflows in generated Firefox code due to CVE-2016-6354 issue in Flex. This Fixed potential buffer overflows in generated Firefox code due to CVE-2016-6354 issue in Flex. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2020-7040P3HIGHCVSS 8.1v8.02020-01-21
CVE-2020-7040 [HIGH] CWE-59 CVE-2020-7040: storeBackup.pl in storeBackup through 3.5 relies on the /tmp/storeBackup.lock pathname, which allows storeBackup.pl in storeBackup through 3.5 relies on the /tmp/storeBackup.lock pathname, which allows symlink attacks that possibly lead to privilege escalation. (Local users can also create a plain file named /tmp/storeBackup.lock to block use of storeBackup until an admin manually deletes that file.)
nvd
CVE-2017-12151P3HIGHCVSS 7.4v8.0v9.02018-07-27
CVE-2017-12151 [HIGH] CWE-300 CVE-2017-12151: A flaw was found in the way samba client before samba 4.4.16, samba 4.5.14 and samba 4.6.8 used encr A flaw was found in the way samba client before samba 4.4.16, samba 4.5.14 and samba 4.6.8 used encryption with the max protocol set as SMB3. The connection could lose the requirement for signing and encrypting to any DFS redirects, allowing an attacker to read or alter the contents of the connection via a man-in-the-middle attack.
nvd
CVE-2020-13398P3HIGHCVSS 8.3v9.0v10.02020-05-22
CVE-2020-13398 [HIGH] CWE-787 CVE-2020-13398: An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) write vulnerability has been An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) write vulnerability has been detected in crypto_rsa_common in libfreerdp/crypto/crypto.c.
nvd
CVE-2023-6863P3HIGHCVSS 8.8v10.0v11.0+1 more2023-12-19
CVE-2023-6863 [HIGH] CVE-2023-6863: The `ShutdownObserver()` was susceptible to potentially undefined behavior due to its reliance on a The `ShutdownObserver()` was susceptible to potentially undefined behavior due to its reliance on a dynamic type that lacked a virtual destructor. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
nvd
CVE-2020-0198P3HIGHCVSS 7.5v8.02020-06-11
CVE-2020-0198 [HIGH] CWE-190 CVE-2020-0198: In exif_data_load_data_content of exif-data.c, there is a possible UBSAN abort due to an integer ove In exif_data_load_data_content of exif-data.c, there is a possible UBSAN abort due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-146428941
nvd
CVE-2021-37978P3HIGHCVSS 8.8v10.0v11.02021-11-02
CVE-2021-37978 [HIGH] CWE-787 CVE-2021-37978: Heap buffer overflow in Blink in Google Chrome prior to 94.0.4606.81 allowed a remote attacker to po Heap buffer overflow in Blink in Google Chrome prior to 94.0.4606.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-37984P3HIGHCVSS 8.8v10.0v11.02021-11-02
CVE-2021-37984 [HIGH] CWE-787 CVE-2021-37984: Heap buffer overflow in PDFium in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to p Heap buffer overflow in PDFium in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-8164P3HIGHCVSS 7.5v8.0v9.0+1 more2020-06-19
CVE-2020-8164 [HIGH] CWE-502 CVE-2020-8164: A deserialization of untrusted data vulnerability exists in rails < 5.2.4.3, rails < 6.0.3.1 which c A deserialization of untrusted data vulnerability exists in rails < 5.2.4.3, rails < 6.0.3.1 which can allow an attacker to supply information can be inadvertently leaked fromStrong Parameters.
nvd
CVE-2021-22885P3HIGHCVSS 7.5v10.02021-05-27
CVE-2021-22885 [HIGH] CWE-209 CVE-2021-22885: A possible information disclosure / unintended method execution vulnerability in Action Pack >= 2.0. A possible information disclosure / unintended method execution vulnerability in Action Pack >= 2.0.0 when using the `redirect_to` or `polymorphic_url`helper with untrusted user input.
nvd
CVE-2021-37959P3HIGHCVSS 8.8v10.0v11.02021-10-08
CVE-2021-37959 [HIGH] CWE-416 CVE-2021-37959: Use after free in Task Manager in Google Chrome prior to 94.0.4606.54 allowed an attacker who convin Use after free in Task Manager in Google Chrome prior to 94.0.4606.54 allowed an attacker who convinced a user to enage in a series of user gestures to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-37998P3HIGHCVSS 8.8v10.0v11.02021-11-23
CVE-2021-37998 [HIGH] CWE-416 CVE-2021-37998: Use after free in Garbage Collection in Google Chrome prior to 95.0.4638.69 allowed a remote attacke Use after free in Garbage Collection in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-9022P3HIGHCVSS 7.5v8.0v9.02019-02-22
CVE-2019-9022 [HIGH] CWE-125 CVE-2019-9022: An issue was discovered in PHP 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.2. dns_g An issue was discovered in PHP 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.2. dns_get_record misparses a DNS response, which can allow a hostile DNS server to cause PHP to misuse memcpy, leading to read operations going past the buffer allocated for DNS data. This affects php_parserr in ext/standard/dns.c for DNS_CAA and DNS_ANY queries
nvd
CVE-2023-1815P3HIGHCVSS 8.8v11.02023-04-04
CVE-2023-1815 [HIGH] CWE-416 CVE-2023-1815: Use after free in Networking APIs in Google Chrome prior to 112.0.5615.49 allowed a remote attacker Use after free in Networking APIs in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
Debian Linux vulnerabilities | cvebase