Debian Linux vulnerabilities
9,911 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,911
CISA KEV
119
actively exploited
Public exploits
429
Exploited in wild
132
Severity breakdown
CRITICAL1128HIGH4110MEDIUM4311LOW362
Vulnerabilities
Page 136 of 496
CVE-2021-38503CRITICALCVSS 10.0v9.0v10.0+1 more2021-12-08
CVE-2021-38503 [CRITICAL] CWE-863 CVE-2021-38503: The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypas
The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypass restrictions such as executing scripts or navigating the top-level frame. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
nvd
CVE-2021-43537HIGHCVSS 8.8v9.0v10.0+1 more2021-12-08
CVE-2021-43537 [HIGH] CWE-704 CVE-2021-43537: An incorrect type conversion of sizes from 64bit to 32bit integers allowed an attacker to corrupt me
An incorrect type conversion of sizes from 64bit to 32bit integers allowed an attacker to corrupt memory leading to a potentially exploitable crash. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
nvd
CVE-2021-43539HIGHCVSS 8.8v9.0v10.0+1 more2021-12-08
CVE-2021-43539 [HIGH] CWE-416 CVE-2021-43539: Failure to correctly record the location of live pointers across wasm instance calls resulted in a G
Failure to correctly record the location of live pointers across wasm instance calls resulted in a GC occurring within the call not tracing those live pointers. This could have led to a use-after-free causing a potentially exploitable crash. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
nvd
CVE-2021-43534HIGHCVSS 8.8v9.0v10.0+1 more2021-12-08
CVE-2021-43534 [HIGH] CWE-787 CVE-2021-43534: Mozilla developers and community members reported memory safety bugs present in Firefox 93 and Firef
Mozilla developers and community members reported memory safety bugs present in Firefox 93 and Firefox ESR 91.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.
nvd
CVE-2021-38504HIGHCVSS 8.8v9.0v10.0+1 more2021-12-08
CVE-2021-38504 [HIGH] CWE-416 CVE-2021-38504: When interacting with an HTML input element's file picker dialog with webkitdirectory set, a use-aft
When interacting with an HTML input element's file picker dialog with webkitdirectory set, a use-after-free could have resulted, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
nvd
CVE-2021-44420HIGHCVSS 7.3v10.0v11.02021-12-08
CVE-2021-44420 [HIGH] CVE-2021-44420: In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with t
In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines could bypass upstream access control based on URL paths.
nvd
CVE-2021-43535HIGHCVSS 8.8v9.0v10.0+1 more2021-12-08
CVE-2021-43535 [HIGH] CWE-416 CVE-2021-43535: A use-after-free could have occured when an HTTP2 session object was released on a different thread,
A use-after-free could have occured when an HTTP2 session object was released on a different thread, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 93, Thunderbird < 91.3, and Firefox ESR < 91.3.
nvd
CVE-2021-43528MEDIUMCVSS 6.5v9.0v10.0+1 more2021-12-08
CVE-2021-43528 [MEDIUM] CWE-269 CVE-2021-43528: Thunderbird unexpectedly enabled JavaScript in the composition area. The JavaScript execution contex
Thunderbird unexpectedly enabled JavaScript in the composition area. The JavaScript execution context was limited to this area and did not receive chrome-level privileges, but could be used as a stepping stone to further an attack with other vulnerabilities. This vulnerability affects Thunderbird < 91.4.0.
nvd
CVE-2021-43542MEDIUMCVSS 6.5v9.0v10.0+1 more2021-12-08
CVE-2021-43542 [MEDIUM] CWE-209 CVE-2021-43542: Using XMLHttpRequest, an attacker could have identified installed applications by probing error mess
Using XMLHttpRequest, an attacker could have identified installed applications by probing error messages for loading external protocols. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
nvd
CVE-2021-43543MEDIUMCVSS 6.1v9.0v10.0+1 more2021-12-08
CVE-2021-43543 [MEDIUM] CWE-79 CVE-2021-43543: Documents loaded with the CSP sandbox directive could have escaped the sandbox's script restriction
Documents loaded with the CSP sandbox directive could have escaped the sandbox's script restriction by embedding additional content. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
nvd
CVE-2021-38508MEDIUMCVSS 4.3v9.0v10.0+1 more2021-12-08
CVE-2021-38508 [MEDIUM] CWE-1021 CVE-2021-38508: By displaying a form validity message in the correct location at the same time as a permission promp
By displaying a form validity message in the correct location at the same time as a permission prompt (such as for geolocation), the validity message could have obscured the prompt, resulting in the user potentially being tricked into granting the permission. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
nvd
CVE-2021-38507MEDIUMCVSS 6.5v9.0v10.0+1 more2021-12-08
CVE-2021-38507 [MEDIUM] CWE-346 CVE-2021-38507: The Opportunistic Encryption feature of HTTP2 (RFC 8164) allows a connection to be transparently upg
The Opportunistic Encryption feature of HTTP2 (RFC 8164) allows a connection to be transparently upgraded to TLS while retaining the visual properties of an HTTP connection, including being same-origin with unencrypted connections on port 80. However, if a second encrypted port on the same IP address (e.g. port 8443) did not opt-in to opportunistic
nvd
CVE-2021-43536MEDIUMCVSS 6.5v9.0v10.0+1 more2021-12-08
CVE-2021-43536 [MEDIUM] CWE-200 CVE-2021-43536: Under certain circumstances, asynchronous functions could have caused a navigation to fail but expos
Under certain circumstances, asynchronous functions could have caused a navigation to fail but expose the target URL. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
nvd
CVE-2021-43541MEDIUMCVSS 6.5v9.0v10.0+1 more2021-12-08
CVE-2021-43541 [MEDIUM] CVE-2021-43541: When invoking protocol handlers for external protocols, a supplied parameter URL containing spaces w
When invoking protocol handlers for external protocols, a supplied parameter URL containing spaces was not properly escaped. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
nvd
CVE-2021-43538MEDIUMCVSS 4.3v9.0v10.0+1 more2021-12-08
CVE-2021-43538 [MEDIUM] CWE-362 CVE-2021-43538: By misusing a race in our notification code, an attacker could have forcefully hidden the notificati
By misusing a race in our notification code, an attacker could have forcefully hidden the notification for pages that had received full screen and pointer lock access, which could have been used for spoofing attacks. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
nvd
CVE-2021-43545MEDIUMCVSS 6.5v9.0v10.0+1 more2021-12-08
CVE-2021-43545 [MEDIUM] CWE-834 CVE-2021-43545: Using the Location API in a loop could have caused severe application hangs and crashes. This vulner
Using the Location API in a loop could have caused severe application hangs and crashes. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
nvd
CVE-2021-43546MEDIUMCVSS 4.3v9.0v10.0+1 more2021-12-08
CVE-2021-43546 [MEDIUM] CWE-1021 CVE-2021-43546: It was possible to recreate previous cursor spoofing attacks against users with a zoomed native curs
It was possible to recreate previous cursor spoofing attacks against users with a zoomed native cursor. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
nvd
CVE-2021-38509MEDIUMCVSS 4.3v9.0v10.0+1 more2021-12-08
CVE-2021-38509 [MEDIUM] CWE-1021 CVE-2021-38509: Due to an unusual sequence of attacker-controlled events, a Javascript alert() dialog with arbitrary
Due to an unusual sequence of attacker-controlled events, a Javascript alert() dialog with arbitrary (although unstyled) contents could be displayed over top an uncontrolled webpage of the attacker's choosing. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
nvd
CVE-2021-38506MEDIUMCVSS 4.3v9.0v10.0+1 more2021-12-08
CVE-2021-38506 [MEDIUM] CWE-1021 CVE-2021-38506: Through a series of navigations, Firefox could have entered fullscreen mode without notification or
Through a series of navigations, Firefox could have entered fullscreen mode without notification or warning to the user. This could lead to spoofing attacks on the browser UI including phishing. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
nvd
CVE-2021-42717HIGHCVSS 7.5v9.0v10.0+1 more2021-12-07
CVE-2021-42717 [HIGH] CWE-674 CVE-2021-42717: ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects with
ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects with nesting tens-of-thousands deep could result in the web server being unable to service legitimate requests. Even a moderately large (e.g., 300KB) HTTP request can occupy one of the limited NGINX worker processes for minutes and consume almost all of the a
nvd