Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 141 of 498
CVE-2015-1779P3HIGHCVSS 8.6v7.0v8.02016-01-12
CVE-2015-1779 [HIGH] CWE-400 CVE-2015-1779: The VNC websocket frame decoder in QEMU allows remote attackers to cause a denial of service (memory
The VNC websocket frame decoder in QEMU allows remote attackers to cause a denial of service (memory and CPU consumption) via a large (1) websocket payload or (2) HTTP headers section.
nvd
CVE-2021-37983P3HIGHCVSS 8.8v10.0v11.02021-11-02
CVE-2021-37983 [HIGH] CWE-416 CVE-2021-37983: Use after free in Dev Tools in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to pote
Use after free in Dev Tools in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-37985P3HIGHCVSS 8.8v10.0v11.02021-11-02
CVE-2021-37985 [HIGH] CWE-416 CVE-2021-37985: Use after free in V8 in Google Chrome prior to 95.0.4638.54 allowed a remote attacker who had convin
Use after free in V8 in Google Chrome prior to 95.0.4638.54 allowed a remote attacker who had convinced a user to allow for connection to debugger to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-43860P3HIGHCVSS 8.6v9.0v10.0+1 more2022-01-12
CVE-2021-43860 [HIGH] CWE-269 CVE-2021-43860: Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.12.3 and 1
Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.12.3 and 1.10.6, Flatpak doesn't properly validate that the permissions displayed to the user for an app at install time match the actual permissions granted to the app at runtime, in the case that there's a null byte in the metadata file of an app. Therefore app
nvd
CVE-2017-9065P3HIGHCVSS 7.5v8.0v9.02017-05-18
CVE-2017-9065 [HIGH] CWE-20 CVE-2017-9065: In WordPress before 4.7.5, there is a lack of capability checks for post meta data in the XML-RPC AP
In WordPress before 4.7.5, there is a lack of capability checks for post meta data in the XML-RPC API.
nvd
CVE-2021-37988P3HIGHCVSS 8.8v10.0v11.02021-11-02
CVE-2021-37988 [HIGH] CWE-416 CVE-2021-37988: Use after free in Profiles in Google Chrome prior to 95.0.4638.54 allowed a remote attacker who conv
Use after free in Profiles in Google Chrome prior to 95.0.4638.54 allowed a remote attacker who convinced a user to engage in specific gestures to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-37993P3HIGHCVSS 8.8v10.0v11.02021-11-02
CVE-2021-37993 [HIGH] CWE-416 CVE-2021-37993: Use after free in PDF Accessibility in Google Chrome prior to 95.0.4638.54 allowed a remote attacker
Use after free in PDF Accessibility in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-40401P3HIGHCVSS 8.6v11.02022-02-04
CVE-2021-40401 [HIGH] CWE-252 CVE-2021-40401: A use-after-free vulnerability exists in the RS-274X aperture definition tokenization functionality
A use-after-free vulnerability exists in the RS-274X aperture definition tokenization functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and Gerbv forked 2.7.1. A specially-crafted gerber file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
nvd
CVE-2021-38011P3HIGHCVSS 8.8v10.0v11.02021-12-23
CVE-2021-38011 [HIGH] CWE-416 CVE-2021-38011: Use after free in storage foundation in Google Chrome prior to 96.0.4664.45 allowed a remote attacke
Use after free in storage foundation in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2023-37202P3HIGHCVSS 8.8v10.0v11.0+1 more2023-07-05
CVE-2023-37202 [HIGH] CWE-416 CVE-2023-37202: Cross-compartment wrappers wrapping a scripted proxy could have caused objects from other compartmen
Cross-compartment wrappers wrapping a scripted proxy could have caused objects from other compartments to be stored in the main compartment resulting in a use-after-free. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.
nvd
CVE-2016-1840P3HIGHCVSS 7.8v8.02016-05-20
CVE-2016-1840 [HIGH] CWE-119 CVE-2016-1840: Heap-based buffer overflow in the xmlFAParsePosCharGroup function in libxml2 before 2.9.4, as used i
Heap-based buffer overflow in the xmlFAParsePosCharGroup function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted XML document.
nvd
CVE-2017-7786P3CRITICALCVSS 9.8v8.0v9.02018-06-11
CVE-2017-7786 [CRITICAL] CWE-119 CVE-2017-7786: A buffer overflow can occur when the image renderer attempts to paint non-displayable SVG elements.
A buffer overflow can occur when the image renderer attempts to paint non-displayable SVG elements. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
nvd
CVE-2023-2726P3HIGHCVSS 8.8v11.02023-05-16
CVE-2023-2726 [HIGH] CVE-2023-2726: Inappropriate implementation in WebApp Installs in Google Chrome prior to 113.0.5672.126 allowed an
Inappropriate implementation in WebApp Installs in Google Chrome prior to 113.0.5672.126 allowed an attacker who convinced a user to install a malicious web app to bypass install dialog via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-4047P3HIGHCVSS 8.8v11.0v12.02023-08-01
CVE-2023-4047 [HIGH] CWE-352 CVE-2023-4047: A bug in popup notifications delay calculation could have made it possible for an attacker to trick
A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.
nvd
CVE-2020-10745P3HIGHCVSS 7.5v9.02020-07-07
CVE-2020-10745 [HIGH] CWE-400 CVE-2020-10745: A flaw was found in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4 in the way i
A flaw was found in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4 in the way it processed NetBios over TCP/IP. This flaw allows a remote attacker could to cause the Samba server to consume excessive CPU use, resulting in a denial of service. This highest threat from this vulnerability is to system availability.
nvd
CVE-2021-38015P3HIGHCVSS 8.8v10.0v11.02021-12-23
CVE-2021-38015 [HIGH] CWE-20 CVE-2021-38015: Inappropriate implementation in input in Google Chrome prior to 96.0.4664.45 allowed an attacker who
Inappropriate implementation in input in Google Chrome prior to 96.0.4664.45 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.
nvd
CVE-2017-3329P3HIGHCVSS 7.5v8.02017-04-24
CVE-2017-3329 [HIGH] CVE-2017-3329: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Thread Pooling).
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Thread Pooling). Supported versions that are affected are 5.5.54 and earlier, 5.6.35 and earlier and 5.7.17 and earlier. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of
nvd
CVE-2017-12562P3CRITICALCVSS 9.8v9.02017-08-05
CVE-2017-12562 [CRITICAL] CWE-119 CVE-2017-12562: Heap-based Buffer Overflow in the psf_binheader_writef function in common.c in libsndfile through 1.
Heap-based Buffer Overflow in the psf_binheader_writef function in common.c in libsndfile through 1.0.28 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
nvd
CVE-2020-8231P3HIGHCVSS 7.5v10.02020-12-14
CVE-2020-8231 [HIGH] CWE-416 CVE-2020-8231: Due to use of a dangling pointer, libcurl 7.29.0 through 7.71.1 can use the wrong connection when se
Due to use of a dangling pointer, libcurl 7.29.0 through 7.71.1 can use the wrong connection when sending data.
nvd
CVE-2018-13054P3HIGHCVSS 8.1v8.02018-07-02
CVE-2018-13054 [HIGH] CWE-59 CVE-2018-13054: An issue was discovered in Cinnamon 1.9.2 through 3.8.6. The cinnamon-settings-users.py GUI runs as
An issue was discovered in Cinnamon 1.9.2 through 3.8.6. The cinnamon-settings-users.py GUI runs as root and allows configuration of (for example) other users' icon files in _on_face_browse_menuitem_activated and _on_face_menuitem_activated. These icon files are written to the respective user's $HOME/.face location. If an unprivileged user prepares a sy
nvd