Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 151 of 498
CVE-2021-39922P3HIGHCVSS 7.5v9.0v10.0+1 more2021-11-19
CVE-2021-39922 [HIGH] CWE-120 CVE-2021-39922: Buffer overflow in the C12.22 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denia
Buffer overflow in the C12.22 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
nvd
CVE-2020-24606P3HIGHCVSS 7.5v9.0v10.02020-08-24
CVE-2020-24606 [HIGH] CWE-667 CVE-2020-24606: Squid before 4.13 and 5.x before 5.0.4 allows a trusted peer to perform Denial of Service by consumi
Squid before 4.13 and 5.x before 5.0.4 allows a trusted peer to perform Denial of Service by consuming all available CPU cycles during handling of a crafted Cache Digest response message. This only occurs when cache_peer is used with the cache digests feature. The problem exists because peerDigestHandleReply() livelocking in peer_digest.cc mishandles
nvd
CVE-2017-0367P3HIGHCVSS 8.8v7.02018-04-13
CVE-2017-0367 [HIGH] CWE-668 CVE-2017-0367: Mediawiki before 1.28.1 / 1.27.2 contains an unsafe use of temporary directory, where having Localis
Mediawiki before 1.28.1 / 1.27.2 contains an unsafe use of temporary directory, where having LocalisationCache directory default to system tmp directory is insecure.
nvd
CVE-2016-1697P3HIGHCVSS 8.8v8.02016-06-05
CVE-2016-1697 [HIGH] CWE-284 CVE-2016-1697: The FrameLoader::startLoad function in WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used i
The FrameLoader::startLoad function in WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 51.0.2704.79, does not prevent frame navigations during DocumentLoader detach operations, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code.
nvd
CVE-2017-15388P3HIGHCVSS 8.8v8.0v9.02018-02-07
CVE-2017-15388 [HIGH] CWE-125 CVE-2017-15388: Iteration through non-finite points in Skia in Google Chrome prior to 62.0.3202.62 allowed a remote
Iteration through non-finite points in Skia in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
nvd
CVE-2017-17515P3HIGHCVSS 8.8v8.0v9.0+1 more2017-12-14
CVE-2017-17515 [HIGH] CWE-74 CVE-2017-17515: etc/ObjectList in Metview 4.7.3 does not validate strings before launching the program specified by
etc/ObjectList in Metview 4.7.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. NOTE: a third party has indicated that the code to access this environment variable is not enabled in the shipped product
nvd
CVE-2022-28042P3HIGHCVSS 8.8v10.02022-04-15
CVE-2022-28042 [HIGH] CWE-416 CVE-2022-28042: stb_image.h v2.27 was discovered to contain an heap-based use-after-free via the function stbi__jpeg
stb_image.h v2.27 was discovered to contain an heap-based use-after-free via the function stbi__jpeg_huff_decode.
nvd
CVE-2021-38496P3HIGHCVSS 8.8v9.0v10.0+1 more2021-11-03
CVE-2021-38496 [HIGH] CWE-416 CVE-2021-38496: During operations on MessageTasks, a task may have been removed while it was still scheduled, result
During operations on MessageTasks, a task may have been removed while it was still scheduled, resulting in memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.15, Thunderbird < 91.2, Firefox ESR < 91.2, Firefox ESR < 78.15, and Firefox < 93.
nvd
CVE-2019-14744P3HIGHCVSS 7.8v9.0v10.02019-08-07
CVE-2019-14744 [HIGH] CWE-78 CVE-2019-14744: In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to cod
In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with minimal user interaction. This relates to libKF5ConfigCore.so, and the mishandling of .desktop and .directory files, as demonstrated by a shell command on an Icon line in a .desktop file.
nvd
CVE-2017-15408P3HIGHCVSS 8.8v9.02018-08-28
CVE-2017-15408 [HIGH] CWE-119 CVE-2017-15408: Heap buffer overflow in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to
Heap buffer overflow in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file that is mishandled by PDFium.
nvd
CVE-2019-13736P3HIGHCVSS 8.8v9.0v10.02019-12-10
CVE-2019-13736 [HIGH] CWE-190 CVE-2019-13736: Integer overflow in PDFium in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to poten
Integer overflow in PDFium in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
nvd
CVE-2016-1672P3HIGHCVSS 8.8v8.02016-06-05
CVE-2016-1672 [HIGH] CWE-254 CVE-2016-1672: The ModuleSystem::RequireForJsInner function in extensions/renderer/module_system.cc in the extensio
The ModuleSystem::RequireForJsInner function in extensions/renderer/module_system.cc in the extension bindings in Google Chrome before 51.0.2704.63 mishandles properties, which allows remote attackers to conduct bindings-interception attacks and bypass the Same Origin Policy via unspecified vectors.
nvd
CVE-2016-1675P3HIGHCVSS 8.8v8.02016-06-05
CVE-2016-1675 [HIGH] CWE-284 CVE-2016-1675: Blink, as used in Google Chrome before 51.0.2704.63, allows remote attackers to bypass the Same Orig
Blink, as used in Google Chrome before 51.0.2704.63, allows remote attackers to bypass the Same Origin Policy by leveraging the mishandling of Document reattachment during destruction, related to FrameLoader.cpp and LocalFrame.cpp.
nvd
CVE-2005-1689P3CRITICALCVSS 9.8v3.0v3.12005-07-18
CVE-2005-1689 [CRITICAL] CWE-415 CVE-2005-1689: Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1.4.1 and earlier a
Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to execute arbitrary code via certain error conditions.
nvd
CVE-2018-6057P3HIGHCVSS 8.8v9.02018-11-14
CVE-2018-6057 [HIGH] CWE-732 CVE-2018-6057: Lack of special casing of Android ashmem in Google Chrome prior to 65.0.3325.146 allowed a remote at
Lack of special casing of Android ashmem in Google Chrome prior to 65.0.3325.146 allowed a remote attacker who had compromised the renderer process to bypass inter-process read only guarantees via a crafted HTML page.
nvd
CVE-2018-18341P3HIGHCVSS 8.8v9.02018-12-11
CVE-2018-18341 [HIGH] CWE-190 CVE-2018-18341: An integer overflow leading to a heap buffer overflow in Blink in Google Chrome prior to 71.0.3578.8
An integer overflow leading to a heap buffer overflow in Blink in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2008-2663P3CRITICALCVSS 10.0v4.02008-06-24
CVE-2008-2663 [CRITICAL] CVE-2008-2663: Multiple integer overflows in the rb_ary_store function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.
Multiple integer overflows in the rb_ary_store function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, and 1.8.7 before 1.8.7-p22 allow context-dependent attackers to execute arbitrary code or cause a denial of service via unknown vectors, a different issue than CVE-2008-2662, CVE-2008-2664, and CVE-2008-2725. NOTE: as of 20080
nvd
CVE-2019-13727P3HIGHCVSS 8.8v9.0v10.02019-12-10
CVE-2019-13727 [HIGH] CWE-281 CVE-2019-13727: Insufficient policy enforcement in WebSockets in Google Chrome prior to 79.0.3945.79 allowed a remot
Insufficient policy enforcement in WebSockets in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass same origin policy via a crafted HTML page.
nvd
CVE-2018-6054P3HIGHCVSS 8.8v8.0v9.02018-09-25
CVE-2018-6054 [HIGH] CWE-416 CVE-2018-6054: Use after free in WebUI in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potenti
Use after free in WebUI in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially exploit heap corruption via a crafted Chrome Extension.
nvd
CVE-2017-5129P3HIGHCVSS 8.8v8.0v9.02018-02-07
CVE-2017-5129 [HIGH] CWE-416 CVE-2017-5129: A use after free in WebAudio in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attack
A use after free in WebAudio in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
nvd