cbcvebase.

Debian Linux vulnerabilities

9,953 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358

Vulnerabilities

Page 152 of 498
CVE-2018-18354P3HIGHCVSS 8.8v9.02018-12-11
CVE-2018-18354 [HIGH] CWE-20 CVE-2018-18354: Insufficient validate of external protocols in Shell Integration in Google Chrome on Windows prior t Insufficient validate of external protocols in Shell Integration in Google Chrome on Windows prior to 71.0.3578.80 allowed a remote attacker to launch external programs via a crafted HTML page.
nvd
CVE-2018-18339P3HIGHCVSS 8.8v9.02018-12-11
CVE-2018-18339 [HIGH] CWE-416 CVE-2018-18339: Incorrect object lifecycle in WebAudio in Google Chrome prior to 71.0.3578.80 allowed a remote attac Incorrect object lifecycle in WebAudio in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2018-18338P3HIGHCVSS 8.8v9.02018-12-11
CVE-2018-18338 [HIGH] CWE-787 CVE-2018-18338: Incorrect, thread-unsafe use of SkImage in Canvas in Google Chrome prior to 71.0.3578.80 allowed a r Incorrect, thread-unsafe use of SkImage in Canvas in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6454P3HIGHCVSS 8.8v9.0v10.02020-04-13
CVE-2020-6454 [HIGH] CWE-416 CVE-2020-6454: Use after free in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convince Use after free in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.
nvd
CVE-2018-18340P3HIGHCVSS 8.8v9.02018-12-11
CVE-2018-18340 [HIGH] CWE-416 CVE-2018-18340: Incorrect object lifecycle in MediaRecorder in Google Chrome prior to 71.0.3578.80 allowed a remote Incorrect object lifecycle in MediaRecorder in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2018-18343P3HIGHCVSS 8.8v9.02018-12-11
CVE-2018-18343 [HIGH] CWE-416 CVE-2018-18343: Incorrect handing of paths leading to a use after free in Skia in Google Chrome prior to 71.0.3578.8 Incorrect handing of paths leading to a use after free in Skia in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2017-15387P3HIGHCVSS 8.8v8.0v9.02018-02-07
CVE-2017-15387 [HIGH] CVE-2017-15387: Insufficient enforcement of Content Security Policy in Blink in Google Chrome prior to 62.0.3202.62 Insufficient enforcement of Content Security Policy in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to open javascript: URL windows when they should not be allowed to via a crafted HTML page.
nvd
CVE-2015-4047P3HIGHCVSS 7.8v7.0v8.0+1 more2015-05-29
CVE-2015-4047 [HIGH] CWE-476 CVE-2015-4047: racoon/gssapi.c in IPsec-Tools 0.8.2 allows remote attackers to cause a denial of service (NULL poin racoon/gssapi.c in IPsec-Tools 0.8.2 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) via a series of crafted UDP requests.
nvd
CVE-2019-5824P3HIGHCVSS 8.8v10.02019-06-27
CVE-2019-5824 [HIGH] CWE-787 CVE-2019-5824: Parameter passing error in media in Google Chrome prior to 74.0.3729.131 allowed a remote attacker t Parameter passing error in media in Google Chrome prior to 74.0.3729.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2018-17474P3HIGHCVSS 8.8v9.02018-11-14
CVE-2018-17474 [HIGH] CWE-416 CVE-2018-17474: Use after free in HTMLImportsController in Blink in Google Chrome prior to 70.0.3538.67 allowed a re Use after free in HTMLImportsController in Blink in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2017-5126P3HIGHCVSS 8.8v8.0v9.02018-02-07
CVE-2017-5126 [HIGH] CWE-416 CVE-2017-5126: A use after free in PDFium in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to poten A use after free in PDFium in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
nvd
CVE-2020-6420P3HIGHCVSS 8.8v9.0v10.02020-03-23
CVE-2020-6420 [HIGH] CVE-2020-6420: Insufficient policy enforcement in media in Google Chrome prior to 80.0.3987.132 allowed a remote at Insufficient policy enforcement in media in Google Chrome prior to 80.0.3987.132 allowed a remote attacker to bypass same origin policy via a crafted HTML page.
nvd
CVE-2019-11287P3HIGHCVSS 7.5v9.02019-11-23
CVE-2019-11287 [HIGH] CWE-400 CVE-2019-11287: Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain a web management plugin that is vulnerable to a denial of service attack. The "X-Reason" HTTP Header can be leveraged to insert a malicious Erlang format string that w
nvd
CVE-2016-1696P3HIGHCVSS 8.8v8.02016-06-05
CVE-2016-1696 [HIGH] CWE-254 CVE-2016-1696: The extensions subsystem in Google Chrome before 51.0.2704.79 does not properly restrict bindings ac The extensions subsystem in Google Chrome before 51.0.2704.79 does not properly restrict bindings access, which allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
nvd
CVE-2019-18197P3HIGHCVSS 7.5v8.02019-10-18
CVE-2019-18197 [HIGH] CWE-416 CVE-2019-18197: In xsltCopyText in transform.c in libxslt 1.1.33, a pointer variable isn't reset under certain circu In xsltCopyText in transform.c in libxslt 1.1.33, a pointer variable isn't reset under certain circumstances. If the relevant memory area happened to be freed and reused in a certain way, a bounds check could fail and memory outside a buffer could be written to, or uninitialized data could be disclosed.
nvd
CVE-2021-41771P3HIGHCVSS 7.5v9.02021-11-08
CVE-2021-41771 [HIGH] CWE-119 CVE-2021-41771: ImportedSymbols in debug/macho (for Open or OpenFat) in Go before 1.16.10 and 1.17.x before 1.17.3 A ImportedSymbols in debug/macho (for Open or OpenFat) in Go before 1.16.10 and 1.17.x before 1.17.3 Accesses a Memory Location After the End of a Buffer, aka an out-of-bounds slice situation.
nvd
CVE-2020-26237P3HIGHCVSS 8.7v9.02020-11-24
CVE-2020-26237 [HIGH] CWE-471 CVE-2020-26237: Highlight.js is a syntax highlighter written in JavaScript. Highlight.js versions before 9.18.2 and Highlight.js is a syntax highlighter written in JavaScript. Highlight.js versions before 9.18.2 and 10.1.2 are vulnerable to Prototype Pollution. A malicious HTML code block can be crafted that will result in prototype pollution of the base object's prototype during highlighting. If you allow users to insert custom HTML code blocks into your page/app v
nvd
CVE-2020-36225P3HIGHCVSS 7.5v9.0v10.02021-01-26
CVE-2020-36225 [HIGH] CWE-415 CVE-2020-36225: A flaw was discovered in OpenLDAP before 2.4.57 leading to a double free and slapd crash in the sasl A flaw was discovered in OpenLDAP before 2.4.57 leading to a double free and slapd crash in the saslAuthzTo processing, resulting in denial of service.
nvd
CVE-2013-7439P3HIGHCVSS 7.5v7.02015-04-16
CVE-2013-7439 [HIGH] CWE-189 CVE-2013-7439: Multiple off-by-one errors in the (1) MakeBigReq and (2) SetReqLen macros in include/X11/Xlibint.h i Multiple off-by-one errors in the (1) MakeBigReq and (2) SetReqLen macros in include/X11/Xlibint.h in X11R6.x and libX11 before 1.6.0 allow remote attackers to have unspecified impact via a crafted request, which triggers a buffer overflow.
nvd
CVE-2021-4052P3HIGHCVSS 8.8v10.0v11.02021-12-23
CVE-2021-4052 [HIGH] CWE-416 CVE-2021-4052: Use after free in web apps in Google Chrome prior to 96.0.4664.93 allowed an attacker who convinced Use after free in web apps in Google Chrome prior to 96.0.4664.93 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.
nvd
Debian Linux vulnerabilities | cvebase