cbcvebase.

Debian Linux vulnerabilities

9,953 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358

Vulnerabilities

Page 153 of 498
CVE-2021-37992P3HIGHCVSS 8.8v10.0v11.02021-11-02
CVE-2021-37992 [HIGH] CWE-125 CVE-2021-37992: Out of bounds read in WebAudio in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to p Out of bounds read in WebAudio in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2015-3167P3HIGHCVSS 7.5v7.0v8.0+1 more2019-11-20
CVE-2015-3167 [HIGH] CWE-200 CVE-2015-3167: contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 uses different error responses when an incorrect key is used, which makes it easier for attackers to obtain the key via a brute force attack.
nvd
CVE-2023-6873P3HIGHCVSS 8.8v10.0v11.0+1 more2023-12-19
CVE-2023-6873 [HIGH] CWE-787 CVE-2023-6873: Memory safety bugs present in Firefox 120. Some of these bugs showed evidence of memory corruption a Memory safety bugs present in Firefox 120. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 121.
nvd
CVE-2021-38016P3HIGHCVSS 8.8v10.0v11.02021-12-23
CVE-2021-38016 [HIGH] CWE-863 CVE-2021-38016: Insufficient policy enforcement in background fetch in Google Chrome prior to 96.0.4664.45 allowed a Insufficient policy enforcement in background fetch in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to bypass same origin policy via a crafted HTML page.
nvd
CVE-2021-38017P3HIGHCVSS 8.8v10.0v11.02021-12-23
CVE-2021-38017 [HIGH] CWE-863 CVE-2021-38017: Insufficient policy enforcement in iframe sandbox in Google Chrome prior to 96.0.4664.45 allowed a r Insufficient policy enforcement in iframe sandbox in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2017-1000433P3HIGHCVSS 8.1v8.0v9.02018-01-02
CVE-2017-1000433 [HIGH] CWE-287 CVE-2017-1000433: pysaml2 version 4.4.0 and older accept any password when run with python optimizations enabled. This pysaml2 version 4.4.0 and older accept any password when run with python optimizations enabled. This allows attackers to log in as any user without knowing their password.
nvd
CVE-2021-40153P3HIGHCVSS 8.1v9.0v10.02021-08-27
CVE-2021-40153 [HIGH] CWE-22 CVE-2021-40153: squashfs_opendir in unsquash-1.c in Squashfs-Tools 4.5 stores the filename in the directory entry; t squashfs_opendir in unsquash-1.c in Squashfs-Tools 4.5 stores the filename in the directory entry; this is then used by unsquashfs to create the new file during the unsquash. The filename is not validated for traversal outside of the destination directory, and thus allows writing to locations outside of the destination.
nvd
CVE-2023-36664P3HIGHCVSS 7.8v11.0v12.02023-06-25
CVE-2023-36664 [HIGH] CWE-552 CVE-2023-36664: Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pip Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).
nvd
CVE-2018-12910P3CRITICALCVSS 9.8v8.0v9.02018-07-05
CVE-2018-12910 [CRITICAL] CWE-125 CVE-2018-12910: The get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers to have unspecified The get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers to have unspecified impact via an empty hostname.
nvd
CVE-2017-7785P3CRITICALCVSS 9.8v8.0v9.02018-06-11
CVE-2017-7785 [CRITICAL] CWE-119 CVE-2017-7785: A buffer overflow can occur when manipulating Accessible Rich Internet Applications (ARIA) attribute A buffer overflow can occur when manipulating Accessible Rich Internet Applications (ARIA) attributes within the DOM. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
nvd
CVE-2019-15538P3HIGHCVSS 7.5v8.02019-08-25
CVE-2019-15538 [HIGH] CWE-400 CVE-2019-15538: An issue was discovered in xfs_setattr_nonsize in fs/xfs/xfs_iops.c in the Linux kernel through 5.2. An issue was discovered in xfs_setattr_nonsize in fs/xfs/xfs_iops.c in the Linux kernel through 5.2.9. XFS partially wedges when a chgrp fails on account of being out of disk quota. xfs_setattr_nonsize is failing to unlock the ILOCK after the xfs_qm_vop_chown_reserve call fails. This is primarily a local DoS attack vector, but it might result as well
nvd
CVE-2020-24165P3HIGHCVSS 8.8v10.02023-08-28
CVE-2020-24165 [HIGH] CVE-2020-24165: An issue was discovered in TCG Accelerator in QEMU 4.2.0, allows local attackers to execute arbitrar An issue was discovered in TCG Accelerator in QEMU 4.2.0, allows local attackers to execute arbitrary code, escalate privileges, and cause a denial of service (DoS). Note: This is disputed as a bug and not a valid security issue by multiple third parties.
nvd
CVE-2022-35414P3HIGHCVSS 8.8v10.02022-07-11
CVE-2022-35414 [HIGH] CWE-908 CVE-2022-35414: softmmu/physmem.c in QEMU through 7.0.0 can perform an uninitialized read on the translate_fail path softmmu/physmem.c in QEMU through 7.0.0 can perform an uninitialized read on the translate_fail path, leading to an io_readx or io_writex crash. NOTE: a third party states that the Non-virtualization Use Case in the qemu.org reference applies here, i.e., "Bugs affecting the non-virtualization use case are not considered security bugs at this time.
nvd
CVE-2018-8798P3HIGHCVSS 7.5v8.0v9.02019-02-05
CVE-2018-8798 [HIGH] CWE-126 CVE-2018-8798: rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function rdpsnd_proces rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function rdpsnd_process_ping() that results in an information leak.
nvd
CVE-2018-8791P3HIGHCVSS 7.5v8.0v9.02019-02-05
CVE-2018-8791 [HIGH] CWE-126 CVE-2018-8791: rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function rdpdr_process rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function rdpdr_process() that results in an information leak.
nvd
CVE-2021-41072P3HIGHCVSS 8.1v9.0v10.0+1 more2021-09-14
CVE-2021-41072 [HIGH] CVE-2021-41072: squashfs_opendir in unsquash-2.c in Squashfs-Tools 4.5 allows Directory Traversal, a different vulne squashfs_opendir in unsquash-2.c in Squashfs-Tools 4.5 allows Directory Traversal, a different vulnerability than CVE-2021-40153. A squashfs filesystem that has been crafted to include a symbolic link and then contents under the same filename in a filesystem can cause unsquashfs to first create the symbolic link pointing outside the expected directory, and th
nvd
CVE-2017-12137P3HIGHCVSS 8.8v8.0v9.02017-08-24
CVE-2017-12137 [HIGH] CWE-120 CVE-2017-12137: arch/x86/mm.c in Xen allows local PV guest OS users to gain host OS privileges via vectors related t arch/x86/mm.c in Xen allows local PV guest OS users to gain host OS privileges via vectors related to map_grant_ref.
nvd
CVE-2020-7238P3HIGHCVSS 7.5v8.0v9.0+1 more2020-01-27
CVE-2020-7238 [HIGH] CVE-2020-7238: Netty 4.1.43.Final allows HTTP Request Smuggling because it mishandles Transfer-Encoding whitespace Netty 4.1.43.Final allows HTTP Request Smuggling because it mishandles Transfer-Encoding whitespace (such as a [space]Transfer-Encoding:chunked line) and a later Content-Length header. This issue exists because of an incomplete fix for CVE-2019-16869.
nvd
CVE-2020-29481P3HIGHCVSS 8.8v10.02020-12-15
CVE-2020-29481 [HIGH] CWE-269 CVE-2020-29481: An issue was discovered in Xen through 4.14.x. Access rights of Xenstore nodes are per domid. Unfort An issue was discovered in Xen through 4.14.x. Access rights of Xenstore nodes are per domid. Unfortunately, existing granted access rights are not removed when a domain is being destroyed. This means that a new domain created with the same domid will inherit the access rights to Xenstore nodes from the previous domain(s) with the same domid. Because
nvd
CVE-2020-14303P3HIGHCVSS 7.5v9.02020-07-06
CVE-2020-14303 [HIGH] CWE-834 CVE-2020-14303: A flaw was found in the AD DC NBT server in all Samba versions before 4.10.17, before 4.11.11 and be A flaw was found in the AD DC NBT server in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4. A samba user could send an empty UDP packet to cause the samba server to crash.
nvd
Debian Linux vulnerabilities | cvebase