cbcvebase.

Debian Linux vulnerabilities

9,953 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358

Vulnerabilities

Page 160 of 498
CVE-2022-42720P3HIGHCVSS 7.8v10.0v11.02022-10-14
CVE-2022-42720 [HIGH] CWE-416 CVE-2022-42720: Various refcounting bugs in the multi-BSS handling in the mac80211 stack in the Linux kernel 5.1 thr Various refcounting bugs in the multi-BSS handling in the mac80211 stack in the Linux kernel 5.1 through 5.19.x before 5.19.16 could be used by local attackers (able to inject WLAN frames) to trigger use-after-free conditions to potentially execute code.
nvd
CVE-2013-2106P3HIGHCVSS 7.5v8.0v9.0+1 more2019-12-03
CVE-2013-2106 [HIGH] CWE-522 CVE-2013-2106: webauth before 4.6.1 has authentication credential disclosure webauth before 4.6.1 has authentication credential disclosure
nvd
CVE-2019-7221P3HIGHCVSS 7.8v8.02019-03-21
CVE-2019-7221 [HIGH] CWE-416 CVE-2019-7221: The KVM implementation in the Linux kernel through 4.20.5 has a Use-after-Free. The KVM implementation in the Linux kernel through 4.20.5 has a Use-after-Free.
nvd
CVE-2022-30594P3HIGHCVSS 7.8v9.0v10.02022-05-12
CVE-2022-30594 [HIGH] CWE-862 CVE-2022-30594: The Linux kernel before 5.17.2 mishandles seccomp permissions. The PTRACE_SEIZE code path allows att The Linux kernel before 5.17.2 mishandles seccomp permissions. The PTRACE_SEIZE code path allows attackers to bypass intended restrictions on setting the PT_SUSPEND_SECCOMP flag.
nvd
CVE-2024-27398P3HIGHCVSS 7.8v10.02024-05-14
CVE-2024-27398 [HIGH] CWE-416 CVE-2024-27398: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix use-after-free b In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix use-after-free bugs caused by sco_sock_timeout When the sco connection is established and then, the sco socket is releasing, timeout_work will be scheduled to judge whether the sco disconnection is timeout. The sock will be deallocated later, but it is dereferenced aga
nvd
CVE-2022-47184P3HIGHCVSS 7.5v11.0v12.02023-06-14
CVE-2022-47184 [HIGH] CWE-200 CVE-2022-47184: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundati Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: 8.0.0 to 9.2.0.
nvd
CVE-2014-3673P3HIGHCVSS 7.5v7.02014-11-10
CVE-2014-3673 [HIGH] CWE-20 CVE-2014-3673: The SCTP implementation in the Linux kernel through 3.17.2 allows remote attackers to cause a denial The SCTP implementation in the Linux kernel through 3.17.2 allows remote attackers to cause a denial of service (system crash) via a malformed ASCONF chunk, related to net/sctp/sm_make_chunk.c and net/sctp/sm_statefuns.c.
nvd
CVE-2023-6356P3HIGHCVSS 7.5v10.02024-02-07
CVE-2023-6356 [HIGH] CWE-476 CVE-2023-6356: A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated maliciou A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages when using NVMe over TCP, leading the NVMe driver to a NULL pointer dereference in the NVMe driver and causing kernel panic and a denial of service.
nvd
CVE-2021-43173P3HIGHCVSS 7.5v11.02021-11-09
CVE-2021-43173 [HIGH] CWE-755 CVE-2021-43173: In NLnet Labs Routinator prior to 0.10.2, a validation run can be delayed significantly by an RRDP r In NLnet Labs Routinator prior to 0.10.2, a validation run can be delayed significantly by an RRDP repository by not answering but slowly drip-feeding bytes to keep the connection alive. This can be used to effectively stall validation. While Routinator has a configurable time-out value for RRDP connections, this time-out was only applied to individua
nvd
CVE-2021-3444P3HIGHCVSS 7.8v9.02021-03-23
CVE-2021-3444 [HIGH] CWE-681 CVE-2021-3444: The bpf verifier in the Linux kernel did not properly handle mod32 destination register truncation w The bpf verifier in the Linux kernel did not properly handle mod32 destination register truncation when the source register was known to be 0. A local attacker with the ability to load bpf programs could use this gain out-of-bounds reads in kernel memory leading to information disclosure (kernel memory), and possibly out-of-bounds writes that could pote
nvd
CVE-2019-15239P3HIGHCVSS 7.8v9.0v10.02019-08-20
CVE-2019-15239 [HIGH] CWE-416 CVE-2019-15239: In the Linux kernel, a certain net/ipv4/tcp_output.c change, which was properly incorporated into 4. In the Linux kernel, a certain net/ipv4/tcp_output.c change, which was properly incorporated into 4.16.12, was incorrectly backported to the earlier longterm kernels, introducing a new vulnerability that was potentially more severe than the issue that was intended to be fixed by backporting. Specifically, by adding to a write queue between disconnecti
nvd
CVE-2022-20421P3HIGHCVSS 7.8v10.0v11.02022-10-11
CVE-2022-20421 [HIGH] CWE-416 CVE-2022-20421: In binder_inc_ref_for_node of binder.c, there is a possible way to corrupt memory due to a use after In binder_inc_ref_for_node of binder.c, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-239630375References: Upstream kernel
nvd
CVE-2022-45188P3HIGHCVSS 7.8v10.0v11.02022-11-12
CVE-2022-45188 [HIGH] CWE-787 CVE-2022-45188: Netatalk through 3.1.13 has an afp_getappl heap-based buffer overflow resulting in code execution vi Netatalk through 3.1.13 has an afp_getappl heap-based buffer overflow resulting in code execution via a crafted .appl file. This provides remote root access on some platforms such as FreeBSD (used for TrueNAS).
nvd
CVE-2023-39354P3HIGHCVSS 7.5v10.02023-08-31
CVE-2023-39354 [HIGH] CWE-125 CVE-2023-39354: FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache lic FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions are subject to an Out-Of-Bounds Read in the `nsc_rle_decompress_data` function. The Out-Of-Bounds Read occurs because it processes `context->Planes` without checking if it contains data of sufficient length. Should an attacker be
nvd
CVE-2016-1521P3HIGHCVSS 8.8v7.0v8.02016-02-13
CVE-2016-1521 [HIGH] CWE-119 CVE-2016-1521: The directrun function in directmachine.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla F The directrun function in directmachine.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not validate a certain skip operation, which allows remote attackers to execute arbitrary code, obtain sensitive information, or cause a denial of service (out-of-bounds read and application cras
nvd
CVE-2017-17806P3HIGHCVSS 7.8v8.0v9.02017-12-20
CVE-2017-17806 [HIGH] CWE-787 CVE-2017-17806: The HMAC implementation (crypto/hmac.c) in the Linux kernel before 4.14.8 does not validate that the The HMAC implementation (crypto/hmac.c) in the Linux kernel before 4.14.8 does not validate that the underlying cryptographic hash algorithm is unkeyed, allowing a local attacker able to use the AF_ALG-based hash interface (CONFIG_CRYPTO_USER_API_HASH) and the SHA-3 hash algorithm (CONFIG_CRYPTO_SHA3) to cause a kernel stack buffer overflow by executi
nvd
CVE-2025-9086P3HIGHCVSS 7.5v11.02025-09-12
CVE-2025-9086 [HIGH] CWE-125 CVE-2025-9086: 1. A cookie is set using the `secure` keyword for `https://target` 2. curl is redirected to or oth 1. A cookie is set using the `secure` keyword for `https://target` 2. curl is redirected to or otherwise made to speak with `http://target` (same hostname, but using clear text HTTP) using the same cookie set 3. The same cookie name is set - but with just a slash as path (`path=\"/\",`). Since this site is not secure, the cookie *should* just be ignored.
nvd
CVE-2012-1577P3CRITICALCVSS 9.8v8.0v9.0+1 more2019-12-10
CVE-2012-1577 [CRITICAL] CWE-335 CVE-2012-1577: lib/libc/stdlib/random.c in OpenBSD returns 0 when seeded with 0. lib/libc/stdlib/random.c in OpenBSD returns 0 when seeded with 0.
nvd
CVE-2023-35788P3HIGHCVSS 7.8v12.0v10.0+1 more2023-06-16
CVE-2023-35788 [HIGH] CWE-787 CVE-2023-35788: An issue was discovered in fl_set_geneve_opt in net/sched/cls_flower.c in the Linux kernel before 6. An issue was discovered in fl_set_geneve_opt in net/sched/cls_flower.c in the Linux kernel before 6.3.7. It allows an out-of-bounds write in the flower classifier code via TCA_FLOWER_KEY_ENC_OPTS_GENEVE packets. This may result in denial of service or privilege escalation.
nvd
CVE-2021-28374P3HIGHCVSS 7.5v9.02021-03-15
CVE-2021-28374 [HIGH] CWE-732 CVE-2021-28374: The Debian courier-authlib package before 0.71.1-2 for Courier Authentication Library creates a /run The Debian courier-authlib package before 0.71.1-2 for Courier Authentication Library creates a /run/courier/authdaemon directory with weak permissions, allowing an attacker to read user information. This may include a cleartext password in some configurations. In general, it includes the user's existence, uid and gids, home and/or Maildir directory,
nvd
Debian Linux vulnerabilities | cvebase