Debian Linux vulnerabilities

9,914 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,914
CISA KEV
119
actively exploited
Public exploits
429
Exploited in wild
132
Severity breakdown
CRITICAL1128HIGH4113MEDIUM4311LOW362

Vulnerabilities

Page 176 of 496
CVE-2021-21169HIGHCVSS 8.8v10.02021-03-09
CVE-2021-21169 [HIGH] CWE-787 CVE-2021-21169: Out of bounds memory access in V8 in Google Chrome prior to 89.0.4389.72 allowed a remote attacker t Out of bounds memory access in V8 in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
nvd
CVE-2021-21172HIGHCVSS 8.1v10.02021-03-09
CVE-2021-21172 [HIGH] CVE-2021-21172: Insufficient policy enforcement in File System API in Google Chrome on Windows prior to 89.0.4389.72 Insufficient policy enforcement in File System API in Google Chrome on Windows prior to 89.0.4389.72 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.
nvd
CVE-2021-21180HIGHCVSS 8.8v10.02021-03-09
CVE-2021-21180 [HIGH] CWE-416 CVE-2021-21180: Use after free in tab search in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to pot Use after free in tab search in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-20275HIGHCVSS 7.5v9.02021-03-09
CVE-2021-20275 [HIGH] CWE-119 CVE-2021-20275: A flaw was found in privoxy before 3.0.32. A invalid read of size two may occur in chunked_body_is_c A flaw was found in privoxy before 3.0.32. A invalid read of size two may occur in chunked_body_is_complete() leading to denial of service.
nvd
CVE-2021-21300HIGHCVSS 7.5PoCv10.02021-03-09
CVE-2021-21300 [HIGH] CWE-59 CVE-2021-21300: Git is an open-source distributed revision control system. In affected versions of Git a specially c Git is an open-source distributed revision control system. In affected versions of Git a specially crafted repository that contains symbolic links as well as files using a clean/smudge filter such as Git LFS, may cause just-checked out script to be executed while cloning onto a case-insensitive file system such as NTFS, HFS+ or APFS (i.e. the default f
nvd
CVE-2021-21159HIGHCVSS 8.8v10.02021-03-09
CVE-2021-21159 [HIGH] CWE-416 CVE-2021-21159: Heap buffer overflow in TabStrip in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to Heap buffer overflow in TabStrip in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-21167HIGHCVSS 8.8v10.02021-03-09
CVE-2021-21167 [HIGH] CWE-416 CVE-2021-21167: Use after free in bookmarks in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to pote Use after free in bookmarks in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-21162HIGHCVSS 8.8v10.02021-03-09
CVE-2021-21162 [HIGH] CWE-416 CVE-2021-21162: Use after free in WebRTC in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potenti Use after free in WebRTC in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-35524HIGHCVSS 7.8v9.0v10.02021-03-09
CVE-2020-35524 [HIGH] CWE-787 CVE-2020-35524: A heap-based buffer overflow flaw was found in libtiff in the handling of TIFF images in libtiff's T A heap-based buffer overflow flaw was found in libtiff in the handling of TIFF images in libtiff's TIFF2PDF tool. A specially crafted TIFF file can lead to arbitrary code execution. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
nvd
CVE-2021-21190HIGHCVSS 8.8v10.02021-03-09
CVE-2021-21190 [HIGH] CWE-908 CVE-2021-21190: Uninitialized data in PDFium in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to obt Uninitialized data in PDFium in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted PDF file.
nvd
CVE-2021-20241MEDIUMCVSS 5.5v9.02021-03-09
CVE-2021-20241 [MEDIUM] CWE-369 CVE-2021-20241: A flaw was found in ImageMagick in coders/jp2.c. An attacker who submits a crafted file that is proc A flaw was found in ImageMagick in coders/jp2.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat from this vulnerability is to system availability.
nvd
CVE-2021-21175MEDIUMCVSS 6.5v10.02021-03-09
CVE-2021-21175 [MEDIUM] CWE-346 CVE-2021-21175: Inappropriate implementation in Site isolation in Google Chrome prior to 89.0.4389.72 allowed a remo Inappropriate implementation in Site isolation in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2021-21187MEDIUMCVSS 4.3v10.02021-03-09
CVE-2021-21187 [MEDIUM] CVE-2021-21187: Insufficient data validation in URL formatting in Google Chrome prior to 89.0.4389.72 allowed a remo Insufficient data validation in URL formatting in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
nvd
CVE-2021-21168MEDIUMCVSS 6.5v10.02021-03-09
CVE-2021-21168 [MEDIUM] CVE-2021-21168: Insufficient policy enforcement in appcache in Google Chrome prior to 89.0.4389.72 allowed a remote Insufficient policy enforcement in appcache in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2021-21184MEDIUMCVSS 4.3v10.02021-03-09
CVE-2021-21184 [MEDIUM] CWE-346 CVE-2021-21184: Inappropriate implementation in performance APIs in Google Chrome prior to 89.0.4389.72 allowed a re Inappropriate implementation in performance APIs in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2021-21171MEDIUMCVSS 6.5v10.02021-03-09
CVE-2021-21171 [MEDIUM] CVE-2021-21171: Incorrect security UI in TabStrip and Navigation in Google Chrome on Android prior to 89.0.4389.72 a Incorrect security UI in TabStrip and Navigation in Google Chrome on Android prior to 89.0.4389.72 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2021-21176MEDIUMCVSS 6.5v10.02021-03-09
CVE-2021-21176 [MEDIUM] CVE-2021-21176: Inappropriate implementation in full screen mode in Google Chrome prior to 89.0.4389.72 allowed a re Inappropriate implementation in full screen mode in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2021-28116MEDIUMCVSS 5.3v10.0v11.02021-03-09
CVE-2021-28116 [MEDIUM] CWE-125 CVE-2021-28116: Squid through 4.14 and 5.x through 5.0.5, in some configurations, allows information disclosure beca Squid through 4.14 and 5.x through 5.0.5, in some configurations, allows information disclosure because of an out-of-bounds read in WCCP protocol data. This can be leveraged as part of a chain for remote code execution as nobody.
nvd
CVE-2021-21185MEDIUMCVSS 4.3v10.02021-03-09
CVE-2021-21185 [MEDIUM] CVE-2021-21185: Insufficient policy enforcement in extensions in Google Chrome prior to 89.0.4389.72 allowed an atta Insufficient policy enforcement in extensions in Google Chrome prior to 89.0.4389.72 allowed an attacker who convinced a user to install a malicious extension to obtain sensitive information via a crafted Chrome Extension.
nvd
CVE-2021-20246MEDIUMCVSS 5.5v9.02021-03-09
CVE-2021-20246 [MEDIUM] CWE-369 CVE-2021-20246: A flaw was found in ImageMagick in MagickCore/resample.c. An attacker who submits a crafted file tha A flaw was found in ImageMagick in MagickCore/resample.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat from this vulnerability is to system availability.
nvd