cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 221 of 498
CVE-2018-16276P3HIGHCVSS 7.8v8.0v9.02018-08-31
CVE-2018-16276 [HIGH] CWE-787 CVE-2018-16276: An issue was discovered in yurex_read in drivers/usb/misc/yurex.c in the Linux kernel before 4.17.7. An issue was discovered in yurex_read in drivers/usb/misc/yurex.c in the Linux kernel before 4.17.7. Local attackers could use user access read/writes with incorrect bounds checking in the yurex USB driver to crash the kernel or potentially escalate privileges.
nvd
CVE-2023-5728P3HIGHCVSS 7.5v10.0v11.02023-10-25
CVE-2023-5728 [HIGH] CWE-416 CVE-2023-5728: During garbage collection extra operations were performed on a object that should not be. This could During garbage collection extra operations were performed on a object that should not be. This could have led to a potentially exploitable crash. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
nvd
CVE-2022-26490P3HIGHCVSS 7.8v9.0v10.02022-03-06
CVE-2022-26490 [HIGH] CWE-120 CVE-2022-26490: st21nfca_connectivity_event_received in drivers/nfc/st21nfca/se.c in the Linux kernel through 5.16.1 st21nfca_connectivity_event_received in drivers/nfc/st21nfca/se.c in the Linux kernel through 5.16.12 has EVT_TRANSACTION buffer overflows because of untrusted length parameters.
nvd
CVE-2018-5332P3HIGHCVSS 7.8v7.0v8.02018-01-11
CVE-2018-5332 [HIGH] CWE-787 CVE-2018-5332: In the Linux kernel through 3.2, the rds_message_alloc_sgs() function does not validate a value that In the Linux kernel through 3.2, the rds_message_alloc_sgs() function does not validate a value that is used during DMA page allocation, leading to a heap-based out-of-bounds write (related to the rds_rdma_extra_size function in net/rds/rdma.c).
nvd
CVE-2021-39258P3HIGHCVSS 7.8v9.0v10.0+1 more2021-09-07
CVE-2021-39258 [HIGH] CWE-125 CVE-2021-39258: A crafted NTFS image can cause out-of-bounds reads in ntfs_attr_find and ntfs_external_attr_find in A crafted NTFS image can cause out-of-bounds reads in ntfs_attr_find and ntfs_external_attr_find in NTFS-3G < 2021.8.22.
nvd
CVE-2008-6124P3HIGHCVSS 7.5v4.02009-02-13
CVE-2008-6124 [HIGH] CWE-89 CVE-2008-6124: SQL injection vulnerability in the hotpot_delete_selected_attempts function in report.php in the Hot SQL injection vulnerability in the hotpot_delete_selected_attempts function in report.php in the HotPot module in Moodle 1.6 before 1.6.7, 1.7 before 1.7.5, 1.8 before 1.8.6, and 1.9 before 1.9.2 allows remote attackers to execute arbitrary SQL commands via a crafted selected attempt.
nvd
CVE-2021-39259P3HIGHCVSS 7.8v9.0v10.0+1 more2021-09-07
CVE-2021-39259 [HIGH] CWE-787 CVE-2021-39259: A crafted NTFS image can trigger an out-of-bounds access, caused by an unsanitized attribute length A crafted NTFS image can trigger an out-of-bounds access, caused by an unsanitized attribute length in ntfs_inode_lookup_by_name, in NTFS-3G < 2021.8.22.
nvd
CVE-2010-4661P3HIGHCVSS 7.8v8.02019-11-13
CVE-2010-4661 [HIGH] CWE-434 CVE-2010-4661: udisks before 1.0.3 allows a local user to load arbitrary Linux kernel modules. udisks before 1.0.3 allows a local user to load arbitrary Linux kernel modules.
nvd
CVE-2012-3409P3HIGHCVSS 7.8v8.0v9.02019-12-20
CVE-2012-3409 [HIGH] CWE-20 CVE-2012-3409: ecryptfs-utils: suid helper does not restrict mounting filesystems with nosuid,nodev which creates a ecryptfs-utils: suid helper does not restrict mounting filesystems with nosuid,nodev which creates a possible privilege escalation
nvd
CVE-2018-19962P3HIGHCVSS 7.8v9.02018-12-08
CVE-2018-19962 [HIGH] CWE-200 CVE-2018-19962: An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because small IOMMU mappings are unsafely combined into larger ones.
nvd
CVE-2018-19961P3HIGHCVSS 7.8v9.02018-12-08
CVE-2018-19961 [HIGH] CWE-459 CVE-2018-19961: An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because TLB flushes do not always occur after IOMMU mapping changes.
nvd
CVE-2021-30163P3HIGHCVSS 7.5v9.02021-04-06
CVE-2021-30163 [HIGH] CVE-2021-30163: Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to discover the names of private projec Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to discover the names of private projects if issue-journal details exist that have changes to project_id values.
nvd
CVE-2022-30784P3HIGHCVSS 7.8v9.0v10.0+1 more2022-05-26
CVE-2022-30784 [HIGH] CWE-120 CVE-2022-30784: A crafted NTFS image can cause heap exhaustion in ntfs_get_attribute_value in NTFS-3G through 2021.8 A crafted NTFS image can cause heap exhaustion in ntfs_get_attribute_value in NTFS-3G through 2021.8.22.
nvd
CVE-2017-5669P3HIGHCVSS 7.8v8.02017-02-24
CVE-2017-5669 [HIGH] CVE-2017-5669: The do_shmat function in ipc/shm.c in the Linux kernel through 4.9.12 does not restrict the address The do_shmat function in ipc/shm.c in the Linux kernel through 4.9.12 does not restrict the address calculated by a certain rounding operation, which allows local users to map page zero, and consequently bypass a protection mechanism that exists for the mmap system call, by making crafted shmget and shmat system calls in a privileged context.
nvd
CVE-2021-26720P3HIGHCVSS 7.8v9.0v10.02021-02-17
CVE-2021-26720 [HIGH] CWE-59 CVE-2021-26720: avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root via /etc/net avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root via /etc/network/if-up.d/avahi-daemon, and allows a local attacker to cause a denial of service or create arbitrary empty files via a symlink attack on files under /run/avahi-daemon. NOTE: this only affects the packaging for Debian GNU/Linux (used indirectly by SUSE
nvd
CVE-2019-25058P3HIGHCVSS 7.8v9.02022-02-24
CVE-2019-25058 [HIGH] CWE-863 CVE-2019-25058: An issue was discovered in USBGuard before 1.1.0. On systems with the usbguard-dbus daemon running, An issue was discovered in USBGuard before 1.1.0. On systems with the usbguard-dbus daemon running, an unprivileged user could make USBGuard allow all USB devices to be connected in the future.
nvd
CVE-2021-23177P3HIGHCVSS 7.8v10.02022-08-23
CVE-2021-23177 [HIGH] CWE-59 CVE-2021-23177: An improper link resolution flaw while extracting an archive can lead to changing the access control An improper link resolution flaw while extracting an archive can lead to changing the access control list (ACL) of the target of the link. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extract the archive. A local attacker may use this flaw to change the ACL of a file on the system and gain mor
nvd
CVE-2020-25595P3HIGHCVSS 7.8v10.02020-09-23
CVE-2020-25595 [HIGH] CWE-269 CVE-2020-25595: An issue was discovered in Xen through 4.14.x. The PCI passthrough code improperly uses register dat An issue was discovered in Xen through 4.14.x. The PCI passthrough code improperly uses register data. Code paths in Xen's MSI handling have been identified that act on unsanitized values read back from device hardware registers. While devices strictly compliant with PCI specifications shouldn't be able to affect these registers, experience shows that
nvd
CVE-2025-38437P3HIGHCVSS 7.8v11.02025-07-25
CVE-2025-38437 [HIGH] CWE-416 CVE-2025-38437: In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix potential use-after- In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix potential use-after-free in oplock/lease break ack If ksmbd_iov_pin_rsp return error, use-after-free can happen by accessing opinfo->state and opinfo_put and ksmbd_fd_put could called twice.
nvd
CVE-2021-27379P3HIGHCVSS 7.8v10.02021-02-18
CVE-2021-27379 [HIGH] CVE-2021-27379: An issue was discovered in Xen through 4.11.x, allowing x86 Intel HVM guest OS users to achieve unin An issue was discovered in Xen through 4.11.x, allowing x86 Intel HVM guest OS users to achieve unintended read/write DMA access, and possibly cause a denial of service (host OS crash) or gain privileges. This occurs because a backport missed a flush, and thus IOMMU updates were not always correct. NOTE: this issue exists because of an incomplete fix for CVE-
nvd
Debian Linux vulnerabilities | cvebase