cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 272 of 498
CVE-2020-15983P4HIGHCVSS 7.8v10.02020-11-03
CVE-2020-15983 [HIGH] CWE-20 CVE-2020-15983: Insufficient data validation in webUI in Google Chrome on ChromeOS prior to 86.0.4240.75 allowed a l Insufficient data validation in webUI in Google Chrome on ChromeOS prior to 86.0.4240.75 allowed a local attacker to bypass content security policy via a crafted HTML page.
nvd
CVE-2018-1066P4MEDIUMCVSS 6.5v8.0v9.02018-03-02
CVE-2018-1066 [MEDIUM] CWE-476 CVE-2018-1066: The Linux kernel before version 4.11 is vulnerable to a NULL pointer dereference in fs/cifs/cifsencr The Linux kernel before version 4.11 is vulnerable to a NULL pointer dereference in fs/cifs/cifsencrypt.c:setup_ntlmv2_rsp() that allows an attacker controlling a CIFS server to kernel panic a client that has this server mounted, because an empty TargetInfo field in an NTLMSSP setup negotiation response is mishandled during session recovery.
nvd
CVE-2018-10938P4MEDIUMCVSS 5.9v9.02018-08-27
CVE-2018-10938 [MEDIUM] CWE-835 CVE-2018-10938: A flaw was found in the Linux kernel present since v4.0-rc1 and through v4.13-rc4. A crafted network A flaw was found in the Linux kernel present since v4.0-rc1 and through v4.13-rc4. A crafted network packet sent remotely by an attacker may force the kernel to enter an infinite loop in the cipso_v4_optptr() function in net/ipv4/cipso_ipv4.c leading to a denial-of-service. A certain non-default configuration of LSM (Linux Security Module) and NetLa
nvd
CVE-2021-35561P4MEDIUMCVSS 5.3v9.0v10.0+1 more2021-10-20
CVE-2021-35561 [MEDIUM] CVE-2021-35561: Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Utility). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compr
nvd
CVE-2019-13117P4MEDIUMCVSS 5.3v8.02019-07-01
CVE-2019-13117 [MEDIUM] CWE-908 CVE-2019-13117: In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitiali In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte on the stack contains the characters A, a, I, i, or 0, or any other character.
nvd
CVE-2020-29260P4HIGHCVSS 7.5v10.02022-09-02
CVE-2020-29260 [HIGH] CWE-400 CVE-2020-29260: libvncclient v0.9.13 was discovered to contain a memory leak via the function rfbClientCleanup(). libvncclient v0.9.13 was discovered to contain a memory leak via the function rfbClientCleanup().
nvd
CVE-2019-6341P4MEDIUMCVSS 5.4v8.02019-03-26
CVE-2019-6341 [MEDIUM] CWE-79 CVE-2019-6341: In Drupal 7 versions prior to 7.65; Drupal 8.6 versions prior to 8.6.13;Drupal 8.5 versions prior to In Drupal 7 versions prior to 7.65; Drupal 8.6 versions prior to 8.6.13;Drupal 8.5 versions prior to 8.5.14. Under certain circumstances the File module/subsystem allows a malicious user to upload a file that can trigger a cross-site scripting (XSS) vulnerability.
nvd
CVE-2015-2568P4MEDIUMCVSS 5.0v7.0v8.02015-04-16
CVE-2015-2568 [MEDIUM] CVE-2015-2568: Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows remote attackers to affect availability via unknown vectors related to Server : Security : Privileges.
nvd
CVE-2007-6601P4HIGHCVSS 7.2v3.1v4.02008-01-09
CVE-2007-6601 [HIGH] CVE-2007-6601: The DBLink module in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, 7.4 before 7 The DBLink module in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, 7.4 before 7.4.19, and 7.3 before 7.3.21, when local trust or ident authentication is used, allows remote attackers to gain privileges via unspecified vectors. NOTE: this issue exists because of an incomplete fix for CVE-2007-3278.
nvd
CVE-2021-35586P4MEDIUMCVSS 5.3v9.0v10.0+1 more2021-10-20
CVE-2021-35586 [MEDIUM] CVE-2021-35586: Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compr
nvd
CVE-2011-0480P4CRITICALCVSS 9.3v6.02011-01-14
CVE-2011-0480 [CRITICAL] CWE-120 CVE-2011-0480: Multiple buffer overflows in vorbis_dec.c in the Vorbis decoder in FFmpeg, as used in Google Chrome Multiple buffer overflows in vorbis_dec.c in the Vorbis decoder in FFmpeg, as used in Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344, allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a crafted WebM file, related to buffers for (1) the channel
nvd
CVE-2015-6251P4MEDIUMCVSS 5.0v8.02015-08-24
CVE-2015-6251 [MEDIUM] CVE-2015-6251: Double free vulnerability in GnuTLS before 3.3.17 and 3.4.x before 3.4.4 allows remote attackers to Double free vulnerability in GnuTLS before 3.3.17 and 3.4.x before 3.4.4 allows remote attackers to cause a denial of service via a long DistinguishedName (DN) entry in a certificate.
nvd
CVE-2018-0735P4MEDIUMCVSS 5.9v8.0v9.02018-10-29
CVE-2018-0735 [MEDIUM] CWE-327 CVE-2018-0735: The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attac The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.1.1a (Affected 1.1.1).
nvd
CVE-2021-35578P4MEDIUMCVSS 5.3v9.0v10.0+1 more2021-10-20
CVE-2021-35578 [MEDIUM] CVE-2021-35578: Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Java SE, Oracle Gra
nvd
CVE-2014-9015P4MEDIUMCVSS 6.8v7.02014-11-24
CVE-2014-9015 [MEDIUM] CWE-264 CVE-2014-9015: Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack sessions via a crafted Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack sessions via a crafted request, as demonstrated by a crafted request to a server that supports both HTTP and HTTPS sessions.
nvd
CVE-2019-5798P4MEDIUMCVSS 6.5v8.0v9.02019-05-23
CVE-2019-5798 [MEDIUM] CWE-125 CVE-2019-5798: Lack of correct bounds checking in Skia in Google Chrome prior to 73.0.3683.75 allowed a remote atta Lack of correct bounds checking in Skia in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
nvd
CVE-2018-10839P4MEDIUMCVSS 6.5v8.0v9.02018-10-16
CVE-2018-10839 [MEDIUM] CWE-121 CVE-2018-10839: Qemu emulator <= 3.0.0 built with the NE2000 NIC emulation support is vulnerable to an integer overf Qemu emulator <= 3.0.0 built with the NE2000 NIC emulation support is vulnerable to an integer overflow, which could lead to buffer overflow issue. It could occur when receiving packets over the network. A user inside guest could use this flaw to crash the Qemu process resulting in DoS.
nvd
CVE-2019-9433P3MEDIUMCVSS 6.5v8.0v9.0+1 more2019-09-27
CVE-2019-9433 [MEDIUM] CWE-20 CVE-2019-9433: In libvpx, there is a possible information disclosure due to improper input validation. This could l In libvpx, there is a possible information disclosure due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-80479354
nvd
CVE-2017-3258P4MEDIUMCVSS 6.5v8.02017-01-27
CVE-2017-3258 [MEDIUM] CWE-20 CVE-2017-3258: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported v Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.5.53 and earlier, 5.6.34 and earlier and 5.7.16 and earlier. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this
nvd
CVE-2021-28957P4MEDIUMCVSS 6.1v9.0v10.02021-03-21
CVE-2021-28957 [MEDIUM] CWE-79 CVE-2021-28957: An XSS vulnerability was discovered in python-lxml's clean module versions before 4.6.3. When disabl An XSS vulnerability was discovered in python-lxml's clean module versions before 4.6.3. When disabling the safe_attrs_only and forms arguments, the Cleaner class does not remove the formaction attribute allowing for JS to bypass the sanitizer. A remote attacker could exploit this flaw to run arbitrary JS code on users who interact with incorrectly s
nvd
Debian Linux vulnerabilities | cvebase