Debian Linux vulnerabilities
9,954 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358
Vulnerabilities
Page 274 of 498
CVE-2008-2136P4HIGHCVSS 7.8v4.02008-05-16
CVE-2008-2136 [HIGH] CWE-399 CVE-2008-2136: Memory leak in the ipip6_rcv function in net/ipv6/sit.c in the Linux kernel 2.4 before 2.4.36.5 and
Memory leak in the ipip6_rcv function in net/ipv6/sit.c in the Linux kernel 2.4 before 2.4.36.5 and 2.6 before 2.6.25.3 allows remote attackers to cause a denial of service (memory consumption) via network traffic to a Simple Internet Transition (SIT) tunnel interface, related to the pskb_may_pull and kfree_skb functions, and management of an skb referen
nvd
CVE-2020-25713P4MEDIUMCVSS 6.5v9.02021-05-13
CVE-2020-25713 [MEDIUM] CWE-20 CVE-2020-25713: A malformed input file can lead to a segfault due to an out of bounds array access in raptor_xml_wri
A malformed input file can lead to a segfault due to an out of bounds array access in raptor_xml_writer_start_element_common.
nvd
CVE-2022-43681P4MEDIUMCVSS 6.5v10.0v11.0+1 more2023-05-03
CVE-2022-43681 [MEDIUM] CWE-125 CVE-2022-43681: An out-of-bounds read exists in the BGP daemon of FRRouting FRR through 8.4. When sending a malforme
An out-of-bounds read exists in the BGP daemon of FRRouting FRR through 8.4. When sending a malformed BGP OPEN message that ends with the option length octet (or the option length word, in case of an extended OPEN message), the FRR code reads of out of the bounds of the packet, throwing a SIGABRT signal and exiting. This results in a bgpd daemon res
nvd
CVE-2020-7070P3MEDIUMCVSS 5.3v9.0v10.02020-10-02
CVE-2020-7070 [MEDIUM] CWE-20 CVE-2020-7070: In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when PHP is processin
In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when PHP is processing incoming HTTP cookie values, the cookie names are url-decoded. This may lead to cookies with prefixes like __Host confused with cookies that decode to such prefix, thus leading to an attacker being able to forge cookie which is supposed to be secure. S
nvd
CVE-2022-29582P4HIGHCVSS 7.0v11.02022-04-22
CVE-2022-29582 [HIGH] CWE-362 CVE-2022-29582: In the Linux kernel before 5.17.3, fs/io_uring.c has a use-after-free due to a race condition in io_
In the Linux kernel before 5.17.3, fs/io_uring.c has a use-after-free due to a race condition in io_uring timeouts. This can be triggered by a local user who has no access to any user namespace; however, the race condition perhaps can only be exploited infrequently.
nvd
CVE-2021-22207P4MEDIUMCVSS 6.5v9.0v10.0+1 more2021-04-23
CVE-2021-22207 [MEDIUM] CWE-770 CVE-2021-22207: Excessive memory consumption in MS-WSP dissector in Wireshark 3.4.0 to 3.4.4 and 3.2.0 to 3.2.12 all
Excessive memory consumption in MS-WSP dissector in Wireshark 3.4.0 to 3.4.4 and 3.2.0 to 3.2.12 allows denial of service via packet injection or crafted capture file
nvd
CVE-2018-0505P4MEDIUMCVSS 6.5v9.02018-10-04
CVE-2018-0505 [MEDIUM] CWE-287 CVE-2018-0505: Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains a flaw where BotPasswords can bypas
Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains a flaw where BotPasswords can bypass CentralAuth's account lock
nvd
CVE-2015-0501P4MEDIUMCVSS 5.7v7.0v8.02015-04-16
CVE-2015-0501 [MEDIUM] CVE-2015-0501: Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier, and 5.6.23 and earlier, allows
Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier, and 5.6.23 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Compiling.
nvd
CVE-2025-37749P4HIGHCVSS 7.1v11.02025-05-01
CVE-2025-37749 [HIGH] CWE-125 CVE-2025-37749: In the Linux kernel, the following vulnerability has been resolved: net: ppp: Add bound checking fo
In the Linux kernel, the following vulnerability has been resolved:
net: ppp: Add bound checking for skb data on ppp_sync_txmung
Ensure we have enough data in linear buffer from skb before accessing
initial bytes. This prevents potential out-of-bounds accesses
when processing short packets.
When ppp_sync_txmung receives an incoming package with an e
nvd
CVE-2020-4030P4MEDIUMCVSS 6.5v10.02020-06-22
CVE-2020-4030 [MEDIUM] CWE-125 CVE-2020-4030: In FreeRDP before version 2.1.2, there is an out of bounds read in TrioParse. Logging might bypass s
In FreeRDP before version 2.1.2, there is an out of bounds read in TrioParse. Logging might bypass string length checks due to an integer overflow. This is fixed in version 2.1.2.
nvd
CVE-2020-11017P4MEDIUMCVSS 6.5v10.02020-05-29
CVE-2020-11017 [MEDIUM] CWE-415 CVE-2020-11017: In FreeRDP less than or equal to 2.0.0, by providing manipulated input a malicious client can create
In FreeRDP less than or equal to 2.0.0, by providing manipulated input a malicious client can create a double free condition and crash the server. This is fixed in version 2.1.0.
nvd
CVE-2021-21212P4MEDIUMCVSS 6.5v10.02021-04-26
CVE-2021-21212 [MEDIUM] CVE-2021-21212: Incorrect security UI in Network Config UI in Google Chrome on ChromeOS prior to 90.0.4430.72 allowe
Incorrect security UI in Network Config UI in Google Chrome on ChromeOS prior to 90.0.4430.72 allowed a remote attacker to potentially compromise WiFi connection security via a malicious WAP.
nvd
CVE-2022-1734P4HIGHCVSS 7.0v9.0v10.02022-05-18
CVE-2022-1734 [HIGH] CWE-416 CVE-2022-1734: A flaw in Linux Kernel found in nfcmrvl_nci_unregister_dev() in drivers/nfc/nfcmrvl/main.c can lead
A flaw in Linux Kernel found in nfcmrvl_nci_unregister_dev() in drivers/nfc/nfcmrvl/main.c can lead to use after free both read or write when non synchronized between cleanup routine and firmware download routine.
nvd
CVE-2024-35871P4HIGHCVSS 7.1v10.02024-05-19
CVE-2024-35871 [HIGH] CVE-2024-35871: In the Linux kernel, the following vulnerability has been resolved: riscv: process: Fix kernel gp l
In the Linux kernel, the following vulnerability has been resolved:
riscv: process: Fix kernel gp leakage
childregs represents the registers which are active for the new thread
in user context. For a kernel thread, childregs->gp is never used since
the kernel gp is not touched by switch_to. For a user mode helper, the
gp value can be observed in user space a
nvd
CVE-2022-3551P4MEDIUMCVSS 6.5v10.0v11.02022-10-17
CVE-2022-3551 [MEDIUM] CWE-404 CVE-2022-3551: A vulnerability, which was classified as problematic, has been found in X.org Server. Affected by th
A vulnerability, which was classified as problematic, has been found in X.org Server. Affected by this issue is the function ProcXkbGetKbdByName of the file xkb/xkb.c. The manipulation leads to memory leak. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211052.
nvd
CVE-2017-1000376P3HIGHCVSS 7.0v8.0v9.02017-06-19
CVE-2017-1000376 [HIGH] CWE-119 CVE-2017-1000376: libffi requests an executable stack allowing attackers to more easily trigger arbitrary code executi
libffi requests an executable stack allowing attackers to more easily trigger arbitrary code execution by overwriting the stack. Please note that libffi is used by a number of other libraries. It was previously stated that this affects libffi version 3.2.1 but this appears to be incorrect. libffi prior to version 3.1 on 32 bit x86 systems was vuln
nvd
CVE-2020-14365P4HIGHCVSS 7.1v10.02020-09-23
CVE-2020-14365 [HIGH] CWE-347 CVE-2020-14365: A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9
A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using the dnf module. GPG signatures are ignored during installation even when disable_gpg_check is set to False, which is the default behavior. This flaw leads to malicious packages being installed on the syst
nvd
CVE-2014-8602P4MEDIUMCVSS 4.3v7.02014-12-11
CVE-2014-8602 [MEDIUM] CWE-399 CVE-2014-8602: iterator.c in NLnet Labs Unbound before 1.5.1 does not limit delegation chaining, which allows remot
iterator.c in NLnet Labs Unbound before 1.5.1 does not limit delegation chaining, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a large or infinite number of referrals.
nvd
CVE-2023-27561P4HIGHCVSS 7.0v10.02023-03-03
CVE-2023-27561 [HIGH] CVE-2023-27561: runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libc
runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. NOTE: this issue exists because of a CVE-2019-19921 regression.
nvd
CVE-2023-6270P4HIGHCVSS 7.0v10.02024-01-04
CVE-2023-6270 [HIGH] CWE-416 CVE-2023-6270: A flaw was found in the ATA over Ethernet (AoE) driver in the Linux kernel. The aoecmd_cfg_pkts() fu
A flaw was found in the ATA over Ethernet (AoE) driver in the Linux kernel. The aoecmd_cfg_pkts() function improperly updates the refcnt on `struct net_device`, and a use-after-free can be triggered by racing between the free on the struct and the access through the `skbtxq` global queue. This could lead to a denial of service condition or potential cod
nvd