Debian Linux vulnerabilities
9,954 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358
Vulnerabilities
Page 279 of 498
CVE-2013-2070P4MEDIUMCVSS 5.8v6.0v7.02013-07-20
CVE-2013-2070 [MEDIUM] CVE-2013-2070: http/modules/ngx_http_proxy_module.c in nginx 1.1.4 through 1.2.8 and 1.3.0 through 1.4.0, when prox
http/modules/ngx_http_proxy_module.c in nginx 1.1.4 through 1.2.8 and 1.3.0 through 1.4.0, when proxy_pass is used with untrusted HTTP servers, allows remote attackers to cause a denial of service (crash) and obtain sensitive information from worker process memory via a crafted proxy response, a similar vulnerability to CVE-2013-2028.
nvd
CVE-2014-3165P4HIGHCVSS 7.5v7.0v8.02014-08-13
CVE-2014-3165 [HIGH] CVE-2014-3165: Use-after-free vulnerability in modules/websockets/WorkerThreadableWebSocketChannel.cpp in the Web S
Use-after-free vulnerability in modules/websockets/WorkerThreadableWebSocketChannel.cpp in the Web Sockets implementation in Blink, as used in Google Chrome before 36.0.1985.143, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an unexpectedly long lifetime of a temporary object during metho
nvd
CVE-2015-1260P4HIGHCVSS 7.5v8.02015-05-20
CVE-2015-1260 [HIGH] CVE-2015-1260: Multiple use-after-free vulnerabilities in content/renderer/media/user_media_client_impl.cc in the W
Multiple use-after-free vulnerabilities in content/renderer/media/user_media_client_impl.cc in the WebRTC implementation in Google Chrome before 43.0.2357.65 allow remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that executes upon completion of a getUserMedia request.
nvd
CVE-2015-1272P4HIGHCVSS 7.5v8.02015-07-23
CVE-2015-1272 [HIGH] CVE-2015-1272: Use-after-free vulnerability in the GPU process implementation in Google Chrome before 44.0.2403.89
Use-after-free vulnerability in the GPU process implementation in Google Chrome before 44.0.2403.89 allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging the continued availability of a GPUChannelHost data structure during Blink shutdown, related to content/browser/gpu/browser_gpu_channel_host_factory.cc and
nvd
CVE-2015-8474P4HIGHCVSS 7.4v7.0v8.02016-04-12
CVE-2015-8474 [HIGH] CVE-2015-8474: Open redirect vulnerability in the valid_back_url function in app/controllers/application_controller
Open redirect vulnerability in the valid_back_url function in app/controllers/application_controller.rb in Redmine before 2.6.7, 3.0.x before 3.0.5, and 3.1.x before 3.1.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted back_url parameter, as demonstrated by "@attacker.com," a different vulnerability t
nvd
CVE-2023-1993P4MEDIUMCVSS 6.5v10.0v12.02023-04-12
CVE-2023-1993 [MEDIUM] CWE-834 CVE-2023-1993: LISP dissector large loop in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service v
LISP dissector large loop in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture file
nvd
CVE-2015-8784P4MEDIUMCVSS 6.5v7.0v8.02016-04-13
CVE-2015-8784 [MEDIUM] CWE-787 CVE-2015-8784: The NeXTDecode function in tif_next.c in LibTIFF allows remote attackers to cause a denial of servic
The NeXTDecode function in tif_next.c in LibTIFF allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted TIFF image, as demonstrated by libtiff5.tif.
nvd
CVE-2015-8666P4HIGHCVSS 7.9v8.02017-04-11
CVE-2015-8666 [HIGH] CWE-787 CVE-2015-8666: Heap-based buffer overflow in QEMU, when built with the Q35-chipset-based PC system emulator.
Heap-based buffer overflow in QEMU, when built with the Q35-chipset-based PC system emulator.
nvd
CVE-2022-41404P4HIGHCVSS 7.5v10.02022-10-11
CVE-2022-41404 [HIGH] CWE-400 CVE-2022-41404: An issue in the fetch() method in the BasicProfile class of org.ini4j through version v0.5.4 allows
An issue in the fetch() method in the BasicProfile class of org.ini4j through version v0.5.4 allows attackers to cause a Denial of Service (DoS) via unspecified vectors.
nvd
CVE-2013-2883P4HIGHCVSS 7.5v7.02013-07-31
CVE-2013-2883 [HIGH] CWE-399 CVE-2013-2883: Use-after-free vulnerability in Google Chrome before 28.0.1500.95 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 28.0.1500.95 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to deleting the registration of a MutationObserver object.
nvd
CVE-2017-17855P4HIGHCVSS 7.8v9.02017-12-27
CVE-2017-17855 [HIGH] CWE-119 CVE-2017-17855: kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of ser
kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging improper use of pointers in place of scalars.
nvd
CVE-2017-17863P4HIGHCVSS 7.8v9.02017-12-27
CVE-2017-17863 [HIGH] CWE-190 CVE-2017-17863: kernel/bpf/verifier.c in the Linux kernel 4.9.x through 4.9.71 does not check the relationship betwe
kernel/bpf/verifier.c in the Linux kernel 4.9.x through 4.9.71 does not check the relationship between pointer values and the BPF stack, which allows local users to cause a denial of service (integer overflow or invalid memory access) or possibly have unspecified other impact.
nvd
CVE-2016-1700P4HIGHCVSS 7.5v8.02016-06-05
CVE-2016-1700 [HIGH] CVE-2016-1700: extensions/renderer/runtime_custom_bindings.cc in Google Chrome before 51.0.2704.79 does not conside
extensions/renderer/runtime_custom_bindings.cc in Google Chrome before 51.0.2704.79 does not consider side effects during creation of an array of extension views, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via vectors related to extensions.
nvd
CVE-2017-16996P4HIGHCVSS 7.8v9.02017-12-27
CVE-2017-16996 [HIGH] CWE-119 CVE-2017-16996: kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of ser
kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging register truncation mishandling.
nvd
CVE-2017-17857P4HIGHCVSS 7.8v9.02017-12-27
CVE-2017-17857 [HIGH] CWE-119 CVE-2017-17857: The check_stack_boundary function in kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows
The check_stack_boundary function in kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging mishandling of invalid variable stack read operations.
nvd
CVE-2017-17856P4HIGHCVSS 7.8v9.02017-12-27
CVE-2017-17856 [HIGH] CWE-119 CVE-2017-17856: kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of ser
kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging the lack of stack-pointer alignment enforcement.
nvd
CVE-2015-8036P4MEDIUMCVSS 6.8v7.0v8.02015-11-02
CVE-2015-8036 [MEDIUM] CVE-2015-8036: Heap-based buffer overflow in ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.x before 2.
Heap-based buffer overflow in ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.x before 2.1.2 allows remote SSL servers to cause a denial of service (client crash) and possibly execute arbitrary code via a long session ticket name to the session ticket extension, which is not properly handled when creating a ClientHello message to resume a session.
nvd
CVE-2017-17853P4HIGHCVSS 7.8v9.02017-12-27
CVE-2017-17853 [HIGH] CWE-119 CVE-2017-17853: kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of ser
kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging incorrect BPF_RSH signed bounds calculations.
nvd
CVE-2022-47655P4HIGHCVSS 7.8v10.02023-01-05
CVE-2022-47655 [HIGH] CWE-787 CVE-2022-47655: Libde265 1.0.9 is vulnerable to Buffer Overflow in function void put_qpel_fallback<unsigned short>
Libde265 1.0.9 is vulnerable to Buffer Overflow in function void put_qpel_fallback
nvd
CVE-2014-9904P4HIGHCVSS 7.8v8.02016-06-27
CVE-2014-9904 [HIGH] CVE-2014-9904: The snd_compress_check_input function in sound/core/compress_offload.c in the ALSA subsystem in the
The snd_compress_check_input function in sound/core/compress_offload.c in the ALSA subsystem in the Linux kernel before 3.17 does not properly check for an integer overflow, which allows local users to cause a denial of service (insufficient memory allocation) or possibly have unspecified other impact via a crafted SNDRV_COMPRESS_SET_PARAMS ioctl call.
nvd