cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 280 of 498
CVE-2013-6049P4HIGHCVSS 7.8v7.0v8.02017-10-20
CVE-2013-6049 [HIGH] CWE-20 CVE-2013-6049: apt-listbugs before 0.1.10 creates temporary files insecurely, which allows attackers to have unspec apt-listbugs before 0.1.10 creates temporary files insecurely, which allows attackers to have unspecified impact via unknown vectors.
nvd
CVE-2017-9076P4HIGHCVSS 7.8v8.0v9.02017-05-19
CVE-2017-9076 [HIGH] CVE-2017-9076: The dccp_v6_request_recv_sock function in net/dccp/ipv6.c in the Linux kernel through 4.11.1 mishand The dccp_v6_request_recv_sock function in net/dccp/ipv6.c in the Linux kernel through 4.11.1 mishandles inheritance, which allows local users to cause a denial of service or possibly have unspecified other impact via crafted system calls, a related issue to CVE-2017-8890.
nvd
CVE-2017-9075P4HIGHCVSS 7.8v8.0v9.02017-05-19
CVE-2017-9075 [HIGH] CVE-2017-9075: The sctp_v6_create_accept_sk function in net/sctp/ipv6.c in the Linux kernel through 4.11.1 mishandl The sctp_v6_create_accept_sk function in net/sctp/ipv6.c in the Linux kernel through 4.11.1 mishandles inheritance, which allows local users to cause a denial of service or possibly have unspecified other impact via crafted system calls, a related issue to CVE-2017-8890.
nvd
CVE-2023-25221P4HIGHCVSS 7.8v10.02023-03-01
CVE-2023-25221 [HIGH] CWE-787 CVE-2023-25221: Libde265 v1.0.10 was discovered to contain a heap-buffer-overflow vulnerability in the derive_spatia Libde265 v1.0.10 was discovered to contain a heap-buffer-overflow vulnerability in the derive_spatial_luma_vector_prediction function in motion.cc.
nvd
CVE-2019-3498P4MEDIUMCVSS 6.5v8.0v9.02019-01-09
CVE-2019-3498 [MEDIUM] CWE-74 CVE-2019-3498: In Django 1.11.x before 1.11.18, 2.0.x before 2.0.10, and 2.1.x before 2.1.5, an Improper Neutraliza In Django 1.11.x before 1.11.18, 2.0.x before 2.0.10, and 2.1.x before 2.1.5, an Improper Neutralization of Special Elements in Output Used by a Downstream Component issue exists in django.views.defaults.page_not_found(), leading to content spoofing (in a 404 error page) if a user fails to recognize that a crafted URL has malicious content.
nvd
CVE-2006-1724P4HIGHCVSS 7.5v3.12006-04-14
CVE-2006-1724 [HIGH] CVE-2006-1724: Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, 1.0.x before 1.0.8, Mozilla Sui Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via attack vectors related to DHTML.
nvd
CVE-2014-9112P4MEDIUMCVSS 5.0v7.02014-12-02
CVE-2014-9112 [MEDIUM] CWE-119 CVE-2014-9112: Heap-based buffer overflow in the process_copy_in function in GNU Cpio 2.11 allows remote attackers Heap-based buffer overflow in the process_copy_in function in GNU Cpio 2.11 allows remote attackers to cause a denial of service via a large block value in a cpio archive.
nvd
CVE-2018-16851P4MEDIUMCVSS 6.5v8.0v9.02018-11-28
CVE-2018-16851 [MEDIUM] CWE-476 CVE-2018-16851: Samba from version 4.0.0 and before versions 4.7.12, 4.8.7, 4.9.3 is vulnerable to a denial of servi Samba from version 4.0.0 and before versions 4.7.12, 4.8.7, 4.9.3 is vulnerable to a denial of service. During the processing of an LDAP search before Samba's AD DC returns the LDAP entries to the client, the entries are cached in a single memory object with a maximum size of 256MB. When this size is reached, the Samba process providing the LDAP ser
nvd
CVE-2018-12365P4MEDIUMCVSS 6.5v8.0v9.02018-10-18
CVE-2018-12365 [MEDIUM] CWE-200 CVE-2018-12365: A compromised IPC child process can escape the content sandbox and list the names of arbitrary files A compromised IPC child process can escape the content sandbox and list the names of arbitrary files on the file system without user consent or interaction. This could result in exposure of private local files. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.
nvd
CVE-2025-25475P4HIGHCVSS 7.5v11.02025-02-18
CVE-2025-25475 [HIGH] CWE-476 CVE-2025-25475: A NULL pointer dereference in the component /libsrc/dcrleccd.cc of DCMTK v3.6.9+ DEV allows attacker A NULL pointer dereference in the component /libsrc/dcrleccd.cc of DCMTK v3.6.9+ DEV allows attackers to cause a Denial of Service (DoS) via a crafted DICOM file.
nvd
CVE-2018-14661P4MEDIUMCVSS 6.5v8.0v9.02018-10-31
CVE-2018-14661 [MEDIUM] CWE-20 CVE-2018-14661: It was found that usage of snprintf function in feature/locks translator of glusterfs server 3.8.4, It was found that usage of snprintf function in feature/locks translator of glusterfs server 3.8.4, as shipped with Red Hat Gluster Storage, was vulnerable to a format string attack. A remote, authenticated attacker could use this flaw to cause remote denial of service.
nvd
CVE-2018-18351P4MEDIUMCVSS 6.5v9.02018-12-11
CVE-2018-18351 [MEDIUM] CWE-20 CVE-2018-18351: Lack of proper validation of ancestor frames site when sending lax cookies in Navigation in Google C Lack of proper validation of ancestor frames site when sending lax cookies in Navigation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to bypass SameSite cookie policy via a crafted HTML page.
nvd
CVE-2019-18420P4MEDIUMCVSS 6.5v9.0v10.02019-10-31
CVE-2019-18420 [MEDIUM] CWE-134 CVE-2019-18420: An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to cause a denial of se An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to cause a denial of service via a VCPUOP_initialise hypercall. hypercall_create_continuation() is a variadic function which uses a printf-like format string to interpret its parameters. Error handling for a bad format character was done using BUG(), which crashes Xen. One
nvd
CVE-2007-5730P4HIGHCVSS 7.2v3.1v4.02007-10-30
CVE-2007-5730 [HIGH] CVE-2007-5730: Heap-based buffer overflow in QEMU 0.8.2, as used in Xen and possibly other products, allows local u Heap-based buffer overflow in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to execute arbitrary code via crafted data in the "net socket listen" option, aka QEMU "net socket" heap overflow. NOTE: some sources have used CVE-2007-1321 to refer to this issue as part of "NE2000 network driver and the socket code," but this is the corre
nvd
CVE-2017-2636P4HIGHCVSS 7.0v8.02017-03-07
CVE-2017-2636 [HIGH] CWE-362 CVE-2017-2636: Race condition in drivers/tty/n_hdlc.c in the Linux kernel through 4.10.1 allows local users to gain Race condition in drivers/tty/n_hdlc.c in the Linux kernel through 4.10.1 allows local users to gain privileges or cause a denial of service (double free) by setting the HDLC line discipline.
nvd
CVE-2014-1737P4HIGHCVSS 7.2v6.0v7.02014-05-11
CVE-2014-1737 [HIGH] CWE-754 CVE-2014-1737: The raw_cmd_copyin function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not pr The raw_cmd_copyin function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly handle error conditions during processing of an FDRAWCMD ioctl call, which allows local users to trigger kfree operations and gain privileges by leveraging write access to a /dev/fd device.
nvd
CVE-2016-3168P4MEDIUMCVSS 6.4v7.0v8.02016-04-12
CVE-2016-3168 [MEDIUM] CWE-254 CVE-2016-3168: The System module in Drupal 6.x before 6.38 and 7.x before 7.43 might allow remote attackers to hija The System module in Drupal 6.x before 6.38 and 7.x before 7.43 might allow remote attackers to hijack the authentication of site administrators for requests that download and run files with arbitrary JSON-encoded content, aka a "reflected file download vulnerability."
nvd
CVE-2020-14562P4MEDIUMCVSS 5.3v10.02020-07-15
CVE-2020-14562 [MEDIUM] CVE-2020-14562: Vulnerability in the Java SE product of Oracle Java SE (component: ImageIO). Supported versions that Vulnerability in the Java SE product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Java SE: 11.0.7 and 14.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cau
nvd
CVE-2020-8648P4HIGHCVSS 7.1v8.02020-02-06
CVE-2020-8648 [HIGH] CWE-416 CVE-2020-8648: There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the n_tty_receive_buf_c There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the n_tty_receive_buf_common function in drivers/tty/n_tty.c.
nvd
CVE-2018-10844P4MEDIUMCVSS 5.9v8.02018-08-22
CVE-2018-10844 [MEDIUM] CWE-385 CVE-2018-10844: It was found that the GnuTLS implementation of HMAC-SHA-256 was vulnerable to a Lucky thirteen style It was found that the GnuTLS implementation of HMAC-SHA-256 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data using crafted packets.
nvd
Debian Linux vulnerabilities | cvebase