cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 284 of 498
CVE-2016-1650P4HIGHCVSS 8.8v8.02016-03-29
CVE-2016-1650 [HIGH] CVE-2016-1650: The PageCaptureSaveAsMHTMLFunction::ReturnFailure function in browser/extensions/api/page_capture/pa The PageCaptureSaveAsMHTMLFunction::ReturnFailure function in browser/extensions/api/page_capture/page_capture_api.cc in Google Chrome before 49.0.2623.108 allows attackers to cause a denial of service or possibly have unspecified other impact by triggering an error in creating an MHTML document.
nvd
CVE-2010-1087P4HIGHCVSS 7.8v5.02010-04-06
CVE-2010-1087 [HIGH] CVE-2010-1087: The nfs_wait_on_request function in fs/nfs/pagelist.c in Linux kernel 2.6.x through 2.6.33-rc5 allow The nfs_wait_on_request function in fs/nfs/pagelist.c in Linux kernel 2.6.x through 2.6.33-rc5 allows attackers to cause a denial of service (Oops) via unknown vectors related to truncating a file and an operation that is not interruptible.
nvd
CVE-2020-14954P4MEDIUMCVSS 5.9v9.0v10.0+1 more2020-06-21
CVE-2020-14954 [MEDIUM] CWE-74 CVE-2020-14954: Mutt before 1.14.4 and NeoMutt before 2020-06-19 have a STARTTLS buffering issue that affects IMAP, Mutt before 1.14.4 and NeoMutt before 2020-06-19 have a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS" response, the client reads additional data (e.g., from a man-in-the-middle attacker) and evaluates it in a TLS context, aka "response injection."
nvd
CVE-2023-37207P4MEDIUMCVSS 6.5v10.0v11.0+1 more2023-07-05
CVE-2023-37207 [MEDIUM] CWE-470 CVE-2023-37207: A website could have obscured the fullscreen notification by using a URL with a scheme handled by an A website could have obscured the fullscreen notification by using a URL with a scheme handled by an external program, such as a mailto URL. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.
nvd
CVE-2022-23633P4MEDIUMCVSS 5.9v10.0v11.02022-02-11
CVE-2022-23633 [MEDIUM] CWE-200 CVE-2022-23633: Action Pack is a framework for handling and responding to web requests. Under certain circumstances Action Pack is a framework for handling and responding to web requests. Under certain circumstances response bodies will not be closed. In the event a response is *not* notified of a `close`, `ActionDispatch::Executor` will not know to reset thread local state for the next request. This can lead to data being leaked to subsequent requests.This has be
nvd
CVE-2020-15988P4MEDIUMCVSS 6.3v10.02020-11-03
CVE-2020-15988 [MEDIUM] CVE-2020-15988: Insufficient policy enforcement in downloads in Google Chrome on Windows prior to 86.0.4240.75 allow Insufficient policy enforcement in downloads in Google Chrome on Windows prior to 86.0.4240.75 allowed a remote attacker who convinced the user to open files to execute arbitrary code via a crafted HTML page.
nvd
CVE-2022-21540P4MEDIUMCVSS 5.3v10.0v11.02022-07-19
CVE-2022-21540 [MEDIUM] CWE-416 CVE-2022-21540: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (co Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 7u343, 8u333, 11.0.15.1, 17.0.3.1, 18.0.1.1; Oracle GraalVM Enterprise Edition: 20.3.6, 21.3.2 and 22.1.0. Easily exploitable vulnerability allows unauthenticated attacker wit
nvd
CVE-2023-5475P4MEDIUMCVSS 6.5v11.0v12.02023-10-11
CVE-2023-5475 [MEDIUM] CVE-2023-5475: Inappropriate implementation in DevTools in Google Chrome prior to 118.0.5993.70 allowed an attacker Inappropriate implementation in DevTools in Google Chrome prior to 118.0.5993.70 allowed an attacker who convinced a user to install a malicious extension to bypass discretionary access control via a crafted Chrome Extension. (Chromium security severity: Medium)
nvd
CVE-2019-3880P4MEDIUMCVSS 5.4v8.02019-04-09
CVE-2019-3880 [MEDIUM] CWE-22 CVE-2019-3880: A flaw was found in the way samba implemented an RPC endpoint emulating the Windows registry service A flaw was found in the way samba implemented an RPC endpoint emulating the Windows registry service API. An unprivileged attacker could use this flaw to create a new registry hive file anywhere they have unix permissions which could lead to creation of a new file in the Samba share. Versions before 4.8.11, 4.9.6 and 4.10.2 are vulnerable.
nvd
CVE-2013-6629P4MEDIUMCVSS 5.0v7.0v8.02013-11-19
CVE-2013-6629 [MEDIUM] CWE-200 CVE-2013-6629: The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, and other products, does not check for certain duplications of component data during the reading of segments that follow Start Of Scan (SOS) JPEG markers, which allows remote attackers to obtain sensitive
nvd
CVE-2012-2143P4MEDIUMCVSS 4.3v6.02012-07-05
CVE-2012-2143 [MEDIUM] CWE-310 CVE-2012-2143: The crypt_des (aka DES-based crypt) function in FreeBSD before 9.0-RELEASE-p2, as used in PHP, Postg The crypt_des (aka DES-based crypt) function in FreeBSD before 9.0-RELEASE-p2, as used in PHP, PostgreSQL, and other products, does not process the complete cleartext password if this password contains a 0x80 character, which makes it easier for context-dependent attackers to obtain access via an authentication attempt with an initial substring of the
nvd
CVE-2023-5473P4MEDIUMCVSS 6.3v11.0v12.02023-10-11
CVE-2023-5473 [MEDIUM] CWE-416 CVE-2023-5473: Use after free in Cast in Google Chrome prior to 118.0.5993.70 allowed a remote attacker who had com Use after free in Cast in Google Chrome prior to 118.0.5993.70 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2021-33910P4MEDIUMCVSS 5.5v10.02021-07-20
CVE-2021-33910 [MEDIUM] CWE-770 CVE-2021-33910: basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with a basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdupa and alloca for a pathname controlled by a local attacker) that results in an operating system crash.
nvd
CVE-2015-2696P4HIGHCVSS 7.1v7.0v8.0+1 more2015-11-09
CVE-2015-2696 [HIGH] CWE-18 CVE-2015-2696: lib/gssapi/krb5/iakerb.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context lib/gssapi/krb5/iakerb.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, which allows remote attackers to cause a denial of service (incorrect pointer read and process crash) via a crafted IAKERB packet that is mishandled during a gss_inquire_context call.
nvd
CVE-2020-4048P4MEDIUMCVSS 5.7v8.0v9.0+1 more2020-06-12
CVE-2020-4048 [MEDIUM] CWE-601 CVE-2020-4048: In affected versions of WordPress, due to an issue in wp_validate_redirect() and URL sanitization, a In affected versions of WordPress, due to an issue in wp_validate_redirect() and URL sanitization, an arbitrary external link can be crafted leading to unintended/open redirect when clicked. This has been patched in version 5.4.2, along with all the previously affected versions via a minor release (5.3.4, 5.2.7, 5.1.6, 5.0.10, 4.9.15, 4.8.14, 4.7.18,
nvd
CVE-2020-28049P4MEDIUMCVSS 6.3v9.0v10.02020-11-04
CVE-2020-28049 [MEDIUM] CWE-362 CVE-2020-28049: An issue was discovered in SDDM before 0.19.0. It incorrectly starts the X server in a way that - fo An issue was discovered in SDDM before 0.19.0. It incorrectly starts the X server in a way that - for a short time period - allows local unprivileged users to create a connection to the X server without providing proper authentication. A local attacker can thus access X server display contents and, for example, intercept keystrokes or access the cli
nvd
CVE-2014-10077P4HIGHCVSS 7.5v8.02018-11-06
CVE-2014-10077 [HIGH] CWE-20 CVE-2014-10077: Hash#slice in lib/i18n/core_ext/hash.rb in the i18n gem before 0.8.0 for Ruby allows remote attacker Hash#slice in lib/i18n/core_ext/hash.rb in the i18n gem before 0.8.0 for Ruby allows remote attackers to cause a denial of service (application crash) via a call in a situation where :some_key is present in keep_keys but not present in the hash.
nvd
CVE-2018-14423P4HIGHCVSS 7.5v8.0v9.02018-07-19
CVE-2018-14423 [HIGH] CWE-369 CVE-2018-14423: Division-by-zero vulnerabilities in the functions pi_next_pcrl, pi_next_cprl, and pi_next_rpcl in li Division-by-zero vulnerabilities in the functions pi_next_pcrl, pi_next_cprl, and pi_next_rpcl in lib/openjp3d/pi.c in OpenJPEG through 2.3.0 allow remote attackers to cause a denial of service (application crash).
nvd
CVE-2013-3561P4HIGHCVSS 7.8v7.02013-05-25
CVE-2013-3561 [HIGH] CWE-189 CVE-2013-3561: Multiple integer overflows in Wireshark 1.8.x before 1.8.7 allow remote attackers to cause a denial Multiple integer overflows in Wireshark 1.8.x before 1.8.7 allow remote attackers to cause a denial of service (loop or application crash) via a malformed packet, related to a crash of the Websocket dissector, an infinite loop in the MySQL dissector, and a large loop in the ETCH dissector.
nvd
CVE-2021-38502P4MEDIUMCVSS 5.9v9.0v10.0+1 more2021-11-03
CVE-2021-38502 [MEDIUM] CVE-2021-38502: Thunderbird ignored the configuration to require STARTTLS security for an SMTP connection. A MITM co Thunderbird ignored the configuration to require STARTTLS security for an SMTP connection. A MITM could perform a downgrade attack to intercept transmitted messages, or could take control of the authenticated session to execute SMTP commands chosen by the MITM. If an unprotected authentication method was configured, the MITM could obtain the authentication
nvd
Debian Linux vulnerabilities | cvebase