Debian Linux vulnerabilities
9,954 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358
Vulnerabilities
Page 289 of 498
CVE-2017-14132P4MEDIUMCVSS 6.5v8.02017-09-04
CVE-2017-14132 [MEDIUM] CWE-125 CVE-2017-14132: JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900
JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20, 1.900.21, 1.900.22, 1.900.23, 1.900.24, 1.900.25, 1.900.26, 1.900.27, 1.900.28, 1.900.29, 1.900.30, 1.900.31, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, 2.0.6, 2.0.7, 2.0.8, 2.0.9, 2.0.10, 2.0.11, 2.0.12, 2.0.13, 2.0.
nvd
CVE-2014-3534P4HIGHCVSS 7.2v7.02014-08-01
CVE-2014-3534 [HIGH] CWE-269 CVE-2014-3534: arch/s390/kernel/ptrace.c in the Linux kernel before 3.15.8 on the s390 platform does not properly r
arch/s390/kernel/ptrace.c in the Linux kernel before 3.15.8 on the s390 platform does not properly restrict address-space control operations in PTRACE_POKEUSR_AREA requests, which allows local users to obtain read and write access to kernel memory locations, and consequently gain privileges, via a crafted application that makes a ptrace system call.
nvd
CVE-2023-28686P4HIGHCVSS 7.1v10.0v11.0+1 more2023-03-24
CVE-2023-28686 [HIGH] CWE-639 CVE-2023-28686: Dino before 0.2.3, 0.3.x before 0.3.2, and 0.4.x before 0.4.2 allows attackers to modify the persona
Dino before 0.2.3, 0.3.x before 0.3.2, and 0.4.x before 0.4.2 allows attackers to modify the personal bookmark store via a crafted message. The attacker can change the display of group chats or force a victim to join a group chat; the victim may then be tricked into disclosing sensitive information.
nvd
CVE-2021-37750P4MEDIUMCVSS 6.5v9.02021-08-23
CVE-2021-37750 [MEDIUM] CWE-476 CVE-2021-37750: The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.5 and 1.19.x before 1.19.
The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.5 and 1.19.x before 1.19.3 has a NULL pointer dereference in kdc/do_tgs_req.c via a FAST inner body that lacks a server field.
nvd
CVE-2018-0489P4MEDIUMCVSS 6.5v7.0v8.0+1 more2018-02-27
CVE-2018-0489 [MEDIUM] CVE-2018-0489: Shibboleth XMLTooling-C before 1.6.4, as used in Shibboleth Service Provider before 2.6.1.4 on Windo
Shibboleth XMLTooling-C before 1.6.4, as used in Shibboleth Service Provider before 2.6.1.4 on Windows and other products, mishandles digital signatures of user data, which allows remote attackers to obtain sensitive information or conduct impersonation attacks via crafted XML data. NOTE: this issue exists because of an incomplete fix for CVE-2018-0486.
nvd
CVE-2018-6091P4MEDIUMCVSS 6.5v8.0v9.02019-01-09
CVE-2018-6091 [MEDIUM] CWE-19 CVE-2018-6091: Service Workers can intercept any request made by an <embed> or <object> tag in Fetch API in Google
Service Workers can intercept any request made by an or tag in Fetch API in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2022-3649P4HIGHCVSS 7.0v10.02022-10-21
CVE-2022-3649 [HIGH] CWE-119 CVE-2022-3649: A vulnerability was found in Linux Kernel. It has been classified as problematic. Affected is the fu
A vulnerability was found in Linux Kernel. It has been classified as problematic. Affected is the function nilfs_new_inode of the file fs/nilfs2/inode.c of the component BPF. The manipulation leads to use after free. It is possible to launch the attack remotely. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability i
nvd
CVE-2017-15698P4MEDIUMCVSS 5.9v8.0v9.02018-01-31
CVE-2017-15698 [MEDIUM] CWE-295 CVE-2017-15698: When parsing the AIA-Extension field of a client certificate, Apache Tomcat Native Connector 1.2.0 t
When parsing the AIA-Extension field of a client certificate, Apache Tomcat Native Connector 1.2.0 to 1.2.14 and 1.1.23 to 1.1.34 did not correctly handle fields longer than 127 bytes. The result of the parsing error was to skip the OCSP check. It was therefore possible for client certificates that should have been rejected (if the OCSP check had be
nvd
CVE-2020-6400P4MEDIUMCVSS 6.5v9.0v10.02020-02-11
CVE-2020-6400 [MEDIUM] CWE-203 CVE-2020-6400: Inappropriate implementation in CORS in Google Chrome prior to 80.0.3987.87 allowed a remote attacke
Inappropriate implementation in CORS in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2022-40302P4MEDIUMCVSS 6.5v10.0v11.0+1 more2023-05-03
CVE-2022-40302 [MEDIUM] CWE-125 CVE-2022-40302: An issue was discovered in bgpd in FRRouting (FRR) through 8.4. By crafting a BGP OPEN message with
An issue was discovered in bgpd in FRRouting (FRR) through 8.4. By crafting a BGP OPEN message with an option of type 0xff (Extended Length from RFC 9072), attackers may cause a denial of service (assertion failure and daemon restart, or out-of-bounds read). This is possible because of inconsistent boundary checks that do not account for reading 3 by
nvd
CVE-2022-40318P4MEDIUMCVSS 6.5v10.0v11.0+1 more2023-05-03
CVE-2022-40318 [MEDIUM] CVE-2022-40318: An issue was discovered in bgpd in FRRouting (FRR) through 8.4. By crafting a BGP OPEN message with
An issue was discovered in bgpd in FRRouting (FRR) through 8.4. By crafting a BGP OPEN message with an option of type 0xff (Extended Length from RFC 9072), attackers may cause a denial of service (assertion failure and daemon restart, or out-of-bounds read). This is possible because of inconsistent boundary checks that do not account for reading 3 bytes (ins
nvd
CVE-2025-39682P4HIGHCVSS 7.1v11.02025-09-05
CVE-2025-39682 [HIGH] CVE-2025-39682: In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-lengt
In the Linux kernel, the following vulnerability has been resolved:
tls: fix handling of zero-length records on the rx_list
Each recvmsg() call must process either
- only contiguous DATA records (any number of them)
- one non-DATA record
If the next record has different type than what has already been
processed we break out of the main processing loop. If t
nvd
CVE-2022-22816P4MEDIUMCVSS 6.5v9.0v10.0+1 more2022-01-10
CVE-2022-22816 [MEDIUM] CWE-125 CVE-2022-22816: path_getbbox in path.c in Pillow before 9.0.0 has a buffer over-read during initialization of ImageP
path_getbbox in path.c in Pillow before 9.0.0 has a buffer over-read during initialization of ImagePath.Path.
nvd
CVE-2020-2830P4MEDIUMCVSS 5.3v8.0v10.02020-04-15
CVE-2020-2830 [MEDIUM] CVE-2020-2830: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Concurrency). S
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Concurrency). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successfu
nvd
CVE-2020-2781P4MEDIUMCVSS 5.3v8.0v9.0+1 more2020-04-15
CVE-2020-2781 [MEDIUM] CVE-2020-2781: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JSSE). Supporte
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Java SE, Java SE Embedded. Successful attacks of this vu
nvd
CVE-2017-5044P4MEDIUMCVSS 6.3v8.0v9.02017-04-24
CVE-2017-5044 [MEDIUM] CWE-787 CVE-2017-5044: Heap buffer overflow in filter processing in Skia in Google Chrome prior to 57.0.2987.98 for Mac, Wi
Heap buffer overflow in filter processing in Skia in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
nvd
CVE-2019-15917P4HIGHCVSS 7.0v8.02019-09-04
CVE-2019-15917 [HIGH] CWE-416 CVE-2019-15917: An issue was discovered in the Linux kernel before 5.0.5. There is a use-after-free issue when hci_u
An issue was discovered in the Linux kernel before 5.0.5. There is a use-after-free issue when hci_uart_register_dev() fails in hci_uart_set_proto() in drivers/bluetooth/hci_ldisc.c.
nvd
CVE-2018-6137P4MEDIUMCVSS 6.5v9.02019-01-09
CVE-2018-6137 [MEDIUM] CWE-200 CVE-2018-6137: CSS Paint API in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to leak cros
CSS Paint API in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2020-6445P4MEDIUMCVSS 6.5v9.0v10.02020-04-13
CVE-2020-6445 [MEDIUM] CWE-276 CVE-2020-6445: Insufficient policy enforcement in trusted types in Google Chrome prior to 81.0.4044.92 allowed a re
Insufficient policy enforcement in trusted types in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass content security policy via a crafted HTML page.
nvd
CVE-2020-11018P4MEDIUMCVSS 6.5v10.02020-05-29
CVE-2020-11018 [MEDIUM] CWE-125 CVE-2020-11018: In FreeRDP less than or equal to 2.0.0, a possible resource exhaustion vulnerability can be performe
In FreeRDP less than or equal to 2.0.0, a possible resource exhaustion vulnerability can be performed. Malicious clients could trigger out of bound reads causing memory allocation with random size. This has been fixed in 2.1.0.
nvd