Debian Linux vulnerabilities
9,954 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358
Vulnerabilities
Page 292 of 498
CVE-2023-51782P4HIGHCVSS 7.0v10.02024-01-11
CVE-2023-51782 [HIGH] CWE-416 CVE-2023-51782: An issue was discovered in the Linux kernel before 6.6.8. rose_ioctl in net/rose/af_rose.c has a use
An issue was discovered in the Linux kernel before 6.6.8. rose_ioctl in net/rose/af_rose.c has a use-after-free because of a rose_accept race condition.
nvd
CVE-2018-6069P4MEDIUMCVSS 6.5v9.02018-11-14
CVE-2018-6069 [MEDIUM] CWE-125 CVE-2018-6069: Stack buffer overflow in Skia in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to p
Stack buffer overflow in Skia in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
nvd
CVE-2020-25599P4HIGHCVSS 7.0v10.02020-09-23
CVE-2020-25599 [HIGH] CWE-119 CVE-2020-25599: An issue was discovered in Xen through 4.14.x. There are evtchn_reset() race conditions. Uses of EVT
An issue was discovered in Xen through 4.14.x. There are evtchn_reset() race conditions. Uses of EVTCHNOP_reset (potentially by a guest on itself) or XEN_DOMCTL_soft_reset (by itself covered by XSA-77) can lead to the violation of various internal assumptions. This may lead to out of bounds memory accesses or triggering of bug checks. In particular, x
nvd
CVE-2018-12029P4HIGHCVSS 7.0v8.02018-06-17
CVE-2018-12029 [HIGH] CWE-362 CVE-2018-12029: A race condition in the nginx module in Phusion Passenger 3.x through 5.x before 5.3.2 allows local
A race condition in the nginx module in Phusion Passenger 3.x through 5.x before 5.3.2 allows local escalation of privileges when a non-standard passenger_instance_registry_dir with insufficiently strict permissions is configured. Replacing a file with a symlink after the file was created, but before it was chowned, leads to the target of the link bein
nvd
CVE-2019-5188P4MEDIUMCVSS 6.7v8.0v9.02020-01-08
CVE-2019-5188 [MEDIUM] CWE-787 CVE-2019-5188: A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1
A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1.45.4. A specially crafted ext4 directory can cause an out-of-bounds write on the stack, resulting in code execution. An attacker can corrupt a partition to trigger this vulnerability.
nvd
CVE-2023-28466P4HIGHCVSS 7.0v10.02023-03-16
CVE-2023-28466 [HIGH] CWE-476 CVE-2023-28466: do_tls_getsockopt in net/tls/tls_main.c in the Linux kernel through 6.2.6 lacks a lock_sock call, le
do_tls_getsockopt in net/tls/tls_main.c in the Linux kernel through 6.2.6 lacks a lock_sock call, leading to a race condition (with a resultant use-after-free or NULL pointer dereference).
nvd
CVE-2020-6561P4MEDIUMCVSS 6.5v10.02020-09-21
CVE-2020-6561 [MEDIUM] CVE-2020-6561: Inappropriate implementation in Content Security Policy in Google Chrome prior to 85.0.4183.83 allow
Inappropriate implementation in Content Security Policy in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2022-42320P4HIGHCVSS 7.0v11.02022-11-01
CVE-2022-42320 [HIGH] CWE-459 CVE-2022-42320: Xenstore: Guests can get access to Xenstore nodes of deleted domains Access rights of Xenstore nodes
Xenstore: Guests can get access to Xenstore nodes of deleted domains Access rights of Xenstore nodes are per domid. When a domain is gone, there might be Xenstore nodes left with access rights containing the domid of the removed domain. This is normally no problem, as those access right entries will be corrected when such a node is written later. Ther
nvd
CVE-2019-3461P4HIGHCVSS 7.0v8.0v9.02019-02-04
CVE-2019-3461 [HIGH] CWE-362 CVE-2019-3461: Debian tmpreaper version 1.6.13+nmu1 has a race condition when doing a (bind) mount via rename() whi
Debian tmpreaper version 1.6.13+nmu1 has a race condition when doing a (bind) mount via rename() which could result in local privilege escalation. Mounting via rename() could potentially lead to a file being placed elsewhereon the filesystem hierarchy (e.g. /etc/cron.d/) if the directory being cleaned up was on the same physical filesystem. Fixed versio
nvd
CVE-2021-3348P4HIGHCVSS 7.0v9.02021-02-01
CVE-2021-3348 [HIGH] CWE-362 CVE-2021-3348: nbd_add_socket in drivers/block/nbd.c in the Linux kernel through 5.10.12 has an ndb_queue_rq use-af
nbd_add_socket in drivers/block/nbd.c in the Linux kernel through 5.10.12 has an ndb_queue_rq use-after-free that could be triggered by local attackers (with access to the nbd device) via an I/O request at a certain point during device setup, aka CID-b98e762e3d71.
nvd
CVE-2020-6484P4MEDIUMCVSS 6.5v9.0v10.02020-05-21
CVE-2020-6484 [MEDIUM] CWE-276 CVE-2020-6484: Insufficient data validation in ChromeDriver in Google Chrome prior to 83.0.4103.61 allowed a remote
Insufficient data validation in ChromeDriver in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted request.
nvd
CVE-2017-16854P4MEDIUMCVSS 6.5v7.0v8.0+1 more2017-12-08
CVE-2017-16854 [MEDIUM] CWE-200 CVE-2017-16854: In Open Ticket Request System (OTRS) through 3.3.20, 4 through 4.0.26, 5 through 5.0.24, and 6 throu
In Open Ticket Request System (OTRS) through 3.3.20, 4 through 4.0.26, 5 through 5.0.24, and 6 through 6.0.1, an attacker who is logged in as a customer can use the ticket search form to disclose internal article information of their customer tickets.
nvd
CVE-2018-7537P4MEDIUMCVSS 5.3v7.0v8.0+1 more2018-03-09
CVE-2018-7537 [MEDIUM] CWE-185 CVE-2018-7537: An issue was discovered in Django 2.0 before 2.0.3, 1.11 before 1.11.11, and 1.8 before 1.8.19. If d
An issue was discovered in Django 2.0 before 2.0.3, 1.11 before 1.11.11, and 1.8 before 1.8.19. If django.utils.text.Truncator's chars() and words() methods were passed the html=True argument, they were extremely slow to evaluate certain inputs due to a catastrophic backtracking vulnerability in a regular expression. The chars() and words() methods ar
nvd
CVE-2023-35823P4HIGHCVSS 7.0v10.02023-06-18
CVE-2023-35823 [HIGH] CWE-362 CVE-2023-35823: An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in saa7134_fini
An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in saa7134_finidev in drivers/media/pci/saa7134/saa7134-core.c.
nvd
CVE-2023-35824P4HIGHCVSS 7.0v10.02023-06-18
CVE-2023-35824 [HIGH] CWE-362 CVE-2023-35824: An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in dm1105_remov
An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in dm1105_remove in drivers/media/pci/dm1105/dm1105.c.
nvd
CVE-2025-38051P4HIGHCVSS 7.0v11.02025-06-18
CVE-2025-38051 [HIGH] CWE-416 CVE-2025-38051: In the Linux kernel, the following vulnerability has been resolved: smb: client: Fix use-after-free
In the Linux kernel, the following vulnerability has been resolved:
smb: client: Fix use-after-free in cifs_fill_dirent
There is a race condition in the readdir concurrency process, which may
access the rsp buffer after it has been released, triggering the
following KASAN warning.
BUG: KASAN: slab-use-after-free in cifs_fill_dirent+0xb03/0xb60 [cifs
nvd
CVE-2018-6109P4MEDIUMCVSS 6.5v8.0v9.02019-01-09
CVE-2018-6109 [MEDIUM] CWE-200 CVE-2018-6109: readAsText() can indefinitely read the file picked by the user, rather than only once at the time th
readAsText() can indefinitely read the file picked by the user, rather than only once at the time the file is picked in File API in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to access data on the user file system without explicit consent via a crafted HTML page.
nvd
CVE-2018-6080P4MEDIUMCVSS 6.5v9.02018-11-14
CVE-2018-6080 [MEDIUM] CWE-269 CVE-2018-6080: Lack of access control checks in Instrumentation in Google Chrome prior to 65.0.3325.146 allowed a r
Lack of access control checks in Instrumentation in Google Chrome prior to 65.0.3325.146 allowed a remote attacker who had compromised the renderer process to obtain memory metadata from privileged processes .
nvd
CVE-2025-39759P4HIGHCVSS 7.0v11.02025-09-11
CVE-2025-39759 [HIGH] CWE-362 CVE-2025-39759: In the Linux kernel, the following vulnerability has been resolved: btrfs: qgroup: fix race between
In the Linux kernel, the following vulnerability has been resolved:
btrfs: qgroup: fix race between quota disable and quota rescan ioctl
There's a race between a task disabling quotas and another running the
rescan ioctl that can result in a use-after-free of qgroup records from
the fs_info->qgroup_tree rbtree.
This happens as follows:
1) Task A en
nvd
CVE-2021-20292P4MEDIUMCVSS 6.7v9.02021-05-28
CVE-2021-20292 [MEDIUM] CWE-416 CVE-2021-20292: There is a flaw reported in the Linux kernel in versions before 5.9 in drivers/gpu/drm/nouveau/nouve
There is a flaw reported in the Linux kernel in versions before 5.9 in drivers/gpu/drm/nouveau/nouveau_sgdma.c in nouveau_sgdma_create_ttm in Nouveau DRM subsystem. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker with a local account with a root privilege, can leverag
nvd