Debian Linux vulnerabilities
9,954 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358
Vulnerabilities
Page 293 of 498
CVE-2019-9741P4MEDIUMCVSS 6.1v8.0v9.02019-03-13
CVE-2019-9741 [MEDIUM] CWE-93 CVE-2019-9741: An issue was discovered in net/http in Go 1.11.5. CRLF injection is possible if the attacker control
An issue was discovered in net/http in Go 1.11.5. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the second argument to http.NewRequest with \r\n followed by an HTTP header or a Redis command.
nvd
CVE-2019-13742P4MEDIUMCVSS 6.5v9.0v10.02019-12-10
CVE-2019-13742 [MEDIUM] CVE-2019-13742: Incorrect security UI in Omnibox in Google Chrome on iOS prior to 79.0.3945.79 allowed a remote atta
Incorrect security UI in Omnibox in Google Chrome on iOS prior to 79.0.3945.79 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
nvd
CVE-2023-41983P4MEDIUMCVSS 6.5v11.0v12.02023-10-25
CVE-2023-41983 [MEDIUM] CWE-119 CVE-2023-41983: The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.1, Saf
The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.1, Safari 17.1, iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1. Processing web content may lead to a denial-of-service.
nvd
CVE-2021-4059P4MEDIUMCVSS 6.5v10.0v11.02021-12-23
CVE-2021-4059 [MEDIUM] CWE-20 CVE-2021-4059: Insufficient data validation in loader in Google Chrome prior to 96.0.4664.93 allowed a remote attac
Insufficient data validation in loader in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2022-2850P4MEDIUMCVSS 6.5v10.02022-10-14
CVE-2022-2850 [MEDIUM] CVE-2022-2850: A flaw was found In 389-ds-base. When the Content Synchronization plugin is enabled, an authenticate
A flaw was found In 389-ds-base. When the Content Synchronization plugin is enabled, an authenticated user can reach a NULL pointer dereference using a specially crafted query. This flaw allows an authenticated attacker to cause a denial of service. This CVE is assigned against an incomplete fix of CVE-2021-3514.
nvd
CVE-2018-6179P4MEDIUMCVSS 6.5v9.02019-01-09
CVE-2018-6179 [MEDIUM] CWE-200 CVE-2018-6179: Insufficient enforcement of file access permission in the activeTab case in Extensions in Google Chr
Insufficient enforcement of file access permission in the activeTab case in Extensions in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced a user to install a malicious extension to access files on the local file system via a crafted Chrome Extension.
nvd
CVE-2023-4273P4MEDIUMCVSS 6.7v11.0v12.02023-08-09
CVE-2023-4273 [MEDIUM] CWE-121 CVE-2023-4273: A flaw was found in the exFAT driver of the Linux kernel. The vulnerability exists in the implementa
A flaw was found in the exFAT driver of the Linux kernel. The vulnerability exists in the implementation of the file name reconstruction function, which is responsible for reading file name entries from a directory index and merging file name parts belonging to one file into a single long file name. Since the file name characters are copied into a sta
nvd
CVE-2020-0182P4MEDIUMCVSS 6.5v8.02020-06-11
CVE-2020-0182 [MEDIUM] CWE-125 CVE-2020-0182: In exif_entry_get_value of exif-entry.c, there is a possible out of bounds read due to a missing bou
In exif_entry_get_value of exif-entry.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-147140917
nvd
CVE-2019-11046P4MEDIUMCVSS 5.3v8.0v9.0+1 more2019-12-23
CVE-2019-11046 [MEDIUM] CWE-125 CVE-2019-11046: In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP bcmath extension functions on
In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP bcmath extension functions on some systems, including Windows, can be tricked into reading beyond the allocated space by supplying it with string containing characters that are identified as numeric by the OS but aren't ASCII numbers. This can read to disclosure of the content of s
nvd
CVE-2021-43332P4MEDIUMCVSS 6.5v9.02021-11-12
CVE-2021-43332 [MEDIUM] CWE-522 CVE-2021-43332: In GNU Mailman before 2.1.36, the CSRF token for the Cgi/admindb.py admindb page contains an encrypt
In GNU Mailman before 2.1.36, the CSRF token for the Cgi/admindb.py admindb page contains an encrypted version of the list admin password. This could potentially be cracked by a moderator via an offline brute-force attack.
nvd
CVE-2011-3617P4MEDIUMCVSS 6.5v8.0v9.0+1 more2019-11-26
CVE-2011-3617 [MEDIUM] CWE-863 CVE-2011-3617: Tahoe-LAFS v1.3.0 through v1.8.2 could allow unauthorized users to delete immutable files in some ca
Tahoe-LAFS v1.3.0 through v1.8.2 could allow unauthorized users to delete immutable files in some cases.
nvd
CVE-2023-4764P4MEDIUMCVSS 6.5v11.0v12.02023-09-05
CVE-2023-4764 [MEDIUM] CVE-2023-4764: Incorrect security UI in BFCache in Google Chrome prior to 116.0.5845.179 allowed a remote attacker
Incorrect security UI in BFCache in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2006-4482P4CRITICALCVSS 9.3v3.12006-08-31
CVE-2006-4482 [CRITICAL] CVE-2006-4482: Multiple heap-based buffer overflows in the (1) str_repeat and (2) wordwrap functions in ext/standar
Multiple heap-based buffer overflows in the (1) str_repeat and (2) wordwrap functions in ext/standard/string.c in PHP before 5.1.5, when used on a 64-bit system, have unspecified impact and attack vectors, a different vulnerability than CVE-2006-1990.
nvd
CVE-2020-17507P4MEDIUMCVSS 5.3v9.02020-08-12
CVE-2020-17507 [MEDIUM] CWE-125 CVE-2020-17507: An issue was discovered in Qt through 5.12.9, and 5.13.x through 5.15.x before 5.15.1. read_xbm_body
An issue was discovered in Qt through 5.12.9, and 5.13.x through 5.15.x before 5.15.1. read_xbm_body in gui/image/qxbmhandler.cpp has a buffer over-read.
nvd
CVE-2023-5169P4MEDIUMCVSS 6.5v10.0v11.0+1 more2023-09-27
CVE-2023-5169 [MEDIUM] CWE-787 CVE-2023-5169: A compromised content process could have provided malicious data in a `PathRecording` resulting in a
A compromised content process could have provided malicious data in a `PathRecording` resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.
nvd
CVE-2023-5484P4MEDIUMCVSS 6.5v11.0v12.02023-10-11
CVE-2023-5484 [MEDIUM] CVE-2023-5484: Inappropriate implementation in Navigation in Google Chrome prior to 118.0.5993.70 allowed a remote
Inappropriate implementation in Navigation in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2016-6351P4MEDIUMCVSS 6.7v8.02016-09-07
CVE-2016-6351 [MEDIUM] CVE-2016-6351: The esp_do_dma function in hw/scsi/esp.c in QEMU (aka Quick Emulator), when built with ESP/NCR53C9x
The esp_do_dma function in hw/scsi/esp.c in QEMU (aka Quick Emulator), when built with ESP/NCR53C9x controller emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) or execute arbitrary code on the QEMU host via vectors involving DMA read into ESP command buffer.
nvd
CVE-2002-0875P4LOWCVSS 2.1PoCv3.02002-09-05
CVE-2002-0875 [LOW] CVE-2002-0875: Vulnerability in FAM 2.6.8, 2.6.6, and other versions allows unprivileged users to obtain the names
Vulnerability in FAM 2.6.8, 2.6.6, and other versions allows unprivileged users to obtain the names of files whose access is restricted to the root group.
nvd
CVE-2023-5732P4MEDIUMCVSS 6.5v10.0v11.02023-10-25
CVE-2023-5732 [MEDIUM] CVE-2023-5732: An attacker could have created a malicious link using bidirectional characters to spoof the location
An attacker could have created a malicious link using bidirectional characters to spoof the location in the address bar when visited. This vulnerability affects Firefox < 117, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
nvd
CVE-2011-4900P4MEDIUMCVSS 6.5v5.0v6.02019-11-06
CVE-2011-4900 [MEDIUM] CWE-200 CVE-2011-4900: TYPO3 before 4.5.4 allows Information Disclosure in the backend.
TYPO3 before 4.5.4 allows Information Disclosure in the backend.
nvd