Debian Linux vulnerabilities
9,954 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358
Vulnerabilities
Page 294 of 498
CVE-2023-27954P4MEDIUMCVSS 6.5v10.02023-05-08
CVE-2023-27954 [MEDIUM] CWE-863 CVE-2023-27954: The issue was addressed by removing origin information. This issue is fixed in macOS Ventura 13.3, S
The issue was addressed by removing origin information. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 16.4, iOS 15.7.4 and iPadOS 15.7.4, tvOS 16.4, watchOS 9.4. A website may be able to track sensitive user information.
nvd
CVE-2023-1814P4MEDIUMCVSS 6.5v11.02023-04-04
CVE-2023-1814 [MEDIUM] CVE-2023-1814: Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 112.0.5615.49
Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to bypass download checking via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-6865P4MEDIUMCVSS 6.5v10.0v11.0+1 more2023-12-19
CVE-2023-6865 [MEDIUM] CVE-2023-6865: `EncryptingOutputStream` was susceptible to exposing uninitialized data. This issue could only be a
`EncryptingOutputStream` was susceptible to exposing uninitialized data. This issue could only be abused in order to write data to a local disk which may have implications for private browsing mode. This vulnerability affects Firefox ESR < 115.6 and Firefox < 121.
nvd
CVE-2020-35357P4MEDIUMCVSS 6.5v10.02023-08-22
CVE-2020-35357 [MEDIUM] CWE-120 CVE-2020-35357: A buffer overflow can occur when calculating the quantile value using the Statistics Library of GSL
A buffer overflow can occur when calculating the quantile value using the Statistics Library of GSL (GNU Scientific Library), versions 2.5 and 2.6. Processing a maliciously crafted input data for gsl_stats_quantile_from_sorted_data of the library may lead to unexpected application termination or arbitrary code execution.
nvd
CVE-2010-1086P4HIGHCVSS 7.8v5.02010-04-06
CVE-2010-1086 [HIGH] CWE-399 CVE-2010-1086: The ULE decapsulation functionality in drivers/media/dvb/dvb-core/dvb_net.c in dvb-core in Linux ker
The ULE decapsulation functionality in drivers/media/dvb/dvb-core/dvb_net.c in dvb-core in Linux kernel 2.6.33 and earlier allows attackers to cause a denial of service (infinite loop) via a crafted MPEG2-TS frame, related to an invalid Payload Pointer ULE.
nvd
CVE-2023-5483P4MEDIUMCVSS 6.5v11.0v12.02023-10-11
CVE-2023-5483 [MEDIUM] CVE-2023-5483: Inappropriate implementation in Intents in Google Chrome prior to 118.0.5993.70 allowed a remote att
Inappropriate implementation in Intents in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2010-3850P4LOWCVSS 2.1PoCv5.02010-12-30
CVE-2010-3850 [LOW] CVE-2010-3850: The ec_dev_ioctl function in net/econet/af_econet.c in the Linux kernel before 2.6.36.2 does not req
The ec_dev_ioctl function in net/econet/af_econet.c in the Linux kernel before 2.6.36.2 does not require the CAP_NET_ADMIN capability, which allows local users to bypass intended access restrictions and configure econet addresses via an SIOCSIFADDR ioctl call.
nvd
CVE-2022-21283P4MEDIUMCVSS 5.3v9.0v10.0+1 more2022-01-19
CVE-2022-21283 [MEDIUM] CWE-693 CVE-2022-21283: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (co
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple prot
nvd
CVE-2018-1000077P4MEDIUMCVSS 5.3v7.02018-03-13
CVE-2018-1000077 [MEDIUM] CWE-20 CVE-2018-1000077: RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 se
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Improper Input Validation vulnerability in ruby gems specification homepage attribute that can result in a malicious gem could set an invalid home
nvd
CVE-2022-21341P4MEDIUMCVSS 5.3v9.0v10.0+1 more2022-01-19
CVE-2022-21341 [MEDIUM] CWE-502 CVE-2022-21341: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (co
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Serialization). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access
nvd
CVE-2023-21400P4MEDIUMCVSS 6.7v10.0v11.02023-07-13
CVE-2023-21400 [MEDIUM] CWE-667 CVE-2023-21400: In multiple functions of io_uring.c, there is a possible kernel memory corruption due to improper l
In multiple functions of io_uring.c, there is a possible kernel memory corruption due to improper locking. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2021-39191P4MEDIUMCVSS 6.1v10.02021-09-03
CVE-2021-39191 [MEDIUM] CWE-601 CVE-2021-39191: mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that funct
mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In versions prior to 2.4.9.4, the 3rd-party init SSO functionality of mod_auth_openidc was reported to be vulnerable to an open redirect attack by supply
nvd
CVE-2023-5481P4MEDIUMCVSS 6.5v11.0v12.02023-10-11
CVE-2023-5481 [MEDIUM] CVE-2023-5481: Inappropriate implementation in Downloads in Google Chrome prior to 118.0.5993.70 allowed a remote a
Inappropriate implementation in Downloads in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2016-0706P4MEDIUMCVSS 4.3v7.0v8.02016-02-25
CVE-2016-0706 [MEDIUM] CWE-200 CVE-2016-0706: Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 does
Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 does not place org.apache.catalina.manager.StatusManagerServlet on the org/apache/catalina/core/RestrictedServlets.properties list, which allows remote authenticated users to bypass intended SecurityManager restrictions and read arbitrary HTTP requests, and c
nvd
CVE-2020-15706P4MEDIUMCVSS 6.4v10.02020-07-29
CVE-2020-15706 [MEDIUM] CWE-362 CVE-2020-15706: GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnera
GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing, leading to arbitrary code execution and secure boot restriction bypass. This issue affects GRUB2 version 2.04 and prior versions.
nvd
CVE-2023-1813P4MEDIUMCVSS 6.5v11.02023-04-04
CVE-2023-1813 [MEDIUM] CVE-2023-1813: Inappropriate implementation in Extensions in Google Chrome prior to 112.0.5615.49 allowed an attack
Inappropriate implementation in Extensions in Google Chrome prior to 112.0.5615.49 allowed an attacker who convinced a user to install a malicious extension to bypass file access restrictions via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2024-0753P4MEDIUMCVSS 6.5v10.02024-01-23
CVE-2024-0753 [MEDIUM] CVE-2024-0753: In specific HSTS configurations an attacker could have bypassed HSTS on a subdomain. This vulnerabil
In specific HSTS configurations an attacker could have bypassed HSTS on a subdomain. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
nvd
CVE-2024-1547P4MEDIUMCVSS 6.5v10.02024-02-20
CVE-2024-1547 [MEDIUM] CWE-290 CVE-2024-1547: Through a series of API calls and redirects, an attacker-controlled alert dialog could have been dis
Through a series of API calls and redirects, an attacker-controlled alert dialog could have been displayed on another website (with the victim website's URL shown). This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.
nvd
CVE-2023-5479P4MEDIUMCVSS 6.5v11.0v12.02023-10-11
CVE-2023-5479 [MEDIUM] CVE-2023-5479: Inappropriate implementation in Extensions API in Google Chrome prior to 118.0.5993.70 allowed an at
Inappropriate implementation in Extensions API in Google Chrome prior to 118.0.5993.70 allowed an attacker who convinced a user to install a malicious extension to bypass an enterprise policy via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-4367P4MEDIUMCVSS 6.5v11.0v12.02023-08-15
CVE-2023-4367 [MEDIUM] CVE-2023-4367: Insufficient policy enforcement in Extensions API in Google Chrome prior to 116.0.5845.96 allowed an
Insufficient policy enforcement in Extensions API in Google Chrome prior to 116.0.5845.96 allowed an attacker who convinced a user to install a malicious extension to bypass an enterprise policy via a crafted HTML page. (Chromium security severity: Medium)
nvd