cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 303 of 498
CVE-2022-23038P4HIGHCVSS 7.0v9.02022-03-10
CVE-2022-23038 [HIGH] CVE-2022-23038: Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Several Linux PV device frontends are using the grant table interfaces for removing access rights of the backends in ways being subject to race conditions, resulting in pote
nvd
CVE-2022-23041P4HIGHCVSS 7.0v9.02022-03-10
CVE-2022-23041 [HIGH] CVE-2022-23041: Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Several Linux PV device frontends are using the grant table interfaces for removing access rights of the backends in ways being subject to race conditions, resulting in pote
nvd
CVE-2020-28038P4MEDIUMCVSS 6.1v9.0v10.02020-11-02
CVE-2020-28038 [MEDIUM] CWE-79 CVE-2020-28038: WordPress before 5.5.2 allows stored XSS via post slugs. WordPress before 5.5.2 allows stored XSS via post slugs.
nvd
CVE-2023-23009P4MEDIUMCVSS 6.5v11.02023-02-21
CVE-2023-23009 [MEDIUM] CWE-400 CVE-2023-23009: Libreswan 4.9 allows remote attackers to cause a denial of service (assert failure and daemon restar Libreswan 4.9 allows remote attackers to cause a denial of service (assert failure and daemon restart) via crafted TS payload with an incorrect selector length.
nvd
CVE-2019-5094P4MEDIUMCVSS 6.7v8.0v9.0+1 more2019-09-24
CVE-2019-5094 [MEDIUM] CWE-787 CVE-2019-5094: An exploitable code execution vulnerability exists in the quota file functionality of E2fsprogs 1.45 An exploitable code execution vulnerability exists in the quota file functionality of E2fsprogs 1.45.3. A specially crafted ext4 partition can cause an out-of-bounds write on the heap, resulting in code execution. An attacker can corrupt a partition to trigger this vulnerability.
nvd
CVE-2018-6095P4MEDIUMCVSS 6.5v8.0v9.02018-12-04
CVE-2018-6095 [MEDIUM] CWE-200 CVE-2018-6095: Inappropriate dismissal of file picker on keyboard events in Blink in Google Chrome prior to 66.0.33 Inappropriate dismissal of file picker on keyboard events in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to read local files via a crafted HTML page.
nvd
CVE-2021-21181P4MEDIUMCVSS 6.5v10.02021-03-09
CVE-2021-21181 [MEDIUM] CWE-203 CVE-2021-21181: Side-channel information leakage in autofill in Google Chrome prior to 89.0.4389.72 allowed a remote Side-channel information leakage in autofill in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2021-21173P4MEDIUMCVSS 6.5v10.02021-03-09
CVE-2021-21173 [MEDIUM] CWE-203 CVE-2021-21173: Side-channel information leakage in Network Internals in Google Chrome prior to 89.0.4389.72 allowed Side-channel information leakage in Network Internals in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2020-6487P4MEDIUMCVSS 6.5v9.0v10.02020-05-21
CVE-2020-6487 [MEDIUM] CWE-276 CVE-2020-6487: Insufficient policy enforcement in downloads in Google Chrome prior to 83.0.4103.61 allowed a remote Insufficient policy enforcement in downloads in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2022-23037P4HIGHCVSS 7.0v9.02022-03-10
CVE-2022-23037 [HIGH] CVE-2022-23037: Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Several Linux PV device frontends are using the grant table interfaces for removing access rights of the backends in ways being subject to race conditions, resulting in pote
nvd
CVE-2020-10711P4MEDIUMCVSS 5.9v8.0v9.0+1 more2020-05-22
CVE-2020-10711 [MEDIUM] CWE-476 CVE-2020-10711: A NULL pointer dereference flaw was found in the Linux kernel's SELinux subsystem in versions before A NULL pointer dereference flaw was found in the Linux kernel's SELinux subsystem in versions before 5.7. This flaw occurs while importing the Commercial IP Security Option (CIPSO) protocol's category bitmap into the SELinux extensible bitmap via the' ebitmap_netlbl_import' routine. While processing the CIPSO restricted bitmap tag in the 'cipso_v4_p
nvd
CVE-2018-6093P4MEDIUMCVSS 6.5v8.0v9.02019-01-09
CVE-2018-6093 [MEDIUM] CWE-200 CVE-2018-6093: Insufficient origin checks in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacke Insufficient origin checks in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2018-6099P4MEDIUMCVSS 6.5v8.0v9.02018-12-04
CVE-2018-6099 [MEDIUM] CWE-200 CVE-2018-6099: A lack of CORS checks in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to A lack of CORS checks in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak limited cross-origin data via a crafted HTML page.
nvd
CVE-2018-6037P4MEDIUMCVSS 6.5v8.0v9.02018-09-25
CVE-2018-6037 [MEDIUM] CWE-200 CVE-2018-6037: Inappropriate implementation in autofill in Google Chrome prior to 64.0.3282.119 allowed a remote at Inappropriate implementation in autofill in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to obtain autofill data with insufficient user gestures via a crafted HTML page.
nvd
CVE-2018-14625P4HIGHCVSS 7.0v8.02018-09-10
CVE-2018-14625 [HIGH] CWE-416 CVE-2018-14625: A flaw was found in the Linux Kernel where an attacker may be able to have an uncontrolled read to k A flaw was found in the Linux Kernel where an attacker may be able to have an uncontrolled read to kernel-memory from within a vm guest. A race condition between connect() and close() function may allow an attacker using the AF_VSOCK protocol to gather a 4 byte information leak or possibly intercept or corrupt AF_VSOCK messages destined to other clien
nvd
CVE-2021-43541P4MEDIUMCVSS 6.5v9.0v10.0+1 more2021-12-08
CVE-2021-43541 [MEDIUM] CVE-2021-43541: When invoking protocol handlers for external protocols, a supplied parameter URL containing spaces w When invoking protocol handlers for external protocols, a supplied parameter URL containing spaces was not properly escaped. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
nvd
CVE-2020-6479P4MEDIUMCVSS 6.5v9.0v10.02020-05-21
CVE-2020-6479 [MEDIUM] CVE-2020-6479: Inappropriate implementation in sharing in Google Chrome prior to 83.0.4103.61 allowed a remote atta Inappropriate implementation in sharing in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to spoof security UI via a crafted HTML page.
nvd
CVE-2020-6478P4MEDIUMCVSS 6.5v9.0v10.02020-05-21
CVE-2020-6478 [MEDIUM] CVE-2020-6478: Inappropriate implementation in full screen in Google Chrome prior to 83.0.4103.61 allowed a remote Inappropriate implementation in full screen in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to spoof security UI via a crafted HTML page.
nvd
CVE-2020-6566P4MEDIUMCVSS 6.5v10.02020-09-21
CVE-2020-6566 [MEDIUM] CVE-2020-6566: Insufficient policy enforcement in media in Google Chrome prior to 85.0.4183.83 allowed a remote att Insufficient policy enforcement in media in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2019-13749P4MEDIUMCVSS 6.5v9.0v10.02019-12-10
CVE-2019-13749 [MEDIUM] CVE-2019-13749: Incorrect security UI in Omnibox in Google Chrome on iOS prior to 79.0.3945.79 allowed a remote atta Incorrect security UI in Omnibox in Google Chrome on iOS prior to 79.0.3945.79 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
Debian Linux vulnerabilities | cvebase