Debian Linux vulnerabilities
9,954 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358
Vulnerabilities
Page 304 of 498
CVE-2020-26976P4MEDIUMCVSS 6.5v9.0v10.02021-01-07
CVE-2020-26976 [MEDIUM] CVE-2020-26976: When a HTTPS pages was embedded in a HTTP page, and there was a service worker registered for the fo
When a HTTPS pages was embedded in a HTTP page, and there was a service worker registered for the former, the service worker could have intercepted the request for the secure page despite the iframe not being a secure context due to the (insecure) framing. This vulnerability affects Firefox < 84.
nvd
CVE-2020-6481P4MEDIUMCVSS 6.5v9.0v10.02020-05-21
CVE-2020-6481 [MEDIUM] CVE-2020-6481: Insufficient policy enforcement in URL formatting in Google Chrome prior to 83.0.4103.61 allowed a r
Insufficient policy enforcement in URL formatting in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to perform domain spoofing via a crafted domain name.
nvd
CVE-2018-6045P4MEDIUMCVSS 6.5v8.0v9.02018-09-25
CVE-2018-6045 [MEDIUM] CWE-200 CVE-2018-6045: Insufficient policy enforcement in DevTools in Google Chrome prior to 64.0.3282.119 allowed a remote
Insufficient policy enforcement in DevTools in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak user local file data via a crafted Chrome Extension.
nvd
CVE-2018-0486P4MEDIUMCVSS 6.5v7.0v8.0+1 more2018-01-13
CVE-2018-0486 [MEDIUM] CWE-347 CVE-2018-0486: Shibboleth XMLTooling-C before 1.6.3, as used in Shibboleth Service Provider before 2.6.0 on Windows
Shibboleth XMLTooling-C before 1.6.3, as used in Shibboleth Service Provider before 2.6.0 on Windows and other products, mishandles digital signatures of user attribute data, which allows remote attackers to obtain sensitive information or conduct impersonation attacks via a crafted DTD.
nvd
CVE-2023-1077P4HIGHCVSS 7.0v10.02023-03-27
CVE-2023-1077 [HIGH] CWE-843 CVE-2023-1077: In the Linux kernel, pick_next_rt_entity() may return a type confused entry, not detected by the BUG
In the Linux kernel, pick_next_rt_entity() may return a type confused entry, not detected by the BUG_ON condition, as the confused entry will not be NULL, but list_head.The buggy error condition would lead to a type confused entry with the list head,which would then be used as a type confused sched_rt_entity,causing memory corruption.
nvd
CVE-2018-6791P4MEDIUMCVSS 6.8v9.02018-02-07
CVE-2018-6791 [MEDIUM] CWE-78 CVE-2018-6791: An issue was discovered in soliduiserver/deviceserviceaction.cpp in KDE Plasma Workspace before 5.12
An issue was discovered in soliduiserver/deviceserviceaction.cpp in KDE Plasma Workspace before 5.12.0. When a vfat thumbdrive that contains `` or $() in its volume label is plugged in and mounted through the device notifier, it's interpreted as a shell command, leading to a possibility of arbitrary command execution. An example of an offending volume
nvd
CVE-2020-27672P4HIGHCVSS 7.0v10.02020-10-22
CVE-2020-27672 [HIGH] CWE-362 CVE-2020-27672: An issue was discovered in Xen through 4.14.x allowing x86 guest OS users to cause a host OS denial
An issue was discovered in Xen through 4.14.x allowing x86 guest OS users to cause a host OS denial of service, achieve data corruption, or possibly gain privileges by exploiting a race condition that leads to a use-after-free involving 2MiB and 1GiB superpages.
nvd
CVE-2017-15416P4MEDIUMCVSS 6.5v9.02018-08-28
CVE-2017-15416 [MEDIUM] CWE-119 CVE-2017-15416: Heap buffer overflow in Blob API in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to
Heap buffer overflow in Blob API in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page, aka a Blink out-of-bounds read.
nvd
CVE-2019-13745P4MEDIUMCVSS 6.5v9.0v10.02019-12-10
CVE-2019-13745 [MEDIUM] CVE-2019-13745: Insufficient policy enforcement in audio in Google Chrome prior to 79.0.3945.79 allowed a remote att
Insufficient policy enforcement in audio in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2022-26357P4HIGHCVSS 7.0v11.02022-04-05
CVE-2022-26357 [HIGH] CWE-362 CVE-2022-26357: race in VT-d domain ID cleanup Xen domain IDs are up to 15 bits wide. VT-d hardware may allow for on
race in VT-d domain ID cleanup Xen domain IDs are up to 15 bits wide. VT-d hardware may allow for only less than 15 bits to hold a domain ID associating a physical device with a particular domain. Therefore internally Xen domain IDs are mapped to the smaller value range. The cleaning up of the housekeeping structures has a race, allowing for VT-d doma
nvd
CVE-2022-23042P4HIGHCVSS 7.0v9.02022-03-10
CVE-2022-23042 [HIGH] CVE-2022-23042: Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to
Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Several Linux PV device frontends are using the grant table interfaces for removing access rights of the backends in ways being subject to race conditions, resulting in pote
nvd
CVE-2020-6567P4MEDIUMCVSS 6.5v10.02020-09-21
CVE-2020-6567 [MEDIUM] CWE-20 CVE-2020-6567: Insufficient validation of untrusted input in command line handling in Google Chrome on Windows prio
Insufficient validation of untrusted input in command line handling in Google Chrome on Windows prior to 85.0.4183.83 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2018-18344P4MEDIUMCVSS 6.5v9.02018-12-11
CVE-2018-18344 [MEDIUM] CWE-269 CVE-2018-18344: Inappropriate allowance of the setDownloadBehavior devtools protocol feature in Extensions in Google
Inappropriate allowance of the setDownloadBehavior devtools protocol feature in Extensions in Google Chrome prior to 71.0.3578.80 allowed a remote attacker with control of an installed extension to access files on the local file system via a crafted Chrome Extension.
nvd
CVE-2020-15977P4MEDIUMCVSS 6.5v10.02020-11-03
CVE-2020-15977 [MEDIUM] CWE-20 CVE-2020-15977: Insufficient data validation in dialogs in Google Chrome on OS X prior to 86.0.4240.75 allowed a rem
Insufficient data validation in dialogs in Google Chrome on OS X prior to 86.0.4240.75 allowed a remote attacker to obtain potentially sensitive information from disk via a crafted HTML page.
nvd
CVE-2024-26872P4HIGHCVSS 7.0v10.02024-04-17
CVE-2024-26872 [HIGH] CWE-416 CVE-2024-26872: In the Linux kernel, the following vulnerability has been resolved: RDMA/srpt: Do not register even
In the Linux kernel, the following vulnerability has been resolved:
RDMA/srpt: Do not register event handler until srpt device is fully setup
Upon rare occasions, KASAN reports a use-after-free Write
in srpt_refresh_port().
This seems to be because an event handler is registered before the
srpt device is fully setup and a race condition upon error m
nvd
CVE-2018-14526P4MEDIUMCVSS 6.5v8.02018-08-08
CVE-2018-14526 [MEDIUM] CWE-924 CVE-2018-14526: An issue was discovered in rsn_supp/wpa.c in wpa_supplicant 2.0 through 2.6. Under certain condition
An issue was discovered in rsn_supp/wpa.c in wpa_supplicant 2.0 through 2.6. Under certain conditions, the integrity of EAPOL-Key messages is not checked, leading to a decryption oracle. An attacker within range of the Access Point and client can abuse the vulnerability to recover sensitive information.
nvd
CVE-2020-6491P4MEDIUMCVSS 6.5v9.0v10.02020-05-21
CVE-2020-6491 [MEDIUM] CVE-2020-6491: Insufficient data validation in site information in Google Chrome prior to 83.0.4103.61 allowed a re
Insufficient data validation in site information in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to spoof security UI via a crafted domain name.
nvd
CVE-2018-18345P4MEDIUMCVSS 6.5v9.02018-12-11
CVE-2018-18345 [MEDIUM] CVE-2018-18345: Incorrect handling of blob URLS in Site Isolation in Google Chrome prior to 71.0.3578.80 allowed a r
Incorrect handling of blob URLS in Site Isolation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker who had compromised the renderer process to bypass site isolation protections via a crafted HTML page.
nvd
CVE-2024-26960P4HIGHCVSS 7.0v10.02024-05-01
CVE-2024-26960 [HIGH] CWE-362 CVE-2024-26960: In the Linux kernel, the following vulnerability has been resolved: mm: swap: fix race between free
In the Linux kernel, the following vulnerability has been resolved:
mm: swap: fix race between free_swap_and_cache() and swapoff()
There was previously a theoretical window where swapoff() could run and
teardown a swap_info_struct while a call to free_swap_and_cache() was
running in another thread. This could cause, amongst other bad
possibilities, s
nvd
CVE-2018-18352P4MEDIUMCVSS 6.5v9.02018-12-11
CVE-2018-18352 [MEDIUM] CWE-732 CVE-2018-18352: Service works could inappropriately gain access to cross origin audio in Media in Google Chrome prio
Service works could inappropriately gain access to cross origin audio in Media in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to bypass same origin policy for audio content via a crafted HTML page.
nvd