Debian Linux vulnerabilities
9,954 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358
Vulnerabilities
Page 305 of 498
CVE-2020-15981P4MEDIUMCVSS 6.5v10.02020-11-03
CVE-2020-15981 [MEDIUM] CWE-125 CVE-2020-15981: Out of bounds read in audio in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to obta
Out of bounds read in audio in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2025-38108P4HIGHCVSS 7.0v11.02025-07-03
CVE-2025-38108 [HIGH] CWE-362 CVE-2025-38108: In the Linux kernel, the following vulnerability has been resolved: net_sched: red: fix a race in _
In the Linux kernel, the following vulnerability has been resolved:
net_sched: red: fix a race in __red_change()
Gerrard Tai reported a race condition in RED, whenever SFQ perturb timer
fires at the wrong time.
The race is as follows:
CPU 0 CPU 1
[1]: lock root
[2]: qdisc_tree_flush_backlog()
[3]: unlock root
|
| [5]: lock root
| [6]: rehash
| [7]:
nvd
CVE-2025-38102P4HIGHCVSS 7.0v11.02025-07-03
CVE-2025-38102 [HIGH] CWE-362 CVE-2025-38102: In the Linux kernel, the following vulnerability has been resolved: VMCI: fix race between vmci_hos
In the Linux kernel, the following vulnerability has been resolved:
VMCI: fix race between vmci_host_setup_notify and vmci_ctx_unset_notify
During our test, it is found that a warning can be trigger in try_grab_folio
as follow:
------------[ cut here ]------------
WARNING: CPU: 0 PID: 1678 at mm/gup.c:147 try_grab_folio+0x106/0x130
Modules linked in
nvd
CVE-2020-6456P4MEDIUMCVSS 6.5v9.0v10.02020-04-13
CVE-2020-6456 [MEDIUM] CWE-276 CVE-2020-6456: Insufficient validation of untrusted input in clipboard in Google Chrome prior to 81.0.4044.92 allow
Insufficient validation of untrusted input in clipboard in Google Chrome prior to 81.0.4044.92 allowed a local attacker to bypass site isolation via crafted clipboard contents.
nvd
CVE-2025-38107P4HIGHCVSS 7.0v11.02025-07-03
CVE-2025-38107 [HIGH] CWE-362 CVE-2025-38107: In the Linux kernel, the following vulnerability has been resolved: net_sched: ets: fix a race in e
In the Linux kernel, the following vulnerability has been resolved:
net_sched: ets: fix a race in ets_qdisc_change()
Gerrard Tai reported a race condition in ETS, whenever SFQ perturb timer
fires at the wrong time.
The race is as follows:
CPU 0 CPU 1
[1]: lock root
[2]: qdisc_tree_flush_backlog()
[3]: unlock root
|
| [5]: lock root
| [6]: rehash
|
nvd
CVE-2018-18353P4MEDIUMCVSS 6.5v9.02018-12-11
CVE-2018-18353 [MEDIUM] CVE-2018-18353: Failure to dismiss http auth dialogs on navigation in Network Authentication in Google Chrome on And
Failure to dismiss http auth dialogs on navigation in Network Authentication in Google Chrome on Android prior to 71.0.3578.80 allowed a remote attacker to confuse the user about the origin of an auto dialog via a crafted HTML page.
nvd
CVE-2020-6476P4MEDIUMCVSS 6.5v9.0v10.02020-05-21
CVE-2020-6476 [MEDIUM] CWE-276 CVE-2020-6476: Insufficient policy enforcement in tab strip in Google Chrome prior to 83.0.4103.61 allowed an attac
Insufficient policy enforcement in tab strip in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.
nvd
CVE-2021-35452P4MEDIUMCVSS 6.5v10.02022-01-10
CVE-2021-35452 [MEDIUM] CWE-125 CVE-2021-35452: An Incorrect Access Control vulnerability exists in libde265 v1.0.8 due to a SEGV in slice.cc.
An Incorrect Access Control vulnerability exists in libde265 v1.0.8 due to a SEGV in slice.cc.
nvd
CVE-2021-4068P4MEDIUMCVSS 6.5v10.0v11.02021-12-23
CVE-2021-4068 [MEDIUM] CWE-116 CVE-2021-4068: Insufficient data validation in new tab page in Google Chrome prior to 96.0.4664.93 allowed a remote
Insufficient data validation in new tab page in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2020-15984P4MEDIUMCVSS 6.5v10.02020-11-03
CVE-2020-15984 [MEDIUM] CVE-2020-15984: Insufficient policy enforcement in Omnibox in Google Chrome on iOS prior to 86.0.4240.75 allowed a r
Insufficient policy enforcement in Omnibox in Google Chrome on iOS prior to 86.0.4240.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted URL.
nvd
CVE-2019-13739P4MEDIUMCVSS 6.5v9.0v10.02019-12-10
CVE-2019-13739 [MEDIUM] CVE-2019-13739: Insufficient policy enforcement in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote a
Insufficient policy enforcement in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
nvd
CVE-2019-5767P4MEDIUMCVSS 6.5v9.02019-02-19
CVE-2019-5767 [MEDIUM] CWE-1021 CVE-2019-5767: Insufficient protection of permission UI in WebAPKs in Google Chrome on Android prior to 72.0.3626.8
Insufficient protection of permission UI in WebAPKs in Google Chrome on Android prior to 72.0.3626.81 allowed an attacker who convinced the user to install a malicious application to access privacy/security sensitive web APIs via a crafted APK.
nvd
CVE-2021-43528P4MEDIUMCVSS 6.5v9.0v10.0+1 more2021-12-08
CVE-2021-43528 [MEDIUM] CWE-269 CVE-2021-43528: Thunderbird unexpectedly enabled JavaScript in the composition area. The JavaScript execution contex
Thunderbird unexpectedly enabled JavaScript in the composition area. The JavaScript execution context was limited to this area and did not receive chrome-level privileges, but could be used as a stepping stone to further an attack with other vulnerabilities. This vulnerability affects Thunderbird < 91.4.0.
nvd
CVE-2019-18424P4MEDIUMCVSS 6.8v9.0v10.02019-10-31
CVE-2019-18424 [MEDIUM] CWE-78 CVE-2019-18424: An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA
An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has access to a physical device. This occurs because passed through PCI devices may corrupt host memory after deassignment. When a PCI device is assigned to an untrusted domain, it is possible for that domain to
nvd
CVE-2017-0369P4MEDIUMCVSS 6.5v7.02018-04-13
CVE-2017-0369 [MEDIUM] CWE-276 CVE-2017-0369: Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw, allowing a sysops to undelete pages, alt
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw, allowing a sysops to undelete pages, although the page is protected against it.
nvd
CVE-2021-4054P4MEDIUMCVSS 6.5v10.0v11.02021-12-23
CVE-2021-4054 [MEDIUM] CVE-2021-4054: Incorrect security UI in autofill in Google Chrome prior to 96.0.4664.93 allowed a remote attacker t
Incorrect security UI in autofill in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
nvd
CVE-2023-3618P4MEDIUMCVSS 6.5v10.02023-07-12
CVE-2023-3618 [MEDIUM] CWE-120 CVE-2023-3618: A flaw was found in libtiff. A specially crafted tiff file can lead to a segmentation fault due to a
A flaw was found in libtiff. A specially crafted tiff file can lead to a segmentation fault due to a buffer overflow in the Fax3Encode function in libtiff/tif_fax3.c, resulting in a denial of service.
nvd
CVE-2021-21239P4MEDIUMCVSS 6.5v9.02021-01-21
CVE-2021-21239 [MEDIUM] CWE-347 CVE-2021-21239: PySAML2 is a pure python implementation of SAML Version 2 Standard. PySAML2 before 6.5.0 has an impr
PySAML2 is a pure python implementation of SAML Version 2 Standard. PySAML2 before 6.5.0 has an improper verification of cryptographic signature vulnerability. Users of pysaml2 that use the default CryptoBackendXmlSec1 backend and need to verify signed SAML documents are impacted. PySAML2 does not ensure that a signed SAML document is correctly sign
nvd
CVE-2020-15705P4MEDIUMCVSS 6.4v10.02020-07-29
CVE-2020-15705 [MEDIUM] CWE-347 CVE-2020-15705: GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to
GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure boot database and the GRUB image is booted directly without the use of shim. This issue affects GRUB2 version 2.04 and prior versions
nvd
CVE-2022-21499P4MEDIUMCVSS 6.7v11.02022-06-09
CVE-2022-21499 [MEDIUM] CWE-787 CVE-2022-21499: KGDB and KDB allow read and write access to kernel memory, and thus should be restricted during lock
KGDB and KDB allow read and write access to kernel memory, and thus should be restricted during lockdown. An attacker with access to a serial port could trigger the debugger so it is important that the debugger respect the lockdown mode when/if it is triggered. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts). CVSS Vecto
nvd