Debian Linux vulnerabilities
9,954 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358
Vulnerabilities
Page 306 of 498
CVE-2016-1000345P4MEDIUMCVSS 5.9v8.02018-06-04
CVE-2016-1000345 [MEDIUM] CWE-361 CVE-2016-1000345: In the Bouncy Castle JCE Provider version 1.55 and earlier the DHIES/ECIES CBC mode vulnerable to pa
In the Bouncy Castle JCE Provider version 1.55 and earlier the DHIES/ECIES CBC mode vulnerable to padding oracle attack. For BC 1.55 and older, in an environment where timings can be easily observed, it is possible with enough observations to identify when the decryption is failing due to padding.
nvd
CVE-2016-1000341P4MEDIUMCVSS 5.9v8.02018-06-04
CVE-2016-1000341 [MEDIUM] CWE-361 CVE-2016-1000341: In the Bouncy Castle JCE Provider version 1.55 and earlier DSA signature generation is vulnerable to
In the Bouncy Castle JCE Provider version 1.55 and earlier DSA signature generation is vulnerable to timing attack. Where timings can be closely observed for the generation of signatures, the lack of blinding in 1.55, or earlier, may allow an attacker to gain information about the signature's k value and ultimately the private value as well.
nvd
CVE-2017-15130P4MEDIUMCVSS 5.9v8.0v9.02018-03-02
CVE-2017-15130 [MEDIUM] CWE-400 CVE-2017-15130: A denial of service flaw was found in dovecot before 2.2.34. An attacker able to generate random SNI
A denial of service flaw was found in dovecot before 2.2.34. An attacker able to generate random SNI server names could exploit TLS SNI configuration lookups, leading to excessive memory usage and the process to restart.
nvd
CVE-2016-0787P4MEDIUMCVSS 5.9v7.0v8.02016-04-13
CVE-2016-0787 [MEDIUM] CWE-200 CVE-2016-0787: The diffie_hellman_sha256 function in kex.c in libssh2 before 1.7.0 improperly truncates secrets to
The diffie_hellman_sha256 function in kex.c in libssh2 before 1.7.0 improperly truncates secrets to 128 or 256 bits, which makes it easier for man-in-the-middle attackers to decrypt or intercept SSH sessions via unspecified vectors, aka a "bits/bytes confusion bug."
nvd
CVE-2022-23607P4MEDIUMCVSS 6.5v9.02022-02-01
CVE-2022-23607 [MEDIUM] CWE-200 CVE-2022-23607: treq is an HTTP library inspired by requests but written on top of Twisted's Agents. Treq's request
treq is an HTTP library inspired by requests but written on top of Twisted's Agents. Treq's request methods (`treq.get`, `treq.post`, etc.) and `treq.client.HTTPClient` constructor accept cookies as a dictionary. Such cookies are not bound to a single domain, and are therefore sent to *every* domain ("supercookies"). This can potentially cause sensit
nvd
CVE-2015-5174P4MEDIUMCVSS 4.3v7.0v8.02016-02-25
CVE-2015-5174 [MEDIUM] CWE-22 CVE-2015-5174: Directory traversal vulnerability in RequestUtil.java in Apache Tomcat 6.x before 6.0.45, 7.x before
Directory traversal vulnerability in RequestUtil.java in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.65, and 8.x before 8.0.27 allows remote authenticated users to bypass intended SecurityManager restrictions and list a parent directory via a /.. (slash dot dot) in a pathname used by a web application in a getResource, getResourceAsStream, or getRe
nvd
CVE-2014-3580P4MEDIUMCVSS 5.0v7.02014-12-18
CVE-2014-3580 [MEDIUM] CVE-2014-3580: The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.x before 1.7.19 and 1.8.x before 1
The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.x before 1.7.19 and 1.8.x before 1.8.11 allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) via a REPORT request for a resource that does not exist.
nvd
CVE-2023-1817P4MEDIUMCVSS 6.5v11.02023-04-04
CVE-2023-1817 [MEDIUM] CVE-2023-1817: Insufficient policy enforcement in Intents in Google Chrome on Android prior to 112.0.5615.49 allowe
Insufficient policy enforcement in Intents in Google Chrome on Android prior to 112.0.5615.49 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2022-44641P4MEDIUMCVSS 6.5v10.0v11.02022-11-18
CVE-2022-44641 [MEDIUM] CWE-776 CVE-2022-44641: In Linaro Automated Validation Architecture (LAVA) before 2022.11, users with valid credentials can
In Linaro Automated Validation Architecture (LAVA) before 2022.11, users with valid credentials can submit crafted XMLRPC requests that cause a recursive XML entity expansion, leading to excessive use of memory on the server and a Denial of Service.
nvd
CVE-2016-4439P4MEDIUMCVSS 6.7v8.02016-05-20
CVE-2016-4439 [MEDIUM] CWE-119 CVE-2016-4439: The esp_reg_write function in hw/scsi/esp.c in the 53C9X Fast SCSI Controller (FSC) support in QEMU
The esp_reg_write function in hw/scsi/esp.c in the 53C9X Fast SCSI Controller (FSC) support in QEMU does not properly check command buffer length, which allows local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) or potentially execute arbitrary code on the QEMU host via unspecified vectors.
nvd
CVE-2023-6860P4MEDIUMCVSS 6.5v10.0v11.0+1 more2023-12-19
CVE-2023-6860 [MEDIUM] CVE-2023-6860: The `VideoBridge` allowed any content process to use textures produced by remote decoders. This cou
The `VideoBridge` allowed any content process to use textures produced by remote decoders. This could be abused to escape the sandbox. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
nvd
CVE-2023-1822P4MEDIUMCVSS 6.5v11.02023-04-04
CVE-2023-1822 [MEDIUM] CVE-2023-1822: Incorrect security UI in Navigation in Google Chrome prior to 112.0.5615.49 allowed a remote attacke
Incorrect security UI in Navigation in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2021-21330P4MEDIUMCVSS 6.1v10.02021-02-26
CVE-2021-21330 [MEDIUM] CWE-601 CVE-2021-21330: aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In aiohttp before ve
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In aiohttp before version 3.7.4 there is an open redirect vulnerability. A maliciously crafted link to an aiohttp-based web-server could redirect the browser to a different website. It is caused by a bug in the `aiohttp.web_middlewares.normalize_path_middleware` middlewa
nvd
CVE-2022-30785P4MEDIUMCVSS 6.7v9.0v10.0+1 more2022-05-26
CVE-2022-30785 [MEDIUM] CVE-2022-30785: A file handle created in fuse_lib_opendir, and later used in fuse_lib_readdir, enables arbitrary mem
A file handle created in fuse_lib_opendir, and later used in fuse_lib_readdir, enables arbitrary memory read and write operations in NTFS-3G through 2021.8.22 when using libfuse-lite.
nvd
CVE-2023-1823P4MEDIUMCVSS 6.5v11.02023-04-04
CVE-2023-1823 [MEDIUM] CVE-2023-1823: Inappropriate implementation in FedCM in Google Chrome prior to 112.0.5615.49 allowed a remote attac
Inappropriate implementation in FedCM in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2023-1819P4MEDIUMCVSS 6.5v11.02023-04-04
CVE-2023-1819 [MEDIUM] CWE-125 CVE-2023-1819: Out of bounds read in Accessibility in Google Chrome prior to 112.0.5615.49 allowed a remote attacke
Out of bounds read in Accessibility in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2020-6444P4MEDIUMCVSS 6.3v9.0v10.02020-04-13
CVE-2020-6444 [MEDIUM] CWE-908 CVE-2020-6444: Uninitialized use in WebRTC in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to pote
Uninitialized use in WebRTC in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2023-1816P4MEDIUMCVSS 6.5v11.02023-04-04
CVE-2023-1816 [MEDIUM] CVE-2023-1816: Incorrect security UI in Picture In Picture in Google Chrome prior to 112.0.5615.49 allowed a remote
Incorrect security UI in Picture In Picture in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to potentially perform navigation spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-1821P4MEDIUMCVSS 6.5v11.02023-04-04
CVE-2023-1821 [MEDIUM] CVE-2023-1821: Inappropriate implementation in WebShare in Google Chrome prior to 112.0.5615.49 allowed a remote at
Inappropriate implementation in WebShare in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to potentially hide the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2023-4350P4MEDIUMCVSS 6.5v11.0v12.02023-08-15
CVE-2023-4350 [MEDIUM] CVE-2023-4350: Inappropriate implementation in Fullscreen in Google Chrome on Android prior to 116.0.5845.96 allowe
Inappropriate implementation in Fullscreen in Google Chrome on Android prior to 116.0.5845.96 allowed a remote attacker to potentially spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: High)
nvd