cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 307 of 498
CVE-2023-6204P4MEDIUMCVSS 6.5v10.0v11.0+1 more2023-11-21
CVE-2023-6204 [MEDIUM] CWE-125 CVE-2023-6204: On some systems—depending on the graphics settings and drivers—it was possible to force an out-of-bo On some systems—depending on the graphics settings and drivers—it was possible to force an out-of-bounds read and leak memory data into the images created on the canvas element. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
nvd
CVE-2021-33655P4MEDIUMCVSS 6.7v10.0v11.02022-07-18
CVE-2021-33655 [MEDIUM] CWE-787 CVE-2021-33655: When sending malicous data to kernel by ioctl cmd FBIOPUT_VSCREENINFO,kernel will write memory out o When sending malicous data to kernel by ioctl cmd FBIOPUT_VSCREENINFO,kernel will write memory out of bounds.
nvd
CVE-2021-38507P4MEDIUMCVSS 6.5v9.0v10.0+1 more2021-12-08
CVE-2021-38507 [MEDIUM] CWE-346 CVE-2021-38507: The Opportunistic Encryption feature of HTTP2 (RFC 8164) allows a connection to be transparently upg The Opportunistic Encryption feature of HTTP2 (RFC 8164) allows a connection to be transparently upgraded to TLS while retaining the visual properties of an HTTP connection, including being same-origin with unencrypted connections on port 80. However, if a second encrypted port on the same IP address (e.g. port 8443) did not opt-in to opportunistic
nvd
CVE-2020-6569P4MEDIUMCVSS 6.3v10.02020-09-21
CVE-2020-6569 [MEDIUM] CWE-190 CVE-2020-6569: Integer overflow in WebUSB in Google Chrome prior to 85.0.4183.83 allowed a remote attacker who had Integer overflow in WebUSB in Google Chrome prior to 85.0.4183.83 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-9658P4MEDIUMCVSS 5.3v8.02019-03-11
CVE-2019-9658 [MEDIUM] CWE-611 CVE-2019-9658: Checkstyle before 8.18 loads external DTDs by default. Checkstyle before 8.18 loads external DTDs by default.
nvd
CVE-2012-1180P4MEDIUMCVSS 5.0v6.02012-04-17
CVE-2012-1180 [MEDIUM] CWE-416 CVE-2012-1180: Use-after-free vulnerability in nginx before 1.0.14 and 1.1.x before 1.1.17 allows remote HTTP serve Use-after-free vulnerability in nginx before 1.0.14 and 1.1.x before 1.1.17 allows remote HTTP servers to obtain sensitive information from process memory via a crafted backend response, in conjunction with a client request.
nvd
CVE-2022-46338P4MEDIUMCVSS 6.5v10.02022-11-30
CVE-2022-46338 [MEDIUM] CWE-732 CVE-2022-46338: g810-led 0.4.2, a LED configuration tool for Logitech Gx10 keyboards, contained a udev rule to make g810-led 0.4.2, a LED configuration tool for Logitech Gx10 keyboards, contained a udev rule to make supported device nodes world-readable and writable, allowing any process on the system to read traffic from keyboards, including sensitive data.
nvd
CVE-2024-0747P4MEDIUMCVSS 6.5v10.02024-01-23
CVE-2024-0747 [MEDIUM] CWE-693 CVE-2024-0747: When a parent page loaded a child in an iframe with `unsafe-inline`, the parent Content Security Pol When a parent page loaded a child in an iframe with `unsafe-inline`, the parent Content Security Policy could have overridden the child Content Security Policy. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
nvd
CVE-2022-21365P4MEDIUMCVSS 5.3v9.0v10.0+1 more2022-01-19
CVE-2022-21365 [MEDIUM] CVE-2022-21365: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (co Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple
nvd
CVE-2022-21360P4MEDIUMCVSS 5.3v9.0v10.0+1 more2022-01-19
CVE-2022-21360 [MEDIUM] CWE-400 CVE-2022-21360: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (co Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via m
nvd
CVE-2022-21299P4MEDIUMCVSS 5.3v9.0v10.0+1 more2022-01-19
CVE-2022-21299 [MEDIUM] CWE-400 CVE-2022-21299: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (co Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via mult
nvd
CVE-2015-0837P4MEDIUMCVSS 5.9v7.0v8.02019-11-29
CVE-2015-0837 [MEDIUM] CWE-203 CVE-2015-0837: The mpi_powm function in Libgcrypt before 1.6.3 and GnuPG before 1.4.19 allows attackers to obtain s The mpi_powm function in Libgcrypt before 1.6.3 and GnuPG before 1.4.19 allows attackers to obtain sensitive information by leveraging timing differences when accessing a pre-computed table during modular exponentiation, related to a "Last-Level Cache Side-Channel Attack."
nvd
CVE-2014-9675P4MEDIUMCVSS 5.0v7.02015-02-08
CVE-2014-9675 [MEDIUM] CWE-264 CVE-2014-9675: bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifying that an initial su bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifying that an initial substring is present, which allows remote attackers to discover heap pointer values and bypass the ASLR protection mechanism via a crafted BDF font.
nvd
CVE-2022-21294P4MEDIUMCVSS 5.3v9.0v10.0+1 more2022-01-19
CVE-2022-21294 [MEDIUM] CWE-770 CVE-2022-21294: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (co Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via
nvd
CVE-2018-14355P4MEDIUMCVSS 5.3v8.0v9.02018-07-17
CVE-2018-14355 [MEDIUM] CWE-22 CVE-2018-14355: An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/util.c mishandles An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/util.c mishandles ".." directory traversal in a mailbox name.
nvd
CVE-2022-21366P4MEDIUMCVSS 5.3v10.0v11.02022-01-19
CVE-2022-21366 [MEDIUM] CWE-400 CVE-2022-21366: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (co Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Oracle Java SE: 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protoc
nvd
CVE-2020-11047P4MEDIUMCVSS 5.9v10.02020-05-07
CVE-2020-11047 [MEDIUM] CWE-125 CVE-2020-11047: In FreeRDP after 1.1 and before 2.0.0, there is an out-of-bounds read in autodetect_recv_bandwidth_m In FreeRDP after 1.1 and before 2.0.0, there is an out-of-bounds read in autodetect_recv_bandwidth_measure_results. A malicious server can extract up to 8 bytes of client memory with a manipulated message by providing a short input and reading the measurement result data. This has been patched in 2.0.0.
nvd
CVE-2022-21426P4MEDIUMCVSS 5.3v9.0v10.0+1 more2022-04-19
CVE-2022-21426 [MEDIUM] CVE-2022-21426: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (co Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle GraalVM Enterprise Edition: 20.3.5, 21.3.1 and 22.0.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access vi
nvd
CVE-2015-8313P4MEDIUMCVSS 5.9v7.0v8.0+2 more2019-12-20
CVE-2015-8313 [MEDIUM] CWE-203 CVE-2015-8313: GnuTLS incorrectly validates the first byte of padding in CBC modes GnuTLS incorrectly validates the first byte of padding in CBC modes
nvd
CVE-2020-14803P4MEDIUMCVSS 5.3v9.0v10.02020-10-21
CVE-2020-14803 [MEDIUM] CVE-2020-14803: Vulnerability in the Java SE product of Oracle Java SE (component: Libraries). Supported versions th Vulnerability in the Java SE product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 11.0.8 and 15. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized read access to a
nvd