cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 311 of 498
CVE-2023-40167P4MEDIUMCVSS 5.3v10.0v11.0+1 more2023-09-15
CVE-2023-40167 [MEDIUM] CWE-130 CVE-2023-40167: Jetty is a Java based web server and servlet engine. Prior to versions 9.4.52, 10.0.16, 11.0.16, and Jetty is a Java based web server and servlet engine. Prior to versions 9.4.52, 10.0.16, 11.0.16, and 12.0.1, Jetty accepts the `+` character proceeding the content-length value in a HTTP/1 header field. This is more permissive than allowed by the RFC and other servers routinely reject such requests with 400 responses. There is no known exploit scena
nvd
CVE-2015-1238P4HIGHCVSS 7.5v8.02015-04-19
CVE-2015-1238 [HIGH] CWE-119 CVE-2015-1238: Skia, as used in Google Chrome before 42.0.2311.90, allows remote attackers to cause a denial of ser Skia, as used in Google Chrome before 42.0.2311.90, allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2016-2533P4MEDIUMCVSS 6.5v7.0v8.02016-04-13
CVE-2016-2533 [MEDIUM] CWE-119 CVE-2016-2533: Buffer overflow in the ImagingPcdDecode function in PcdDecode.c in Pillow before 3.1.1 and Python Im Buffer overflow in the ImagingPcdDecode function in PcdDecode.c in Pillow before 3.1.1 and Python Imaging Library (PIL) 1.1.7 and earlier allows remote attackers to cause a denial of service (crash) via a crafted PhotoCD file.
nvd
CVE-2013-2885P4HIGHCVSS 7.5v7.02013-07-31
CVE-2013-2885 [HIGH] CWE-399 CVE-2013-2885: Use-after-free vulnerability in Google Chrome before 28.0.1500.95 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 28.0.1500.95 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to not properly considering focus during the processing of JavaScript events in the presence of a multiple-fields input type.
nvd
CVE-2020-26870P4MEDIUMCVSS 6.1v9.02020-10-07
CVE-2020-26870 [MEDIUM] CWE-79 CVE-2020-26870: Cure53 DOMPurify before 2.0.17 allows mutation XSS. This occurs because a serialize-parse roundtrip Cure53 DOMPurify before 2.0.17 allows mutation XSS. This occurs because a serialize-parse roundtrip does not necessarily return the original DOM tree, and a namespace can change from HTML to MathML, as demonstrated by nesting of FORM elements.
nvd
CVE-2015-1249P4HIGHCVSS 7.5v8.02015-04-19
CVE-2015-1249 [HIGH] CVE-2015-1249: Multiple unspecified vulnerabilities in Google Chrome before 42.0.2311.90 allow attackers to cause a Multiple unspecified vulnerabilities in Google Chrome before 42.0.2311.90 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2015-1289P4HIGHCVSS 7.5v8.02015-07-23
CVE-2015-1289 [HIGH] CVE-2015-1289: Multiple unspecified vulnerabilities in Google Chrome before 44.0.2403.89 allow attackers to cause a Multiple unspecified vulnerabilities in Google Chrome before 44.0.2403.89 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2017-18635P4MEDIUMCVSS 6.1v8.0v9.02019-09-25
CVE-2017-18635 [MEDIUM] CWE-79 CVE-2017-18635: An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could injec An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name.
nvd
CVE-2014-9030P4HIGHCVSS 7.1v7.02014-11-24
CVE-2014-9030 [HIGH] CWE-20 CVE-2014-9030: The do_mmu_update function in arch/x86/mm.c in Xen 3.2.x through 4.4.x does not properly manage page The do_mmu_update function in arch/x86/mm.c in Xen 3.2.x through 4.4.x does not properly manage page references, which allows remote domains to cause a denial of service by leveraging control over an HVM guest and a crafted MMU_MACHPHYS_UPDATE.
nvd
CVE-2022-21123P4MEDIUMCVSS 5.5v9.0v10.0+1 more2022-06-15
CVE-2022-21123 [MEDIUM] CWE-459 CVE-2022-21123: Incomplete cleanup of multi-core shared buffers for some Intel(R) Processors may allow an authentica Incomplete cleanup of multi-core shared buffers for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
nvd
CVE-2013-2858P4HIGHCVSS 7.5v7.0v8.02013-06-05
CVE-2013-2858 [HIGH] CWE-416 CVE-2013-2858: Use-after-free vulnerability in the HTML5 Audio implementation in Google Chrome before 27.0.1453.110 Use-after-free vulnerability in the HTML5 Audio implementation in Google Chrome before 27.0.1453.110 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2013-2861P4HIGHCVSS 7.5v7.0v8.02013-06-05
CVE-2013-2861 [HIGH] CWE-399 CVE-2013-2861: Use-after-free vulnerability in the SVG implementation in Google Chrome before 27.0.1453.110 allows Use-after-free vulnerability in the SVG implementation in Google Chrome before 27.0.1453.110 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2013-2860P4HIGHCVSS 7.5v7.0v8.02013-06-05
CVE-2013-2860 [HIGH] CWE-416 CVE-2013-2860: Use-after-free vulnerability in Google Chrome before 27.0.1453.110 allows remote attackers to cause Use-after-free vulnerability in Google Chrome before 27.0.1453.110 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving access to a database API by a worker process.
nvd
CVE-2016-1690P4HIGHCVSS 7.5v8.02016-06-05
CVE-2016-1690 [HIGH] CVE-2016-1690: The Autofill implementation in Google Chrome before 51.0.2704.63 mishandles the interaction between The Autofill implementation in Google Chrome before 51.0.2704.63 mishandles the interaction between field updates and JavaScript code that triggers a frame deletion, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted web site, a different vulnerability than CVE-2016-1701.
nvd
CVE-2016-2191P4MEDIUMCVSS 6.5v7.0v8.02016-04-13
CVE-2016-2191 [MEDIUM] CWE-119 CVE-2016-2191: The bmp_read_rows function in pngxtern/pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to The bmp_read_rows function in pngxtern/pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (invalid memory write and crash) via a series of delta escapes in a crafted BMP image.
nvd
CVE-2019-20807P4MEDIUMCVSS 5.3v9.02020-05-28
CVE-2019-20807 [MEDIUM] CWE-78 CVE-2019-20807: In Vim before 8.1.0881, users can circumvent the rvim restricted mode and execute arbitrary OS comma In Vim before 8.1.0881, users can circumvent the rvim restricted mode and execute arbitrary OS commands via scripting interfaces (e.g., Python, Ruby, or Lua).
nvd
CVE-2018-1152P4MEDIUMCVSS 6.5v8.02018-06-18
CVE-2018-1152 [MEDIUM] CWE-369 CVE-2018-1152: libjpeg-turbo 1.5.90 is vulnerable to a denial of service vulnerability caused by a divide by zero w libjpeg-turbo 1.5.90 is vulnerable to a denial of service vulnerability caused by a divide by zero when processing a crafted BMP image.
nvd
CVE-2015-3333P4HIGHCVSS 7.5v8.02015-04-19
CVE-2015-3333 [HIGH] CVE-2015-3333: Multiple unspecified vulnerabilities in Google V8 before 4.2.77.14, as used in Google Chrome before Multiple unspecified vulnerabilities in Google V8 before 4.2.77.14, as used in Google Chrome before 42.0.2311.90, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2019-1000019P4MEDIUMCVSS 6.5v8.02019-02-04
CVE-2019-1000019 [MEDIUM] CWE-125 CVE-2019-1000019: libarchive version commit bf9aec176c6748f0ee7a678c5f9f9555b9a757c1 onwards (release v3.0.2 onwards) libarchive version commit bf9aec176c6748f0ee7a678c5f9f9555b9a757c1 onwards (release v3.0.2 onwards) contains a CWE-125: Out-of-bounds Read vulnerability in 7zip decompression, archive_read_support_format_7zip.c, header_bytes() that can result in a crash (denial of service). This attack appears to be exploitable via the victim opening a specially
nvd
CVE-2019-7663P4MEDIUMCVSS 6.5v8.02019-02-09
CVE-2019-7663 [MEDIUM] CVE-2019-7663: An Invalid Address dereference was discovered in TIFFWriteDirectoryTagTransferfunction in libtiff/ti An Invalid Address dereference was discovered in TIFFWriteDirectoryTagTransferfunction in libtiff/tif_dirwrite.c in LibTIFF 4.0.10, affecting the cpSeparateBufToContigBuf function in tiffcp.c. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted tiff file. This is different from CVE-2018-12900.
nvd
Debian Linux vulnerabilities | cvebase