Debian Linux vulnerabilities
9,954 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358
Vulnerabilities
Page 314 of 498
CVE-2021-32399P4HIGHCVSS 7.0v9.02021-05-10
CVE-2021-32399 [HIGH] CWE-362 CVE-2021-32399: net/bluetooth/hci_request.c in the Linux kernel through 5.12.2 has a race condition for removal of t
net/bluetooth/hci_request.c in the Linux kernel through 5.12.2 has a race condition for removal of the HCI controller.
nvd
CVE-2018-7873P4MEDIUMCVSS 6.5v7.02018-03-08
CVE-2018-7873 [MEDIUM] CWE-787 CVE-2018-7873: There is a heap-based buffer overflow in the getString function of util/decompile.c in libming 0.4.8
There is a heap-based buffer overflow in the getString function of util/decompile.c in libming 0.4.8 for INTEGER data. A Crafted input will lead to a denial of service attack.
nvd
CVE-2020-13596P4MEDIUMCVSS 6.1v9.0v10.02020-06-03
CVE-2020-13596 [MEDIUM] CWE-79 CVE-2020-13596: An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated
An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin ForeignKeyRawIdWidget were not properly URL encoded, leading to a possibility of an XSS attack.
nvd
CVE-2017-13063P4MEDIUMCVSS 6.5v8.0v9.02017-08-22
CVE-2017-13063 [MEDIUM] CWE-119 CVE-2017-13063: GraphicsMagick 1.3.26 has a heap-based buffer overflow vulnerability in the function GetStyleTokens
GraphicsMagick 1.3.26 has a heap-based buffer overflow vulnerability in the function GetStyleTokens in coders/svg.c:314:12.
nvd
CVE-2015-5694P4MEDIUMCVSS 6.5v8.0v9.0+1 more2019-11-22
CVE-2015-5694 [MEDIUM] CWE-835 CVE-2015-5694: Designate does not enforce the DNS protocol limit concerning record set sizes
Designate does not enforce the DNS protocol limit concerning record set sizes
nvd
CVE-2020-12626P4MEDIUMCVSS 6.5v9.0v10.02020-05-04
CVE-2020-12626 [MEDIUM] CWE-352 CVE-2020-12626: An issue was discovered in Roundcube Webmail before 1.4.4. A CSRF attack can cause an authenticated
An issue was discovered in Roundcube Webmail before 1.4.4. A CSRF attack can cause an authenticated user to be logged out because POST was not considered.
nvd
CVE-2022-33742P4HIGHCVSS 7.1v10.0v11.02022-07-05
CVE-2022-33742 [HIGH] CVE-2022-33742: Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text
Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Linux Block and Network PV device frontends don't zero memory regions before sharing them with the backend (CVE-2022-26365, CVE-2022-33740). Additionally the granularity of the grant table doesn't
nvd
CVE-2022-26365P4HIGHCVSS 7.1v10.0v11.02022-07-05
CVE-2022-26365 [HIGH] CWE-401 CVE-2022-26365: Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text
Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Linux Block and Network PV device frontends don't zero memory regions before sharing them with the backend (CVE-2022-26365, CVE-2022-33740). Additionally the granularity of the grant table
nvd
CVE-2022-33740P4HIGHCVSS 7.1v10.0v11.02022-07-05
CVE-2022-33740 [HIGH] CVE-2022-33740: Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text
Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Linux Block and Network PV device frontends don't zero memory regions before sharing them with the backend (CVE-2022-26365, CVE-2022-33740). Additionally the granularity of the grant table doesn't
nvd
CVE-2022-33741P4HIGHCVSS 7.1v10.0v11.02022-07-05
CVE-2022-33741 [HIGH] CVE-2022-33741: Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text
Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Linux Block and Network PV device frontends don't zero memory regions before sharing them with the backend (CVE-2022-26365, CVE-2022-33740). Additionally the granularity of the grant table doesn't
nvd
CVE-2018-19107P4MEDIUMCVSS 6.5v8.0v10.02018-11-08
CVE-2018-19107 [MEDIUM] CWE-125 CVE-2018-19107: In Exiv2 0.26, Exiv2::IptcParser::decode in iptc.cpp (called from psdimage.cpp in the PSD image read
In Exiv2 0.26, Exiv2::IptcParser::decode in iptc.cpp (called from psdimage.cpp in the PSD image reader) may suffer from a denial of service (heap-based buffer over-read) caused by an integer overflow via a crafted PSD image file.
nvd
CVE-2019-13626P4MEDIUMCVSS 6.5v10.02019-07-17
CVE-2019-13626 [MEDIUM] CWE-125 CVE-2019-13626: SDL (Simple DirectMedia Layer) 2.x through 2.0.9 has a heap-based buffer over-read in Fill_IMA_ADPCM
SDL (Simple DirectMedia Layer) 2.x through 2.0.9 has a heap-based buffer over-read in Fill_IMA_ADPCM_block, caused by an integer overflow in IMA_ADPCM_decode() in audio/SDL_wave.c.
nvd
CVE-2024-26763P4HIGHCVSS 7.1v10.02024-04-03
CVE-2024-26763 [HIGH] CWE-787 CVE-2024-26763: In the Linux kernel, the following vulnerability has been resolved: dm-crypt: don't modify the data
In the Linux kernel, the following vulnerability has been resolved:
dm-crypt: don't modify the data when using authenticated encryption
It was said that authenticated encryption could produce invalid tag when
the data that is being encrypted is modified [1]. So, fix this problem by
copying the data into the clone bio first and then encrypt them insid
nvd
CVE-2020-20453P4MEDIUMCVSS 6.5v9.0v10.0+1 more2021-05-25
CVE-2020-20453 [MEDIUM] CWE-369 CVE-2020-20453: FFmpeg 4.2 is affected by a Divide By Zero issue via libavcodec/aaccoder, which allows a remote mali
FFmpeg 4.2 is affected by a Divide By Zero issue via libavcodec/aaccoder, which allows a remote malicious user to cause a Denial of Service
nvd
CVE-2019-20042P4MEDIUMCVSS 6.1v9.0v10.02019-12-27
CVE-2019-20042 [MEDIUM] CWE-79 CVE-2019-20042: In wp-includes/formatting.php in WordPress 3.7 to 5.3.0, the function wp_targeted_link_rel() can be
In wp-includes/formatting.php in WordPress 3.7 to 5.3.0, the function wp_targeted_link_rel() can be used in a particular way to result in a stored cross-site scripting (XSS) vulnerability. This has been patched in WordPress 5.3.1, along with all the previous WordPress versions from 3.7 to 5.3 via a minor release.
nvd
CVE-2024-35849P4HIGHCVSS 7.1v10.02024-05-17
CVE-2024-35849 [HIGH] CWE-908 CVE-2024-35849: In the Linux kernel, the following vulnerability has been resolved: btrfs: fix information leak in
In the Linux kernel, the following vulnerability has been resolved:
btrfs: fix information leak in btrfs_ioctl_logical_to_ino()
Syzbot reported the following information leak for in
btrfs_ioctl_logical_to_ino():
BUG: KMSAN: kernel-infoleak in instrument_copy_to_user include/linux/instrumented.h:114 [inline]
BUG: KMSAN: kernel-infoleak in _copy_to_use
nvd
CVE-2024-26664P4HIGHCVSS 7.1v10.02024-04-02
CVE-2024-26664 [HIGH] CWE-787 CVE-2024-26664: In the Linux kernel, the following vulnerability has been resolved: hwmon: (coretemp) Fix out-of-bo
In the Linux kernel, the following vulnerability has been resolved:
hwmon: (coretemp) Fix out-of-bounds memory access
Fix a bug that pdata->cpu_map[] is set before out-of-bounds check.
The problem might be triggered on systems with more than 128 cores per
package.
nvd
CVE-2020-20446P4MEDIUMCVSS 6.5v9.0v10.0+1 more2021-05-25
CVE-2020-20446 [MEDIUM] CWE-369 CVE-2020-20446: FFmpeg 4.2 is affected by a Divide By Zero issue via libavcodec/aacpsy.c, which allows a remote mali
FFmpeg 4.2 is affected by a Divide By Zero issue via libavcodec/aacpsy.c, which allows a remote malicious user to cause a Denial of Service.
nvd
CVE-2025-23157P4HIGHCVSS 7.1v11.02025-05-01
CVE-2025-23157 [HIGH] CWE-125 CVE-2025-23157: In the Linux kernel, the following vulnerability has been resolved: media: venus: hfi_parser: add c
In the Linux kernel, the following vulnerability has been resolved:
media: venus: hfi_parser: add check to avoid out of bound access
There is a possibility that init_codecs is invoked multiple times during
manipulated payload from video firmware. In such case, if codecs_count
can get incremented to value more than MAX_CODEC_NUM, there can be OOB
acce
nvd
CVE-2025-37780P4HIGHCVSS 7.1v11.02025-05-01
CVE-2025-37780 [HIGH] CWE-125 CVE-2025-37780: In the Linux kernel, the following vulnerability has been resolved: isofs: Prevent the use of too s
In the Linux kernel, the following vulnerability has been resolved:
isofs: Prevent the use of too small fid
syzbot reported a slab-out-of-bounds Read in isofs_fh_to_parent. [1]
The handle_bytes value passed in by the reproducing program is equal to 12.
In handle_to_path(), only 12 bytes of memory are allocated for the structure
file_handle->f_handle
nvd