Debian Linux vulnerabilities
9,954 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358
Vulnerabilities
Page 316 of 498
CVE-2020-6408P4MEDIUMCVSS 6.5v9.0v10.02020-02-11
CVE-2020-6408 [MEDIUM] CVE-2020-6408: Insufficient policy enforcement in CORS in Google Chrome prior to 80.0.3987.87 allowed a local attac
Insufficient policy enforcement in CORS in Google Chrome prior to 80.0.3987.87 allowed a local attacker to obtain potentially sensitive information via a crafted HTML page.
nvd
CVE-2017-14136P4MEDIUMCVSS 6.5v8.02017-09-04
CVE-2017-14136 [MEDIUM] CVE-2017-14136: OpenCV (Open Source Computer Vision Library) 3.3 has an out-of-bounds write error in the function Fi
OpenCV (Open Source Computer Vision Library) 3.3 has an out-of-bounds write error in the function FillColorRow1 in utils.cpp when reading an image file by using cv::imread. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-12597.
nvd
CVE-2014-5255P4HIGHCVSS 7.0v8.0v9.0+1 more2019-11-21
CVE-2014-5255 [HIGH] CVE-2014-5255: xcfa before 5.0.1 creates temporary files insecurely which could allow local users to launch a symli
xcfa before 5.0.1 creates temporary files insecurely which could allow local users to launch a symlink attack and overwrite arbitrary files. Note: A different vulnerability than CVE-2014-5254.
nvd
CVE-2019-11486P4HIGHCVSS 7.0v9.02019-04-23
CVE-2019-11486 [HIGH] CWE-362 CVE-2019-11486: The Siemens R3964 line discipline driver in drivers/tty/n_r3964.c in the Linux kernel before 5.0.8 h
The Siemens R3964 line discipline driver in drivers/tty/n_r3964.c in the Linux kernel before 5.0.8 has multiple race conditions.
nvd
CVE-2019-5818P4MEDIUMCVSS 6.5v10.02019-06-27
CVE-2019-5818 [MEDIUM] CWE-908 CVE-2019-5818: Uninitialized data in media in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obt
Uninitialized data in media in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted video file.
nvd
CVE-2018-12385P4HIGHCVSS 7.0v8.0v9.02018-10-18
CVE-2018-12385 [HIGH] CWE-20 CVE-2018-12385: A potentially exploitable crash in TransportSecurityInfo used for SSL can be triggered by data store
A potentially exploitable crash in TransportSecurityInfo used for SSL can be triggered by data stored in the local cache in the user profile directory. This issue is only exploitable in combination with another vulnerability allowing an attacker to write data into the local cache or from locally installed malware. This issue also triggers a non-exploit
nvd
CVE-2018-6143P4MEDIUMCVSS 6.5v9.02019-01-09
CVE-2018-6143 [MEDIUM] CWE-125 CVE-2018-6143: Insufficient validation in V8 in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to pe
Insufficient validation in V8 in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
nvd
CVE-2018-6089P4MEDIUMCVSS 6.5v8.0v9.02018-12-04
CVE-2018-6089 [MEDIUM] CWE-20 CVE-2018-6089: A lack of CORS checks, after a Service Worker redirected to a cross-origin PDF, in Service Worker in
A lack of CORS checks, after a Service Worker redirected to a cross-origin PDF, in Service Worker in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak limited cross-origin data via a crafted HTML page.
nvd
CVE-2021-40490P4HIGHCVSS 7.0v9.0v11.02021-09-03
CVE-2021-40490 [HIGH] CWE-362 CVE-2021-40490: A race condition was discovered in ext4_write_inline_data_end in fs/ext4/inline.c in the ext4 subsys
A race condition was discovered in ext4_write_inline_data_end in fs/ext4/inline.c in the ext4 subsystem in the Linux kernel through 5.13.13.
nvd
CVE-2020-6564P4MEDIUMCVSS 6.5v10.02020-09-21
CVE-2020-6564 [MEDIUM] CWE-281 CVE-2020-6564: Inappropriate implementation in permissions in Google Chrome prior to 85.0.4183.83 allowed a remote
Inappropriate implementation in permissions in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to spoof the contents of a permission dialog via a crafted HTML page.
nvd
CVE-2020-21597P4MEDIUMCVSS 6.5v10.0v11.02021-09-16
CVE-2020-21597 [MEDIUM] CWE-787 CVE-2020-21597: libde265 v1.0.4 contains a heap buffer overflow in the mc_chroma function, which can be exploited vi
libde265 v1.0.4 contains a heap buffer overflow in the mc_chroma function, which can be exploited via a crafted a file.
nvd
CVE-2019-5837P4MEDIUMCVSS 6.5v10.02019-06-27
CVE-2019-5837 [MEDIUM] CVE-2019-5837: Resource size information leakage in Blink in Google Chrome prior to 75.0.3770.80 allowed a remote a
Resource size information leakage in Blink in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2018-6077P4MEDIUMCVSS 6.5v9.02018-11-14
CVE-2018-6077 [MEDIUM] CWE-200 CVE-2018-6077: Displacement map filters being applied to cross-origin images in Blink SVG rendering in Google Chrom
Displacement map filters being applied to cross-origin images in Blink SVG rendering in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2020-6557P4MEDIUMCVSS 6.5v10.02020-11-03
CVE-2020-6557 [MEDIUM] CVE-2020-6557: Inappropriate implementation in networking in Google Chrome prior to 86.0.4240.75 allowed a remote a
Inappropriate implementation in networking in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
nvd
CVE-2019-17342P4HIGHCVSS 7.0v9.0v10.02019-10-08
CVE-2019-17342 [HIGH] CWE-362 CVE-2019-17342: An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of se
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges by leveraging a race condition that arose when XENMEM_exchange was introduced.
nvd
CVE-2024-26654P4HIGHCVSS 7.0v10.02024-04-01
CVE-2024-26654 [HIGH] CWE-416 CVE-2024-26654: In the Linux kernel, the following vulnerability has been resolved: ALSA: sh: aica: reorder cleanup
In the Linux kernel, the following vulnerability has been resolved:
ALSA: sh: aica: reorder cleanup operations to avoid UAF bugs
The dreamcastcard->timer could schedule the spu_dma_work and the
spu_dma_work could also arm the dreamcastcard->timer.
When the snd_pcm_substream is closing, the aica_channel will be
deallocated. But it could still be dere
nvd
CVE-2020-6568P4MEDIUMCVSS 6.5v10.02020-09-21
CVE-2020-6568 [MEDIUM] CVE-2020-6568: Insufficient policy enforcement in intent handling in Google Chrome on Android prior to 85.0.4183.83
Insufficient policy enforcement in intent handling in Google Chrome on Android prior to 85.0.4183.83 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2020-6562P4MEDIUMCVSS 6.5v10.02020-09-21
CVE-2020-6562 [MEDIUM] CWE-79 CVE-2020-6562: Insufficient policy enforcement in Blink in Google Chrome prior to 85.0.4183.83 allowed a remote att
Insufficient policy enforcement in Blink in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2018-6103P4MEDIUMCVSS 6.5v8.0v9.02018-12-04
CVE-2018-6103 [MEDIUM] CVE-2018-6103: A stagnant permission prompt in Prompts in Google Chrome prior to 66.0.3359.117 allowed a remote att
A stagnant permission prompt in Prompts in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to bypass permission policy via a crafted HTML page.
nvd
CVE-2020-6565P4MEDIUMCVSS 6.5v10.02020-09-21
CVE-2020-6565 [MEDIUM] CVE-2020-6565: Inappropriate implementation in Omnibox in Google Chrome on iOS prior to 85.0.4183.83 allowed a remo
Inappropriate implementation in Omnibox in Google Chrome on iOS prior to 85.0.4183.83 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd