cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 318 of 498
CVE-2019-5830P4MEDIUMCVSS 6.5v10.02019-06-27
CVE-2019-5830 [MEDIUM] CVE-2019-5830: Insufficient policy enforcement in CORS in Google Chrome prior to 75.0.3770.80 allowed a remote atta Insufficient policy enforcement in CORS in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2020-15982P4MEDIUMCVSS 6.5v10.02020-11-03
CVE-2020-15982 [MEDIUM] CVE-2020-15982: Inappropriate implementation in cache in Google Chrome prior to 86.0.4240.75 allowed a remote attack Inappropriate implementation in cache in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2016-1699P4MEDIUMCVSS 6.5v8.02016-06-05
CVE-2016-1699 [MEDIUM] CWE-284 CVE-2016-1699: WebKit/Source/devtools/front_end/devtools.js in the Developer Tools (aka DevTools) subsystem in Blin WebKit/Source/devtools/front_end/devtools.js in the Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 51.0.2704.79, does not ensure that the remoteFrontendUrl parameter is associated with a chrome-devtools-frontend.appspot.com URL, which allows remote attackers to bypass intended access restrictions via a crafted URL.
nvd
CVE-2019-13737P4MEDIUMCVSS 6.5v9.0v10.02019-12-10
CVE-2019-13737 [MEDIUM] CWE-200 CVE-2019-13737: Insufficient policy enforcement in autocomplete in Google Chrome prior to 79.0.3945.79 allowed a rem Insufficient policy enforcement in autocomplete in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2018-18350P4MEDIUMCVSS 6.5v9.02018-12-11
CVE-2018-18350 [MEDIUM] CVE-2018-18350: Incorrect handling of CSP enforcement during navigations in Blink in Google Chrome prior to 71.0.357 Incorrect handling of CSP enforcement during navigations in Blink in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to bypass content security policy via a crafted HTML page.
nvd
CVE-2019-1010065P4MEDIUMCVSS 6.5v9.02019-07-18
CVE-2019-1010065 [MEDIUM] CWE-190 CVE-2019-1010065: The Sleuth Kit 4.6.0 and earlier is affected by: Integer Overflow. The impact is: Opening crafted di The Sleuth Kit 4.6.0 and earlier is affected by: Integer Overflow. The impact is: Opening crafted disk image triggers crash in tsk/fs/hfs_dent.c:237. The component is: Overflow in fls tool used on HFS image. Bug is in tsk/fs/hfs.c file in function hfs_cat_traverse() in lines: 952, 1062. The attack vector is: Victim must open a crafted HFS filesy
nvd
CVE-2019-13746P4MEDIUMCVSS 6.5v9.0v10.02019-12-10
CVE-2019-13746 [MEDIUM] CVE-2019-13746: Insufficient policy enforcement in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote a Insufficient policy enforcement in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2019-2762P4MEDIUMCVSS 5.3v8.02019-07-23
CVE-2019-2762 [MEDIUM] CVE-2019-2762: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Utilities) Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Utilities). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Su
nvd
CVE-2019-2769P4MEDIUMCVSS 5.3v8.02019-07-23
CVE-2019-2769 [MEDIUM] CVE-2019-2769: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Utilities) Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Utilities). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Su
nvd
CVE-2018-6169P4MEDIUMCVSS 6.5v9.02019-01-09
CVE-2018-6169 [MEDIUM] CWE-20 CVE-2018-6169: Lack of timeout on extension install prompt in Extensions in Google Chrome prior to 68.0.3440.75 all Lack of timeout on extension install prompt in Extensions in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to trigger installation of an unwanted extension via a crafted HTML page.
nvd
CVE-2020-6482P4MEDIUMCVSS 6.5v9.0v10.02020-05-21
CVE-2020-6482 [MEDIUM] CWE-276 CVE-2020-6482: Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.
nvd
CVE-2020-15986P4MEDIUMCVSS 6.5v10.02020-11-03
CVE-2020-15986 [MEDIUM] CWE-190 CVE-2020-15986: Integer overflow in media in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potent Integer overflow in media in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2017-15391P4MEDIUMCVSS 6.5v8.0v9.02018-02-07
CVE-2017-15391 [MEDIUM] CVE-2017-15391: Insufficient Policy Enforcement in Extensions in Google Chrome prior to 62.0.3202.62 allowed a remot Insufficient Policy Enforcement in Extensions in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to access Extension pages without authorisation via a crafted HTML page.
nvd
CVE-2023-1667P4MEDIUMCVSS 6.5v10.02023-05-26
CVE-2023-1667 [MEDIUM] CWE-476 CVE-2023-1667: A NULL pointer dereference was found In libssh during re-keying with algorithm guessing. This issue A NULL pointer dereference was found In libssh during re-keying with algorithm guessing. This issue may allow an authenticated client to cause a denial of service.
nvd
CVE-2019-13738P4MEDIUMCVSS 6.5v9.0v10.02019-12-10
CVE-2019-13738 [MEDIUM] CWE-269 CVE-2019-13738: Insufficient policy enforcement in navigation in Google Chrome prior to 79.0.3945.79 allowed a remot Insufficient policy enforcement in navigation in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass site isolation via a crafted HTML page.
nvd
CVE-2017-15419P4MEDIUMCVSS 6.5v9.02018-08-28
CVE-2017-15419 [MEDIUM] CWE-601 CVE-2017-15419: Insufficient policy enforcement in Resource Timing API in Google Chrome prior to 63.0.3239.84 allowe Insufficient policy enforcement in Resource Timing API in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to infer browsing history by triggering a leaked cross-origin URL via a crafted HTML page.
nvd
CVE-2015-0410P4MEDIUMCVSS 5.0v7.0v8.02015-01-21
CVE-2015-0410 [MEDIUM] CVE-2015-0410: Unspecified vulnerability in the Java SE, Java SE Embedded, JRockit component in Oracle Java SE 5.0u Unspecified vulnerability in the Java SE, Java SE Embedded, JRockit component in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit R27.8.4 and R28.3.4 allows remote attackers to affect availability via unknown vectors related to Security.
nvd
CVE-2019-13743P4MEDIUMCVSS 6.5v9.0v10.02019-12-10
CVE-2019-13743 [MEDIUM] CVE-2019-13743: Incorrect security UI in external protocol handling in Google Chrome prior to 79.0.3945.79 allowed a Incorrect security UI in external protocol handling in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to spoof security UI via a crafted HTML page.
nvd
CVE-2006-1531P4HIGHCVSS 7.5v3.12006-04-14
CVE-2006-1531 [HIGH] CVE-2006-1531: Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonkey before 1.0.1, all Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonkey before 1.0.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown attack vectors related to DHTML. NOTE: due to the lack of sufficient public details from the vendor as of 20060413, it is unclear how CVE-2006-1529, CVE-2006
nvd
CVE-2006-1530P4HIGHCVSS 7.5v3.12006-04-14
CVE-2006-1530 [HIGH] CVE-2006-1530: Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonkey before 1.0.1, all Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonkey before 1.0.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown attack vectors related to DHTML. NOTE: due to the lack of sufficient public details from the vendor as of 20060413, it is unclear how CVE-2006-1529, CVE-2006
nvd
Debian Linux vulnerabilities | cvebase