Debian Linux vulnerabilities
9,954 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358
Vulnerabilities
Page 319 of 498
CVE-2012-6123P4MEDIUMCVSS 6.5v8.0v9.0+1 more2019-10-31
CVE-2012-6123 [MEDIUM] CWE-20 CVE-2012-6123: Chicken before 4.8.0 does not properly handle NUL bytes in certain strings, which allows an attacker
Chicken before 4.8.0 does not properly handle NUL bytes in certain strings, which allows an attacker to conduct "poisoned NUL byte attack."
nvd
CVE-2019-5832P4MEDIUMCVSS 6.5v10.02019-06-27
CVE-2019-5832 [MEDIUM] CVE-2019-5832: Insufficient policy enforcement in XMLHttpRequest in Google Chrome prior to 75.0.3770.80 allowed a r
Insufficient policy enforcement in XMLHttpRequest in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2019-5768P4MEDIUMCVSS 6.5v9.02019-02-19
CVE-2019-5768 [MEDIUM] CWE-269 CVE-2019-5768: DevTools API not correctly gating on extension capability in DevTools in Google Chrome prior to 72.0
DevTools API not correctly gating on extension capability in DevTools in Google Chrome prior to 72.0.3626.81 allowed an attacker who convinced a user to install a malicious extension to read local files via a crafted Chrome Extension.
nvd
CVE-2021-21175P4MEDIUMCVSS 6.5v10.02021-03-09
CVE-2021-21175 [MEDIUM] CWE-346 CVE-2021-21175: Inappropriate implementation in Site isolation in Google Chrome prior to 89.0.4389.72 allowed a remo
Inappropriate implementation in Site isolation in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2022-26691P4MEDIUMCVSS 6.7v9.0v10.0+1 more2022-05-26
CVE-2022-26691 [MEDIUM] CWE-697 CVE-2022-26691: A logic issue was addressed with improved state management. This issue is fixed in Security Update 2
A logic issue was addressed with improved state management. This issue is fixed in Security Update 2022-003 Catalina, macOS Monterey 12.3, macOS Big Sur 11.6.5. An application may be able to gain elevated privileges.
nvd
CVE-2024-24857P4MEDIUMCVSS 6.8v10.02024-02-05
CVE-2024-24857 [MEDIUM] CWE-362 CVE-2024-24857: A race condition was found in the Linux kernel's net/bluetooth device driver in conn_info_{min,max}_
A race condition was found in the Linux kernel's net/bluetooth device driver in conn_info_{min,max}_age_set() function. This can result in integrity overflow issue, possibly leading to bluetooth connection abnormality or denial of service.
nvd
CVE-2016-1698P4MEDIUMCVSS 6.5v8.02016-06-05
CVE-2016-1698 [MEDIUM] CWE-200 CVE-2016-1698: The createCustomType function in extensions/renderer/resources/binding.js in the extension bindings
The createCustomType function in extensions/renderer/resources/binding.js in the extension bindings in Google Chrome before 51.0.2704.79 does not validate module types, which might allow attackers to load arbitrary modules or obtain sensitive information by leveraging a poisoned definition.
nvd
CVE-2020-15973P4MEDIUMCVSS 6.5v10.02020-11-03
CVE-2020-15973 [MEDIUM] CVE-2020-15973: Insufficient policy enforcement in extensions in Google Chrome prior to 86.0.4240.75 allowed an atta
Insufficient policy enforcement in extensions in Google Chrome prior to 86.0.4240.75 allowed an attacker who convinced a user to install a malicious extension to bypass same origin policy via a crafted Chrome Extension.
nvd
CVE-2023-5171P4MEDIUMCVSS 6.5v10.0v11.0+1 more2023-09-27
CVE-2023-5171 [MEDIUM] CWE-416 CVE-2023-5171: During Ion compilation, a Garbage Collection could have resulted in a use-after-free condition, allo
During Ion compilation, a Garbage Collection could have resulted in a use-after-free condition, allowing an attacker to write two NUL bytes, and cause a potentially exploitable crash. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.
nvd
CVE-2019-5778P4MEDIUMCVSS 6.5v9.02019-02-19
CVE-2019-5778 [MEDIUM] CWE-79 CVE-2019-5778: A missing case for handling special schemes in permission request checks in Extensions in Google Chr
A missing case for handling special schemes in permission request checks in Extensions in Google Chrome prior to 72.0.3626.81 allowed an attacker who convinced a user to install a malicious extension to bypass extension permission checks for privileged pages via a crafted Chrome Extension.
nvd
CVE-2023-29469P4MEDIUMCVSS 6.5v10.02023-04-24
CVE-2023-29469 [MEDIUM] CWE-415 CVE-2023-29469: An issue was discovered in libxml2 before 2.10.4. When hashing empty dict strings in a crafted XML d
An issue was discovered in libxml2 before 2.10.4. When hashing empty dict strings in a crafted XML document, xmlDictComputeFastKey in dict.c can produce non-deterministic values, leading to various logic and memory errors, such as a double free. This behavior occurs because there is an attempt to use the first byte of an empty string, and any value
nvd
CVE-2021-21209P4MEDIUMCVSS 6.5v10.02021-04-26
CVE-2021-21209 [MEDIUM] CWE-346 CVE-2021-21209: Inappropriate implementation in storage in Google Chrome prior to 90.0.4430.72 allowed a remote atta
Inappropriate implementation in storage in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2021-31229P4MEDIUMCVSS 6.5v9.02021-04-15
CVE-2021-31229 [MEDIUM] CWE-787 CVE-2021-31229: An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_internal_dtd() performs inc
An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_internal_dtd() performs incorrect memory handling while parsing crafted XML files, which leads to an out-of-bounds write of a one byte constant.
nvd
CVE-2022-24301P4MEDIUMCVSS 6.5v10.0v11.02022-02-02
CVE-2022-24301 [MEDIUM] CWE-276 CVE-2022-24301: In Minetest before 5.4.0, players can add or subtract items from a different player's inventory.
In Minetest before 5.4.0, players can add or subtract items from a different player's inventory.
nvd
CVE-2018-18349P4MEDIUMCVSS 6.5v9.02018-12-11
CVE-2018-18349 [MEDIUM] CWE-732 CVE-2018-18349: Remote frame navigations was incorrectly permitted to local resources in Blink in Google Chrome prio
Remote frame navigations was incorrectly permitted to local resources in Blink in Google Chrome prior to 71.0.3578.80 allowed an attacker who convinced a user to install a malicious extension to access files on the local file system via a crafted Chrome Extension.
nvd
CVE-2023-2459P4MEDIUMCVSS 6.5v11.02023-05-03
CVE-2023-2459 [MEDIUM] CVE-2023-2459: Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 allowed a remote att
Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to bypass permission restrictions via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2021-21163P4MEDIUMCVSS 6.5v10.02021-03-09
CVE-2021-21163 [MEDIUM] CWE-346 CVE-2021-21163: Insufficient data validation in Reader Mode in Google Chrome on iOS prior to 89.0.4389.72 allowed a
Insufficient data validation in Reader Mode in Google Chrome on iOS prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page and a malicious server.
nvd
CVE-2016-0739P4MEDIUMCVSS 5.9v7.0v8.02016-04-13
CVE-2016-0739 [MEDIUM] CWE-200 CVE-2016-0739: libssh before 0.7.3 improperly truncates ephemeral secrets generated for the (1) diffie-hellman-grou
libssh before 0.7.3 improperly truncates ephemeral secrets generated for the (1) diffie-hellman-group1 and (2) diffie-hellman-group14 key exchange methods to 128 bits, which makes it easier for man-in-the-middle attackers to decrypt or intercept SSH sessions via unspecified vectors, aka a "bits/bytes confusion bug."
nvd
CVE-2022-30787P4MEDIUMCVSS 6.7v9.0v10.0+1 more2022-05-26
CVE-2022-30787 [MEDIUM] CWE-191 CVE-2022-30787: An integer underflow in fuse_lib_readdir enables arbitrary memory read operations in NTFS-3G through
An integer underflow in fuse_lib_readdir enables arbitrary memory read operations in NTFS-3G through 2021.8.22 when using libfuse-lite.
nvd
CVE-2017-4967P4MEDIUMCVSS 6.1v9.02017-06-13
CVE-2017-4967 [MEDIUM] CWE-79 CVE-2017-4967: An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions,
An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these RabbitMQ for PCF versions: all 1.5.x versions, 1.6.x versions prior to 1.6.18, and 1.7.x versions prior to 1.7.15. Several forms in the RabbitMQ management UI are vulnerable to XSS attacks.
nvd