cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 321 of 498
CVE-2017-10053P4MEDIUMCVSS 5.3v9.0v10.02017-08-08
CVE-2017-10053 [MEDIUM] CVE-2017-10053: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: 2 Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131; JRockit: R28.3.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java S
nvd
CVE-2004-1145P4MEDIUMCVSS 5.0v3.02004-12-15
CVE-2004-1145 [MEDIUM] CVE-2004-1145: Multiple vulnerabilities in Konqueror in KDE 3.3.1 and earlier (1) allow access to restricted Java c Multiple vulnerabilities in Konqueror in KDE 3.3.1 and earlier (1) allow access to restricted Java classes via JavaScript and (2) do not properly restrict access to certain Java classes from the Java applet, which allows remote attackers to bypass sandbox restrictions and read or write arbitrary files.
nvd
CVE-2022-21349P4MEDIUMCVSS 5.3v9.02022-01-19
CVE-2022-21349 [MEDIUM] CVE-2022-21349: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (co Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 7u321, 8u311; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromis
nvd
CVE-2018-1108P4MEDIUMCVSS 5.9v9.02018-05-21
CVE-2018-1108 [MEDIUM] CWE-330 CVE-2018-1108: kernel drivers before version 4.17-rc1 are vulnerable to a weakness in the Linux kernel's implementa kernel drivers before version 4.17-rc1 are vulnerable to a weakness in the Linux kernel's implementation of random seed data. Programs, early in the boot sequence, could use the data allocated for the seed before it was sufficiently generated.
nvd
CVE-2021-30890P4MEDIUMCVSS 6.1v10.0v11.02021-08-24
CVE-2021-30890 [MEDIUM] CWE-79 CVE-2021-30890: A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12 A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.0.1, iOS 15.1 and iPadOS 15.1, watchOS 8.1, tvOS 15.1. Processing maliciously crafted web content may lead to universal cross site scripting.
nvd
CVE-2016-2372P4MEDIUMCVSS 5.9v8.02017-01-06
CVE-2016-2372 [MEDIUM] CWE-125 CVE-2016-2372: An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT da An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in an out-of-bounds read. A malicious user, server, or man-in-the-middle attacker can send an invalid size for a file transfer which will trigger an out-of-bounds read vulnerability. This could result in a
nvd
CVE-2020-11042P4MEDIUMCVSS 5.9v9.0v10.02020-05-07
CVE-2020-11042 [MEDIUM] CWE-125 CVE-2020-11042: In FreeRDP greater than 1.1 and before 2.0.0, there is an out-of-bounds read in update_read_icon_inf In FreeRDP greater than 1.1 and before 2.0.0, there is an out-of-bounds read in update_read_icon_info. It allows reading a attacker-defined amount of client memory (32bit unsigned -> 4GB) to an intermediate buffer. This can be used to crash the client or store information for later retrieval. This has been patched in 2.0.0.
nvd
CVE-1999-0832P4CRITICALCVSS 10.0v2.11999-11-09
CVE-1999-0832 [CRITICAL] CVE-1999-0832: Buffer overflow in NFS server on Linux allows attackers to execute commands via a long pathname. Buffer overflow in NFS server on Linux allows attackers to execute commands via a long pathname.
nvd
CVE-2020-13765P4MEDIUMCVSS 5.6v8.0v9.02020-06-04
CVE-2020-13765 [MEDIUM] CWE-787 CVE-2020-13765: rom_copy() in hw/core/loader.c in QEMU 4.0 and 4.1.0 does not validate the relationship between two rom_copy() in hw/core/loader.c in QEMU 4.0 and 4.1.0 does not validate the relationship between two addresses, which allows attackers to trigger an invalid memory copy operation.
nvd
CVE-2017-10347P4MEDIUMCVSS 5.3v7.0v8.0+1 more2017-10-19
CVE-2017-10347 [MEDIUM] CVE-2017-10347: Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: Serialization). Sup Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, JRockit. Successful attacks o
nvd
CVE-2020-15257P4MEDIUMCVSS 5.2v10.02020-12-01
CVE-2020-15257 [MEDIUM] CWE-669 CVE-2020-15257: containerd is an industry-standard container runtime and is available as a daemon for Linux and Wind containerd is an industry-standard container runtime and is available as a daemon for Linux and Windows. In containerd before versions 1.3.9 and 1.4.3, the containerd-shim API is improperly exposed to host network containers. Access controls for the shim’s API socket verified that the connecting process had an effective UID of 0, but did not otherwi
nvd
CVE-2019-3902P4MEDIUMCVSS 5.9v8.02019-04-22
CVE-2019-3902 [MEDIUM] CWE-22 CVE-2019-3902: A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to def A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path-checking logic and write files outside a repository.
nvd
CVE-2023-38633P4MEDIUMCVSS 5.5v11.0v12.02023-07-22
CVE-2023-38633 [MEDIUM] CWE-22 CVE-2023-38633: A directory traversal problem in the URL decoder of librsvg before 2.56.3 could be used by local or A directory traversal problem in the URL decoder of librsvg before 2.56.3 could be used by local or remote attackers to disclose files (on the local filesystem outside of the expected area), as demonstrated by href=".?../../../../../../../../../../etc/passwd" in an xi:include element.
nvd
CVE-2020-25653P4MEDIUMCVSS 6.3v9.02020-11-26
CVE-2020-25653 [MEDIUM] CWE-362 CVE-2020-25653: A race condition vulnerability was found in the way the spice-vdagentd daemon handled new client con A race condition vulnerability was found in the way the spice-vdagentd daemon handled new client connections. This flaw may allow an unprivileged local guest user to become the active agent for spice-vdagentd, possibly resulting in a denial of service or information leakage from the host. The highest threat from this vulnerability is to data confide
nvd
CVE-2023-5981P4MEDIUMCVSS 5.9v10.02023-11-28
CVE-2023-5981 [MEDIUM] CWE-208 CVE-2023-5981: A vulnerability was found that the response times to malformed ciphertexts in RSA-PSK ClientKeyExcha A vulnerability was found that the response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from response times of ciphertexts with correct PKCS#1 v1.5 padding.
nvd
CVE-2023-1855P4MEDIUMCVSS 6.3v10.02023-04-05
CVE-2023-1855 [MEDIUM] CWE-416 CVE-2023-1855: A use-after-free flaw was found in xgene_hwmon_remove in drivers/hwmon/xgene-hwmon.c in the Hardware A use-after-free flaw was found in xgene_hwmon_remove in drivers/hwmon/xgene-hwmon.c in the Hardware Monitoring Linux Kernel Driver (xgene-hwmon). This flaw could allow a local attacker to crash the system due to a race problem. This vulnerability could even lead to a kernel information leak problem.
nvd
CVE-2024-33600P4MEDIUMCVSS 5.9v10.02024-05-06
CVE-2024-33600 [MEDIUM] CWE-476 CVE-2024-33600: nscd: Null pointer crashes after notfound response If the Name Service Cache Daemon's (nscd) cache nscd: Null pointer crashes after notfound response If the Name Service Cache Daemon's (nscd) cache fails to add a not-found netgroup response to the cache, the client request can result in a null pointer dereference. This flaw was introduced in glibc 2.15 when the cache was added to nscd. This vulnerability is only present in the nscd binary.
nvd
CVE-2023-28755P4MEDIUMCVSS 5.3v10.02023-03-31
CVE-2023-28755 [MEDIUM] CWE-1333 CVE-2023-28755: A ReDoS issue was discovered in the URI component through 0.12.0 in Ruby through 3.2.1. The URI pars A ReDoS issue was discovered in the URI component through 0.12.0 in Ruby through 3.2.1. The URI parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to URI objects. The fixed versions are 0.12.1, 0.11.1, 0.10.2 and 0.10.0.1.
nvd
CVE-2019-18282P4MEDIUMCVSS 5.3v8.02020-01-16
CVE-2019-18282 [MEDIUM] CWE-330 CVE-2019-18282: The flow_dissector feature in the Linux kernel 4.3 through 5.x before 5.3.10 has a device tracking v The flow_dissector feature in the Linux kernel 4.3 through 5.x before 5.3.10 has a device tracking vulnerability, aka CID-55667441c84f. This occurs because the auto flowlabel of a UDP IPv6 packet relies on a 32-bit hashrnd value as a secret, and because jhash (instead of siphash) is used. The hashrnd value remains the same starting from boot time, a
nvd
CVE-2018-16876P4MEDIUMCVSS 5.3v9.02019-01-03
CVE-2018-16876 [MEDIUM] CWE-200 CVE-2018-16876: ansible before versions 2.5.14, 2.6.11, 2.7.5 is vulnerable to a information disclosure flaw in vvv+ ansible before versions 2.5.14, 2.6.11, 2.7.5 is vulnerable to a information disclosure flaw in vvv+ mode with no_log on that can lead to leakage of sensible data.
nvd
Debian Linux vulnerabilities | cvebase