Debian Linux vulnerabilities
9,954 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358
Vulnerabilities
Page 328 of 498
CVE-2019-5777P4MEDIUMCVSS 6.5v9.02019-02-19
CVE-2019-5777 [MEDIUM] CVE-2019-5777: Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allow
Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
nvd
CVE-2019-5775P4MEDIUMCVSS 6.5v9.02019-02-19
CVE-2019-5775 [MEDIUM] CVE-2019-5775: Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allow
Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
nvd
CVE-2019-5781P4MEDIUMCVSS 6.5v9.02019-02-19
CVE-2019-5781 [MEDIUM] CVE-2019-5781: Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allow
Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
nvd
CVE-2018-16066P4MEDIUMCVSS 6.5v9.02019-01-09
CVE-2018-16066 [MEDIUM] CWE-416 CVE-2018-16066: A use after free in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potent
A use after free in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-5805P4MEDIUMCVSS 6.5v10.02019-06-27
CVE-2019-5805 [MEDIUM] CWE-416 CVE-2019-5805: Use-after-free in PDFium in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potent
Use-after-free in PDFium in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
nvd
CVE-2018-6097P4MEDIUMCVSS 6.5v8.0v9.02019-01-09
CVE-2018-6097 [MEDIUM] CWE-19 CVE-2018-6097: Incorrect handling of asynchronous methods in Fullscreen in Google Chrome on macOS prior to 66.0.335
Incorrect handling of asynchronous methods in Fullscreen in Google Chrome on macOS prior to 66.0.3359.117 allowed a remote attacker to enter full screen without showing a warning via a crafted HTML page.
nvd
CVE-2018-6113P4MEDIUMCVSS 6.5v9.02019-01-09
CVE-2018-6113 [MEDIUM] CWE-20 CVE-2018-6113: Improper handling of pending navigation entries in Navigation in Google Chrome on iOS prior to 66.0.
Improper handling of pending navigation entries in Navigation in Google Chrome on iOS prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
nvd
CVE-2018-6049P4MEDIUMCVSS 6.5v8.0v9.02018-09-25
CVE-2018-6049 [MEDIUM] CVE-2018-6049: Incorrect security UI in permissions prompt in Google Chrome prior to 64.0.3282.119 allowed a remote
Incorrect security UI in permissions prompt in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to spoof the origin to which permission is granted via a crafted HTML page.
nvd
CVE-2018-6135P4MEDIUMCVSS 6.5v9.02019-01-09
CVE-2018-6135 [MEDIUM] CVE-2018-6135: Lack of clearing the previous site before loading alerts from a new one in Blink in Google Chrome pr
Lack of clearing the previous site before loading alerts from a new one in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
nvd
CVE-2018-6116P4MEDIUMCVSS 6.5v8.0v9.02018-12-04
CVE-2018-6116 [MEDIUM] CWE-476 CVE-2018-6116: A nullptr dereference in WebAssembly in Google Chrome prior to 66.0.3359.117 allowed a remote attack
A nullptr dereference in WebAssembly in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
nvd
CVE-2018-16067P4MEDIUMCVSS 6.5v9.02019-01-09
CVE-2018-16067 [MEDIUM] CWE-416 CVE-2018-16067: A use after free in WebAudio in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to pot
A use after free in WebAudio in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2017-5110P4MEDIUMCVSS 6.5v9.02017-10-27
CVE-2017-5110 [MEDIUM] CWE-20 CVE-2017-5110: Inappropriate implementation of the web payments API on blob: and data: schemes in Web Payments in G
Inappropriate implementation of the web payments API on blob: and data: schemes in Web Payments in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to spoof the contents of the Omnibox via a crafted HTML page.
nvd
CVE-2018-6100P4MEDIUMCVSS 6.5v8.0v9.02019-01-09
CVE-2018-6100 [MEDIUM] CWE-19 CVE-2018-6100: Incorrect handling of confusable characters in URL Formatter in Google Chrome on macOS prior to 66.0
Incorrect handling of confusable characters in URL Formatter in Google Chrome on macOS prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
nvd
CVE-2018-6104P4MEDIUMCVSS 6.5v8.0v9.02018-12-04
CVE-2018-6104 [MEDIUM] CVE-2018-6104: Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117
Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
nvd
CVE-2018-6107P4MEDIUMCVSS 6.5v8.0v9.02018-12-04
CVE-2018-6107 [MEDIUM] CVE-2018-6107: Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117
Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
nvd
CVE-2020-15169P4MEDIUMCVSS 6.1v10.02020-09-11
CVE-2020-15169 [MEDIUM] CWE-79 CVE-2020-15169: In Action View before versions 5.2.4.4 and 6.0.3.3 there is a potential Cross-Site Scripting (XSS) v
In Action View before versions 5.2.4.4 and 6.0.3.3 there is a potential Cross-Site Scripting (XSS) vulnerability in Action View's translation helpers. Views that allow the user to control the default (not found) value of the `t` and `translate` helpers could be susceptible to XSS attacks. When an HTML-unsafe string is passed as the default for a miss
nvd
CVE-2018-11805P4MEDIUMCVSS 6.7v8.0v9.0+1 more2019-12-12
CVE-2018-11805 [MEDIUM] CWE-78 CVE-2018-11805: In Apache SpamAssassin before 3.4.3, nefarious CF files can be configured to run system commands wit
In Apache SpamAssassin before 3.4.3, nefarious CF files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA 3.4.3, we recommend that users should only use update channels or 3rd party .cf files from trusted places.
nvd
CVE-2017-5105P4MEDIUMCVSS 6.5v9.02017-10-27
CVE-2017-5105 [MEDIUM] CWE-20 CVE-2017-5105: Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 60.0.3112.78 for Mac, Windows,
Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.
nvd
CVE-2017-5106P4MEDIUMCVSS 6.5v9.02017-10-27
CVE-2017-5106 [MEDIUM] CWE-20 CVE-2017-5106: Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 60.0.3112.78 for Mac, Windows,
Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.
nvd
CVE-2018-6050P4MEDIUMCVSS 6.5v8.0v9.02018-09-25
CVE-2018-6050 [MEDIUM] CWE-20 CVE-2018-6050: Incorrect security UI in Omnibox in Google Chrome prior to 64.0.3282.119 allowed a remote attacker t
Incorrect security UI in Omnibox in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd