cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 329 of 498
CVE-2018-18346P4MEDIUMCVSS 6.5v9.02018-12-11
CVE-2018-18346 [MEDIUM] CVE-2018-18346: Incorrect handling of alert box display in Blink in Google Chrome prior to 71.0.3578.80 allowed a re Incorrect handling of alert box display in Blink in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to present confusing browser UI via a crafted HTML page.
nvd
CVE-2017-15389P4MEDIUMCVSS 6.5v8.0v9.02018-02-07
CVE-2017-15389 [MEDIUM] CWE-20 CVE-2017-15389: An insufficient watchdog timer in navigation in Google Chrome prior to 62.0.3202.62 allowed a remote An insufficient watchdog timer in navigation in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2014-8150P4MEDIUMCVSS 4.3v7.02015-01-15
CVE-2014-8150 [MEDIUM] CVE-2014-8150: CRLF injection vulnerability in libcurl 6.0 through 7.x before 7.40.0, when using an HTTP proxy, all CRLF injection vulnerability in libcurl 6.0 through 7.x before 7.40.0, when using an HTTP proxy, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in a URL.
nvd
CVE-2020-12137P4MEDIUMCVSS 6.1v9.0v10.0+1 more2020-04-24
CVE-2020-12137 [MEDIUM] CWE-79 CVE-2020-12137: GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME par GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may contribute to XSS attacks against list-archive visitors, because an HTTP reply from an archive web server may lack a MIME type, and a web browser may perform MIME sniffing, conclude that the MIME type should have been text/html, a
nvd
CVE-2018-6105P4MEDIUMCVSS 6.5v8.0v9.02018-12-04
CVE-2018-6105 [MEDIUM] CVE-2018-6105: Incorrect handling of confusable characters in Omnibox in Google Chrome prior to 66.0.3359.117 allow Incorrect handling of confusable characters in Omnibox in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
nvd
CVE-2018-20340P4MEDIUMCVSS 6.8v9.02019-03-21
CVE-2018-20340 [MEDIUM] CWE-119 CVE-2018-20340: Yubico libu2f-host 1.1.6 contains unchecked buffers in devs.c, which could enable a malicious token Yubico libu2f-host 1.1.6 contains unchecked buffers in devs.c, which could enable a malicious token to exploit a buffer overflow. An attacker could use this to attempt to execute malicious code using a crafted USB device masquerading as a security token on a computer where the affected library is currently in use. It is not possible to perform this a
nvd
CVE-2017-15390P4MEDIUMCVSS 6.5v8.0v9.02018-02-07
CVE-2017-15390 [MEDIUM] CWE-20 CVE-2017-15390: Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 62.0.3202.62 allowed a remote a Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.
nvd
CVE-2018-19970P4MEDIUMCVSS 6.1v8.02018-12-11
CVE-2018-19970 [MEDIUM] CWE-79 CVE-2018-19970: In phpMyAdmin before 4.8.4, an XSS vulnerability was found in the navigation tree, where an attacker In phpMyAdmin before 4.8.4, an XSS vulnerability was found in the navigation tree, where an attacker can deliver a payload to a user through a crafted database/table name.
nvd
CVE-2020-6480P4MEDIUMCVSS 6.5v9.0v10.02020-05-21
CVE-2020-6480 [MEDIUM] CWE-276 CVE-2020-6480: Insufficient policy enforcement in enterprise in Google Chrome prior to 83.0.4103.61 allowed a local Insufficient policy enforcement in enterprise in Google Chrome prior to 83.0.4103.61 allowed a local attacker to bypass navigation restrictions via UI actions.
nvd
CVE-2021-26676P4MEDIUMCVSS 6.5v9.0v10.02021-02-09
CVE-2021-26676 [MEDIUM] CVE-2021-26676: gdhcp in ConnMan before 1.39 could be used by network-adjacent attackers to leak sensitive stack inf gdhcp in ConnMan before 1.39 could be used by network-adjacent attackers to leak sensitive stack information, allowing further exploitation of bugs in gdhcp.
nvd
CVE-2017-15424P4MEDIUMCVSS 6.5v9.02018-08-28
CVE-2017-15424 [MEDIUM] CWE-20 CVE-2017-15424: Insufficient policy enforcement in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a remote a Insufficient policy enforcement in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.
nvd
CVE-2021-0308P4MEDIUMCVSS 6.8v9.02021-01-11
CVE-2021-0308 [MEDIUM] CWE-787 CVE-2021-0308: In ReadLogicalParts of basicmbr.cc, there is a possible out of bounds write due to a missing bounds In ReadLogicalParts of basicmbr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-8.1, Android-9, Android-10, Android-11, Android-8.0; Android ID:
nvd
CVE-2015-7295P4MEDIUMCVSS 5.0v7.0v8.02015-11-09
CVE-2015-7295 [MEDIUM] CWE-119 CVE-2015-7295: hw/virtio/virtio.c in the Virtual Network Device (virtio-net) support in QEMU, when big or mergeable hw/virtio/virtio.c in the Virtual Network Device (virtio-net) support in QEMU, when big or mergeable receive buffers are not supported, allows remote attackers to cause a denial of service (guest network consumption) via a flood of jumbo frames on the (1) tuntap or (2) macvtap interface.
nvd
CVE-2017-15426P4MEDIUMCVSS 6.5v9.02018-08-28
CVE-2017-15426 [MEDIUM] CWE-20 CVE-2017-15426: Insufficient policy enforcement in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a remote a Insufficient policy enforcement in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.
nvd
CVE-2017-15425P4MEDIUMCVSS 6.5v9.02018-08-28
CVE-2017-15425 [MEDIUM] CWE-20 CVE-2017-15425: Insufficient policy enforcement in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a remote a Insufficient policy enforcement in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.
nvd
CVE-2016-7179P4MEDIUMCVSS 5.9v8.02016-09-09
CVE-2016-7179 [MEDIUM] CWE-119 CVE-2016-7179: Stack-based buffer overflow in epan/dissectors/packet-catapult-dct2000.c in the Catapult DCT2000 dis Stack-based buffer overflow in epan/dissectors/packet-catapult-dct2000.c in the Catapult DCT2000 dissector in Wireshark 2.x before 2.0.6 allows remote attackers to cause a denial of service (application crash) via a crafted packet.
nvd
CVE-2020-11029P4MEDIUMCVSS 6.1v8.0v9.0+1 more2020-04-30
CVE-2020-11029 [MEDIUM] CWE-79 CVE-2020-11029: In affected versions of WordPress, a vulnerability in the stats() method of class-wp-object-cache.ph In affected versions of WordPress, a vulnerability in the stats() method of class-wp-object-cache.php can be exploited to execute cross-site scripting (XSS) attacks. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4
nvd
CVE-2020-7106P4MEDIUMCVSS 6.1v8.0v9.02020-01-16
CVE-2020-7106 [MEDIUM] CWE-79 CVE-2020-7106: Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.ph Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automation.php, user_admin.php, and user_group_admin.php, as demonstrated by the description parameter in data_sources.php (a raw string from the database that is displayed by $header to trigger the XSS).
nvd
CVE-2017-5120P4MEDIUMCVSS 6.5v9.0v10.02017-10-27
CVE-2017-5120 [MEDIUM] CVE-2017-5120: Inappropriate use of www mismatch redirects in browser navigation in Google Chrome prior to 61.0.316 Inappropriate use of www mismatch redirects in browser navigation in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.3163.81 for Android, allowed a remote attacker to potentially downgrade HTTPS requests to HTTP via a crafted HTML page. In other words, Chrome could transmit cleartext even though the user had entered an https URL, bec
nvd
CVE-2023-2952P4MEDIUMCVSS 6.5v10.0v12.02023-05-30
CVE-2023-2952 [MEDIUM] CWE-835 CVE-2023-2952: XRA dissector infinite loop in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service XRA dissector infinite loop in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via packet injection or crafted capture file
nvd
Debian Linux vulnerabilities | cvebase