Debian Linux vulnerabilities
9,954 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358
Vulnerabilities
Page 330 of 498
CVE-2021-31348P4MEDIUMCVSS 6.5v9.02021-04-16
CVE-2021-31348 [MEDIUM] CWE-125 CVE-2021-31348: An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_parse_str() performs incorr
An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_parse_str() performs incorrect memory handling while parsing crafted XML files (out-of-bounds read after a certain strcspn failure).
nvd
CVE-2020-6547P4MEDIUMCVSS 6.5v10.02020-09-21
CVE-2020-6547 [MEDIUM] CWE-1021 CVE-2020-6547: Incorrect security UI in media in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to
Incorrect security UI in media in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially obtain sensitive information via a crafted HTML page.
nvd
CVE-2020-6495P4MEDIUMCVSS 6.5v9.0v10.02020-06-03
CVE-2020-6495 [MEDIUM] CWE-276 CVE-2020-6495: Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.97 allowed an
Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.97 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
nvd
CVE-2021-40491P4MEDIUMCVSS 6.5v10.02021-09-03
CVE-2021-40491 [MEDIUM] CVE-2021-40491: The ftp client in GNU Inetutils before 2.2 does not validate addresses returned by PASV/LSPV respons
The ftp client in GNU Inetutils before 2.2 does not validate addresses returned by PASV/LSPV responses to make sure they match the server address. This is similar to CVE-2020-8284 for curl.
nvd
CVE-2021-21211P4MEDIUMCVSS 6.5v10.02021-04-26
CVE-2021-21211 [MEDIUM] CWE-346 CVE-2021-21211: Inappropriate implementation in Navigation in Google Chrome on iOS prior to 90.0.4430.72 allowed a r
Inappropriate implementation in Navigation in Google Chrome on iOS prior to 90.0.4430.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2020-6538P4MEDIUMCVSS 6.5v10.02020-09-21
CVE-2020-6538 [MEDIUM] CVE-2020-6538: Inappropriate implementation in WebView in Google Chrome on Android prior to 84.0.4147.105 allowed a
Inappropriate implementation in WebView in Google Chrome on Android prior to 84.0.4147.105 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2015-5315P4MEDIUMCVSS 5.9v8.02018-02-21
CVE-2015-5315 [MEDIUM] CWE-119 CVE-2015-5315: The eap_pwd_process function in eap_peer/eap_pwd.c in wpa_supplicant 2.x before 2.6 does not validat
The eap_pwd_process function in eap_peer/eap_pwd.c in wpa_supplicant 2.x before 2.6 does not validate that the reassembly buffer is large enough for the final fragment when EAP-pwd is enabled in a network configuration profile, which allows remote attackers to cause a denial of service (process termination) via a large final fragment in an EAP-pwd mes
nvd
CVE-2022-26364P4MEDIUMCVSS 6.7v11.02022-06-09
CVE-2022-26364 [MEDIUM] CVE-2022-26364: x86 pv: Insufficient care with non-coherent mappings T[his CNA information record relates to multipl
x86 pv: Insufficient care with non-coherent mappings T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Xen maintains a type reference count for pages, in addition to a regular reference count. This scheme is used to maintain invariants required for Xen's safety, e.g. PV guests ma
nvd
CVE-2016-2366P4MEDIUMCVSS 5.9v8.02017-01-06
CVE-2016-2366 [MEDIUM] CWE-125 CVE-2016-2366: A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially c
A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in an out-of-bounds read. A malicious server or an attacker who intercepts the network traffic can send invalid data to trigger this vulnerability and cause a crash.
nvd
CVE-2020-29668P4LOWCVSS 3.7v9.0v10.02020-12-10
CVE-2020-29668 [LOW] CWE-287 CVE-2020-29668: Sympa before 6.2.59b.2 allows remote attackers to obtain full SOAP API access by sending any arbitra
Sympa before 6.2.59b.2 allows remote attackers to obtain full SOAP API access by sending any arbitrary string (except one from an expired cookie) as the cookie value to authenticateAndRun.
nvd
CVE-2016-9074P4MEDIUMCVSS 5.9v8.02018-06-11
CVE-2016-9074 [MEDIUM] CWE-200 CVE-2016-9074: An existing mitigation of timing side-channel attacks is insufficient in some circumstances. This is
An existing mitigation of timing side-channel attacks is insufficient in some circumstances. This issue is addressed in Network Security Services (NSS) 3.26.1. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.
nvd
CVE-2021-42739P4MEDIUMCVSS 6.7v9.02021-10-20
CVE-2021-42739 [MEDIUM] CWE-787 CVE-2021-42739: The firewire subsystem in the Linux kernel through 5.14.13 has a buffer overflow related to drivers/
The firewire subsystem in the Linux kernel through 5.14.13 has a buffer overflow related to drivers/media/firewire/firedtv-avc.c and drivers/media/firewire/firedtv-ci.c, because avc_ca_pmt mishandles bounds checking.
nvd
CVE-2016-2365P4MEDIUMCVSS 5.9v8.02017-01-06
CVE-2016-2365 [MEDIUM] CWE-476 CVE-2016-2365: A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially c
A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in a null pointer dereference. A malicious server or an attacker who intercepts the network traffic can send invalid data to trigger this vulnerability and cause a crash.
nvd
CVE-2019-5814P4MEDIUMCVSS 6.5v10.02019-06-27
CVE-2019-5814 [MEDIUM] CWE-352 CVE-2019-5814: Insufficient policy enforcement in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote at
Insufficient policy enforcement in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2020-13754P4MEDIUMCVSS 6.7v9.0v10.02020-06-02
CVE-2020-13754 [MEDIUM] CWE-119 CVE-2020-13754: hw/pci/msix.c in QEMU 4.2.0 allows guest OS users to trigger an out-of-bounds access via a crafted a
hw/pci/msix.c in QEMU 4.2.0 allows guest OS users to trigger an out-of-bounds access via a crafted address in an msi-x mmio operation.
nvd
CVE-2021-38010P4MEDIUMCVSS 6.5v10.0v11.02021-12-23
CVE-2021-38010 [MEDIUM] CVE-2021-38010: Inappropriate implementation in service workers in Google Chrome prior to 96.0.4664.45 allowed a rem
Inappropriate implementation in service workers in Google Chrome prior to 96.0.4664.45 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.
nvd
CVE-2018-16471P4MEDIUMCVSS 6.1v8.02018-11-13
CVE-2018-16471 [MEDIUM] CWE-79 CVE-2018-16471: There is a possible XSS vulnerability in Rack before 2.0.6 and 1.6.11. Carefully crafted requests ca
There is a possible XSS vulnerability in Rack before 2.0.6 and 1.6.11. Carefully crafted requests can impact the data returned by the `scheme` method on `Rack::Request`. Applications that expect the scheme to be limited to 'http' or 'https' and do not escape the return value could be vulnerable to an XSS attack. Note that applications using the norma
nvd
CVE-2020-26934P4MEDIUMCVSS 6.1v9.02020-10-10
CVE-2020-26934 [MEDIUM] CWE-79 CVE-2020-26934: phpMyAdmin before 4.9.6 and 5.x before 5.0.3 allows XSS through the transformation feature via a cra
phpMyAdmin before 4.9.6 and 5.x before 5.0.3 allows XSS through the transformation feature via a crafted link.
nvd
CVE-2020-6498P4MEDIUMCVSS 6.5v9.0v10.02020-06-03
CVE-2020-6498 [MEDIUM] CWE-276 CVE-2020-6498: Incorrect implementation in user interface in Google Chrome on iOS prior to 83.0.4103.88 allowed a r
Incorrect implementation in user interface in Google Chrome on iOS prior to 83.0.4103.88 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
nvd
CVE-2011-2910P4MEDIUMCVSS 6.7v8.0v9.0+1 more2019-11-15
CVE-2011-2910 [MEDIUM] CWE-269 CVE-2011-2910: The AX.25 daemon (ax25d) in ax25-tools before 0.0.8-13 does not check the return value of a setuid c
The AX.25 daemon (ax25d) in ax25-tools before 0.0.8-13 does not check the return value of a setuid call. The setuid call is responsible for dropping privileges but if the call fails the daemon would continue to run with root privileges which can allow possible privilege escalation.
nvd