cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358

Vulnerabilities

Page 331 of 498
CVE-2023-6205P4MEDIUMCVSS 6.5v10.0v11.0+1 more2023-11-21
CVE-2023-6205 [MEDIUM] CWE-416 CVE-2023-6205: It was possible to cause the use of a MessagePort after it had already been freed, which could poten It was possible to cause the use of a MessagePort after it had already been freed, which could potentially have led to an exploitable crash. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
nvd
CVE-2021-21229P4MEDIUMCVSS 6.5v10.02021-04-30
CVE-2021-21229 [MEDIUM] CWE-346 CVE-2021-21229: Incorrect security UI in downloads in Google Chrome on Android prior to 90.0.4430.93 allowed a remot Incorrect security UI in downloads in Google Chrome on Android prior to 90.0.4430.93 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
nvd
CVE-2019-13740P4MEDIUMCVSS 6.5v9.0v10.02019-12-10
CVE-2019-13740 [MEDIUM] CWE-346 CVE-2019-13740: Incorrect security UI in sharing in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to Incorrect security UI in sharing in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
nvd
CVE-2013-6712P4MEDIUMCVSS 5.0v6.0v7.02013-11-28
CVE-2013-6712 [MEDIUM] CWE-119 CVE-2013-6712: The scan function in ext/date/lib/parse_iso_intervals.c in PHP through 5.5.6 does not properly restr The scan function in ext/date/lib/parse_iso_intervals.c in PHP through 5.5.6 does not properly restrict creation of DateInterval objects, which might allow remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted interval specification.
nvd
CVE-2019-16218P4MEDIUMCVSS 6.1v8.0v9.0+1 more2019-09-11
CVE-2019-16218 [MEDIUM] CWE-79 CVE-2019-16218: WordPress before 5.2.3 allows XSS in stored comments. WordPress before 5.2.3 allows XSS in stored comments.
nvd
CVE-2020-6497P4MEDIUMCVSS 6.5v9.0v10.02020-06-03
CVE-2020-6497 [MEDIUM] CWE-276 CVE-2020-6497: Insufficient policy enforcement in Omnibox in Google Chrome on iOS prior to 83.0.4103.88 allowed a r Insufficient policy enforcement in Omnibox in Google Chrome on iOS prior to 83.0.4103.88 allowed a remote attacker to perform domain spoofing via a crafted URI.
nvd
CVE-2013-1429P4MEDIUMCVSS 6.3v8.0v9.0+1 more2019-11-07
CVE-2013-1429 [MEDIUM] CWE-59 CVE-2013-1429: Lintian before 2.5.12 allows remote attackers to gather information about the "host" system using cr Lintian before 2.5.12 allows remote attackers to gather information about the "host" system using crafted symlinks.
nvd
CVE-2021-38021P4MEDIUMCVSS 6.5v10.0v11.02021-12-23
CVE-2021-38021 [MEDIUM] CVE-2021-38021: Inappropriate implementation in referrer in Google Chrome prior to 96.0.4664.45 allowed a remote att Inappropriate implementation in referrer in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2021-37995P4MEDIUMCVSS 6.5v10.0v11.02021-11-02
CVE-2021-37995 [MEDIUM] CVE-2021-37995: Inappropriate implementation in WebApp Installer in Google Chrome prior to 95.0.4638.54 allowed a re Inappropriate implementation in WebApp Installer in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially overlay and spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2021-38018P4MEDIUMCVSS 6.5v10.0v11.02021-12-23
CVE-2021-38018 [MEDIUM] CVE-2021-38018: Inappropriate implementation in navigation in Google Chrome prior to 96.0.4664.45 allowed a remote a Inappropriate implementation in navigation in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
nvd
CVE-2019-17672P4MEDIUMCVSS 6.1v9.0v10.02019-10-17
CVE-2019-17672 [MEDIUM] CWE-79 CVE-2019-17672: WordPress before 5.2.4 is vulnerable to a stored XSS attack to inject JavaScript into STYLE elements WordPress before 5.2.4 is vulnerable to a stored XSS attack to inject JavaScript into STYLE elements.
nvd
CVE-2015-5314P4MEDIUMCVSS 5.9v8.02018-02-21
CVE-2015-5314 [MEDIUM] CWE-119 CVE-2015-5314: The eap_pwd_process function in eap_server/eap_server_pwd.c in hostapd 2.x before 2.6 does not valid The eap_pwd_process function in eap_server/eap_server_pwd.c in hostapd 2.x before 2.6 does not validate that the reassembly buffer is large enough for the final fragment when used with (1) an internal EAP server or (2) a RADIUS server and EAP-pwd is enabled in a runtime configuration, which allows remote attackers to cause a denial of service (process
nvd
CVE-2024-0746P4MEDIUMCVSS 6.5v10.02024-01-23
CVE-2024-0746 [MEDIUM] CWE-416 CVE-2024-0746: A Linux user opening the print preview dialog could have caused the browser to crash. This vulnerabi A Linux user opening the print preview dialog could have caused the browser to crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
nvd
CVE-2019-5834P4MEDIUMCVSS 6.5v10.02019-06-27
CVE-2019-5834 [MEDIUM] CWE-346 CVE-2019-5834: Insufficient data validation in Blink in Google Chrome prior to 75.0.3770.80 allowed a remote attack Insufficient data validation in Blink in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
nvd
CVE-2022-22577P4MEDIUMCVSS 6.1v10.02022-05-26
CVE-2022-22577 [MEDIUM] CWE-79 CVE-2022-22577: An XSS Vulnerability in Action Pack >= 5.2.0 and < 5.2.0 that could allow an attacker to bypass CSP An XSS Vulnerability in Action Pack >= 5.2.0 and < 5.2.0 that could allow an attacker to bypass CSP for non HTML like responses.
nvd
CVE-2017-5038P4MEDIUMCVSS 6.3v8.0v9.02017-04-24
CVE-2017-5038 [MEDIUM] CWE-416 CVE-2017-5038: Chrome Apps in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac had a use after free Chrome Apps in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac had a use after free bug in GuestView, which allowed a remote attacker to perform an out of bounds memory read via a crafted Chrome extension.
nvd
CVE-2016-2370P4MEDIUMCVSS 5.9v8.02017-01-06
CVE-2016-2370 [MEDIUM] CWE-125 CVE-2016-2370: A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially c A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent from the server could potentially result in an out-of-bounds read. A malicious server or man-in-the-middle attacker can send invalid data to trigger this vulnerability.
nvd
CVE-2015-0407P4MEDIUMCVSS 5.0v7.0v8.02015-01-21
CVE-2015-0407 [MEDIUM] CVE-2015-0407: Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality via unknown vectors related to Swing.
nvd
CVE-2016-6313P4MEDIUMCVSS 5.3v8.02016-12-13
CVE-2016-6313 [MEDIUM] CWE-200 CVE-2016-6313: The mixing functions in the random number generator in Libgcrypt before 1.5.6, 1.6.x before 1.6.6, a The mixing functions in the random number generator in Libgcrypt before 1.5.6, 1.6.x before 1.6.6, and 1.7.x before 1.7.3 and GnuPG before 1.4.21 make it easier for attackers to obtain the values of 160 bits by leveraging knowledge of the previous 4640 bits.
nvd
CVE-2005-3625P4CRITICALCVSS 10.0v3.0v3.12005-12-31
CVE-2005-3625 [CRITICAL] CWE-399 CVE-2005-3625: Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and oth Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and (2) DCTDecode streams, aka "Infinite CPU spins."
nvd
Debian Linux vulnerabilities | cvebase