Debian Linux vulnerabilities
9,954 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358
Vulnerabilities
Page 340 of 498
CVE-2021-33656P4MEDIUMCVSS 6.8v10.02022-07-18
CVE-2021-33656 [MEDIUM] CWE-787 CVE-2021-33656: When setting font with malicous data by ioctl cmd PIO_FONT,kernel will write memory out of bounds.
When setting font with malicous data by ioctl cmd PIO_FONT,kernel will write memory out of bounds.
nvd
CVE-2015-3196P4MEDIUMCVSS 4.3v7.0v8.02015-12-06
CVE-2015-3196 [MEDIUM] CWE-362 CVE-2015-3196: ssl/s3_clnt.c in OpenSSL 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1p, and 1.0.2 before 1.0.2d, when use
ssl/s3_clnt.c in OpenSSL 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1p, and 1.0.2 before 1.0.2d, when used for a multi-threaded client, writes the PSK identity hint to an incorrect data structure, which allows remote servers to cause a denial of service (race condition and double free) via a crafted ServerKeyExchange message.
nvd
CVE-2017-15395P4MEDIUMCVSS 6.5v8.0v9.02018-02-07
CVE-2017-15395 [MEDIUM] CWE-416 CVE-2017-15395: A use after free in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potent
A use after free in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page, aka an ImageCapture NULL pointer dereference.
nvd
CVE-2020-23226P4MEDIUMCVSS 6.1v9.0v10.02021-08-27
CVE-2020-23226 [MEDIUM] CWE-79 CVE-2020-23226: Multiple Cross Site Scripting (XSS) vulneratiblities exist in Cacti 1.2.12 in (1) reports_admin.php,
Multiple Cross Site Scripting (XSS) vulneratiblities exist in Cacti 1.2.12 in (1) reports_admin.php, (2) data_queries.php, (3) data_input.php, (4) graph_templates.php, (5) graphs.php, (6) reports_admin.php, and (7) data_input.php.
nvd
CVE-2015-5623P4MEDIUMCVSS 4.0v8.02015-08-03
CVE-2015-5623 [MEDIUM] CWE-284 CVE-2015-5623: WordPress before 4.2.3 does not properly verify the edit_posts capability, which allows remote authe
WordPress before 4.2.3 does not properly verify the edit_posts capability, which allows remote authenticated users to bypass intended access restrictions and create drafts by leveraging the Subscriber role, as demonstrated by a post-quickdraft-save action to wp-admin/post.php.
nvd
CVE-2019-16275P4MEDIUMCVSS 6.5v8.0v10.02019-09-12
CVE-2019-16275 [MEDIUM] CWE-346 CVE-2019-16275: hostapd before 2.10 and wpa_supplicant before 2.10 allow an incorrect indication of disconnection in
hostapd before 2.10 and wpa_supplicant before 2.10 allow an incorrect indication of disconnection in certain situations because source address validation is mishandled. This is a denial of service that should have been prevented by PMF (aka management frame protection). The attacker must send a crafted 802.11 frame from a location that is within the
nvd
CVE-2019-19527P4MEDIUMCVSS 6.8v8.02019-12-03
CVE-2019-19527 [MEDIUM] CWE-416 CVE-2019-19527: In the Linux kernel before 5.2.10, there is a use-after-free bug that can be caused by a malicious U
In the Linux kernel before 5.2.10, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/hid/usbhid/hiddev.c driver, aka CID-9c09b214f30e.
nvd
CVE-2019-16222P4MEDIUMCVSS 6.1v8.0v9.0+1 more2019-09-11
CVE-2019-16222 [MEDIUM] CWE-79 CVE-2019-16222: WordPress before 5.2.3 has an issue with URL sanitization in wp_kses_bad_protocol_once in wp-include
WordPress before 5.2.3 has an issue with URL sanitization in wp_kses_bad_protocol_once in wp-includes/kses.php that can lead to cross-site scripting (XSS) attacks.
nvd
CVE-2020-19716P4MEDIUMCVSS 6.5v10.02021-07-13
CVE-2020-19716 [MEDIUM] CWE-120 CVE-2020-19716: A buffer overflow vulnerability in the Databuf function in types.cpp of Exiv2 v0.27.1 leads to a den
A buffer overflow vulnerability in the Databuf function in types.cpp of Exiv2 v0.27.1 leads to a denial of service (DOS).
nvd
CVE-2021-30485P4MEDIUMCVSS 6.5v9.02021-04-11
CVE-2021-30485 [MEDIUM] CWE-476 CVE-2021-30485: An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_internal_dtd(), while parsi
An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_internal_dtd(), while parsing a crafted XML file, performs incorrect memory handling, leading to a NULL pointer dereference while running strcmp() on a NULL pointer.
nvd
CVE-2020-12770P4MEDIUMCVSS 6.7v8.0v9.0+1 more2020-05-09
CVE-2020-12770 [MEDIUM] CVE-2020-12770: An issue was discovered in the Linux kernel through 5.6.11. sg_write lacks an sg_remove_request call
An issue was discovered in the Linux kernel through 5.6.11. sg_write lacks an sg_remove_request call in a certain failure case, aka CID-83c6f2390040.
nvd
CVE-2021-31347P4MEDIUMCVSS 6.5v9.02021-04-16
CVE-2021-31347 [MEDIUM] CWE-91 CVE-2021-31347: An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_parse_str() performs incorr
An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_parse_str() performs incorrect memory handling while parsing crafted XML files (writing outside a memory region created by mmap).
nvd
CVE-2021-41229P4MEDIUMCVSS 6.5v9.0v10.02021-11-12
CVE-2021-41229 [MEDIUM] CWE-400 CVE-2021-41229: BlueZ is a Bluetooth protocol stack for Linux. In affected versions a vulnerability exists in sdp_cs
BlueZ is a Bluetooth protocol stack for Linux. In affected versions a vulnerability exists in sdp_cstate_alloc_buf which allocates memory which will always be hung in the singly linked list of cstates and will not be freed. This will cause a memory leak over time. The data can be a very large object, which can be caused by an attacker continuously s
nvd
CVE-2015-5146P4MEDIUMCVSS 5.3v7.0v8.02017-08-24
CVE-2015-5146 [MEDIUM] CWE-20 CVE-2015-5146: ntpd in ntp before 4.2.8p3 with remote configuration enabled allows remote authenticated users with
ntpd in ntp before 4.2.8p3 with remote configuration enabled allows remote authenticated users with knowledge of the configuration password and access to a computer entrusted to perform remote configuration to cause a denial of service (service crash) via a NULL byte in a crafted configuration directive packet.
nvd
CVE-2019-5810P4MEDIUMCVSS 6.5v10.02019-06-27
CVE-2019-5810 [MEDIUM] CWE-312 CVE-2019-5810: Information leak in autofill in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to ob
Information leak in autofill in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2019-13748P4MEDIUMCVSS 6.5v9.0v10.02019-12-10
CVE-2019-13748 [MEDIUM] CWE-862 CVE-2019-13748: Insufficient policy enforcement in developer tools in Google Chrome prior to 79.0.3945.79 allowed a
Insufficient policy enforcement in developer tools in Google Chrome prior to 79.0.3945.79 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2022-3627P4MEDIUMCVSS 6.5v10.0v11.02022-10-21
CVE-2022-3627 [MEDIUM] CWE-787 CVE-2022-3627: LibTIFF 4.4.0 has an out-of-bounds write in _TIFFmemcpy in libtiff/tif_unix.c:346 when called from e
LibTIFF 4.4.0 has an out-of-bounds write in _TIFFmemcpy in libtiff/tif_unix.c:346 when called from extractImageSection, tools/tiffcrop.c:6860, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 236b7191.
nvd
CVE-2023-1994P4MEDIUMCVSS 6.5v10.0v12.02023-04-12
CVE-2023-1994 [MEDIUM] CWE-400 CVE-2023-1994: GQUIC dissector crash in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via p
GQUIC dissector crash in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture file
nvd
CVE-2019-17016P4MEDIUMCVSS 6.1v8.0v9.0+1 more2020-01-08
CVE-2019-17016 [MEDIUM] CWE-79 CVE-2019-17016: When pasting a <style> tag from the clipboard into a rich text editor, the CSS sanitizer incor
When pasting a tag from the clipboard into a rich text editor, the CSS sanitizer incorrectly rewrites a @namespace rule. This could allow for injection into certain types of websites resulting in data exfiltration. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.
nvd
CVE-2022-3597P4MEDIUMCVSS 6.5v10.0v11.02022-10-21
CVE-2022-3597 [MEDIUM] CWE-787 CVE-2022-3597: LibTIFF 4.4.0 has an out-of-bounds write in _TIFFmemcpy in libtiff/tif_unix.c:346 when called from e
LibTIFF 4.4.0 has an out-of-bounds write in _TIFFmemcpy in libtiff/tif_unix.c:346 when called from extractImageSection, tools/tiffcrop.c:6826, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 236b7191.
nvd