Debian Linux vulnerabilities
9,954 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358
Vulnerabilities
Page 343 of 498
CVE-2018-10850P4MEDIUMCVSS 5.9v8.02018-06-13
CVE-2018-10850 [MEDIUM] CWE-362 CVE-2018-10850: 389-ds-base before versions 1.4.0.10, 1.3.8.3 is vulnerable to a race condition in the way 389-ds-ba
389-ds-base before versions 1.4.0.10, 1.3.8.3 is vulnerable to a race condition in the way 389-ds-base handles persistent search, resulting in a crash if the server is under load. An anonymous attacker could use this flaw to trigger a denial of service.
nvd
CVE-2013-4584P4MEDIUMCVSS 5.9v8.0v9.0+1 more2019-11-15
CVE-2013-4584 [MEDIUM] CWE-755 CVE-2013-4584: Perdition before 2.2 may have weak security when handling outbound connections, caused by an error i
Perdition before 2.2 may have weak security when handling outbound connections, caused by an error in the STARTTLS IMAP and POP server. ssl_outgoing_ciphers not being applied to STARTTLS connections
nvd
CVE-2015-4896P4MEDIUMCVSS 5.0v7.0v8.0+1 more2015-10-21
CVE-2015-4896 [MEDIUM] CVE-2015-4896: Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 4.0.34, 4.1.42, 4.2.34, 4.3.32, and 5.0.8, when a VM has the Remote Display feature (RDP) enabled, allows remote attackers to affect availability via unknown vectors related to Core.
nvd
CVE-2016-5728P4MEDIUMCVSS 6.3v8.02016-06-27
CVE-2016-5728 [MEDIUM] CWE-119 CVE-2016-5728: Race condition in the vop_ioctl function in drivers/misc/mic/vop/vop_vringh.c in the MIC VOP driver
Race condition in the vop_ioctl function in drivers/misc/mic/vop/vop_vringh.c in the MIC VOP driver in the Linux kernel before 4.6.1 allows local users to obtain sensitive information from kernel memory or cause a denial of service (memory corruption and system crash) by changing a certain header, aka a "double fetch" vulnerability.
nvd
CVE-2007-0897P4HIGHCVSS 7.5v3.12007-02-16
CVE-2007-0897 [HIGH] CWE-772 CVE-2007-0897: Clam AntiVirus ClamAV before 0.90 does not close open file descriptors under certain conditions, whi
Clam AntiVirus ClamAV before 0.90 does not close open file descriptors under certain conditions, which allows remote attackers to cause a denial of service (file descriptor consumption and failed scans) via CAB archives with a cabinet header record length of zero, which causes a function to return without closing a file descriptor.
nvd
CVE-2022-43593P4MEDIUMCVSS 5.9v11.02022-12-22
CVE-2022-43593 [MEDIUM] CWE-476 CVE-2022-43593: A denial of service vulnerability exists in the DPXOutput::close() functionality of OpenImageIO Proj
A denial of service vulnerability exists in the DPXOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to null pointer dereference. An attacker can provide malicious input to trigger this vulnerability.
nvd
CVE-2024-1551P4MEDIUMCVSS 6.1v10.02024-02-20
CVE-2024-1551 [MEDIUM] CWE-565 CVE-2024-1551: Set-Cookie response headers were being incorrectly honored in multipart HTTP responses. If an attack
Set-Cookie response headers were being incorrectly honored in multipart HTTP responses. If an attacker could control the Content-Type response header, as well as control part of the response body, they could inject Set-Cookie response headers that would have been honored by the browser. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, an
nvd
CVE-2023-52644P4MEDIUMCVSS 6.3v10.02024-04-17
CVE-2023-52644 [MEDIUM] CVE-2023-52644: In the Linux kernel, the following vulnerability has been resolved: wifi: b43: Stop/wake correct qu
In the Linux kernel, the following vulnerability has been resolved:
wifi: b43: Stop/wake correct queue in DMA Tx path when QoS is disabled
When QoS is disabled, the queue priority value will not map to the correct
ieee80211 queue since there is only one queue. Stop/wake queue 0 when QoS
is disabled to prevent trying to stop/wake a non-existent queue and fa
nvd
CVE-2023-36823P4MEDIUMCVSS 6.1v10.02023-07-06
CVE-2023-36823 [MEDIUM] CWE-79 CVE-2023-36823: Sanitize is an allowlist-based HTML and CSS sanitizer. Using carefully crafted input, an attacker ma
Sanitize is an allowlist-based HTML and CSS sanitizer. Using carefully crafted input, an attacker may be able to sneak arbitrary HTML and CSS through Sanitize starting with version 3.0.0 and prior to version 6.0.2 when Sanitize is configured to use the built-in "relaxed" config or when using a custom config that allows `style` elements and one or mor
nvd
CVE-2018-15599P4MEDIUMCVSS 5.3v8.02018-08-21
CVE-2018-15599 [MEDIUM] CWE-200 CVE-2018-15599: The recv_msg_userauth_request function in svr-auth.c in Dropbear through 2018.76 is prone to a user
The recv_msg_userauth_request function in svr-auth.c in Dropbear through 2018.76 is prone to a user enumeration vulnerability because username validity affects how fields in SSH_MSG_USERAUTH messages are handled, a similar issue to CVE-2018-15473 in an unrelated codebase.
nvd
CVE-2019-18603P4MEDIUMCVSS 5.9v8.02019-10-29
CVE-2019-18603 [MEDIUM] CWE-908 CVE-2019-18603: OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to information leakage upon certain error cond
OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to information leakage upon certain error conditions because uninitialized RPC output variables are sent over the network to a peer.
nvd
CVE-2016-5440P4MEDIUMCVSS 4.9v8.02016-07-21
CVE-2016-5440 [MEDIUM] CVE-2016-5440: Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and ear
Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and earlier and MariaDB before 5.5.50, 10.0.x before 10.0.26, and 10.1.x before 10.1.15 allows remote administrators to affect availability via vectors related to Server: RBR.
nvd
CVE-2024-27030P4MEDIUMCVSS 6.3v10.02024-05-01
CVE-2024-27030 [MEDIUM] CWE-362 CVE-2024-27030: In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: Use separate hand
In the Linux kernel, the following vulnerability has been resolved:
octeontx2-af: Use separate handlers for interrupts
For PF to AF interrupt vector and VF to AF vector same
interrupt handler is registered which is causing race condition.
When two interrupts are raised to two CPUs at same time
then two cores serve same event corrupting the data.
nvd
CVE-2016-1000339P4MEDIUMCVSS 5.3v8.02018-06-04
CVE-2016-1000339 [MEDIUM] CWE-310 CVE-2016-1000339: In the Bouncy Castle JCE Provider version 1.55 and earlier the primary engine class used for AES was
In the Bouncy Castle JCE Provider version 1.55 and earlier the primary engine class used for AES was AESFastEngine. Due to the highly table driven approach used in the algorithm it turns out that if the data channel on the CPU can be monitored the lookup table accesses are sufficient to leak information on the AES key being used. There was also
nvd
CVE-2023-6867P4MEDIUMCVSS 6.1v10.0v11.0+1 more2023-12-19
CVE-2023-6867 [MEDIUM] CWE-1021 CVE-2023-6867: The timing of a button click causing a popup to disappear was approximately the same length as the a
The timing of a button click causing a popup to disappear was approximately the same length as the anti-clickjacking delay on permission prompts. It was possible to use this fact to surprise users by luring them to click where the permission grant button would be about to appear. This vulnerability affects Firefox ESR < 115.6 and Firefox < 121.
nvd
CVE-2023-46734P4MEDIUMCVSS 6.1v10.02023-11-10
CVE-2023-46734 [MEDIUM] CWE-79 CVE-2023-46734: Symfony is a PHP framework for web and console applications and a set of reusable PHP components. St
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 2.0.0, 5.0.0, and 6.0.0 and prior to versions 4.4.51, 5.4.31, and 6.3.8, some Twig filters in CodeExtension use `is_safe=html` but don't actually ensure their input is safe. As of versions 4.4.51, 5.4.31, and 6.3.8, Symfony now escap
nvd
CVE-2017-15105P4MEDIUMCVSS 5.3v7.0v8.02018-01-23
CVE-2017-15105 [MEDIUM] CWE-358 CVE-2017-15105: A flaw was found in the way unbound before 1.6.8 validated wildcard-synthesized NSEC records. An imp
A flaw was found in the way unbound before 1.6.8 validated wildcard-synthesized NSEC records. An improperly validated wildcard NSEC record could be used to prove the non-existence (NXDOMAIN answer) of an existing wildcard record, or trick unbound into accepting a NODATA proof.
nvd
CVE-2024-1550P4MEDIUMCVSS 6.1v10.02024-02-20
CVE-2024-1550 [MEDIUM] CWE-1021 CVE-2024-1550: A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock
A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user's mouse to be re-positioned unexpectedly, which could have led to user confusion and inadvertently granting permissions they did not intend to grant. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 1
nvd
CVE-2015-3339P4MEDIUMCVSS 6.2v7.0v8.02015-05-27
CVE-2015-3339 [MEDIUM] CWE-362 CVE-2015-3339: Race condition in the prepare_binprm function in fs/exec.c in the Linux kernel before 3.19.6 allows
Race condition in the prepare_binprm function in fs/exec.c in the Linux kernel before 3.19.6 allows local users to gain privileges by executing a setuid program at a time instant when a chown to root is in progress, and the ownership is changed but the setuid bit is not yet stripped.
nvd
CVE-2013-4081P4MEDIUMCVSS 5.0v7.02013-06-09
CVE-2013-4081 [MEDIUM] CWE-119 CVE-2013-4081: The http_payload_subdissector function in epan/dissectors/packet-http.c in the HTTP dissector in Wir
The http_payload_subdissector function in epan/dissectors/packet-http.c in the HTTP dissector in Wireshark 1.6.x before 1.6.16 and 1.8.x before 1.8.8 does not properly determine when to use a recursive approach, which allows remote attackers to cause a denial of service (stack consumption) via a crafted packet.
nvd