cbcvebase.

Debian Linux vulnerabilities

9,955 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358

Vulnerabilities

Page 345 of 498
CVE-2016-0702P4MEDIUMCVSS 5.1v7.0v8.02016-03-03
CVE-2016-0702 [MEDIUM] CWE-200 CVE-2016-0702: The MOD_EXP_CTIME_COPY_FROM_PREBUF function in crypto/bn/bn_exp.c in OpenSSL 1.0.1 before 1.0.1s and The MOD_EXP_CTIME_COPY_FROM_PREBUF function in crypto/bn/bn_exp.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g does not properly consider cache-bank access times during modular exponentiation, which makes it easier for local users to discover RSA keys by running a crafted application on the same Intel Sandy Bridge CPU core as a victim and le
nvd
CVE-2017-9775P4MEDIUMCVSS 6.5v8.0v9.02017-06-22
CVE-2017-9775 [MEDIUM] CWE-119 CVE-2017-9775: Stack buffer overflow in GfxState.cc in pdftocairo in Poppler before 0.56 allows remote attackers to Stack buffer overflow in GfxState.cc in pdftocairo in Poppler before 0.56 allows remote attackers to cause a denial of service (application crash) via a crafted PDF document.
nvd
CVE-2020-8624P4MEDIUMCVSS 4.3v10.02020-08-21
CVE-2020-8624 [MEDIUM] CWE-269 CVE-2020-8624: In BIND 9.9.12 -> 9.9.13, 9.10.7 -> 9.10.8, 9.11.3 -> 9.11.21, 9.12.1 -> 9.16.5, 9.17.0 -> 9.17.3, a In BIND 9.9.12 -> 9.9.13, 9.10.7 -> 9.10.8, 9.11.3 -> 9.11.21, 9.12.1 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.12-S1 -> 9.9.13-S1, 9.11.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker who has been granted privileges to change a specific subset of the zone's content could abuse these unintended additional privileges to upda
nvd
CVE-2021-42326P4MEDIUMCVSS 5.3v9.02021-10-12
CVE-2021-42326 [MEDIUM] CVE-2021-42326: Redmine before 4.1.5 and 4.2.x before 4.2.3 may disclose the names of users on activity views due to Redmine before 4.1.5 and 4.2.x before 4.2.3 may disclose the names of users on activity views due to an insufficient access filter.
nvd
CVE-2020-1753P4MEDIUMCVSS 5.5v10.02020-03-16
CVE-2020-1753 [MEDIUM] CWE-200 CVE-2020-1753: A security flaw was found in Ansible Engine, all Ansible 2.7.x versions prior to 2.7.17, all Ansible A security flaw was found in Ansible Engine, all Ansible 2.7.x versions prior to 2.7.17, all Ansible 2.8.x versions prior to 2.8.11 and all Ansible 2.9.x versions prior to 2.9.7, when managing kubernetes using the k8s module. Sensitive parameters such as passwords and tokens are passed to kubectl from the command line, not using an environment variabl
nvd
CVE-2007-0994P4MEDIUMCVSS 6.8v3.12007-03-06
CVE-2007-0994 [MEDIUM] CWE-94 CVE-2007-0994: A regression error in Mozilla Firefox 2.x before 2.0.0.2 and 1.x before 1.5.0.10, and SeaMonkey 1.1 A regression error in Mozilla Firefox 2.x before 2.0.0.2 and 1.x before 1.5.0.10, and SeaMonkey 1.1 before 1.1.1 and 1.0 before 1.0.8, allows remote attackers to execute arbitrary JavaScript as the user via an HTML mail message with a javascript: URI in an (1) img, (2) link, or (3) style tag, which bypasses the access checks and executes code with chrom
nvd
CVE-2022-0487P4MEDIUMCVSS 5.5v9.0v11.02022-02-04
CVE-2022-0487 [MEDIUM] CWE-416 CVE-2022-0487: A use-after-free vulnerability was found in rtsx_usb_ms_drv_remove in drivers/memstick/host/rtsx_usb A use-after-free vulnerability was found in rtsx_usb_ms_drv_remove in drivers/memstick/host/rtsx_usb_ms.c in memstick in the Linux kernel. In this flaw, a local attacker with a user privilege may impact system Confidentiality. This flaw affects kernel versions prior to 5.14 rc1.
nvd
CVE-2010-4817P4MEDIUMCVSS 5.5v8.0v9.0+1 more2019-11-13
CVE-2010-4817 [MEDIUM] CWE-59 CVE-2010-4817: pithos before 0.3.5 allows overwrite of arbitrary files via symlinks. pithos before 0.3.5 allows overwrite of arbitrary files via symlinks.
nvd
CVE-2011-2923P4MEDIUMCVSS 5.5v8.0v9.0+1 more2019-11-19
CVE-2011-2923 [MEDIUM] CWE-59 CVE-2011-2923: foomatic-rip filter, all versions, used insecurely creates temporary files for storage of PostScript foomatic-rip filter, all versions, used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct symlink attacks by overwriting arbitrary files accessible with the privileges of the user running the foomatic-rip universal print filt
nvd
CVE-2020-14347P4MEDIUMCVSS 5.5v9.0v10.02020-08-05
CVE-2020-14347 [MEDIUM] CWE-665 CVE-2020-14347: A flaw was found in the way xserver memory was not properly initialized. This could leak parts of se A flaw was found in the way xserver memory was not properly initialized. This could leak parts of server memory to the X client. In cases where Xorg server runs with elevated privileges, this could result in possible ASLR bypass. Xorg-server before version 1.20.9 is vulnerable.
nvd
CVE-2020-10685P4MEDIUMCVSS 5.5v10.02020-05-11
CVE-2020-10685 [MEDIUM] CWE-459 CVE-2020-10685: A flaw was found in Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x b A flaw was found in Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and 2.9.x before 2.9.7 as well as Ansible Tower before and including versions 3.4.5 and 3.5.5 and 3.6.3 when using modules which decrypts vault files such as assemble, script, unarchive, win_copy, aws_s3 or copy modules. The temporary dir
nvd
CVE-2023-32762P4MEDIUMCVSS 5.3v10.02023-05-28
CVE-2023-32762 [MEDIUM] CVE-2023-32762: An issue was discovered in Qt before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1 An issue was discovered in Qt before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. Qt Network incorrectly parses the strict-transport-security (HSTS) header, allowing unencrypted connections to be established, even when explicitly prohibited by the server. This happens if the case used for this header does not exactly match.
nvd
CVE-2011-2691P4MEDIUMCVSS 6.5v5.0v6.02011-07-17
CVE-2011-2691 [MEDIUM] CWE-476 CVE-2011-2691: The png_err function in pngerror.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before The png_err function in pngerror.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 makes a function call using a NULL pointer argument instead of an empty-string argument, which allows remote attackers to cause a denial of service (application crash) via a crafted PNG image.
nvd
CVE-2013-2865P4HIGHCVSS 7.5v7.02013-06-05
CVE-2013-2865 [HIGH] CVE-2013-2865: Multiple unspecified vulnerabilities in Google Chrome before 27.0.1453.110 allow attackers to cause Multiple unspecified vulnerabilities in Google Chrome before 27.0.1453.110 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2018-10963P4MEDIUMCVSS 6.5v8.0v9.02018-05-10
CVE-2018-10963 [MEDIUM] CVE-2018-10963: The TIFFWriteDirectorySec() function in tif_dirwrite.c in LibTIFF through 4.0.9 allows remote attack The TIFFWriteDirectorySec() function in tif_dirwrite.c in LibTIFF through 4.0.9 allows remote attackers to cause a denial of service (assertion failure and application crash) via a crafted file, a different vulnerability than CVE-2017-13726.
nvd
CVE-2021-44717P4MEDIUMCVSS 4.8v9.02022-01-01
CVE-2021-44717 [MEDIUM] CWE-404 CVE-2021-44717: Go before 1.16.12 and 1.17.x before 1.17.5 on UNIX allows write operations to an unintended file or Go before 1.16.12 and 1.17.x before 1.17.5 on UNIX allows write operations to an unintended file or unintended network connection as a consequence of erroneous closing of file descriptor 0 after file-descriptor exhaustion.
nvd
CVE-2013-2886P4HIGHCVSS 7.5v7.02013-07-31
CVE-2013-2886 [HIGH] CVE-2013-2886: Multiple unspecified vulnerabilities in Google Chrome before 28.0.1500.95 allow attackers to cause a Multiple unspecified vulnerabilities in Google Chrome before 28.0.1500.95 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2015-1270P4MEDIUMCVSS 6.8v8.02015-07-23
CVE-2015-1270 [MEDIUM] CWE-19 CVE-2015-1270: The ucnv_io_getConverterName function in common/ucnv_io.cpp in International Components for Unicode The ucnv_io_getConverterName function in common/ucnv_io.cpp in International Components for Unicode (ICU), as used in Google Chrome before 44.0.2403.89, mishandles converter names with initial x- substrings, which allows remote attackers to cause a denial of service (read of uninitialized memory) or possibly have unspecified other impact via a crafted f
nvd
CVE-2014-3487P4MEDIUMCVSS 4.3v7.0v8.02014-07-09
CVE-2014-3487 [MEDIUM] CWE-20 CVE-2014-3487: The cdf_read_property_info function in file before 5.19, as used in the Fileinfo component in PHP be The cdf_read_property_info function in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, does not properly validate a stream offset, which allows remote attackers to cause a denial of service (application crash) via a crafted CDF file.
nvd
CVE-2018-20481P4MEDIUMCVSS 6.5v8.02018-12-26
CVE-2018-20481 [MEDIUM] CWE-476 CVE-2018-20481: XRef::getEntry in XRef.cc in Poppler 0.72.0 mishandles unallocated XRef entries, which allows remote XRef::getEntry in XRef.cc in Poppler 0.72.0 mishandles unallocated XRef entries, which allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted PDF document, when XRefEntry::setFlag in XRef.h is called from Parser::makeStream in Parser.cc.
nvd
Debian Linux vulnerabilities | cvebase