Debian Linux vulnerabilities
9,955 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358
Vulnerabilities
Page 351 of 498
CVE-2020-15677P4MEDIUMCVSS 6.1v9.0v10.02020-10-01
CVE-2020-15677 [MEDIUM] CWE-601 CVE-2020-15677: By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site d
By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the download file dialog to show the original site (the one suffering from the open redirect) rather than the site the file was actually downloaded from. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and Firefox ESR < 78.3.
nvd
CVE-2017-3157P4MEDIUMCVSS 5.5v8.0v9.02017-11-20
CVE-2017-3157 [MEDIUM] CWE-200 CVE-2017-3157: By exploiting the way Apache OpenOffice before 4.1.4 renders embedded objects, an attacker could cra
By exploiting the way Apache OpenOffice before 4.1.4 renders embedded objects, an attacker could craft a document that allows reading in a file from the user's filesystem. Information could be retrieved by the attacker by, e.g., using hidden sections to store the information, tricking the user into saving the document and convincing the user to send t
nvd
CVE-2020-15676P4MEDIUMCVSS 6.1v9.0v10.02020-10-01
CVE-2020-15676 [MEDIUM] CWE-79 CVE-2020-15676: Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove,
Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, resulting in JavaScript being executed after pasting attacker-controlled data into a contenteditable element. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and Firefox ESR < 78.3.
nvd
CVE-2015-3026P4MEDIUMCVSS 5.0v8.02015-04-29
CVE-2015-3026 [MEDIUM] CVE-2015-3026: Icecast before 2.4.2, when a stream_auth handler is defined for URL authentication, allows remote at
Icecast before 2.4.2, when a stream_auth handler is defined for URL authentication, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a request without login credentials, as demonstrated by a request to "admin/killsource?mount=/test.ogg."
nvd
CVE-2021-40403P4MEDIUMCVSS 6.3v11.02022-02-04
CVE-2021-40403 [MEDIUM] CWE-456 CVE-2021-40403: An information disclosure vulnerability exists in the pick-and-place rotation parsing functionality
An information disclosure vulnerability exists in the pick-and-place rotation parsing functionality of Gerbv 2.7.0 and dev (commit b5f1eacd), and Gerbv forked 2.8.0. A specially-crafted pick-and-place file can exploit the missing initialization of a structure to leak memory contents. An attacker can provide a malicious file to trigger this vulnerabil
nvd
CVE-2012-1114P4MEDIUMCVSS 6.1v8.0v9.02019-12-05
CVE-2012-1114 [MEDIUM] CWE-79 CVE-2012-1114: A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the filte
A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the filter parameter to cmd.php in an export and exporter_id action. and the filteruid parameter to list.php.
nvd
CVE-2012-1115P4MEDIUMCVSS 6.1v8.0v9.02019-12-05
CVE-2012-1115 [MEDIUM] CWE-79 CVE-2012-1115: A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the expor
A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the export, add_value_form, and dn parameters to cmd.php.
nvd
CVE-2018-8763P4MEDIUMCVSS 6.1v7.0v8.0+1 more2018-03-27
CVE-2018-8763 [MEDIUM] CWE-79 CVE-2018-8763: Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 has XSS via the dn parameter to th
Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 has XSS via the dn parameter to the templates/3rdParty/pla/htdocs/cmd.php URI or the template parameter to the templates/3rdParty/pla/htdocs/cmd.php?cmd=rename_form URI.
nvd
CVE-2015-3281P4MEDIUMCVSS 5.0v8.02015-07-06
CVE-2015-3281 [MEDIUM] CWE-119 CVE-2015-3281: The buffer_slow_realign function in HAProxy 1.5.x before 1.5.14 and 1.6-dev does not properly realig
The buffer_slow_realign function in HAProxy 1.5.x before 1.5.14 and 1.6-dev does not properly realign a buffer that is used for pending outgoing data, which allows remote attackers to obtain sensitive information (uninitialized memory contents of previous requests) via a crafted request.
nvd
CVE-2017-15722P4MEDIUMCVSS 5.9v7.0v8.0+1 more2017-10-22
CVE-2017-15722 [MEDIUM] CWE-125 CVE-2017-15722: In certain cases, Irssi before 1.0.5 may fail to verify that a Safe channel ID is long enough, causi
In certain cases, Irssi before 1.0.5 may fail to verify that a Safe channel ID is long enough, causing reads beyond the end of the string.
nvd
CVE-2017-17741P4MEDIUMCVSS 6.5v9.02017-12-18
CVE-2017-17741 [MEDIUM] CWE-125 CVE-2017-17741: The KVM implementation in the Linux kernel through 4.14.7 allows attackers to obtain potentially sen
The KVM implementation in the Linux kernel through 4.14.7 allows attackers to obtain potentially sensitive information from kernel memory, aka a write_mmio stack-based out-of-bounds read, related to arch/x86/kvm/x86.c and include/trace/events/kvm.h.
nvd
CVE-2016-2858P4MEDIUMCVSS 6.5v8.02016-04-07
CVE-2016-2858 [MEDIUM] CWE-331 CVE-2016-2858: QEMU, when built with the Pseudo Random Number Generator (PRNG) back-end support, allows local guest
QEMU, when built with the Pseudo Random Number Generator (PRNG) back-end support, allows local guest OS users to cause a denial of service (process crash) via an entropy request, which triggers arbitrary stack based allocation and memory corruption.
nvd
CVE-2020-29483P4MEDIUMCVSS 6.5v10.02020-12-15
CVE-2020-29483 [MEDIUM] CWE-416 CVE-2020-29483: An issue was discovered in Xen through 4.14.x. Xenstored and guests communicate via a shared memory
An issue was discovered in Xen through 4.14.x. Xenstored and guests communicate via a shared memory page using a specific protocol. When a guest violates this protocol, xenstored will drop the connection to that guest. Unfortunately, this is done by just removing the guest from xenstored's internal management, resulting in the same actions as if the
nvd
CVE-2020-6535P4MEDIUMCVSS 6.1v10.02020-07-22
CVE-2020-6535 [MEDIUM] CWE-79 CVE-2020-6535: Insufficient data validation in WebUI in Google Chrome prior to 84.0.4147.89 allowed a remote attack
Insufficient data validation in WebUI in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had compromised the renderer process to inject scripts or HTML into a privileged page via a crafted HTML page.
nvd
CVE-2021-28652P4MEDIUMCVSS 4.9v9.0v10.02021-05-27
CVE-2021-28652 [MEDIUM] CWE-401 CVE-2021-28652: An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to incorrect parser validatio
An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to incorrect parser validation, it allows a Denial of Service attack against the Cache Manager API. This allows a trusted client to trigger memory leaks that. over time, lead to a Denial of Service via an unspecified short query string. This attack is limited to clients with Cach
nvd
CVE-2021-28715P4MEDIUMCVSS 6.5v9.0v10.0+1 more2022-01-06
CVE-2021-28715 [MEDIUM] CVE-2021-28715: Guest can force Linux netback driver to hog large amounts of kernel memory T[his CNA information rec
Guest can force Linux netback driver to hog large amounts of kernel memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Incoming data packets for a guest in the Linux kernel's netback driver are buffered until the guest is ready to process them. There are some measures taken
nvd
CVE-2021-28714P4MEDIUMCVSS 6.5v10.0v11.02022-01-06
CVE-2021-28714 [MEDIUM] CWE-770 CVE-2021-28714: Guest can force Linux netback driver to hog large amounts of kernel memory T[his CNA information rec
Guest can force Linux netback driver to hog large amounts of kernel memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Incoming data packets for a guest in the Linux kernel's netback driver are buffered until the guest is ready to process them. There are some measur
nvd
CVE-2021-43331P4MEDIUMCVSS 6.1v9.02021-11-12
CVE-2021-43331 [MEDIUM] CWE-79 CVE-2021-43331: In GNU Mailman before 2.1.36, a crafted URL to the Cgi/options.py user options page can execute arbi
In GNU Mailman before 2.1.36, a crafted URL to the Cgi/options.py user options page can execute arbitrary JavaScript for XSS.
nvd
CVE-2017-0917P4MEDIUMCVSS 6.1v9.02018-03-21
CVE-2017-0917 [MEDIUM] CWE-79 CVE-2017-0917: Gitlab Community Edition version 10.2.4 is vulnerable to lack of input validation in the CI job comp
Gitlab Community Edition version 10.2.4 is vulnerable to lack of input validation in the CI job component resulting in persistent cross site scripting.
nvd
CVE-2020-26215P4MEDIUMCVSS 6.1v9.02020-11-18
CVE-2020-26215 [MEDIUM] CWE-601 CVE-2020-26215: Jupyter Notebook before version 6.1.5 has an Open redirect vulnerability. A maliciously crafted link
Jupyter Notebook before version 6.1.5 has an Open redirect vulnerability. A maliciously crafted link to a notebook server could redirect the browser to a different website. All notebook servers are technically affected, however, these maliciously crafted links can only be reasonably made for known notebook server hosts. A link to your notebook serve
nvd