cbcvebase.

Debian Linux vulnerabilities

9,955 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358

Vulnerabilities

Page 352 of 498
CVE-2018-6039P4MEDIUMCVSS 6.1v8.0v9.02018-09-25
CVE-2018-6039 [MEDIUM] CWE-20 CVE-2018-6039: Insufficient data validation in DevTools in Google Chrome prior to 64.0.3282.119 allowed a remote at Insufficient data validation in DevTools in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak user cross-origin data via a crafted Chrome Extension.
nvd
CVE-2018-6046P4MEDIUMCVSS 6.1v8.0v9.02018-09-25
CVE-2018-6046 [MEDIUM] CWE-20 CVE-2018-6046: Insufficient data validation in DevTools in Google Chrome prior to 64.0.3282.119 allowed a remote at Insufficient data validation in DevTools in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak user cross-origin data via a crafted Chrome Extension.
nvd
CVE-2021-37159P4MEDIUMCVSS 6.4v9.02021-07-21
CVE-2021-37159 [MEDIUM] CWE-415 CVE-2021-37159: hso_free_net_device in drivers/net/usb/hso.c in the Linux kernel through 5.13.4 calls unregister_net hso_free_net_device in drivers/net/usb/hso.c in the Linux kernel through 5.13.4 calls unregister_netdev without checking for the NETREG_REGISTERED state, leading to a use-after-free and a double free.
nvd
CVE-2018-0202P4MEDIUMCVSS 5.5v7.02018-03-27
CVE-2018-0202 [MEDIUM] CWE-125 CVE-2018-0202: clamscan in ClamAV before 0.99.4 contains a vulnerability that could allow an unauthenticated, remot clamscan in ClamAV before 0.99.4 contains a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper input validation checking mechanisms when handling Portable Document Format (.pdf) files sent to an affected device. An unauthenticated,
nvd
CVE-2016-1682P4MEDIUMCVSS 6.1v8.02016-06-05
CVE-2016-1682 [MEDIUM] CWE-254 CVE-2016-1682: The ServiceWorkerContainer::registerServiceWorkerImpl function in WebKit/Source/modules/serviceworke The ServiceWorkerContainer::registerServiceWorkerImpl function in WebKit/Source/modules/serviceworkers/ServiceWorkerContainer.cpp in Blink, as used in Google Chrome before 51.0.2704.63, allows remote attackers to bypass the Content Security Policy (CSP) protection mechanism via a ServiceWorker registration.
nvd
CVE-2023-5480P4MEDIUMCVSS 6.1v11.0v12.02023-11-01
CVE-2023-5480 [MEDIUM] CWE-79 CVE-2023-5480: Inappropriate implementation in Payments in Google Chrome prior to 119.0.6045.105 allowed a remote a Inappropriate implementation in Payments in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to bypass XSS preventions via a malicious file. (Chromium security severity: High)
nvd
CVE-2016-9374P4MEDIUMCVSS 5.9v8.02016-11-17
CVE-2016-9374 [MEDIUM] CWE-119 CVE-2016-9374: In Wireshark 2.2.0 to 2.2.1 and 2.0.0 to 2.0.7, the AllJoyn dissector could crash with a buffer over In Wireshark 2.2.0 to 2.2.1 and 2.0.0 to 2.0.7, the AllJoyn dissector could crash with a buffer over-read, triggered by network traffic or a capture file. This was addressed in epan/dissectors/packet-alljoyn.c by ensuring that a length variable properly tracked the state of a signature variable.
nvd
CVE-2017-6814P4MEDIUMCVSS 5.4v8.0v9.02017-03-12
CVE-2017-6814 [MEDIUM] CWE-79 CVE-2017-6814: In WordPress before 4.7.3, there is authenticated Cross-Site Scripting (XSS) via Media File Metadata In WordPress before 4.7.3, there is authenticated Cross-Site Scripting (XSS) via Media File Metadata. This is demonstrated by both (1) mishandling of the playlist shortcode in the wp_playlist_shortcode function in wp-includes/media.php and (2) mishandling of meta information in the renderTracks function in wp-includes/js/mediaelement/wp-playlist.js.
nvd
CVE-2017-10356P4MEDIUMCVSS 6.2v7.0v8.0+1 more2017-10-19
CVE-2017-10356 [MEDIUM] CVE-2017-10356: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: S Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144; JRockit: R28.3.15. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Java SE, Java SE Embedde
nvd
CVE-2015-0381P4MEDIUMCVSS 4.3v7.02015-01-21
CVE-2015-0381 [MEDIUM] CVE-2015-0381: Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows re Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows remote attackers to affect availability via unknown vectors related to Server : Replication, a different vulnerability than CVE-2015-0382.
nvd
CVE-2018-2599P4MEDIUMCVSS 4.8v7.0v8.0+1 more2018-01-18
CVE-2018-2599 [MEDIUM] CVE-2018-2599: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: J Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JNDI). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java S
nvd
CVE-2012-3509P4MEDIUMCVSS 5.0v7.02012-09-05
CVE-2012-3509 [MEDIUM] CWE-189 CVE-2012-3509: Multiple integer overflows in the (1) _objalloc_alloc function in objalloc.c and (2) objalloc_alloc Multiple integer overflows in the (1) _objalloc_alloc function in objalloc.c and (2) objalloc_alloc macro in include/objalloc.h in GNU libiberty, as used by binutils 2.22, allow remote attackers to cause a denial of service (crash) via vectors related to the "addition of CHUNK_HEADER_SIZE to the length," which triggers a heap-based buffer overflow.
nvd
CVE-2021-40716P4MEDIUMCVSS 5.5v10.02021-09-29
CVE-2021-40716 [MEDIUM] CWE-125 CVE-2021-40716: XMP Toolkit SDK versions 2021.07 (and earlier) are affected by an out-of-bounds read vulnerability t XMP Toolkit SDK versions 2021.07 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2022-43603P4MEDIUMCVSS 5.9v11.02022-12-22
CVE-2022-43603 [MEDIUM] CWE-476 CVE-2022-43603: A denial of service vulnerability exists in the ZfileOutput::close() functionality of OpenImageIO Pr A denial of service vulnerability exists in the ZfileOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to denial of service. An attacker can provide a malicious file to trigger this vulnerability.
nvd
CVE-2004-0809P4MEDIUMCVSS 5.0v3.02004-09-16
CVE-2004-0809 [MEDIUM] CVE-2004-0809: The mod_dav module in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service The mod_dav module in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (child process crash) via a certain sequence of LOCK requests for a location that allows WebDAV authoring access.
nvd
CVE-2004-0458P4HIGHCVSS 7.5v3.02004-09-28
CVE-2004-0458 [HIGH] CWE-476 CVE-2004-0458: mah-jong before 1.6.2 allows remote attackers to cause a denial of service (server crash) via a miss mah-jong before 1.6.2 allows remote attackers to cause a denial of service (server crash) via a missing argument, which triggers a null pointer dereference.
nvd
CVE-2017-5462P4MEDIUMCVSS 5.3v8.02018-06-11
CVE-2017-5462 [MEDIUM] CWE-682 CVE-2017-5462: A flaw in DRBG number generation within the Network Security Services (NSS) library where the intern A flaw in DRBG number generation within the Network Security Services (NSS) library where the internal state V does not correctly carry bits over. The NSS library has been updated to fix this issue to address this issue and Firefox ESR 52.1 has been updated with NSS version 3.28.4. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Fir
nvd
CVE-2020-26421P4MEDIUMCVSS 5.3v9.02020-12-11
CVE-2020-26421 [MEDIUM] CWE-125 CVE-2020-26421: Crash in USB HID protocol dissector and possibly other dissectors in Wireshark 3.4.0 and 3.2.0 to 3. Crash in USB HID protocol dissector and possibly other dissectors in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.
nvd
CVE-2022-39842P4MEDIUMCVSS 6.1v10.0v11.02022-09-05
CVE-2022-39842 [MEDIUM] CWE-190 CVE-2022-39842: An issue was discovered in the Linux kernel before 5.19. In pxa3xx_gcu_write in drivers/video/fbdev/ An issue was discovered in the Linux kernel before 5.19. In pxa3xx_gcu_write in drivers/video/fbdev/pxa3xx-gcu.c, the count parameter has a type conflict of size_t versus int, causing an integer overflow and bypassing the size check. After that, because it is used as the third argument to copy_from_user(), a heap overflow may occur. NOTE: the origin
nvd
CVE-2022-32166P4MEDIUMCVSS 6.1v10.02022-09-28
CVE-2022-32166 [MEDIUM] CWE-125 CVE-2022-32166: In ovs versions v0.90.0 through v2.5.0 are vulnerable to heap buffer over-read in flow.c. An unsafe In ovs versions v0.90.0 through v2.5.0 are vulnerable to heap buffer over-read in flow.c. An unsafe comparison of “minimasks” function could lead access to an unmapped region of memory. This vulnerability is capable of crashing the software, memory modification, and possible remote execution.
nvd
Debian Linux vulnerabilities | cvebase