cbcvebase.

Debian Linux vulnerabilities

9,955 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358

Vulnerabilities

Page 353 of 498
CVE-2024-4768P4MEDIUMCVSS 6.1v10.02024-05-14
CVE-2024-4768 [MEDIUM] CWE-281 CVE-2024-4768: A bug in popup notifications' interaction with WebAuthn made it easier for an attacker to trick a us A bug in popup notifications' interaction with WebAuthn made it easier for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
nvd
CVE-2024-1549P4MEDIUMCVSS 6.1v10.02024-02-20
CVE-2024-1549 [MEDIUM] CVE-2024-1549: If a website set a large custom cursor, portions of the cursor could have overlapped with the permis If a website set a large custom cursor, portions of the cursor could have overlapped with the permission dialog, potentially resulting in user confusion and unexpected granted permissions. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.
nvd
CVE-2024-37384P4MEDIUMCVSS 6.1v10.02024-06-07
CVE-2024-37384 [MEDIUM] CWE-79 CVE-2024-37384: Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via list columns from user preferen Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via list columns from user preferences.
nvd
CVE-2017-2836P4MEDIUMCVSS 5.9v8.0v9.02018-04-24
CVE-2017-2836 [MEDIUM] CWE-295 CVE-2017-2836: An exploitable denial of service vulnerability exists within the reading of proprietary server certi An exploitable denial of service vulnerability exists within the reading of proprietary server certificates in FreeRDP 2.0.0-beta1+android11. A specially crafted challenge packet can cause the program termination leading to a denial of service condition. An attacker can compromise the server or use man in the middle to trigger this vulnerability.
nvd
CVE-2020-16304P4MEDIUMCVSS 5.5v9.0v10.02020-08-13
CVE-2020-16304 [MEDIUM] CWE-787 CVE-2020-16304: A buffer overflow vulnerability in image_render_color_thresh() in base/gxicolor.c of Artifex Softwar A buffer overflow vulnerability in image_render_color_thresh() in base/gxicolor.c of Artifex Software GhostScript v9.18 to v9.50 allows a remote attacker to escalate privileges via a crafted eps file. This is fixed in v9.51.
nvd
CVE-2020-8647P4MEDIUMCVSS 6.1v8.0v9.02020-02-06
CVE-2020-8647 [MEDIUM] CWE-416 CVE-2020-8647: There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the vc_do_resize functi There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the vc_do_resize function in drivers/tty/vt/vt.c.
nvd
CVE-2020-16302P4MEDIUMCVSS 5.5v9.0v10.02020-08-13
CVE-2020-16302 [MEDIUM] CWE-120 CVE-2020-16302: A buffer overflow vulnerability in jetp3852_print_page() in devices/gdev3852.c of Artifex Software G A buffer overflow vulnerability in jetp3852_print_page() in devices/gdev3852.c of Artifex Software GhostScript v9.50 allows a remote attacker to escalate privileges via a crafted PDF file. This is fixed in v9.51.
nvd
CVE-2020-2655P4MEDIUMCVSS 4.8v9.0v10.02020-01-15
CVE-2020-2655 [MEDIUM] CVE-2020-2655: Vulnerability in the Java SE product of Oracle Java SE (component: JSSE). Supported versions that ar Vulnerability in the Java SE product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 11.0.5 and 13.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized update, insert or delete acces
nvd
CVE-2016-7116P4MEDIUMCVSS 6.0v8.02016-12-10
CVE-2016-7116 [MEDIUM] CWE-22 CVE-2016-7116: Directory traversal vulnerability in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS Directory traversal vulnerability in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to access host files outside the export path via a .. (dot dot) in an unspecified string.
nvd
CVE-2019-1788P4MEDIUMCVSS 5.5v8.02019-04-08
CVE-2019-1788 [MEDIUM] CWE-20 CVE-2019-1788: A vulnerability in the Object Linking & Embedding (OLE2) file scanning functionality of Clam AntiVir A vulnerability in the Object Linking & Embedding (OLE2) file scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and prior could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to a lack of proper input and validation checking mechanisms for OLE2 f
nvd
CVE-2014-5265P4MEDIUMCVSS 5.0v7.02014-08-18
CVE-2014-5265 [MEDIUM] CWE-399 CVE-2014-5265: The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, permits entity declarations without considering recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested ent
nvd
CVE-2020-22217P4MEDIUMCVSS 5.9v10.02023-08-22
CVE-2020-22217 [MEDIUM] CWE-125 CVE-2020-22217: Buffer overflow vulnerability in c-ares before 1_16_1 thru 1_17_0 via function ares_parse_soa_reply Buffer overflow vulnerability in c-ares before 1_16_1 thru 1_17_0 via function ares_parse_soa_reply in ares_parse_soa_reply.c.
nvd
CVE-2018-20153P4MEDIUMCVSS 5.4v8.0v9.02018-12-14
CVE-2018-20153 [MEDIUM] CWE-79 CVE-2018-20153: In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could modify new comments made by users In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could modify new comments made by users with greater privileges, possibly causing XSS.
nvd
CVE-2021-45942P4MEDIUMCVSS 5.5v10.0v11.02022-01-01
CVE-2021-45942 [MEDIUM] CWE-787 CVE-2021-45942: OpenEXR 3.1.x before 3.1.4 has a heap-based buffer overflow in Imf_3_1::LineCompositeTask::execute ( OpenEXR 3.1.x before 3.1.4 has a heap-based buffer overflow in Imf_3_1::LineCompositeTask::execute (called from IlmThread_3_1::NullThreadPoolProvider::addTask and IlmThread_3_1::ThreadPool::addGlobalTask). NOTE: db217f2 may be inapplicable.
nvd
CVE-2017-17094P4MEDIUMCVSS 5.4v7.0v8.0+1 more2017-12-02
CVE-2017-17094 [MEDIUM] CWE-79 CVE-2017-17094: wp-includes/feed.php in WordPress before 4.9.1 does not properly restrict enclosures in RSS and Atom wp-includes/feed.php in WordPress before 4.9.1 does not properly restrict enclosures in RSS and Atom fields, which might allow attackers to conduct XSS attacks via a crafted URL.
nvd
CVE-2015-2620P4MEDIUMCVSS 4.3v8.02015-07-16
CVE-2015-2620 [MEDIUM] CVE-2015-2620: Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.23 and earlier allows re Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.23 and earlier allows remote authenticated users to affect confidentiality via unknown vectors related to Server : Security : Privileges.
nvd
CVE-2020-15250P4MEDIUMCVSS 5.5v9.02020-10-12
CVE-2020-15250 [MEDIUM] CWE-200 CVE-2020-15250: In JUnit4 from version 4.7 and before 4.13.1, the test rule TemporaryFolder contains a local informa In JUnit4 from version 4.7 and before 4.13.1, the test rule TemporaryFolder contains a local information disclosure vulnerability. On Unix like systems, the system's temporary directory is shared between all users on that system. Because of this, when files and directories are written into this directory they are, by default, readable by other users
nvd
CVE-2010-4532P4MEDIUMCVSS 5.9v8.0v9.0+1 more2019-11-13
CVE-2010-4532 [MEDIUM] CWE-295 CVE-2010-4532: offlineimap before 6.3.2 does not check for SSL server certificate validation when "ssl = yes" optio offlineimap before 6.3.2 does not check for SSL server certificate validation when "ssl = yes" option is specified which can allow man-in-the-middle attacks.
nvd
CVE-2021-45958P4MEDIUMCVSS 5.5v9.02022-01-01
CVE-2021-45958 [MEDIUM] CWE-787 CVE-2021-45958: UltraJSON (aka ujson) through 5.1.0 has a stack-based buffer overflow in Buffer_AppendIndentUnchecke UltraJSON (aka ujson) through 5.1.0 has a stack-based buffer overflow in Buffer_AppendIndentUnchecked (called from encode). Exploitation can, for example, use a large amount of indentation.
nvd
CVE-2022-24769P4MEDIUMCVSS 5.9v11.02022-03-24
CVE-2022-24769 [MEDIUM] CWE-732 CVE-2022-24769: Moby is an open-source project created by Docker to enable and accelerate software containerization. Moby is an open-source project created by Docker to enable and accelerate software containerization. A bug was found in Moby (Docker Engine) prior to version 20.10.14 where containers were incorrectly started with non-empty inheritable Linux process capabilities, creating an atypical Linux environment and enabling programs with inheritable file capa
nvd
Debian Linux vulnerabilities | cvebase