Debian Linux vulnerabilities
9,955 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358
Vulnerabilities
Page 354 of 498
CVE-2020-14410P4MEDIUMCVSS 5.4v9.02021-01-19
CVE-2020-14410 [MEDIUM] CWE-125 CVE-2020-14410: SDL (Simple DirectMedia Layer) through 2.0.12 has a heap-based buffer over-read in Blit_3or4_to_3or4
SDL (Simple DirectMedia Layer) through 2.0.12 has a heap-based buffer over-read in Blit_3or4_to_3or4__inversed_rgb in video/SDL_blit_N.c via a crafted .BMP file.
nvd
CVE-2006-1244P4HIGHCVSS 7.6v3.12006-03-15
CVE-2006-1244 [HIGH] CVE-2006-1244: Unspecified vulnerability in certain versions of xpdf after 3.00, as used in various products includ
Unspecified vulnerability in certain versions of xpdf after 3.00, as used in various products including (a) pdfkit.framework, (b) gpdf, (c) pdftohtml, and (d) libextractor, has unknown impact and user-assisted attack vectors, possibly involving errors in (1) gmem.c, (2) SplashXPathScanner.cc, (3) JBIG2Stream.cc, (4) JPXStream.cc, and/or (5) Stream.cc. NOTE: thi
nvd
CVE-2022-29869P4MEDIUMCVSS 5.3v9.0v10.0+1 more2022-04-28
CVE-2022-29869 [MEDIUM] CWE-532 CVE-2022-29869: cifs-utils through 6.14, with verbose logging, can cause an information leak when a file contains =
cifs-utils through 6.14, with verbose logging, can cause an information leak when a file contains = (equal sign) characters but is not a valid credentials file.
nvd
CVE-2019-17674P4MEDIUMCVSS 5.4v9.0v10.02019-10-17
CVE-2019-17674 [MEDIUM] CWE-79 CVE-2019-17674: WordPress before 5.2.4 is vulnerable to stored XSS (cross-site scripting) via the Customizer.
WordPress before 5.2.4 is vulnerable to stored XSS (cross-site scripting) via the Customizer.
nvd
CVE-2020-2593P4MEDIUMCVSS 4.8v8.0v9.0+1 more2020-01-15
CVE-2020-2593 [MEDIUM] CVE-2020-2593: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Su
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1; Java SE Embedded: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Succ
nvd
CVE-2020-11030P4MEDIUMCVSS 5.4v9.0v10.02020-04-30
CVE-2020-11030 [MEDIUM] CWE-707 CVE-2020-11030: In affected versions of WordPress, a special payload can be crafted that can lead to scripts getting
In affected versions of WordPress, a special payload can be crafted that can lead to scripts getting executed within the search block of the block editor. This requires an authenticated user with the ability to add content. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.
nvd
CVE-2005-1268P4MEDIUMCVSS 5.0v3.12005-08-05
CVE-2005-1268 [MEDIUM] CWE-193 CVE-2005-1268: Off-by-one error in the mod_ssl Certificate Revocation List (CRL) verification callback in Apache, w
Off-by-one error in the mod_ssl Certificate Revocation List (CRL) verification callback in Apache, when configured to use a CRL, allows remote attackers to cause a denial of service (child process crash) via a CRL that causes a buffer overflow of one null byte.
nvd
CVE-2017-7825P4MEDIUMCVSS 5.3v7.02018-06-11
CVE-2017-7825 [MEDIUM] CWE-20 CVE-2017-7825: Several fonts on OS X display some Tibetan and Arabic characters as whitespace. When used in the add
Several fonts on OS X display some Tibetan and Arabic characters as whitespace. When used in the addressbar as part of an IDN this can be used for domain name spoofing attacks. Note: This attack only affects OS X operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.
nvd
CVE-2003-0360P4HIGHCVSS 7.5v0.9.1v0.9.2+2 more2003-06-09
CVE-2003-0360 [HIGH] CVE-2003-0360: Multiple buffer overflows in gPS before 1.0.0 allow attackers to cause a denial of service and possi
Multiple buffer overflows in gPS before 1.0.0 allow attackers to cause a denial of service and possibly execute arbitrary code.
nvd
CVE-2017-0366P4MEDIUMCVSS 5.4v7.02018-04-13
CVE-2017-0366 [MEDIUM] CWE-20 CVE-2017-0366: Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw allowing to evade SVG filter using defaul
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw allowing to evade SVG filter using default attribute values in DTD declaration.
nvd
CVE-2021-37695P4MEDIUMCVSS 5.4v9.02021-08-13
CVE-2021-37695 [MEDIUM] CWE-79 CVE-2021-37695: ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability
ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Fake Objects](https://ckeditor.com/cke4/addon/fakeobjects) package. The vulnerability allowed to inject malformed Fake Objects HTML, which could result in executing JavaScript code. It affects all users using the CKEdi
nvd
CVE-2021-29155P4MEDIUMCVSS 5.5v9.02021-04-20
CVE-2021-29155 [MEDIUM] CWE-125 CVE-2021-29155: An issue was discovered in the Linux kernel through 5.11.x. kernel/bpf/verifier.c performs undesirab
An issue was discovered in the Linux kernel through 5.11.x. kernel/bpf/verifier.c performs undesirable out-of-bounds speculation on pointer arithmetic, leading to side-channel attacks that defeat Spectre mitigations and obtain sensitive information from kernel memory. Specifically, for sequences of pointer arithmetic operations, the pointer modifica
nvd
CVE-2017-15423P4MEDIUMCVSS 5.3v9.02018-08-28
CVE-2017-15423 [MEDIUM] CWE-310 CVE-2017-15423: Inappropriate implementation in BoringSSL SPAKE2 in Google Chrome prior to 63.0.3239.84 allowed a re
Inappropriate implementation in BoringSSL SPAKE2 in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to leak the low-order bits of SHA512(password) by inspecting protocol traffic.
nvd
CVE-2003-0361P4HIGHCVSS 7.5v0.9.1v0.9.2+2 more2003-06-09
CVE-2003-0361 [HIGH] CVE-2003-0361: gPS before 1.1.0 does not properly follow the rgpsp connection source acceptation policy as specifie
gPS before 1.1.0 does not properly follow the rgpsp connection source acceptation policy as specified in the rgpsp.conf file, which could allow unauthorized remote attackers to connect to rgpsp.
nvd
CVE-2024-35910P4MEDIUMCVSS 5.8v10.02024-05-19
CVE-2024-35910 [MEDIUM] CVE-2024-35910: In the Linux kernel, the following vulnerability has been resolved: tcp: properly terminate timers
In the Linux kernel, the following vulnerability has been resolved:
tcp: properly terminate timers for kernel sockets
We had various syzbot reports about tcp timers firing after
the corresponding netns has been dismantled.
Fortunately Josef Bacik could trigger the issue more often,
and could test a patch I wrote two years ago.
When TCP sockets are closed,
nvd
CVE-2022-2663P4MEDIUMCVSS 5.3v10.0v11.02022-09-01
CVE-2022-2663 [MEDIUM] CWE-923 CVE-2022-2663: An issue was found in the Linux kernel in nf_conntrack_irc where the message handling can be confuse
An issue was found in the Linux kernel in nf_conntrack_irc where the message handling can be confused and incorrectly matches the message. A firewall may be able to be bypassed when users are using unencrypted IRC with nf_conntrack_irc configured.
nvd
CVE-2017-0370P4MEDIUMCVSS 5.3v7.02018-04-13
CVE-2017-0370 [MEDIUM] CWE-20 CVE-2017-0370: Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw were Spam blacklist is ineffective on enc
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw were Spam blacklist is ineffective on encoded URLs inside file inclusion syntax's link parameter.
nvd
CVE-2021-28963P4MEDIUMCVSS 5.3v10.02021-03-22
CVE-2021-28963 [MEDIUM] CWE-74 CVE-2021-28963: Shibboleth Service Provider before 3.2.1 allows content injection because template generation uses a
Shibboleth Service Provider before 3.2.1 allows content injection because template generation uses attacker-controlled parameters.
nvd
CVE-2018-10472P4MEDIUMCVSS 5.6v9.02018-04-27
CVE-2018-10472 [MEDIUM] CWE-200 CVE-2018-10472: An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users (in certain configurat
An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users (in certain configurations) to read arbitrary dom0 files via QMP live insertion of a CDROM, in conjunction with specifying the target file as the backing file of a snapshot.
nvd
CVE-2024-2611P4MEDIUMCVSS 5.5v10.02024-03-19
CVE-2024-2611 [MEDIUM] CVE-2024-2611: A missing delay on when pointer lock was used could have allowed a malicious page to trick a user in
A missing delay on when pointer lock was used could have allowed a malicious page to trick a user into granting permissions. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
nvd