cbcvebase.

Debian Linux vulnerabilities

9,955 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358

Vulnerabilities

Page 355 of 498
CVE-2019-2816P4MEDIUMCVSS 4.8v8.02019-07-23
CVE-2019-2816 [MEDIUM] CVE-2019-2816: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded.
nvd
CVE-2024-35823P4MEDIUMCVSS 5.3v10.02024-05-17
CVE-2024-35823 [MEDIUM] CWE-120 CVE-2024-35823: In the Linux kernel, the following vulnerability has been resolved: vt: fix unicode buffer corrupti In the Linux kernel, the following vulnerability has been resolved: vt: fix unicode buffer corruption when deleting characters This is the same issue that was fixed for the VGA text buffer in commit 39cdb68c64d8 ("vt: fix memory overlapping when deleting chars in the buffer"). The cure is also the same i.e. replace memcpy() with memmove() due to th
nvd
CVE-2020-36425P4MEDIUMCVSS 5.3v10.02021-07-19
CVE-2020-36425 [MEDIUM] CWE-295 CVE-2020-36425: An issue was discovered in Arm Mbed TLS before 2.24.0. It incorrectly uses a revocationDate check wh An issue was discovered in Arm Mbed TLS before 2.24.0. It incorrectly uses a revocationDate check when deciding whether to honor certificate revocation via a CRL. In some situations, an attacker can exploit this by changing the local clock.
nvd
CVE-2015-1254P4MEDIUMCVSS 5.0v8.02015-05-20
CVE-2015-1254 [MEDIUM] CWE-264 CVE-2015-1254: core/dom/Document.cpp in Blink, as used in Google Chrome before 43.0.2357.65, enables the inheritanc core/dom/Document.cpp in Blink, as used in Google Chrome before 43.0.2357.65, enables the inheritance of the designMode attribute, which allows remote attackers to bypass the Same Origin Policy by leveraging the availability of editing.
nvd
CVE-2014-2079P4MEDIUMCVSS 5.5v7.0v8.02018-07-16
CVE-2014-2079 [MEDIUM] CWE-264 CVE-2014-2079: X File Explorer (aka xfe) might allow local users to bypass intended access restrictions and gain ac X File Explorer (aka xfe) might allow local users to bypass intended access restrictions and gain access to arbitrary files by leveraging failure to use directory masks when creating files on Samba and NFS shares.
nvd
CVE-2018-1106P4MEDIUMCVSS 5.5v9.02018-04-23
CVE-2018-1106 [MEDIUM] CWE-287 CVE-2018-1106: An authentication bypass flaw has been found in PackageKit before 1.1.10 that allows users without a An authentication bypass flaw has been found in PackageKit before 1.1.10 that allows users without administrator privileges to install signed packages. A local attacker can use this vulnerability to install vulnerable packages to further compromise a system.
nvd
CVE-2022-3201P4MEDIUMCVSS 5.4v11.02022-09-26
CVE-2022-3201 [MEDIUM] CWE-20 CVE-2022-3201: Insufficient validation of untrusted input in DevTools in Google Chrome on Chrome OS prior to 105.0. Insufficient validation of untrusted input in DevTools in Google Chrome on Chrome OS prior to 105.0.5195.125 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2022-2905P4MEDIUMCVSS 5.5v10.02022-09-09
CVE-2022-2905 [MEDIUM] CWE-125 CVE-2022-2905: An out-of-bounds memory read flaw was found in the Linux kernel's BPF subsystem in how a user calls An out-of-bounds memory read flaw was found in the Linux kernel's BPF subsystem in how a user calls the bpf_tail_call function with a key larger than the max_entries of the map. This flaw allows a local user to gain unauthorized access to data.
nvd
CVE-2019-25026P4MEDIUMCVSS 5.3v9.02021-04-06
CVE-2019-25026 [MEDIUM] CVE-2019-25026: Redmine before 3.4.13 and 4.x before 4.0.6 mishandles markup data during Textile formatting. Redmine before 3.4.13 and 4.x before 4.0.6 mishandles markup data during Textile formatting.
nvd
CVE-2023-4194P4MEDIUMCVSS 5.5v10.0v11.0+1 more2023-08-07
CVE-2023-4194 [MEDIUM] CVE-2023-4194: A flaw was found in the Linux kernel's TUN/TAP functionality. This issue could allow a local user to A flaw was found in the Linux kernel's TUN/TAP functionality. This issue could allow a local user to bypass network filters and gain unauthorized access to some resources. The original patches fixing CVE-2023-1076 are incorrect or incomplete. The problem is that the following upstream commits - a096ccca6e50 ("tun: tun_chr_open(): correctly initialize socket u
nvd
CVE-2023-4359P4MEDIUMCVSS 5.3v11.0v12.02023-08-15
CVE-2023-4359 [MEDIUM] CVE-2023-4359: Inappropriate implementation in App Launcher in Google Chrome on iOS prior to 116.0.5845.96 allowed Inappropriate implementation in App Launcher in Google Chrome on iOS prior to 116.0.5845.96 allowed a remote attacker to potentially spoof elements of the security UI via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-52618P4MEDIUMCVSS 5.3v10.02024-03-18
CVE-2023-52618 [MEDIUM] CVE-2023-52618: In the Linux kernel, the following vulnerability has been resolved: block/rnbd-srv: Check for unlik In the Linux kernel, the following vulnerability has been resolved: block/rnbd-srv: Check for unlikely string overflow Since "dev_search_path" can technically be as large as PATH_MAX, there was a risk of truncation when copying it and a second string into "full_path" since it was also PATH_MAX sized. The W=1 builds were reporting this warning: drivers/blo
nvd
CVE-2023-34410P4MEDIUMCVSS 5.3v10.02023-06-05
CVE-2023-34410 [MEDIUM] CWE-295 CVE-2023-34410: An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2 An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2. Certificate validation for TLS does not always consider whether the root of a chain is a configured CA certificate.
nvd
CVE-2023-4045P4MEDIUMCVSS 5.3v11.0v12.02023-08-01
CVE-2023-4045 [MEDIUM] CWE-346 CVE-2023-4045: Offscreen Canvas did not properly track cross-origin tainting, which could have been used to access Offscreen Canvas did not properly track cross-origin tainting, which could have been used to access image data from another site in violation of same-origin policy. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.
nvd
CVE-2008-5512P4MEDIUMCVSS 6.8v4.0v5.02008-12-17
CVE-2008-5512 [MEDIUM] CWE-264 CVE-2008-5512: Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Th Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allow remote attackers to run arbitrary JavaScript with chrome privileges via unknown vectors in which "page content can pollute XPCNativeWrappers."
nvd
CVE-2001-0195P4HIGHCVSS 7.8v2.22001-03-26
CVE-2001-0195 [HIGH] CWE-281 CVE-2001-0195: sash before 3.4-4 in Debian GNU/Linux does not properly clone /etc/shadow, which makes it world-read sash before 3.4-4 in Debian GNU/Linux does not properly clone /etc/shadow, which makes it world-readable and could allow local users to gain privileges via password cracking.
nvd
CVE-2017-6313P4HIGHCVSS 7.1v8.02017-03-10
CVE-2017-6313 [HIGH] CWE-191 CVE-2017-6313: Integer underflow in the load_resources function in io-icns.c in gdk-pixbuf allows context-dependent Integer underflow in the load_resources function in io-icns.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (out-of-bounds read and program crash) via a crafted image entry size in an ICO file.
nvd
CVE-2011-2515P4MEDIUMCVSS 5.3v8.0v9.0+1 more2019-11-27
CVE-2011-2515 [MEDIUM] CWE-732 CVE-2011-2515: PackageKit 0.6.17 allows installation of unsigned RPM packages as though they were signed which may PackageKit 0.6.17 allows installation of unsigned RPM packages as though they were signed which may allow installation of non-trusted packages and execution of arbitrary code.
nvd
CVE-2020-27674P4MEDIUMCVSS 5.3v10.02020-10-22
CVE-2020-27674 [MEDIUM] CWE-787 CVE-2020-27674: An issue was discovered in Xen through 4.14.x allowing x86 PV guest OS users to gain guest OS privil An issue was discovered in Xen through 4.14.x allowing x86 PV guest OS users to gain guest OS privileges by modifying kernel memory contents, because invalidation of TLB entries is mishandled during use of an INVLPG-like attack technique.
nvd
CVE-2025-23419P4MEDIUMCVSS 4.3v11.02025-02-05
CVE-2025-23419 [MEDIUM] CWE-863 CVE-2025-23419: When multiple server blocks are configured to share the same IP address and port, an attacker can us When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate authentication requirements on these servers. This vulnerability arises when TLS Session Tickets https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_ticket_key are used and/or the SSL s
nvd
Debian Linux vulnerabilities | cvebase