Debian Linux vulnerabilities
9,955 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358
Vulnerabilities
Page 360 of 498
CVE-2013-1951P4MEDIUMCVSS 6.1v9.0v10.02019-10-31
CVE-2013-1951 [MEDIUM] CWE-79 CVE-2013-1951: A cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.5 and 1.20.x before 1.20.4 and a
A cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.5 and 1.20.x before 1.20.4 and allows remote attackers to inject arbitrary web script or HTML via Lua function names.
nvd
CVE-2022-36351P4MEDIUMCVSS 6.5v10.02023-08-11
CVE-2022-36351 [MEDIUM] CWE-20 CVE-2022-36351: Improper input validation in some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may all
Improper input validation in some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow an unauthenticated user to potentially enable denial of service via adjacent access.
nvd
CVE-2019-16217P4MEDIUMCVSS 6.1v8.0v9.0+1 more2019-09-11
CVE-2019-16217 [MEDIUM] CWE-79 CVE-2019-16217: WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attachment is mishandled.
WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attachment is mishandled.
nvd
CVE-2018-15572P4MEDIUMCVSS 6.5v8.0v9.02018-08-20
CVE-2018-15572 [MEDIUM] CVE-2018-15572: The spectre_v2_select_mitigation function in arch/x86/kernel/cpu/bugs.c in the Linux kernel before 4
The spectre_v2_select_mitigation function in arch/x86/kernel/cpu/bugs.c in the Linux kernel before 4.18.1 does not always fill RSB upon a context switch, which makes it easier for attackers to conduct userspace-userspace spectreRSB attacks.
nvd
CVE-2021-20196P4MEDIUMCVSS 6.5v9.0v10.02021-05-26
CVE-2021-20196 [MEDIUM] CWE-476 CVE-2021-20196: A NULL pointer dereference flaw was found in the floppy disk emulator of QEMU. This issue occurs whi
A NULL pointer dereference flaw was found in the floppy disk emulator of QEMU. This issue occurs while processing read/write ioport commands if the selected floppy drive is not initialized with a block device. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. The highest threat from thi
nvd
CVE-2020-24513P4MEDIUMCVSS 6.5v9.0v10.02021-06-09
CVE-2020-24513 [MEDIUM] CVE-2020-24513: Domain-bypass transient execution vulnerability in some Intel Atom(R) Processors may allow an authen
Domain-bypass transient execution vulnerability in some Intel Atom(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
nvd
CVE-2020-35479P4MEDIUMCVSS 6.1v9.0v10.02020-12-18
CVE-2020-35479 [MEDIUM] CWE-79 CVE-2020-35479: MediaWiki before 1.35.1 allows XSS via BlockLogFormatter.php. Language::translateBlockExpiry itself
MediaWiki before 1.35.1 allows XSS via BlockLogFormatter.php. Language::translateBlockExpiry itself does not escape in all code paths. For example, the return of Language::userTimeAndDate is is always unsafe for HTML in a month value. This affects MediaWiki 1.12.0 and later.
nvd
CVE-2013-7371P4MEDIUMCVSS 6.1v8.0v9.0+1 more2019-12-11
CVE-2013-7371 [MEDIUM] CVE-2013-7371: node-connects before 2.8.2 has cross site scripting in Sencha Labs Connect middleware (vulnerability
node-connects before 2.8.2 has cross site scripting in Sencha Labs Connect middleware (vulnerability due to incomplete fix for CVE-2013-7370)
nvd
CVE-2016-0640P4MEDIUMCVSS 6.1v8.02016-04-21
CVE-2016-0640 [MEDIUM] CVE-2016-0640: Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and ear
Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.48, 10.0.x before 10.0.24, and 10.1.x before 10.1.12 allows local users to affect integrity and availability via vectors related to DML.
nvd
CVE-2020-15566P4MEDIUMCVSS 6.5v10.02020-07-07
CVE-2020-15566 [MEDIUM] CWE-754 CVE-2020-15566: An issue was discovered in Xen through 4.13.x, allowing guest OS users to cause a host OS crash beca
An issue was discovered in Xen through 4.13.x, allowing guest OS users to cause a host OS crash because of incorrect error handling in event-channel port allocation. The allocation of an event-channel port may fail for multiple reasons: (1) port is already in use, (2) the memory allocation failed, or (3) the port we try to allocate is higher than wh
nvd
CVE-2021-30157P4MEDIUMCVSS 6.1v10.02021-04-06
CVE-2021-30157 [MEDIUM] CWE-79 CVE-2021-30157: An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. On Chan
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. On ChangesList special pages such as Special:RecentChanges and Special:Watchlist, some of the rcfilters-filter-* label messages are output in HTML unescaped, leading to XSS.
nvd
CVE-2021-3582P4MEDIUMCVSS 6.5v10.02022-03-25
CVE-2021-3582 [MEDIUM] CWE-119 CVE-2021-3582: A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. The issue occurs wh
A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. The issue occurs while handling a "PVRDMA_CMD_CREATE_MR" command due to improper memory remapping (mremap). This flaw allows a malicious guest to crash the QEMU process on the host. The highest threat from this vulnerability is to system availability.
nvd
CVE-2016-4020P4MEDIUMCVSS 6.5v8.02016-05-25
CVE-2016-4020 [MEDIUM] CVE-2016-4020: The patch_instruction function in hw/i386/kvmvapic.c in QEMU does not initialize the imm32 variable,
The patch_instruction function in hw/i386/kvmvapic.c in QEMU does not initialize the imm32 variable, which allows local guest OS administrators to obtain sensitive information from host stack memory by accessing the Task Priority Register (TPR).
nvd
CVE-2021-20257P4MEDIUMCVSS 6.5v10.02022-03-16
CVE-2021-20257 [MEDIUM] CWE-835 CVE-2021-20257: An infinite loop flaw was found in the e1000 NIC emulator of the QEMU. This issue occurs while proce
An infinite loop flaw was found in the e1000 NIC emulator of the QEMU. This issue occurs while processing transmits (tx) descriptors in process_tx_desc if various descriptor fields are initialized with invalid values. This flaw allows a guest to consume CPU cycles on the host, resulting in a denial of service. The highest threat from this vulnerabil
nvd
CVE-2025-22921P4MEDIUMCVSS 6.5v11.02025-02-18
CVE-2025-22921 [MEDIUM] CWE-476 CVE-2025-22921: FFmpeg git-master,N-113007-g8d24a28d06 was discovered to contain a segmentation violation via the co
FFmpeg git-master,N-113007-g8d24a28d06 was discovered to contain a segmentation violation via the component /libavcodec/jpeg2000dec.c.
nvd
CVE-2021-28688P4MEDIUMCVSS 6.5v9.02021-04-06
CVE-2021-28688 [MEDIUM] CWE-665 CVE-2021-28688: The fix for XSA-365 includes initialization of pointers such that subsequent cleanup code wouldn't u
The fix for XSA-365 includes initialization of pointers such that subsequent cleanup code wouldn't use uninitialized or stale values. This initialization went too far and may under certain conditions also overwrite pointers which are in need of cleaning up. The lack of cleanup would result in leaking persistent grants. The leak in turn would prevent
nvd
CVE-2021-30154P4MEDIUMCVSS 6.1v10.02021-04-06
CVE-2021-30154 [MEDIUM] CWE-79 CVE-2021-30154: An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. On Spec
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. On Special:NewFiles, all the mediastatistics-header-* messages are output in HTML unescaped, leading to XSS.
nvd
CVE-2021-3941P4MEDIUMCVSS 6.5v10.0v11.02022-03-25
CVE-2021-3941 [MEDIUM] CWE-369 CVE-2021-3941: In ImfChromaticities.cpp routine RGBtoXYZ(), there are some division operations such as `float Z = (
In ImfChromaticities.cpp routine RGBtoXYZ(), there are some division operations such as `float Z = (1 - chroma.white.x - chroma.white.y) * Y / chroma.white.y;` and `chroma.green.y * (X + Z))) / d;` but the divisor is not checked for a 0 value. A specially crafted file could trigger a divide-by-zero condition which could affect the availability of prog
nvd
CVE-2017-12378P4MEDIUMCVSS 5.5v7.02018-01-26
CVE-2017-12378 [MEDIUM] CWE-125 CVE-2017-12378: ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unau
ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper input validation checking mechanisms of .tar (Tape Archive) files sent to an affected device. A successful exploit co
nvd
CVE-2019-12471P4MEDIUMCVSS 6.1v9.02019-07-10
CVE-2019-12471 [MEDIUM] CWE-79 CVE-2019-12471: Wikimedia MediaWiki 1.30.0 through 1.32.1 has XSS. Loading user JavaScript from a non-existent accou
Wikimedia MediaWiki 1.30.0 through 1.32.1 has XSS. Loading user JavaScript from a non-existent account allows anyone to create the account, and perform XSS on users loading that script. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
nvd