Debian Linux vulnerabilities
9,955 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358
Vulnerabilities
Page 361 of 498
CVE-2022-42321P4MEDIUMCVSS 6.5v11.02022-11-01
CVE-2022-42321 [MEDIUM] CWE-674 CVE-2022-42321: Xenstore: Guests can crash xenstored via exhausting the stack Xenstored is using recursion for some
Xenstore: Guests can crash xenstored via exhausting the stack Xenstored is using recursion for some Xenstore operations (e.g. for deleting a sub-tree of Xenstore nodes). With sufficiently deep nesting levels this can result in stack exhaustion on xenstored, leading to a crash of xenstored.
nvd
CVE-2022-42319P4MEDIUMCVSS 6.5v11.02022-11-01
CVE-2022-42319 [MEDIUM] CWE-401 CVE-2022-42319: Xenstore: Guests can cause Xenstore to not free temporary memory When working on a request of a gues
Xenstore: Guests can cause Xenstore to not free temporary memory When working on a request of a guest, xenstored might need to allocate quite large amounts of memory temporarily. This memory is freed only after the request has been finished completely. A request is regarded to be finished only after the guest has read the response message of the req
nvd
CVE-2017-6929P4MEDIUMCVSS 6.1v7.0v8.0+1 more2018-03-01
CVE-2017-6929 [MEDIUM] CWE-79 CVE-2017-6929: A jQuery cross site scripting vulnerability is present when making Ajax requests to untrusted domain
A jQuery cross site scripting vulnerability is present when making Ajax requests to untrusted domains. This vulnerability is mitigated by the fact that it requires contributed or custom modules in order to exploit. For Drupal 8, this vulnerability was already fixed in Drupal 8.4.0 in the Drupal core upgrade to jQuery 3. For Drupal 7, it is fixed in the
nvd
CVE-2023-3180P4MEDIUMCVSS 6.5v10.02023-08-03
CVE-2023-3180 [MEDIUM] CWE-122 CVE-2023-3180: A flaw was found in the QEMU virtual crypto device while handling data encryption/decryption request
A flaw was found in the QEMU virtual crypto device while handling data encryption/decryption requests in virtio_crypto_handle_sym_req. There is no check for the value of `src_len` and `dst_len` in virtio_crypto_sym_op_helper, potentially leading to a heap buffer overflow when the two values differ.
nvd
CVE-2017-18121P4MEDIUMCVSS 6.1v7.0v8.0+1 more2018-02-02
CVE-2017-18121 [MEDIUM] CWE-79 CVE-2017-18121: The consentAdmin module in SimpleSAMLphp through 1.14.15 is vulnerable to a Cross-Site Scripting att
The consentAdmin module in SimpleSAMLphp through 1.14.15 is vulnerable to a Cross-Site Scripting attack, allowing an attacker to craft links that could execute arbitrary JavaScript code on the victim's web browser.
nvd
CVE-2014-3616P4MEDIUMCVSS 4.3v7.0v8.02014-12-08
CVE-2014-3616 [MEDIUM] CWE-613 CVE-2014-3616: nginx 0.5.6 through 1.7.4, when using the same shared ssl_session_cache or ssl_session_ticket_key fo
nginx 0.5.6 through 1.7.4, when using the same shared ssl_session_cache or ssl_session_ticket_key for multiple servers, can reuse a cached SSL session for an unrelated context, which allows remote attackers with certain privileges to conduct "virtual host confusion" attacks.
nvd
CVE-2018-11408P4MEDIUMCVSS 6.1v8.02018-06-13
CVE-2018-11408 [MEDIUM] CVE-2018-11408: The security handlers in the Security component in Symfony in 2.7.x before 2.7.48, 2.8.x before 2.8.
The security handlers in the Security component in Symfony in 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11 have an Open redirect vulnerability when security.http_utils is inlined by a container. NOTE: this issue exists because of an incomplete fix for CVE-2017-16652.
nvd
CVE-2022-23520P4MEDIUMCVSS 6.1v10.02022-12-14
CVE-2022-23520 [MEDIUM] CWE-79 CVE-2022-23520: rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Prior to ve
rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Prior to version 1.4.4, there is a possible XSS vulnerability with certain configurations of Rails::Html::Sanitizer due to an incomplete fix of CVE-2022-32209. Rails::Html::Sanitizer may allow an attacker to inject content if the application developer has overrid
nvd
CVE-2014-9221P4MEDIUMCVSS 5.0v7.02015-01-07
CVE-2014-9221 [MEDIUM] CWE-19 CVE-2014-9221: strongSwan 4.5.x through 5.2.x before 5.2.1 allows remote attackers to cause a denial of service (in
strongSwan 4.5.x through 5.2.x before 5.2.1 allows remote attackers to cause a denial of service (invalid pointer dereference) via a crafted IKEv2 Key Exchange (KE) message with Diffie-Hellman (DH) group 1025.
nvd
CVE-2020-6470P4MEDIUMCVSS 6.1v9.0v10.02020-05-21
CVE-2020-6470 [MEDIUM] CWE-79 CVE-2020-6470: Insufficient validation of untrusted input in clipboard in Google Chrome prior to 83.0.4103.61 allow
Insufficient validation of untrusted input in clipboard in Google Chrome prior to 83.0.4103.61 allowed a local attacker to inject arbitrary scripts or HTML (UXSS) via crafted clipboard contents.
nvd
CVE-2010-3873P4MEDIUMCVSS 5.0v5.02011-01-03
CVE-2010-3873 [MEDIUM] CWE-119 CVE-2010-3873: The X.25 implementation in the Linux kernel before 2.6.36.2 does not properly parse facilities, whic
The X.25 implementation in the Linux kernel before 2.6.36.2 does not properly parse facilities, which allows remote attackers to cause a denial of service (heap memory corruption and panic) or possibly have unspecified other impact via malformed (1) X25_FAC_CALLING_AE or (2) X25_FAC_CALLED_AE data, related to net/x25/x25_facilities.c and net/x25/x25_i
nvd
CVE-2014-9745P4MEDIUMCVSS 5.0v7.0v8.02015-09-14
CVE-2014-9745 [MEDIUM] CWE-399 CVE-2014-9745: The parse_encoding function in type1/t1load.c in FreeType before 2.5.3 allows remote attackers to ca
The parse_encoding function in type1/t1load.c in FreeType before 2.5.3 allows remote attackers to cause a denial of service (infinite loop) via a "broken number-with-base" in a Postscript stream, as demonstrated by 8#garbage.
nvd
CVE-2020-26418P4MEDIUMCVSS 5.3v9.02020-12-11
CVE-2020-26418 [MEDIUM] CWE-401 CVE-2020-26418: Memory leak in Kafka protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of servi
Memory leak in Kafka protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.
nvd
CVE-2021-37999P4MEDIUMCVSS 6.1v10.0v11.02021-11-23
CVE-2021-37999 [MEDIUM] CWE-79 CVE-2021-37999: Insufficient data validation in New Tab Page in Google Chrome prior to 95.0.4638.69 allowed a remote
Insufficient data validation in New Tab Page in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to inject arbitrary scripts or HTML in a new browser tab via a crafted HTML page.
nvd
CVE-2022-0529P4MEDIUMCVSS 5.5v10.0v11.02022-02-09
CVE-2022-0529 [MEDIUM] CWE-787 CVE-2022-0529: A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a loca
A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.
nvd
CVE-2015-3310P4MEDIUMCVSS 4.3v7.02015-04-24
CVE-2015-3310 [MEDIUM] CWE-119 CVE-2015-3310: Buffer overflow in the rc_mksid function in plugins/radius/util.c in Paul's PPP Package (ppp) 2.4.6
Buffer overflow in the rc_mksid function in plugins/radius/util.c in Paul's PPP Package (ppp) 2.4.6 and earlier, when the PID for pppd is greater than 65535, allows remote attackers to cause a denial of service (crash) via a start accounting message to the RADIUS server.
nvd
CVE-2020-8020P4MEDIUMCVSS 6.1v9.02020-05-13
CVE-2020-8020 [MEDIUM] CWE-79 CVE-2020-8020: A Improper Neutralization of Input During Web Page Generation vulnerability in open-build-service al
A Improper Neutralization of Input During Web Page Generation vulnerability in open-build-service allows remote attackers to store arbitrary JS code to cause XSS. This issue affects: openSUSE open-build-service versions prior to 7cc32c8e2ff7290698e101d9a80a9dc29a5500fb.
nvd
CVE-2022-23518P4MEDIUMCVSS 6.1v10.02022-12-14
CVE-2022-23518 [MEDIUM] CWE-79 CVE-2022-23518: rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Versions >=
rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Versions >= 1.0.3, = 2.1.0. This issue is patched in version 1.4.4.
nvd
CVE-2018-6070P4MEDIUMCVSS 6.1v9.02018-11-14
CVE-2018-6070 [MEDIUM] CWE-79 CVE-2018-6070: Lack of CSP enforcement on WebUI pages in Bink in Google Chrome prior to 65.0.3325.146 allowed an at
Lack of CSP enforcement on WebUI pages in Bink in Google Chrome prior to 65.0.3325.146 allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a crafted Chrome Extension.
nvd
CVE-2018-18245P4MEDIUMCVSS 5.4v8.02018-12-17
CVE-2018-18245 [MEDIUM] CWE-79 CVE-2018-18245: Nagios Core 4.4.2 has XSS via the alert summary reports of plugin results, as demonstrated by a SCRI
Nagios Core 4.4.2 has XSS via the alert summary reports of plugin results, as demonstrated by a SCRIPT element delivered by a modified check_load plugin to NRPE.
nvd