cbcvebase.

Debian Linux vulnerabilities

9,955 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358

Vulnerabilities

Page 364 of 498
CVE-2020-35477P4MEDIUMCVSS 5.3v9.0v10.02020-12-18
CVE-2020-35477 [MEDIUM] CWE-670 CVE-2020-35477: MediaWiki before 1.35.1 blocks legitimate attempts to hide log entries in some situations. If one se MediaWiki before 1.35.1 blocks legitimate attempts to hide log entries in some situations. If one sets MediaWiki:Mainpage to Special:MyLanguage/Main Page, visits a log entry on Special:Log, and toggles the "Change visibility of selected log entries" checkbox (or a tags checkbox) next to it, there is a redirection to the main page's action=historysub
nvd
CVE-2017-15417P4MEDIUMCVSS 5.3v9.02018-08-28
CVE-2017-15417 [MEDIUM] CWE-119 CVE-2017-15417: Inappropriate implementation in Skia canvas composite operations in Google Chrome prior to 63.0.3239 Inappropriate implementation in Skia canvas composite operations in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2023-4875P4MEDIUMCVSS 5.7v10.0v11.0+1 more2023-09-09
CVE-2023-4875 [MEDIUM] CWE-475 CVE-2023-4875: Null pointer dereference when composing from a specially crafted draft message in Mutt >1.5.2 <2.2.1 Null pointer dereference when composing from a specially crafted draft message in Mutt >1.5.2 <2.2.12
nvd
CVE-2020-0499P4MEDIUMCVSS 4.3v9.02020-12-15
CVE-2020-0499 [MEDIUM] CWE-125 CVE-2020-0499: In FLAC__bitreader_read_rice_signed_block of bitreader.c, there is a possible out of bounds read due In FLAC__bitreader_read_rice_signed_block of bitreader.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-156076070
nvd
CVE-2018-20217P4MEDIUMCVSS 5.3v8.0v9.02018-12-26
CVE-2018-20217 [MEDIUM] CWE-617 CVE-2018-20217: A Reachable Assertion issue was discovered in the KDC in MIT Kerberos 5 (aka krb5) before 1.17. If a A Reachable Assertion issue was discovered in the KDC in MIT Kerberos 5 (aka krb5) before 1.17. If an attacker can obtain a krbtgt ticket using an older encryption type (single-DES, triple-DES, or RC4), the attacker can crash the KDC by making an S4U2Self request.
nvd
CVE-2020-6425P4MEDIUMCVSS 5.4v9.0v10.02020-03-23
CVE-2020-6425 [MEDIUM] CWE-20 CVE-2020-6425: Insufficient policy enforcement in extensions in Google Chrome prior to 80.0.3987.149 allowed an att Insufficient policy enforcement in extensions in Google Chrome prior to 80.0.3987.149 allowed an attacker who convinced a user to install a malicious extension to bypass site isolation via a crafted Chrome Extension.
nvd
CVE-2015-1165P4MEDIUMCVSS 5.0v7.02015-03-09
CVE-2015-1165 [MEDIUM] CWE-200 CVE-2015-1165: RT (aka Request Tracker) 3.8.8 through 4.x before 4.0.23 and 4.2.x before 4.2.10 allows remote attac RT (aka Request Tracker) 3.8.8 through 4.x before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to obtain sensitive RSS feed URLs and ticket data via unspecified vectors.
nvd
CVE-2017-5042P4MEDIUMCVSS 5.7v8.0v9.02017-04-24
CVE-2017-5042 [MEDIUM] CWE-311 CVE-2017-5042: Cast in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Androi Cast in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android sent cookies to sites discovered via SSDP, which allowed an attacker on the local network segment to initiate connections to arbitrary URLs and observe any plaintext cookies sent.
nvd
CVE-2022-3435P4MEDIUMCVSS 4.3v10.02022-10-08
CVE-2022-3435 [MEDIUM] CWE-119 CVE-2022-3435: A vulnerability classified as problematic has been found in Linux Kernel. This affects the function A vulnerability classified as problematic has been found in Linux Kernel. This affects the function fib_nh_match of the file net/ipv4/fib_semantics.c of the component IPv4 Handler. The manipulation leads to out-of-bounds read. It is possible to initiate the attack remotely. It is recommended to apply a patch to fix this issue. The identifier VDB-210357
nvd
CVE-2019-15902P4MEDIUMCVSS 5.6v8.0v9.0+1 more2019-09-04
CVE-2019-15902 [MEDIUM] CWE-200 CVE-2019-15902: A backporting error was discovered in the Linux stable/longterm kernel 4.4.x through 4.4.190, 4.9.x A backporting error was discovered in the Linux stable/longterm kernel 4.4.x through 4.4.190, 4.9.x through 4.9.190, 4.14.x through 4.14.141, 4.19.x through 4.19.69, and 5.2.x through 5.2.11. Misuse of the upstream "x86/ptrace: Fix possible spectre-v1 in ptrace_get_debugreg()" commit reintroduced the Spectre vulnerability that it aimed to eliminate.
nvd
CVE-2012-2351P4MEDIUMCVSS 5.0v6.02012-07-12
CVE-2012-2351 [MEDIUM] CWE-16 CVE-2012-2351: The default configuration of the auth/saml plugin in Mahara before 1.4.2 sets the "Match username at The default configuration of the auth/saml plugin in Mahara before 1.4.2 sets the "Match username attribute to Remote username" option to false, which allows remote SAML IdP servers to spoof users of other SAML IdP servers by using the same internal username.
nvd
CVE-2020-24586P4LOWCVSS 3.5v9.02021-05-11
CVE-2020-24586 [LOW] CVE-2020-24586: The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that received fragments be cleared from memory after (re)connecting to a network. Under the right circumstances, when another device sends fragmented frames encrypted using WEP, CCMP, or GCMP, this can be abused to inject arbitrary
nvd
CVE-2020-36422P4MEDIUMCVSS 5.3v10.02021-07-19
CVE-2020-36422 [MEDIUM] CWE-203 CVE-2020-36422: An issue was discovered in Arm Mbed TLS before 2.23.0. A side channel allows recovery of an ECC priv An issue was discovered in Arm Mbed TLS before 2.23.0. A side channel allows recovery of an ECC private key, related to mbedtls_ecp_check_pub_priv, mbedtls_pk_parse_key, mbedtls_pk_parse_keyfile, mbedtls_ecp_mul, and mbedtls_ecp_mul_restartable.
nvd
CVE-2019-12467P4MEDIUMCVSS 5.3v9.02019-07-10
CVE-2019-12467 [MEDIUM] CVE-2019-12467: MediaWiki through 1.32.1 has Incorrect Access Control (issue 1 of 3). A spammer can use Special:Chan MediaWiki through 1.32.1 has Incorrect Access Control (issue 1 of 3). A spammer can use Special:ChangeEmail to send out spam with no rate limiting or ability to block them. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
nvd
CVE-2022-23960P4MEDIUMCVSS 5.6v9.0v10.02022-03-13
CVE-2022-23960 [MEDIUM] CVE-2022-23960: Certain Arm Cortex and Neoverse processors through 2022-03-08 do not properly restrict cache specula Certain Arm Cortex and Neoverse processors through 2022-03-08 do not properly restrict cache speculation, aka Spectre-BHB. An attacker can leverage the shared branch history in the Branch History Buffer (BHB) to influence mispredicted branches. Then, cache allocation can allow the attacker to obtain sensitive information.
nvd
CVE-2023-4046P4MEDIUMCVSS 5.3v11.0v12.02023-08-01
CVE-2023-4046 [MEDIUM] CWE-770 CVE-2023-4046: In some circumstances, a stale value could have been used for a global variable in WASM JIT analysis In some circumstances, a stale value could have been used for a global variable in WASM JIT analysis. This resulted in incorrect compilation and a potentially exploitable crash in the content process. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.
nvd
CVE-2019-2999P4MEDIUMCVSS 4.7v8.0v9.0+1 more2019-10-16
CVE-2019-2999 [MEDIUM] CVE-2019-2999: Vulnerability in the Java SE product of Oracle Java SE (component: Javadoc). Supported versions that Vulnerability in the Java SE product of Oracle Java SE (component: Javadoc). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than th
nvd
CVE-2015-5144P4MEDIUMCVSS 4.3v7.0v8.02015-07-14
CVE-2015-5144 [MEDIUM] CWE-20 CVE-2015-5144: Django before 1.4.21, 1.5.x through 1.6.x, 1.7.x before 1.7.9, and 1.8.x before 1.8.3 uses an incorr Django before 1.4.21, 1.5.x through 1.6.x, 1.7.x before 1.7.9, and 1.8.x before 1.8.3 uses an incorrect regular expression, which allows remote attackers to inject arbitrary headers and conduct HTTP response splitting attacks via a newline character in an (1) email message to the EmailValidator, a (2) URL to the URLValidator, or unspecified vectors to
nvd
CVE-2017-7763P4MEDIUMCVSS 5.3v8.0v9.02018-06-11
CVE-2017-7763 [MEDIUM] CWE-20 CVE-2017-7763: Default fonts on OS X display some Tibetan characters as whitespace. When used in the addressbar as Default fonts on OS X display some Tibetan characters as whitespace. When used in the addressbar as part of an IDN this can be used for domain name spoofing attacks. Note: This attack only affects OS X operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
nvd
CVE-2020-8619P4MEDIUMCVSS 4.9v10.02020-06-17
CVE-2020-8619 [MEDIUM] CWE-404 CVE-2020-8619: In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -> 9.14.12, BIND 9.16.0 -> 9.16.3, BIND S In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -> 9.14.12, BIND 9.16.0 -> 9.16.3, BIND Supported Preview Edition 9.11.14-S1 -> 9.11.19-S1: Unless a nameserver is providing authoritative service for one or more zones and at least one zone contains an empty non-terminal entry containing an asterisk ("*") character, this defect cannot be enco
nvd
Debian Linux vulnerabilities | cvebase