cbcvebase.

Debian Linux vulnerabilities

9,955 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358

Vulnerabilities

Page 365 of 498
CVE-2020-14330P4MEDIUMCVSS 5.5v10.02020-09-11
CVE-2020-14330 [MEDIUM] CWE-532 CVE-2020-14330: An Improper Output Neutralization for Logs flaw was found in Ansible when using the uri module, wher An Improper Output Neutralization for Logs flaw was found in Ansible when using the uri module, where sensitive data is exposed to content and json output. This flaw allows an attacker to access the logs or outputs of performed tasks to read keys used in playbooks from other users within the uri module. The highest threat from this vulnerability is
nvd
CVE-2014-3690P4MEDIUMCVSS 5.5v7.02014-11-10
CVE-2014-3690 [MEDIUM] CWE-400 CVE-2014-3690: arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 3.17.2 on Intel processors does n arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 3.17.2 on Intel processors does not ensure that the value in the CR4 control register remains the same after a VM entry, which allows host OS users to kill arbitrary processes or cause a denial of service (system disruption) by leveraging /dev/kvm access, as demonstrated by PR_SET_TSC
nvd
CVE-2018-18710P4MEDIUMCVSS 5.5v8.02018-10-29
CVE-2018-18710 [MEDIUM] CVE-2018-18710: An issue was discovered in the Linux kernel through 4.19. An information leak in cdrom_ioctl_select_ An issue was discovered in the Linux kernel through 4.19. An information leak in cdrom_ioctl_select_disc in drivers/cdrom/cdrom.c could be used by local attackers to read kernel memory because a cast from unsigned long to int interferes with bounds checking. This is similar to CVE-2018-10940 and CVE-2018-16658.
nvd
CVE-2023-52699P4MEDIUMCVSS 5.3v10.02024-05-19
CVE-2023-52699 [MEDIUM] CWE-667 CVE-2023-52699: In the Linux kernel, the following vulnerability has been resolved: sysv: don't call sb_bread() wit In the Linux kernel, the following vulnerability has been resolved: sysv: don't call sb_bread() with pointers_lock held syzbot is reporting sleep in atomic context in SysV filesystem [1], for sb_bread() is called with rw_spinlock held. A "write_lock(&pointers_lock) => read_lock(&pointers_lock) deadlock" bug and a "sb_bread() with write_lock(&point
nvd
CVE-2021-0561P4MEDIUMCVSS 5.5v9.0v10.02021-06-22
CVE-2021-0561 [MEDIUM] CWE-787 CVE-2021-0561: In append_to_verify_fifo_interleaved_ of stream_encoder.c, there is a possible out of bounds write d In append_to_verify_fifo_interleaved_ of stream_encoder.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-174302683
nvd
CVE-2020-10942P4MEDIUMCVSS 5.3v8.0v9.0+1 more2020-03-24
CVE-2020-10942 [MEDIUM] CWE-787 CVE-2020-10942: In the Linux kernel before 5.5.8, get_raw_socket in drivers/vhost/net.c lacks validation of an sk_fa In the Linux kernel before 5.5.8, get_raw_socket in drivers/vhost/net.c lacks validation of an sk_family field, which might allow attackers to trigger kernel stack corruption via crafted system calls.
nvd
CVE-2020-10729P4MEDIUMCVSS 5.5v10.02021-05-27
CVE-2020-10729 [MEDIUM] CWE-330 CVE-2020-10729: A flaw was found in the use of insufficiently random values in Ansible. Two random password lookups A flaw was found in the use of insufficiently random values in Ansible. Two random password lookups of the same length generate the equal value as the template caching action for the same file since no re-evaluation happens. The highest threat from this vulnerability would be that all passwords are exposed at once for the file. This flaw affects Ansi
nvd
CVE-2020-3812P4MEDIUMCVSS 5.5v8.0v9.0+1 more2020-05-26
CVE-2020-3812 [MEDIUM] CWE-269 CVE-2020-3812: qmail-verify as used in netqmail 1.06 is prone to an information disclosure vulnerability. A local a qmail-verify as used in netqmail 1.06 is prone to an information disclosure vulnerability. A local attacker can test for the existence of files and directories anywhere in the filesystem because qmail-verify runs as root and tests for the existence of files in the attacker's home directory, without dropping its privileges first.
nvd
CVE-2020-14332P4MEDIUMCVSS 5.5v10.02020-09-11
CVE-2020-14332 [MEDIUM] CWE-117 CVE-2020-14332: A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--che A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not properly neutralize sensitive data exposed in the event data. This flaw allows unauthorized users to read this data. The highest threat from this vulnerability is to confidentiality.
nvd
CVE-2020-26571P4MEDIUMCVSS 5.5v9.02020-10-06
CVE-2020-26571 [MEDIUM] CWE-787 CVE-2020-26571: The gemsafe GPK smart card software driver in OpenSC before 0.21.0-rc1 has a stack-based buffer over The gemsafe GPK smart card software driver in OpenSC before 0.21.0-rc1 has a stack-based buffer overflow in sc_pkcs15emu_gemsafeGPK_init.
nvd
CVE-2020-26572P4MEDIUMCVSS 5.5v9.02020-10-06
CVE-2020-26572 [MEDIUM] CWE-787 CVE-2020-26572: The TCOS smart card software driver in OpenSC before 0.21.0-rc1 has a stack-based buffer overflow in The TCOS smart card software driver in OpenSC before 0.21.0-rc1 has a stack-based buffer overflow in tcos_decipher.
nvd
CVE-2021-28700P4MEDIUMCVSS 4.9v11.02021-08-27
CVE-2021-28700 [MEDIUM] CWE-770 CVE-2021-28700: xen/arm: No memory limit for dom0less domUs The dom0less feature allows an administrator to create m xen/arm: No memory limit for dom0less domUs The dom0less feature allows an administrator to create multiple unprivileged domains directly from Xen. Unfortunately, the memory limit from them is not set. This allow a domain to allocate memory beyond what an administrator originally configured.
nvd
CVE-2020-2767P4MEDIUMCVSS 4.8v10.02020-04-15
CVE-2020-2767 [MEDIUM] CVE-2020-2767: Vulnerability in the Java SE product of Oracle Java SE (component: JSSE). Supported versions that ar Vulnerability in the Java SE product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 11.0.6 and 14. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to
nvd
CVE-2025-39770P4MEDIUMCVSS 5.5v11.02025-09-11
CVE-2025-39770 [MEDIUM] CVE-2025-39770: In the Linux kernel, the following vulnerability has been resolved: net: gso: Forbid IPv6 TSO with In the Linux kernel, the following vulnerability has been resolved: net: gso: Forbid IPv6 TSO with extensions on devices with only IPV6_CSUM When performing Generic Segmentation Offload (GSO) on an IPv6 packet that contains extension headers, the kernel incorrectly requests checksum offload if the egress device only advertises NETIF_F_IPV6_CSUM feature, whi
nvd
CVE-2021-26313P4MEDIUMCVSS 5.5v10.02021-06-09
CVE-2021-26313 [MEDIUM] CWE-208 CVE-2021-26313: Potential speculative code store bypass in all supported CPU products, in conjunction with software Potential speculative code store bypass in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution of overwritten instructions, may cause an incorrect speculation and could result in data leakage.
nvd
CVE-2021-31829P4MEDIUMCVSS 5.5v9.02021-05-06
CVE-2021-31829 [MEDIUM] CWE-863 CVE-2021-31829: kernel/bpf/verifier.c in the Linux kernel through 5.12.1 performs undesirable speculative loads, lea kernel/bpf/verifier.c in the Linux kernel through 5.12.1 performs undesirable speculative loads, leading to disclosure of stack content via side-channel attacks, aka CID-801c6058d14a. The specific concern is not protecting the BPF stack area against speculative loads. Also, the BPF stack can contain uninitialized data that might represent sensitive
nvd
CVE-2023-6206P4MEDIUMCVSS 5.4v10.0v11.0+1 more2023-11-21
CVE-2023-6206 [MEDIUM] CWE-1021 CVE-2023-6206: The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking dela The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking delay on permission prompts. It was possible to use this fact to surprise users by luring them to click where the permission grant button would be about to appear. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
nvd
CVE-2022-36354P4MEDIUMCVSS 5.3v11.02022-12-22
CVE-2022-36354 [MEDIUM] CWE-193 CVE-2022-36354: A heap out-of-bounds read vulnerability exists in the RLA format parser of OpenImageIO master-branch A heap out-of-bounds read vulnerability exists in the RLA format parser of OpenImageIO master-branch-9aeece7a and v2.3.19.0. More specifically, in the way run-length encoded byte spans are handled. A malformed RLA file can lead to an out-of-bounds read of heap metadata which can result in sensitive information leak. An attacker can provide a malicio
nvd
CVE-2023-4361P4MEDIUMCVSS 5.3v11.0v12.02023-08-15
CVE-2023-4361 [MEDIUM] CVE-2023-4361: Inappropriate implementation in Autofill in Google Chrome on Android prior to 116.0.5845.96 allowed Inappropriate implementation in Autofill in Google Chrome on Android prior to 116.0.5845.96 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2010-3440P4MEDIUMCVSS 5.5v8.0v9.0+1 more2019-11-12
CVE-2010-3440 [MEDIUM] CWE-494 CVE-2010-3440: babiloo 2.0.9 before 2.0.11 creates temporary files with predictable names when downloading and unpa babiloo 2.0.9 before 2.0.11 creates temporary files with predictable names when downloading and unpacking dictionary files, allowing a local attacker to overwrite arbitrary files.
nvd
Debian Linux vulnerabilities | cvebase