Debian Linux vulnerabilities
9,955 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358
Vulnerabilities
Page 370 of 498
CVE-2015-7513P4MEDIUMCVSS 6.5v7.0v8.02016-02-08
CVE-2015-7513 [MEDIUM] CWE-369 CVE-2015-7513: arch/x86/kvm/x86.c in the Linux kernel before 4.4 does not reset the PIT counter values during state
arch/x86/kvm/x86.c in the Linux kernel before 4.4 does not reset the PIT counter values during state restoration, which allows guest OS users to cause a denial of service (divide-by-zero error and host OS crash) via a zero value, related to the kvm_vm_ioctl_set_pit and kvm_vm_ioctl_set_pit2 functions.
nvd
CVE-2009-5046P4MEDIUMCVSS 6.1v8.02019-11-06
CVE-2009-5046 [MEDIUM] CWE-79 CVE-2009-5046: JSP Dump and Session Dump Servlet XSS in jetty before 6.1.22.
JSP Dump and Session Dump Servlet XSS in jetty before 6.1.22.
nvd
CVE-2017-6832P4MEDIUMCVSS 5.5v8.0v9.02017-03-20
CVE-2017-6832 [MEDIUM] CWE-119 CVE-2017-6832: Heap-based buffer overflow in the decodeBlock in MSADPCM.cpp in Audio File Library (aka audiofile) 0
Heap-based buffer overflow in the decodeBlock in MSADPCM.cpp in Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0, 0.2.7 allows remote attackers to cause a denial of service (crash) via a crafted file.
nvd
CVE-2021-45087P4MEDIUMCVSS 6.1v10.0v11.02021-12-16
CVE-2021-45087 [MEDIUM] CWE-79 CVE-2021-45087: XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 when View Source mode or
XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 when View Source mode or Reader mode is used, as demonstrated by a a page title.
nvd
CVE-2021-45085P4MEDIUMCVSS 6.1v10.0v11.02021-12-16
CVE-2021-45085 [MEDIUM] CWE-79 CVE-2021-45085: XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an about: page, as de
XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an about: page, as demonstrated by ephy-about:overview when a user visits an XSS payload page often enough to place that page on the Most Visited list.
nvd
CVE-2018-19790P4MEDIUMCVSS 6.1v8.02018-12-18
CVE-2018-19790 [MEDIUM] CWE-601 CVE-2018-19790: An open redirect was discovered in Symfony 2.7.x before 2.7.50, 2.8.x before 2.8.49, 3.x before 3.4.
An open redirect was discovered in Symfony 2.7.x before 2.7.50, 2.8.x before 2.8.49, 3.x before 3.4.20, 4.0.x before 4.0.15, 4.1.x before 4.1.9 and 4.2.x before 4.2.1. By using backslashes in the `_failure_path` input field of login forms, an attacker can work around the redirection target restrictions and effectively redirect the user to any domain
nvd
CVE-2021-3544P4MEDIUMCVSS 6.5v11.02021-06-02
CVE-2021-3544 [MEDIUM] CWE-401 CVE-2021-3544: Several memory leaks were found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in vers
Several memory leaks were found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including 6.0. They exist in contrib/vhost-user-gpu/vhost-user-gpu.c and contrib/vhost-user-gpu/virgl.c due to improper release of memory (i.e., free) after effective lifetime.
nvd
CVE-2019-2537P4MEDIUMCVSS 4.9v8.02019-01-16
CVE-2019-2537 [MEDIUM] CVE-2019-2537: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported v
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.6.42 and prior, 5.7.24 and prior and 8.0.13 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerabili
nvd
CVE-2013-7370P4MEDIUMCVSS 6.1v8.0v9.0+1 more2019-12-11
CVE-2013-7370 [MEDIUM] CWE-79 CVE-2013-7370: node-connect before 2.8.1 has XSS in the Sencha Labs Connect middleware
node-connect before 2.8.1 has XSS in the Sencha Labs Connect middleware
nvd
CVE-2020-15563P4MEDIUMCVSS 6.5v10.02020-07-07
CVE-2020-15563 [MEDIUM] CWE-119 CVE-2020-15563: An issue was discovered in Xen through 4.13.x, allowing x86 HVM guest OS users to cause a hypervisor
An issue was discovered in Xen through 4.13.x, allowing x86 HVM guest OS users to cause a hypervisor crash. An inverted conditional in x86 HVM guests' dirty video RAM tracking code allows such guests to make Xen de-reference a pointer guaranteed to point at unmapped space. A malicious or buggy HVM guest may cause the hypervisor to crash, resulting i
nvd
CVE-2015-8613P4MEDIUMCVSS 6.5v8.02017-04-11
CVE-2015-8613 [MEDIUM] CWE-787 CVE-2015-8613: Stack-based buffer overflow in the megasas_ctrl_get_info function in QEMU, when built with SCSI Mega
Stack-based buffer overflow in the megasas_ctrl_get_info function in QEMU, when built with SCSI MegaRAID SAS HBA emulation support, allows local guest users to cause a denial of service (QEMU instance crash) via a crafted SCSI controller CTRL_GET_INFO command.
nvd
CVE-2008-5507P4MEDIUMCVSS 6.0v4.0v5.02008-12-17
CVE-2008-5507 [MEDIUM] CWE-200 CVE-2008-5507: Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMo
Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allow remote attackers to bypass the same origin policy and access portions of data from another domain via a JavaScript URL that redirects to the target resource, which generates an error if the target data does not have JavaScri
nvd
CVE-2020-15564P4MEDIUMCVSS 6.5v10.02020-07-07
CVE-2020-15564 [MEDIUM] CWE-119 CVE-2020-15564: An issue was discovered in Xen through 4.13.x, allowing Arm guest OS users to cause a hypervisor cra
An issue was discovered in Xen through 4.13.x, allowing Arm guest OS users to cause a hypervisor crash because of a missing alignment check in VCPUOP_register_vcpu_info. The hypercall VCPUOP_register_vcpu_info is used by a guest to register a shared region with the hypervisor. The region will be mapped into Xen address space so it can be directly ac
nvd
CVE-2008-4989P4MEDIUMCVSS 5.9v4.02008-11-13
CVE-2008-4989 [MEDIUM] CWE-295 CVE-2008-4989: The _gnutls_x509_verify_certificate function in lib/x509/verify.c in libgnutls in GnuTLS before 2.6.
The _gnutls_x509_verify_certificate function in lib/x509/verify.c in libgnutls in GnuTLS before 2.6.1 trusts certificate chains in which the last certificate is an arbitrary trusted, self-signed certificate, which allows man-in-the-middle attackers to insert a spoofed certificate for any Distinguished Name (DN).
nvd
CVE-2021-0089P4MEDIUMCVSS 6.5v10.02021-06-09
CVE-2021-0089 [MEDIUM] CWE-203 CVE-2021-0089: Observable response discrepancy in some Intel(R) Processors may allow an authorized user to potentia
Observable response discrepancy in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.
nvd
CVE-2021-43543P4MEDIUMCVSS 6.1v9.0v10.0+1 more2021-12-08
CVE-2021-43543 [MEDIUM] CWE-79 CVE-2021-43543: Documents loaded with the CSP sandbox directive could have escaped the sandbox's script restriction
Documents loaded with the CSP sandbox directive could have escaped the sandbox's script restriction by embedding additional content. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
nvd
CVE-2020-29568P4MEDIUMCVSS 6.5v9.0v10.02020-12-15
CVE-2020-29568 [MEDIUM] CWE-770 CVE-2020-29568: An issue was discovered in Xen through 4.14.x. Some OSes (such as Linux, FreeBSD, and NetBSD) are pr
An issue was discovered in Xen through 4.14.x. Some OSes (such as Linux, FreeBSD, and NetBSD) are processing watch events using a single thread. If the events are received faster than the thread is able to handle, they will get queued. As the queue is unbounded, a guest may be able to trigger an OOM in the backend. All systems with a FreeBSD, Linux,
nvd
CVE-2021-3930P4MEDIUMCVSS 6.5v9.0v10.02022-02-18
CVE-2021-3930 [MEDIUM] CWE-193 CVE-2021-3930: An off-by-one error was found in the SCSI device emulation in QEMU. It could occur while processing
An off-by-one error was found in the SCSI device emulation in QEMU. It could occur while processing MODE SELECT commands in mode_sense_page() if the 'page' argument was set to MODE_PAGE_ALLS (0x3f). A malicious guest could use this flaw to potentially crash QEMU, resulting in a denial of service condition.
nvd
CVE-2021-28713P4MEDIUMCVSS 6.5v9.0v10.0+1 more2022-01-05
CVE-2021-28713 [MEDIUM] CVE-2021-28713: Rogue backends can cause DoS of guests via high frequency events T[his CNA information record relate
Rogue backends can cause DoS of guests via high frequency events T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Xen offers the ability to run PV backends in regular unprivileged guests, typically referred to as "driver domains". Running PV backends in driver domains has one pr
nvd
CVE-2021-28711P4MEDIUMCVSS 6.5v9.0v10.0+1 more2022-01-05
CVE-2021-28711 [MEDIUM] CVE-2021-28711: Rogue backends can cause DoS of guests via high frequency events T[his CNA information record relate
Rogue backends can cause DoS of guests via high frequency events T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Xen offers the ability to run PV backends in regular unprivileged guests, typically referred to as "driver domains". Running PV backends in driver domains has one pr
nvd