cbcvebase.

Debian Linux vulnerabilities

9,955 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358

Vulnerabilities

Page 371 of 498
CVE-2021-28712P4MEDIUMCVSS 6.5v9.0v10.0+1 more2022-01-05
CVE-2021-28712 [MEDIUM] CVE-2021-28712: Rogue backends can cause DoS of guests via high frequency events T[his CNA information record relate Rogue backends can cause DoS of guests via high frequency events T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Xen offers the ability to run PV backends in regular unprivileged guests, typically referred to as "driver domains". Running PV backends in driver domains has one pr
nvd
CVE-2017-5938P4MEDIUMCVSS 6.1v8.02017-03-15
CVE-2017-5938 [MEDIUM] CWE-79 CVE-2017-5938: Cross-site scripting (XSS) vulnerability in the nav_path function in lib/viewvc.py in ViewVC before Cross-site scripting (XSS) vulnerability in the nav_path function in lib/viewvc.py in ViewVC before 1.0.14 and 1.1.x before 1.1.26 allows remote attackers to inject arbitrary web script or HTML via the nav_data name.
nvd
CVE-2021-45086P4MEDIUMCVSS 6.1v11.02021-12-16
CVE-2021-45086 [MEDIUM] CWE-79 CVE-2021-45086: XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 because a server's sugges XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 because a server's suggested_filename is used as the pdf_name value in PDF.js.
nvd
CVE-2022-42334P4MEDIUMCVSS 6.5v11.02023-03-21
CVE-2022-42334 [MEDIUM] CVE-2022-42334: x86/HVM pinned cache attributes mis-handling T[his CNA information record relates to multiple CVEs; x86/HVM pinned cache attributes mis-handling T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To allow cachability control for HVM guests with passed through devices, an interface exists to explicitly override defaults which would otherwise be put in place. While not exposed to t
nvd
CVE-2013-4158P4MEDIUMCVSS 6.1v8.0v9.0+1 more2019-12-11
CVE-2013-4158 [MEDIUM] CVE-2013-4158: smokeping before 2.6.9 has XSS (incomplete fix for CVE-2012-0790) smokeping before 2.6.9 has XSS (incomplete fix for CVE-2012-0790)
nvd
CVE-2017-5045P4MEDIUMCVSS 6.1v8.0v9.02017-04-24
CVE-2017-5045 [MEDIUM] CWE-79 CVE-2017-5045: XSS Auditor in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for XSS Auditor in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed detection of a blocked iframe load, which allowed a remote attacker to brute force JavaScript variables via a crafted HTML page.
nvd
CVE-2014-4913P4MEDIUMCVSS 6.1v8.02019-12-15
CVE-2014-4913 [MEDIUM] CWE-79 CVE-2014-4913: ZF2014-03 has a potential cross site scripting vector in multiple view helpers ZF2014-03 has a potential cross site scripting vector in multiple view helpers
nvd
CVE-2012-3972P4MEDIUMCVSS 5.0v6.0v7.02012-08-29
CVE-2012-3972 [MEDIUM] CWE-200 CVE-2012-3972: The format-number functionality in the XSLT implementation in Mozilla Firefox before 15.0, Firefox E The format-number functionality in the XSLT implementation in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to obtain sensitive information via unspecified vectors that trigger a heap-based buffer over-read.
nvd
CVE-2020-35738P4MEDIUMCVSS 6.1v9.02020-12-28
CVE-2020-35738 [MEDIUM] CWE-190 CVE-2020-35738: WavPack 5.3.0 has an out-of-bounds write in WavpackPackSamples in pack_utils.c because of an integer WavPack 5.3.0 has an out-of-bounds write in WavpackPackSamples in pack_utils.c because of an integer overflow in a malloc argument. NOTE: some third-parties claim that there are later "unofficial" releases through 5.3.2, which are also affected.
nvd
CVE-2018-14609P4MEDIUMCVSS 5.5v8.0v9.02018-07-27
CVE-2018-14609 [MEDIUM] CWE-476 CVE-2018-14609: An issue was discovered in the Linux kernel through 4.17.10. There is an invalid pointer dereference An issue was discovered in the Linux kernel through 4.17.10. There is an invalid pointer dereference in __del_reloc_root() in fs/btrfs/relocation.c when mounting a crafted btrfs image, related to removing reloc rb_trees when reloc control has not been initialized.
nvd
CVE-2022-28202P4MEDIUMCVSS 6.1v10.02022-03-30
CVE-2022-28202 [MEDIUM] CWE-79 CVE-2022-28202: An XSS issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37 An XSS issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. The widthheight, widthheightpage, and nbytes properties of messages are not escaped when used in galleries or Special:RevisionDelete.
nvd
CVE-2019-15945P4MEDIUMCVSS 6.4v8.0v9.02019-09-05
CVE-2019-15945 [MEDIUM] CWE-119 CVE-2019-15945: OpenSC before 0.20.0-rc1 has an out-of-bounds access of an ASN.1 Bitstring in decode_bit_string in l OpenSC before 0.20.0-rc1 has an out-of-bounds access of an ASN.1 Bitstring in decode_bit_string in libopensc/asn1.c.
nvd
CVE-2019-16392P4MEDIUMCVSS 6.1v8.0v9.0+1 more2019-09-17
CVE-2019-16392 [MEDIUM] CWE-79 CVE-2019-16392: SPIP before 3.1.11 and 3.2 before 3.2.5 allows prive/formulaires/login.php XSS via error messages. SPIP before 3.1.11 and 3.2 before 3.2.5 allows prive/formulaires/login.php XSS via error messages.
nvd
CVE-2018-6076P4MEDIUMCVSS 6.1v9.02018-11-14
CVE-2018-6076 [MEDIUM] CWE-79 CVE-2018-6076: Insufficient encoding of URL fragment identifiers in Blink in Google Chrome prior to 65.0.3325.146 a Insufficient encoding of URL fragment identifiers in Blink in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to perform a DOM based XSS attack via a crafted HTML page.
nvd
CVE-2019-15946P4MEDIUMCVSS 6.4v8.0v9.02019-09-05
CVE-2019-15946 [MEDIUM] CWE-119 CVE-2019-15946: OpenSC before 0.20.0-rc1 has an out-of-bounds access of an ASN.1 Octet string in asn1_decode_entry i OpenSC before 0.20.0-rc1 has an out-of-bounds access of an ASN.1 Octet string in asn1_decode_entry in libopensc/asn1.c.
nvd
CVE-2017-15574P4MEDIUMCVSS 6.1v9.02017-10-18
CVE-2017-15574 [MEDIUM] CWE-79 CVE-2017-15574: In Redmine before 3.2.6 and 3.3.x before 3.3.3, stored XSS is possible by using an SVG document as a In Redmine before 3.2.6 and 3.3.x before 3.3.3, stored XSS is possible by using an SVG document as an attachment.
nvd
CVE-2019-16393P4MEDIUMCVSS 6.1v8.0v9.0+1 more2019-09-17
CVE-2019-16393 [MEDIUM] CWE-601 CVE-2019-16393: SPIP before 3.1.11 and 3.2 before 3.2.5 mishandles redirect URLs in ecrire/inc/headers.php with a %0 SPIP before 3.1.11 and 3.2 before 3.2.5 mishandles redirect URLs in ecrire/inc/headers.php with a %0D, %0A, or %20 character.
nvd
CVE-2018-13096P4MEDIUMCVSS 5.5v8.02018-07-03
CVE-2018-13096 [MEDIUM] CWE-125 CVE-2018-13096: An issue was discovered in fs/f2fs/super.c in the Linux kernel through 4.14. A denial of service (ou An issue was discovered in fs/f2fs/super.c in the Linux kernel through 4.14. A denial of service (out-of-bounds memory access and BUG) can occur upon encountering an abnormal bitmap size when mounting a crafted f2fs image.
nvd
CVE-2024-27285P4MEDIUMCVSS 6.1v10.02024-02-28
CVE-2024-27285 [MEDIUM] CWE-79 CVE-2024-27285: YARD is a Ruby Documentation tool. The "frames.html" file within the Yard Doc's generated documentat YARD is a Ruby Documentation tool. The "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. This vulnerability is fixed in 0.9.36.
nvd
CVE-2021-44025P4MEDIUMCVSS 6.1v9.0v10.0+1 more2021-11-19
CVE-2021-44025 [MEDIUM] CWE-79 CVE-2021-44025: Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to XSS in handling an attachment's filename Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to XSS in handling an attachment's filename extension when displaying a MIME type warning message.
nvd
Debian Linux vulnerabilities | cvebase