cbcvebase.

Debian Linux vulnerabilities

9,955 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358

Vulnerabilities

Page 373 of 498
CVE-2017-5383P4MEDIUMCVSS 5.3v8.02018-06-11
CVE-2017-5383 [MEDIUM] CWE-20 CVE-2017-5383: URLs containing certain unicode glyphs for alternative hyphens and quotes do not properly trigger pu URLs containing certain unicode glyphs for alternative hyphens and quotes do not properly trigger punycode display, allowing for domain name spoofing attacks in the location bar. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
nvd
CVE-2015-6496P4MEDIUMCVSS 5.0v7.0v8.02015-08-24
CVE-2015-6496 [MEDIUM] CWE-17 CVE-2015-6496: conntrackd in conntrack-tools 1.4.2 and earlier does not ensure that the optional kernel modules are conntrackd in conntrack-tools 1.4.2 and earlier does not ensure that the optional kernel modules are loaded before using them, which allows remote attackers to cause a denial of service (crash) via a (1) DCCP, (2) SCTP, or (3) ICMPv6 packet.
nvd
CVE-2021-1094P4MEDIUMCVSS 6.1v9.02021-07-22
CVE-2021-1094 [MEDIUM] CWE-125 CVE-2021-1094: NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (n NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where an out of bounds array access may lead to denial of service or information disclosure.
nvd
CVE-2013-2881P4MEDIUMCVSS 5.8v7.02013-07-31
CVE-2013-2881 [MEDIUM] CWE-264 CVE-2013-2881: Google Chrome before 28.0.1500.95 does not properly handle frames, which allows remote attackers to Google Chrome before 28.0.1500.95 does not properly handle frames, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.
nvd
CVE-2020-27171P4MEDIUMCVSS 6.0v9.02021-03-20
CVE-2020-27171 [MEDIUM] CWE-193 CVE-2020-27171: An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c has an off-by-one e An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c has an off-by-one error (with a resultant integer underflow) affecting out-of-bounds speculation on pointer arithmetic, leading to side-channel attacks that defeat Spectre mitigations and obtain sensitive information from kernel memory, aka CID-10d2bb2e6b1d.
nvd
CVE-2016-4428P4MEDIUMCVSS 5.4v8.0v9.02016-07-12
CVE-2016-4428 [MEDIUM] CWE-79 CVE-2016-4428: Cross-site scripting (XSS) vulnerability in OpenStack Dashboard (Horizon) 8.0.1 and earlier and 9.0. Cross-site scripting (XSS) vulnerability in OpenStack Dashboard (Horizon) 8.0.1 and earlier and 9.0.0 through 9.0.1 allows remote authenticated users to inject arbitrary web script or HTML by injecting an AngularJS template in a dashboard form.
nvd
CVE-2020-25211P4MEDIUMCVSS 6.0v9.0v10.02020-09-09
CVE-2020-25211 [MEDIUM] CWE-120 CVE-2020-25211: In the Linux kernel through 5.8.7, local attackers able to inject conntrack netlink configuration co In the Linux kernel through 5.8.7, local attackers able to inject conntrack netlink configuration could overflow a local buffer, causing crashes or triggering use of incorrect protocol numbers in ctnetlink_parse_tuple_filter in net/netfilter/nf_conntrack_netlink.c, aka CID-1cc5ef91d2ff.
nvd
CVE-2016-9601P4MEDIUMCVSS 5.5v8.0v9.02018-04-24
CVE-2016-9601 [MEDIUM] CWE-190 CVE-2016-9601: ghostscript before version 9.21 is vulnerable to a heap based buffer overflow that was found in the ghostscript before version 9.21 is vulnerable to a heap based buffer overflow that was found in the ghostscript jbig2_decode_gray_scale_image function which is used to decode halftone segments in a JBIG2 image. A document (PostScript or PDF) with an embedded, specially crafted, jbig2 image could trigger a segmentation fault in ghostscript.
nvd
CVE-2020-6516P4MEDIUMCVSS 4.3v10.02020-07-22
CVE-2020-6516 [MEDIUM] CVE-2020-6516: Policy bypass in CORS in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross Policy bypass in CORS in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2017-17093P4MEDIUMCVSS 5.4v7.0v8.0+1 more2017-12-02
CVE-2017-17093 [MEDIUM] CWE-79 CVE-2017-17093: wp-includes/general-template.php in WordPress before 4.9.1 does not properly restrict the lang attri wp-includes/general-template.php in WordPress before 4.9.1 does not properly restrict the lang attribute of an HTML element, which might allow attackers to conduct XSS attacks via the language setting of a site.
nvd
CVE-2018-16062P4MEDIUMCVSS 5.5v8.0v9.02018-08-29
CVE-2018-16062 [MEDIUM] CWE-125 CVE-2018-16062: dwarf_getaranges in dwarf_getaranges.c in libdw in elfutils before 2018-08-18 allows remote attacker dwarf_getaranges in dwarf_getaranges.c in libdw in elfutils before 2018-08-18 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file.
nvd
CVE-2007-2833P4HIGHCVSS 7.8v4.02007-06-21
CVE-2007-2833 [HIGH] CVE-2007-2833: Emacs 21 allows user-assisted attackers to cause a denial of service (crash) via certain crafted ima Emacs 21 allows user-assisted attackers to cause a denial of service (crash) via certain crafted images, as demonstrated via a GIF image in vm mode, related to image size calculation.
nvd
CVE-2017-3641P4MEDIUMCVSS 4.9v8.0v9.02017-08-08
CVE-2017-3641 [MEDIUM] CVE-2017-3641: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML). Supported v Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML). Supported versions that are affected are 5.5.56 and earlier, 5.6.36 and earlier and 5.7.18 and earlier. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulne
nvd
CVE-2020-11759P4MEDIUMCVSS 5.5v9.0v10.02020-04-14
CVE-2020-11759 [MEDIUM] CWE-190 CVE-2020-11759: An issue was discovered in OpenEXR before 2.4.1. Because of integer overflows in CompositeDeepScanLi An issue was discovered in OpenEXR before 2.4.1. Because of integer overflows in CompositeDeepScanLine::Data::handleDeepFrameBuffer and readSampleCountForLineBlock, an attacker can write to an out-of-bounds pointer.
nvd
CVE-2022-24130P4MEDIUMCVSS 5.5v9.02022-01-31
CVE-2022-24130 [MEDIUM] CWE-120 CVE-2022-24130: xterm through Patch 370, when Sixel support is enabled, allows attackers to trigger a buffer overflo xterm through Patch 370, when Sixel support is enabled, allows attackers to trigger a buffer overflow in set_sixel in graphics_sixel.c via crafted text.
nvd
CVE-2021-21217P4MEDIUMCVSS 5.5v10.02021-04-26
CVE-2021-21217 [MEDIUM] CWE-252 CVE-2021-21217: Uninitialized data in PDFium in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to obt Uninitialized data in PDFium in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted PDF file.
nvd
CVE-2020-27824P4MEDIUMCVSS 5.5v9.0v10.02021-05-13
CVE-2020-27824 [MEDIUM] CWE-20 CVE-2020-27824: A flaw was found in OpenJPEG’s encoder in the opj_dwt_calc_explicit_stepsizes() function. This flaw A flaw was found in OpenJPEG’s encoder in the opj_dwt_calc_explicit_stepsizes() function. This flaw allows an attacker who can supply crafted input to decomposition levels to cause a buffer overflow. The highest threat from this vulnerability is to system availability.
nvd
CVE-2019-1010305P4MEDIUMCVSS 5.5v8.0v9.02019-07-15
CVE-2019-1010305 [MEDIUM] CWE-119 CVE-2019-1010305: libmspack 0.9.1alpha is affected by: Buffer Overflow. The impact is: Information Disclosure. The com libmspack 0.9.1alpha is affected by: Buffer Overflow. The impact is: Information Disclosure. The component is: function chmd_read_headers() in libmspack(file libmspack/mspack/chmd.c). The attack vector is: the victim must open a specially crafted chm file. The fixed version is: after commit 2f084136cfe0d05e5bf5703f3e83c6d955234b4d.
nvd
CVE-2024-26894P4MEDIUMCVSS 6.0v10.02024-04-17
CVE-2024-26894 [MEDIUM] CWE-770 CVE-2024-26894: In the Linux kernel, the following vulnerability has been resolved: ACPI: processor_idle: Fix memor In the Linux kernel, the following vulnerability has been resolved: ACPI: processor_idle: Fix memory leak in acpi_processor_power_exit() After unregistering the CPU idle device, the memory associated with it is not freed, leading to a memory leak: unreferenced object 0xffff896282f6c000 (size 1024): comm "swapper/0", pid 1, jiffies 4294893170 hex d
nvd
CVE-2020-8649P4MEDIUMCVSS 5.9v8.0v9.02020-02-06
CVE-2020-8649 [MEDIUM] CWE-416 CVE-2020-8649: There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the vgacon_invert_regio There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the vgacon_invert_region function in drivers/video/console/vgacon.c.
nvd
Debian Linux vulnerabilities | cvebase