cbcvebase.

Debian Linux vulnerabilities

9,955 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358

Vulnerabilities

Page 376 of 498
CVE-2012-1105P4MEDIUMCVSS 5.5v8.02019-12-05
CVE-2012-1105 [MEDIUM] CWE-200 CVE-2012-1105: An Information Disclosure vulnerability exists in the Jasig Project php-pear-CAS 1.2.2 package in th An Information Disclosure vulnerability exists in the Jasig Project php-pear-CAS 1.2.2 package in the /tmp directory. The Central Authentication Service client library archives the debug logging file in an insecure manner.
nvd
CVE-2022-0854P4MEDIUMCVSS 5.5v9.0v10.0+1 more2022-03-23
CVE-2022-0854 [MEDIUM] CWE-200 CVE-2022-0854: A memory leak flaw was found in the Linux kernel’s DMA subsystem, in the way a user calls DMA_FROM_D A memory leak flaw was found in the Linux kernel’s DMA subsystem, in the way a user calls DMA_FROM_DEVICE. This flaw allows a local user to read random memory from the kernel space.
nvd
CVE-2021-35477P4MEDIUMCVSS 5.5v9.02021-08-02
CVE-2021-35477 [MEDIUM] CWE-203 CVE-2021-35477: In the Linux kernel through 5.13.7, an unprivileged BPF program can obtain sensitive information fro In the Linux kernel through 5.13.7, an unprivileged BPF program can obtain sensitive information from kernel memory via a Speculative Store Bypass side-channel attack because a certain preempting store operation does not necessarily occur before a store operation that has an attacker-controlled value.
nvd
CVE-2021-2369P4MEDIUMCVSS 4.3v9.0v10.02021-07-21
CVE-2021-2369 [MEDIUM] CVE-2021-2369: Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Library). Supported versions that are affected are Java SE: 7u301, 8u291, 11.0.11, 16.0.1; Oracle GraalVM Enterprise Edition: 20.3.2 and 21.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to com
nvd
CVE-2016-5291P4MEDIUMCVSS 5.5v8.02018-06-11
CVE-2016-5291 [MEDIUM] CWE-20 CVE-2016-5291: A same-origin policy bypass with local shortcut files to load arbitrary local content from disk. Thi A same-origin policy bypass with local shortcut files to load arbitrary local content from disk. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.
nvd
CVE-2023-51384P4MEDIUMCVSS 5.5v11.0v12.02023-12-18
CVE-2023-51384 [MEDIUM] CWE-284 CVE-2023-51384: In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. Whe In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are specified during addition of PKCS#11-hosted private keys, these constraints are only applied to the first key, even if a PKCS#11 token returns multiple keys.
nvd
CVE-2018-1118P4MEDIUMCVSS 5.5v8.02018-05-10
CVE-2018-1118 [MEDIUM] CWE-665 CVE-2018-1118: Linux kernel vhost since version 4.8 does not properly initialize memory in messages passed between Linux kernel vhost since version 4.8 does not properly initialize memory in messages passed between virtual guests and the host operating system in the vhost/vhost.c:vhost_new_msg() function. This can allow local privileged users to read some kernel memory contents when reading from the /dev/vhost-net device file.
nvd
CVE-2019-2101P4MEDIUMCVSS 5.5v8.02019-06-07
CVE-2019-2101 [MEDIUM] CWE-125 CVE-2019-2101: In uvc_parse_standard_control of uvc_driver.c, there is a possible out-of-bound read due to improper In uvc_parse_standard_control of uvc_driver.c, there is a possible out-of-bound read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-111760968.
nvd
CVE-2020-16150P4MEDIUMCVSS 5.5v10.02020-09-02
CVE-2020-16150 [MEDIUM] CWE-203 CVE-2020-16150: A Lucky 13 timing side channel in mbedtls_ssl_decrypt_buf in library/ssl_msg.c in Trusted Firmware M A Lucky 13 timing side channel in mbedtls_ssl_decrypt_buf in library/ssl_msg.c in Trusted Firmware Mbed TLS through 2.23.0 allows an attacker to recover secret key information. This affects CBC mode because of a computed time difference based on a padding length.
nvd
CVE-2019-18391P4MEDIUMCVSS 5.5v10.02019-12-23
CVE-2019-18391 [MEDIUM] CWE-787 CVE-2019-18391: A heap-based buffer overflow in the vrend_renderer_transfer_write_iov function in vrend_renderer.c i A heap-based buffer overflow in the vrend_renderer_transfer_write_iov function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service via VIRGL_CCMD_RESOURCE_INLINE_WRITE commands.
nvd
CVE-2022-42824P4MEDIUMCVSS 5.5v10.0v11.02022-11-01
CVE-2022-42824 [MEDIUM] CVE-2022-42824: A logic issue was addressed with improved state management. This issue is fixed in tvOS 16.1, macOS A logic issue was addressed with improved state management. This issue is fixed in tvOS 16.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Processing maliciously crafted web content may disclose sensitive user information.
nvd
CVE-2022-21704P4MEDIUMCVSS 5.5v10.02022-01-19
CVE-2022-21704 [MEDIUM] CWE-276 CVE-2022-21704: log4js-node is a port of log4js to node.js. In affected versions default file permissions for log fi log4js-node is a port of log4js to node.js. In affected versions default file permissions for log files created by the file, fileSync and dateFile appenders are world-readable (in unix). This could cause problems if log files contain sensitive information. This would affect any users that have not supplied their own permissions for the files via the
nvd
CVE-2021-23225P4MEDIUMCVSS 5.4v9.02022-01-19
CVE-2021-23225 [MEDIUM] CWE-79 CVE-2021-23225: Cacti 1.1.38 allows authenticated users with User Management permissions to inject arbitrary web scr Cacti 1.1.38 allows authenticated users with User Management permissions to inject arbitrary web script or HTML in the "new_username" field during creation of a new user via "Copy" method at user_admin.php.
nvd
CVE-2023-6857P4MEDIUMCVSS 5.3v10.0v11.0+1 more2023-12-19
CVE-2023-6857 [MEDIUM] CWE-362 CVE-2023-6857: When resolving a symlink, a race may occur where the buffer passed to `readlink` may actually be sma When resolving a symlink, a race may occur where the buffer passed to `readlink` may actually be smaller than necessary. *This bug only affects Firefox on Unix-based operating systems (Android, Linux, MacOS). Windows is unaffected.* This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
nvd
CVE-2025-39716P4MEDIUMCVSS 5.5v11.02025-09-05
CVE-2025-39716 [MEDIUM] CVE-2025-39716: In the Linux kernel, the following vulnerability has been resolved: parisc: Revise __get_user() to In the Linux kernel, the following vulnerability has been resolved: parisc: Revise __get_user() to probe user read access Because of the way read access support is implemented, read access interruptions are only triggered at privilege levels 2 and 3. The kernel executes at privilege level 0, so __get_user() never triggers a read access interruption (code 26
nvd
CVE-2025-39801P4MEDIUMCVSS 5.5v11.02025-09-15
CVE-2025-39801 [MEDIUM] CWE-617 CVE-2025-39801: In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: Remove WARN_ON for d In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: Remove WARN_ON for device endpoint command timeouts This commit addresses a rarely observed endpoint command timeout which causes kernel panic due to warn when 'panic_on_warn' is enabled and unnecessary call trace prints when 'panic_on_warn' is disabled. It is seen durin
nvd
CVE-1999-0434P4HIGHCVSS 7.5v2.0v2.11999-03-30
CVE-1999-0434 [HIGH] CVE-1999-0434: XFree86 xfs command is vulnerable to a symlink attack, allowing local users to create files in restr XFree86 xfs command is vulnerable to a symlink attack, allowing local users to create files in restricted directories, possibly allowing them to gain privileges or cause a denial of service.
nvd
CVE-2021-42762P4MEDIUMCVSS 5.3v10.0v11.02021-10-20
CVE-2021-42762 [MEDIUM] CVE-2021-42762: BubblewrapLauncher.cpp in WebKitGTK and WPE WebKit before 2.34.1 allows a limited sandbox bypass tha BubblewrapLauncher.cpp in WebKitGTK and WPE WebKit before 2.34.1 allows a limited sandbox bypass that allows a sandboxed process to trick host processes into thinking the sandboxed process is not confined by the sandbox, by abusing VFS syscalls that manipulate its filesystem namespace. The impact is limited to host services that create UNIX sockets that Web
nvd
CVE-2017-3636P4MEDIUMCVSS 5.3v8.0v9.02017-08-08
CVE-2017-3636 [MEDIUM] CVE-2017-3636: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs). Support Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs). Supported versions that are affected are 5.5.56 and earlier and 5.6.36 and earlier. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attacks of this vuln
nvd
CVE-2015-7542P4MEDIUMCVSS 5.3v8.0v9.0+2 more2019-12-03
CVE-2015-7542 [MEDIUM] CWE-319 CVE-2015-7542: A vulnerability exists in libgwenhywfar through 4.12.0 due to the usage of outdated bundled CA certi A vulnerability exists in libgwenhywfar through 4.12.0 due to the usage of outdated bundled CA certificates.
nvd
Debian Linux vulnerabilities | cvebase