cbcvebase.

Debian Linux vulnerabilities

9,955 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358

Vulnerabilities

Page 380 of 498
CVE-2022-42316P4MEDIUMCVSS 6.5v11.02022-11-01
CVE-2022-42316 [MEDIUM] CWE-770 CVE-2022-42316: Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multipl Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Malicious guests can cause xenstored to allocate vast amounts of memory, eventually resulting in a Denial of Service (DoS) of xenstored. There are multiple ways how gues
nvd
CVE-2022-42317P4MEDIUMCVSS 6.5v11.02022-11-01
CVE-2022-42317 [MEDIUM] CWE-770 CVE-2022-42317: Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multipl Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Malicious guests can cause xenstored to allocate vast amounts of memory, eventually resulting in a Denial of Service (DoS) of xenstored. There are multiple ways how gues
nvd
CVE-2022-42312P4MEDIUMCVSS 6.5v11.02022-11-01
CVE-2022-42312 [MEDIUM] CWE-770 CVE-2022-42312: Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multipl Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Malicious guests can cause xenstored to allocate vast amounts of memory, eventually resulting in a Denial of Service (DoS) of xenstored. There are multiple ways how gues
nvd
CVE-2022-42311P4MEDIUMCVSS 6.5v11.02022-11-01
CVE-2022-42311 [MEDIUM] CWE-770 CVE-2022-42311: Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multipl Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Malicious guests can cause xenstored to allocate vast amounts of memory, eventually resulting in a Denial of Service (DoS) of xenstored. There are multiple ways how gues
nvd
CVE-2022-42315P4MEDIUMCVSS 6.5v11.02022-11-01
CVE-2022-42315 [MEDIUM] CWE-770 CVE-2022-42315: Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multipl Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Malicious guests can cause xenstored to allocate vast amounts of memory, eventually resulting in a Denial of Service (DoS) of xenstored. There are multiple ways how gues
nvd
CVE-2022-42313P4MEDIUMCVSS 6.5v11.02022-11-01
CVE-2022-42313 [MEDIUM] CWE-770 CVE-2022-42313: Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multipl Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Malicious guests can cause xenstored to allocate vast amounts of memory, eventually resulting in a Denial of Service (DoS) of xenstored. There are multiple ways how gues
nvd
CVE-2022-42318P4MEDIUMCVSS 6.5v11.02022-11-01
CVE-2022-42318 [MEDIUM] CWE-770 CVE-2022-42318: Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multipl Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Malicious guests can cause xenstored to allocate vast amounts of memory, eventually resulting in a Denial of Service (DoS) of xenstored. There are multiple ways how gues
nvd
CVE-2022-42314P4MEDIUMCVSS 6.5v11.02022-11-01
CVE-2022-42314 [MEDIUM] CWE-770 CVE-2022-42314: Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multipl Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Malicious guests can cause xenstored to allocate vast amounts of memory, eventually resulting in a Denial of Service (DoS) of xenstored. There are multiple ways how gues
nvd
CVE-2017-15570P4MEDIUMCVSS 6.1v9.02017-10-18
CVE-2017-15570 [MEDIUM] CWE-79 CVE-2017-15570: In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/views/timelog In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/views/timelog/_list.html.erb via crafted column data.
nvd
CVE-2012-0812P4MEDIUMCVSS 6.1v8.0v9.0+1 more2019-11-22
CVE-2012-0812 [MEDIUM] CWE-79 CVE-2012-0812: PostfixAdmin 2.3.4 has multiple XSS vulnerabilities PostfixAdmin 2.3.4 has multiple XSS vulnerabilities
nvd
CVE-2021-22570P4MEDIUMCVSS 5.5v9.0v10.0+1 more2022-01-26
CVE-2021-22570 [MEDIUM] CWE-476 CVE-2021-22570: Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file's name during generation of the resulting error message. Since the symbol is incorrectly parsed, the file is nullptr. We recommend upgrading to version 3.15.0 or greater.
nvd
CVE-2017-15429P4MEDIUMCVSS 6.1v8.0v9.02018-08-28
CVE-2017-15429 [MEDIUM] CWE-79 CVE-2017-15429: Inappropriate implementation in V8 WebAssembly JS bindings in Google Chrome prior to 63.0.3239.108 a Inappropriate implementation in V8 WebAssembly JS bindings in Google Chrome prior to 63.0.3239.108 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.
nvd
CVE-2017-15573P4MEDIUMCVSS 6.1v9.02017-10-18
CVE-2017-15573 [MEDIUM] CWE-79 CVE-2017-15573: In Redmine before 3.2.6 and 3.3.x before 3.3.3, XSS exists because markup is mishandled in wiki cont In Redmine before 3.2.6 and 3.3.x before 3.3.3, XSS exists because markup is mishandled in wiki content.
nvd
CVE-2017-0364P4MEDIUMCVSS 6.1v7.02018-04-13
CVE-2017-0364 [MEDIUM] CWE-601 CVE-2017-0364: Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw where Special:Search allows redirects to Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw where Special:Search allows redirects to any interwiki link.
nvd
CVE-2017-6834P4MEDIUMCVSS 5.5v8.0v9.02017-03-20
CVE-2017-6834 [MEDIUM] CWE-119 CVE-2017-6834: Heap-based buffer overflow in the ulaw2linear_buf function in G711.cpp in Audio File Library (aka au Heap-based buffer overflow in the ulaw2linear_buf function in G711.cpp in Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0, 0.2.7 allows remote attackers to cause a denial of service (crash) via a crafted file.
nvd
CVE-2013-4168P4MEDIUMCVSS 6.1v8.0v9.0+1 more2019-11-01
CVE-2013-4168 [MEDIUM] CWE-79 CVE-2013-4168: Cross-site scripting (XSS) vulnerability in SmokePing 2.6.9 in the start and end time fields. Cross-site scripting (XSS) vulnerability in SmokePing 2.6.9 in the start and end time fields.
nvd
CVE-2014-3469P4MEDIUMCVSS 5.0v7.02014-06-05
CVE-2014-3469 [MEDIUM] CWE-476 CVE-2014-3469: The (1) asn1_read_value_type and (2) asn1_read_value functions in GNU Libtasn1 before 3.6 allows con The (1) asn1_read_value_type and (2) asn1_read_value functions in GNU Libtasn1 before 3.6 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via a NULL value in an ivalue argument.
nvd
CVE-2016-1652P4MEDIUMCVSS 6.1v8.02016-04-18
CVE-2016-1652 [MEDIUM] CWE-79 CVE-2016-1652: Cross-site scripting (XSS) vulnerability in the ModuleSystem::RequireForJsInner function in extensio Cross-site scripting (XSS) vulnerability in the ModuleSystem::RequireForJsInner function in extensions/renderer/module_system.cc in the Extensions subsystem in Google Chrome before 50.0.2661.75 allows remote attackers to inject arbitrary web script or HTML via a crafted web site, aka "Universal XSS (UXSS)."
nvd
CVE-2016-1833P4MEDIUMCVSS 5.5v8.02016-05-20
CVE-2016-1833 [MEDIUM] CWE-125 CVE-2016-1833: The htmlCurrentChar function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before The htmlCurrentChar function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document.
nvd
CVE-2020-25285P4MEDIUMCVSS 6.4v9.02020-09-13
CVE-2020-25285 [MEDIUM] CWE-362 CVE-2020-25285: A race condition between hugetlb sysctl handlers in mm/hugetlb.c in the Linux kernel before 5.8.8 co A race condition between hugetlb sysctl handlers in mm/hugetlb.c in the Linux kernel before 5.8.8 could be used by local attackers to corrupt memory, cause a NULL pointer dereference, or possibly have unspecified other impact, aka CID-17743798d812.
nvd
Debian Linux vulnerabilities | cvebase