Debian Linux vulnerabilities
9,955 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358
Vulnerabilities
Page 384 of 498
CVE-2019-2977P4MEDIUMCVSS 4.8v10.02019-10-16
CVE-2019-2977 [MEDIUM] CVE-2019-2977: Vulnerability in the Java SE product of Oracle Java SE (component: Hotspot). Supported versions that
Vulnerability in the Java SE product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Java SE: 11.0.4 and 13. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized read access to a s
nvd
CVE-2019-5823P4MEDIUMCVSS 5.4v10.02019-06-27
CVE-2019-5823 [MEDIUM] CWE-601 CVE-2019-5823: Insufficient policy enforcement in service workers in Google Chrome prior to 74.0.3729.108 allowed a
Insufficient policy enforcement in service workers in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2020-27825P4MEDIUMCVSS 5.7v9.0v10.02020-12-11
CVE-2020-27825 [MEDIUM] CWE-362 CVE-2020-27825: A use-after-free flaw was found in kernel/trace/ring_buffer.c in Linux kernel (before 5.10-rc1). The
A use-after-free flaw was found in kernel/trace/ring_buffer.c in Linux kernel (before 5.10-rc1). There was a race problem in trace_open and resize of cpu buffer running parallely on different cpus, may cause a denial of service problem (DOS). This flaw could even allow a local attacker with special user privilege to a kernel information leak threat.
nvd
CVE-2018-10876P4MEDIUMCVSS 5.5v8.02018-07-26
CVE-2018-10876 [MEDIUM] CWE-416 CVE-2018-10876: A flaw was found in Linux kernel in the ext4 filesystem code. A use-after-free is possible in ext4_e
A flaw was found in Linux kernel in the ext4 filesystem code. A use-after-free is possible in ext4_ext_remove_space() function when mounting and operating a crafted ext4 image.
nvd
CVE-2021-37958P4MEDIUMCVSS 5.4v10.0v11.02021-10-08
CVE-2021-37958 [MEDIUM] CVE-2021-37958: Inappropriate implementation in Navigation in Google Chrome on Windows prior to 94.0.4606.54 allowed
Inappropriate implementation in Navigation in Google Chrome on Windows prior to 94.0.4606.54 allowed a remote attacker to inject scripts or HTML into a privileged page via a crafted HTML page.
nvd
CVE-2012-1183P4MEDIUMCVSS 4.3v6.02012-09-18
CVE-2012-1183 [MEDIUM] CWE-119 CVE-2012-1183: Stack-based buffer overflow in the milliwatt_generate function in the Miliwatt application in Asteri
Stack-based buffer overflow in the milliwatt_generate function in the Miliwatt application in Asterisk 1.4.x before 1.4.44, 1.6.x before 1.6.2.23, 1.8.x before 1.8.10.1, and 10.x before 10.2.1, when the o option is used and the internal_timing option is off, allows remote attackers to cause a denial of service (application crash) via a large number of
nvd
CVE-2019-19039P4MEDIUMCVSS 5.5v9.02019-11-21
CVE-2019-19039 [MEDIUM] CWE-532 CVE-2019-19039: __btrfs_free_extent in fs/btrfs/extent-tree.c in the Linux kernel through 5.3.12 calls btrfs_print_l
__btrfs_free_extent in fs/btrfs/extent-tree.c in the Linux kernel through 5.3.12 calls btrfs_print_leaf in a certain ENOENT case, which allows local users to obtain potentially sensitive information about register values via the dmesg program. NOTE: The BTRFS development team disputes this issues as not being a vulnerability because “1) The kernel p
nvd
CVE-2013-5807P4MEDIUMCVSS 4.9v7.02013-10-16
CVE-2013-5807 [MEDIUM] CVE-2013-5807: Unspecified vulnerability in Oracle MySQL Server 5.5.x through 5.5.32 and 5.6.x through 5.6.12 allow
Unspecified vulnerability in Oracle MySQL Server 5.5.x through 5.5.32 and 5.6.x through 5.6.12 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Replication.
nvd
CVE-2019-7222P4MEDIUMCVSS 5.5v8.02019-03-21
CVE-2019-7222 [MEDIUM] CVE-2019-7222: The KVM implementation in the Linux kernel through 4.20.5 has an Information Leak.
The KVM implementation in the Linux kernel through 4.20.5 has an Information Leak.
nvd
CVE-2019-11833P4MEDIUMCVSS 5.5v8.0v9.02019-05-15
CVE-2019-11833 [MEDIUM] CWE-908 CVE-2019-11833: fs/ext4/extents.c in the Linux kernel through 5.1.2 does not zero out the unused memory region in th
fs/ext4/extents.c in the Linux kernel through 5.1.2 does not zero out the unused memory region in the extent tree block, which might allow local users to obtain sensitive information by reading uninitialized data in the filesystem.
nvd
CVE-2018-5729P4MEDIUMCVSS 4.7v8.0v9.02018-03-06
CVE-2018-5729 [MEDIUM] CWE-476 CVE-2018-5729: MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Ke
MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to cause a denial of service (NULL pointer dereference) or bypass a DN container check by supplying tagged data that is internal to the database module.
nvd
CVE-2020-14390P4MEDIUMCVSS 5.6v9.02020-09-18
CVE-2020-14390 [MEDIUM] CWE-787 CVE-2020-14390: A flaw was found in the Linux kernel in versions before 5.9-rc6. When changing screen size, an out-o
A flaw was found in the Linux kernel in versions before 5.9-rc6. When changing screen size, an out-of-bounds memory write can occur leading to memory corruption or a denial of service. Due to the nature of the flaw, privilege escalation cannot be fully ruled out.
nvd
CVE-2020-13397P4MEDIUMCVSS 5.5v9.0v10.02020-05-22
CVE-2020-13397 [MEDIUM] CWE-125 CVE-2020-13397: An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) read vulnerability has been
An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) read vulnerability has been detected in security_fips_decrypt in libfreerdp/core/security.c due to an uninitialized value.
nvd
CVE-2020-25650P4MEDIUMCVSS 5.5v9.02020-11-25
CVE-2020-25650 [MEDIUM] CWE-770 CVE-2020-25650: A flaw was found in the way the spice-vdagentd daemon handled file transfers from the host system to
A flaw was found in the way the spice-vdagentd daemon handled file transfers from the host system to the virtual machine. Any unprivileged local guest user with access to the UNIX domain socket path `/run/spice-vdagentd/spice-vdagent-sock` could use this flaw to perform a memory denial of service for spice-vdagentd or even other processes in the VM
nvd
CVE-2021-34693P4MEDIUMCVSS 5.5v9.0v10.02021-06-14
CVE-2021-34693 [MEDIUM] CWE-909 CVE-2021-34693: net/can/bcm.c in the Linux kernel through 5.12.10 allows local users to obtain sensitive information
net/can/bcm.c in the Linux kernel through 5.12.10 allows local users to obtain sensitive information from kernel stack memory because parts of a data structure are uninitialized.
nvd
CVE-2020-0427P4MEDIUMCVSS 5.5v9.02020-09-17
CVE-2020-0427 [MEDIUM] CWE-125 CVE-2020-0427: In create_pinctrl of core.c, there is a possible out of bounds read due to a use after free. This co
In create_pinctrl of core.c, there is a possible out of bounds read due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-140550171
nvd
CVE-2018-12383P4MEDIUMCVSS 5.5v8.0v9.02018-10-18
CVE-2018-12383 [MEDIUM] CWE-522 CVE-2018-12383: If a user saved passwords before Firefox 58 and then later set a master password, an unencrypted cop
If a user saved passwords before Firefox 58 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is because the older stored password file was not deleted when the data was copied to a new format starting in Firefox 58. The new master password is added only on the new file. This could allow the expos
nvd
CVE-2018-4181P4MEDIUMCVSS 5.5v8.0v9.02019-01-11
CVE-2018-4181 [MEDIUM] CVE-2018-4181: In macOS High Sierra before 10.13.5, an issue existed in CUPS. This issue was addressed with improve
In macOS High Sierra before 10.13.5, an issue existed in CUPS. This issue was addressed with improved access restrictions.
nvd
CVE-2022-48281P4MEDIUMCVSS 5.5v10.0v11.02023-01-23
CVE-2022-48281 [MEDIUM] CWE-787 CVE-2022-48281: processCropSelections in tools/tiffcrop.c in LibTIFF through 4.5.0 has a heap-based buffer overflow
processCropSelections in tools/tiffcrop.c in LibTIFF through 4.5.0 has a heap-based buffer overflow (e.g., "WRITE of size 307203") via a crafted TIFF image.
nvd
CVE-2020-8631P4MEDIUMCVSS 5.5v8.02020-02-05
CVE-2020-8631 [MEDIUM] CWE-330 CVE-2020-8631: cloud-init through 19.4 relies on Mersenne Twister for a random password, which makes it easier for
cloud-init through 19.4 relies on Mersenne Twister for a random password, which makes it easier for attackers to predict passwords, because rand_str in cloudinit/util.py calls the random.choice function.
nvd