Debian Linux vulnerabilities
9,955 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358
Vulnerabilities
Page 385 of 498
CVE-2018-2588P4MEDIUMCVSS 4.3v7.0v8.0+1 more2018-01-18
CVE-2018-2588 [MEDIUM] CVE-2018-2588: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: L
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: LDAP). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Java SE,
nvd
CVE-2020-11740P4MEDIUMCVSS 5.5v10.02020-04-14
CVE-2020-11740 [MEDIUM] CWE-212 CVE-2020-11740: An issue was discovered in xenoprof in Xen through 4.13.x, allowing guest OS users (without active p
An issue was discovered in xenoprof in Xen through 4.13.x, allowing guest OS users (without active profiling) to obtain sensitive information about other guests. Unprivileged guests can request to map xenoprof buffers, even if profiling has not been enabled for those guests. These buffers were not scrubbed.
nvd
CVE-2019-19479P4MEDIUMCVSS 5.5v8.0v9.02019-12-01
CVE-2019-19479 [MEDIUM] CWE-125 CVE-2019-19479: An issue was discovered in OpenSC through 0.19.0 and 0.20.x through 0.20.0-rc3. libopensc/card-setco
An issue was discovered in OpenSC through 0.19.0 and 0.20.x through 0.20.0-rc3. libopensc/card-setcos.c has an incorrect read operation during parsing of a SETCOS file attribute.
nvd
CVE-2021-34556P4MEDIUMCVSS 5.5v9.02021-08-02
CVE-2021-34556 [MEDIUM] CWE-203 CVE-2021-34556: In the Linux kernel through 5.13.7, an unprivileged BPF program can obtain sensitive information fro
In the Linux kernel through 5.13.7, an unprivileged BPF program can obtain sensitive information from kernel memory via a Speculative Store Bypass side-channel attack because the protection mechanism neglects the possibility of uninitialized memory locations on the BPF stack.
nvd
CVE-2021-20255P4MEDIUMCVSS 5.5v9.02021-03-09
CVE-2021-20255 [MEDIUM] CWE-835 CVE-2021-20255: A stack overflow via an infinite recursion vulnerability was found in the eepro100 i8255x device emu
A stack overflow via an infinite recursion vulnerability was found in the eepro100 i8255x device emulator of QEMU. This issue occurs while processing controller commands due to a DMA reentry issue. This flaw allows a guest user or process to consume CPU cycles or crash the QEMU process on the host, resulting in a denial of service. The highest threa
nvd
CVE-2012-5644P4MEDIUMCVSS 5.5v8.0v9.0+1 more2019-11-25
CVE-2012-5644 [MEDIUM] CWE-200 CVE-2012-5644: libuser has information disclosure when moving user's home directory
libuser has information disclosure when moving user's home directory
nvd
CVE-2015-1235P4MEDIUMCVSS 5.0v8.02015-04-19
CVE-2015-1235 [MEDIUM] CWE-264 CVE-2015-1235: The ContainerNode::parserRemoveChild function in core/dom/ContainerNode.cpp in the HTML parser in Bl
The ContainerNode::parserRemoveChild function in core/dom/ContainerNode.cpp in the HTML parser in Blink, as used in Google Chrome before 42.0.2311.90, allows remote attackers to bypass the Same Origin Policy via a crafted HTML document with an IFRAME element.
nvd
CVE-2022-31030P4MEDIUMCVSS 5.5v11.02022-06-09
CVE-2022-31030 [MEDIUM] CWE-400 CVE-2022-31030: containerd is an open source container runtime. A bug was found in the containerd's CRI implementati
containerd is an open source container runtime. A bug was found in the containerd's CRI implementation where programs inside a container can cause the containerd daemon to consume memory without bound during invocation of the `ExecSync` API. This can cause containerd to consume all available memory on the computer, denying service to other legitimat
nvd
CVE-2024-26931P4MEDIUMCVSS 5.5v10.02024-05-01
CVE-2024-26931 [MEDIUM] CWE-476 CVE-2024-26931: In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix command flus
In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Fix command flush on cable pull
System crash due to command failed to flush back to SCSI layer.
BUG: unable to handle kernel NULL pointer dereference at 0000000000000000
PGD 0 P4D 0
Oops: 0000 [#1] SMP NOPTI
CPU: 27 PID: 793455 Comm: kworker/u130:6 Kdump: loaded Tai
nvd
CVE-2022-26966P4MEDIUMCVSS 5.5v9.02022-03-12
CVE-2022-26966 [MEDIUM] CVE-2022-26966: An issue was discovered in the Linux kernel before 5.16.12. drivers/net/usb/sr9700.c allows attacker
An issue was discovered in the Linux kernel before 5.16.12. drivers/net/usb/sr9700.c allows attackers to obtain sensitive information from heap memory via crafted frame lengths from a device.
nvd
CVE-2013-1425P4MEDIUMCVSS 5.5v8.0v9.0+1 more2019-11-07
CVE-2013-1425 [MEDIUM] CWE-276 CVE-2013-1425: ldap-git-backup before 1.0.4 exposes password hashes due to incorrect directory permissions.
ldap-git-backup before 1.0.4 exposes password hashes due to incorrect directory permissions.
nvd
CVE-2021-26933P4MEDIUMCVSS 5.5v10.02021-02-17
CVE-2021-26933 [MEDIUM] CVE-2021-26933: An issue was discovered in Xen 4.9 through 4.14.x. On Arm, a guest is allowed to control whether mem
An issue was discovered in Xen 4.9 through 4.14.x. On Arm, a guest is allowed to control whether memory accesses are bypassing the cache. This means that Xen needs to ensure that all writes (such as the ones during scrubbing) have reached the memory before handing over the page to a guest. Unfortunately, the operation to clean the cache is happening before
nvd
CVE-2025-38331P4MEDIUMCVSS 5.5v11.02025-07-10
CVE-2025-38331 [MEDIUM] CVE-2025-38331: In the Linux kernel, the following vulnerability has been resolved: net: ethernet: cortina: Use TOE
In the Linux kernel, the following vulnerability has been resolved:
net: ethernet: cortina: Use TOE/TSO on all TCP
It is desireable to push the hardware accelerator to also
process non-segmented TCP frames: we pass the skb->len
to the "TOE/TSO" offloader and it will handle them.
Without this quirk the driver becomes unstable and lock
up and and crash.
I
nvd
CVE-2022-42322P4MEDIUMCVSS 5.5v11.02022-11-01
CVE-2022-42322 [MEDIUM] CWE-401 CVE-2022-42322: Xenstore: Cooperating guests can create arbitrary numbers of nodes T[his CNA information record rela
Xenstore: Cooperating guests can create arbitrary numbers of nodes T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Since the fix of XSA-322 any Xenstore node owned by a removed domain will be modified to be owned by Dom0. This will allow two malicious guests working tog
nvd
CVE-2022-42323P4MEDIUMCVSS 5.5v11.02022-11-01
CVE-2022-42323 [MEDIUM] CWE-401 CVE-2022-42323: Xenstore: Cooperating guests can create arbitrary numbers of nodes T[his CNA information record rela
Xenstore: Cooperating guests can create arbitrary numbers of nodes T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Since the fix of XSA-322 any Xenstore node owned by a removed domain will be modified to be owned by Dom0. This will allow two malicious guests working tog
nvd
CVE-2024-1151P4MEDIUMCVSS 5.5v10.02024-02-11
CVE-2024-1151 [MEDIUM] CWE-121 CVE-2024-1151: A vulnerability was reported in the Open vSwitch sub-component in the Linux Kernel. The flaw occurs
A vulnerability was reported in the Open vSwitch sub-component in the Linux Kernel. The flaw occurs when a recursive operation of code push recursively calls into the code block. The OVS module does not validate the stack depth, pushing too many frames and causing a stack overflow. As a result, this can lead to a crash or other related issues.
nvd
CVE-2015-2047P4LOWCVSS 2.6v7.02015-02-23
CVE-2015-2047 [LOW] CWE-287 CVE-2015-2047: The rsaauth extension in TYPO3 4.3.0 through 4.3.14, 4.4.0 through 4.4.15, 4.5.0 through 4.5.39, and
The rsaauth extension in TYPO3 4.3.0 through 4.3.14, 4.4.0 through 4.4.15, 4.5.0 through 4.5.39, and 4.6.0 through 4.6.18, when configured for the frontend, allows remote attackers to bypass authentication via a password that is casted to an empty value.
nvd
CVE-2024-26937P4MEDIUMCVSS 5.5v10.02024-05-01
CVE-2024-26937 [MEDIUM] CWE-617 CVE-2024-26937: In the Linux kernel, the following vulnerability has been resolved: drm/i915/gt: Reset queue_priori
In the Linux kernel, the following vulnerability has been resolved:
drm/i915/gt: Reset queue_priority_hint on parking
Originally, with strict in order execution, we could complete execution
only when the queue was empty. Preempt-to-busy allows replacement of an
active request that may complete before the preemption is processed by
HW. If that happe
nvd
CVE-2024-34509P4MEDIUMCVSS 5.3v10.02024-05-05
CVE-2024-34509 [MEDIUM] CVE-2024-34509: dcmdata in DCMTK before 3.6.9 has a segmentation fault via an invalid DIMSE message.
dcmdata in DCMTK before 3.6.9 has a segmentation fault via an invalid DIMSE message.
nvd
CVE-2023-27932P4MEDIUMCVSS 5.5v10.02023-05-08
CVE-2023-27932 [MEDIUM] CWE-346 CVE-2023-27932: This issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3,
This issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 16.4, tvOS 16.4, watchOS 9.4. Processing maliciously crafted web content may bypass Same Origin Policy.
nvd