Debian Linux vulnerabilities
9,955 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358
Vulnerabilities
Page 386 of 498
CVE-2025-23143P4MEDIUMCVSS 5.5v11.02025-05-01
CVE-2025-23143 [MEDIUM] CWE-476 CVE-2025-23143: In the Linux kernel, the following vulnerability has been resolved: net: Fix null-ptr-deref by sock
In the Linux kernel, the following vulnerability has been resolved:
net: Fix null-ptr-deref by sock_lock_init_class_and_name() and rmmod.
When I ran the repro [0] and waited a few seconds, I observed two
LOCKDEP splats: a warning immediately followed by a null-ptr-deref. [1]
Reproduction Steps:
1) Mount CIFS
2) Add an iptables rule to drop incomi
nvd
CVE-2020-2875P4MEDIUMCVSS 4.7v8.0v9.02020-04-15
CVE-2020-2875 [MEDIUM] CVE-2020-2875: Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported ve
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.14 and prior and 5.1.48 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks require human interaction from a
nvd
CVE-2025-39718P4MEDIUMCVSS 5.5v11.02025-09-05
CVE-2025-39718 [MEDIUM] CWE-787 CVE-2025-39718: In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: Validate length i
In the Linux kernel, the following vulnerability has been resolved:
vsock/virtio: Validate length in packet header before skb_put()
When receiving a vsock packet in the guest, only the virtqueue buffer
size is validated prior to virtio_vsock_skb_rx_put(). Unfortunately,
virtio_vsock_skb_rx_put() uses the length from the packet header as the
length
nvd
CVE-2025-39715P4MEDIUMCVSS 5.5v11.02025-09-05
CVE-2025-39715 [MEDIUM] CVE-2025-39715: In the Linux kernel, the following vulnerability has been resolved: parisc: Revise gateway LWS call
In the Linux kernel, the following vulnerability has been resolved:
parisc: Revise gateway LWS calls to probe user read access
We use load and stbys,e instructions to trigger memory reference
interruptions without writing to memory. Because of the way read
access support is implemented, read access interruptions are only
triggered at privilege levels 2 and
nvd
CVE-2024-34397P4MEDIUMCVSS 5.2v10.02024-05-07
CVE-2024-34397 [MEDIUM] CWE-290 CVE-2024-34397: An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDB
An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subscribes to signals from a trusted system service such as NetworkManager on a shared computer, other users of the same computer can send spoofed D-Bus signals that the GDBus-based client will wrongly interpret as having been sent by
nvd
CVE-2025-25472P4MEDIUMCVSS 5.3v11.02025-02-18
CVE-2025-25472 [MEDIUM] CWE-120 CVE-2025-25472: A buffer overflow in DCMTK git master v3.6.9+ DEV allows attackers to cause a Denial of Service (DoS
A buffer overflow in DCMTK git master v3.6.9+ DEV allows attackers to cause a Denial of Service (DoS) via a crafted DCM file.
nvd
CVE-2020-7066P4MEDIUMCVSS 4.3v8.0v9.0+1 more2020-04-01
CVE-2020-7066 [MEDIUM] CWE-170 CVE-2020-7066: In PHP versions 7.2.x below 7.2.29, 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using get_header
In PHP versions 7.2.x below 7.2.29, 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using get_headers() with user-supplied URL, if the URL contains zero (\0) character, the URL will be silently truncated at it. This may cause some software to make incorrect assumptions about the target of the get_headers() and possibly send some information to a wrong
nvd
CVE-2018-2813P4MEDIUMCVSS 4.3v7.0v8.0+1 more2018-04-19
CVE-2018-2813 [MEDIUM] CVE-2018-2813: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported v
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.5.59 and prior, 5.6.39 and prior and 5.7.21 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerabilit
nvd
CVE-2019-11498P4MEDIUMCVSS 6.5v9.02019-04-24
CVE-2019-11498 [MEDIUM] CWE-824 CVE-2019-11498: WavpackSetConfiguration64 in pack_utils.c in libwavpack.a in WavPack through 5.1.0 has a "Conditiona
WavpackSetConfiguration64 in pack_utils.c in libwavpack.a in WavPack through 5.1.0 has a "Conditional jump or move depends on uninitialised value" condition, which might allow attackers to cause a denial of service (application crash) via a DFF file that lacks valid sample-rate data.
nvd
CVE-2023-22041P4MEDIUMCVSS 5.1v10.0v11.0+1 more2023-07-18
CVE-2023-22041 [MEDIUM] CVE-2023-22041: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK produ
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u371-perf, 11.0.19, 17.0.7, 20.0.1; Oracle GraalVM Enterprise Edition: 20.3.10, 21.3.6, 22.3.2; Oracle GraalVM for JDK: 17.0.7 and 20.0.1. Difficult to exploi
nvd
CVE-2020-1746P4MEDIUMCVSS 5.0v10.02020-05-12
CVE-2020-1746 [MEDIUM] CWE-200 CVE-2020-1746: A flaw was found in the Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8
A flaw was found in the Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and 2.9.x before 2.9.7 as well as Ansible Tower before and including versions 3.4.5 and 3.5.5 and 3.6.3 when the ldap_attr and ldap_entry community modules are used. The issue discloses the LDAP bind password to stdout or a log file if
nvd
CVE-2017-3464P4MEDIUMCVSS 4.3v8.02017-04-24
CVE-2017-3464 [MEDIUM] CVE-2017-3464: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported v
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.5.54 and earlier, 5.6.35 and earlier and 5.7.17 and earlier. Easily "exploitable" vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vuln
nvd
CVE-2017-3651P4MEDIUMCVSS 4.3v8.02017-08-08
CVE-2017-3651 [MEDIUM] CVE-2017-3651: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client mysqldump). Suppor
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client mysqldump). Supported versions that are affected are 5.5.56 and earlier, 5.6.36 and earlier and 5.7.18 and earlier. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this v
nvd
CVE-2019-16708P4MEDIUMCVSS 6.5v10.02019-09-23
CVE-2019-16708 [MEDIUM] CWE-401 CVE-2019-16708: ImageMagick 7.0.8-35 has a memory leak in magick/xwindow.c, related to XCreateImage.
ImageMagick 7.0.8-35 has a memory leak in magick/xwindow.c, related to XCreateImage.
nvd
CVE-2024-46901P4MEDIUMCVSS 4.3v11.02024-12-09
CVE-2024-46901 [MEDIUM] CWE-20 CVE-2024-46901: Insufficient validation of filenames against control characters in Apache Subversion repositories se
Insufficient validation of filenames against control characters in Apache Subversion repositories served via mod_dav_svn allows authenticated users with commit access to commit a corrupted revision, leading to disruption for users of the repository.
All versions of Subversion up to and including Subversion 1.14.4 are affected if serving repositories
nvd
CVE-2021-33624P4MEDIUMCVSS 4.7v9.02021-06-23
CVE-2021-33624 [MEDIUM] CWE-843 CVE-2021-33624: In kernel/bpf/verifier.c in the Linux kernel before 5.12.13, a branch can be mispredicted (e.g., bec
In kernel/bpf/verifier.c in the Linux kernel before 5.12.13, a branch can be mispredicted (e.g., because of type confusion) and consequently an unprivileged BPF program can read arbitrary memory locations via a side-channel attack, aka CID-9183671af6db.
nvd
CVE-2020-15011P4MEDIUMCVSS 4.3v8.0v9.0+1 more2020-06-24
CVE-2020-15011 [MEDIUM] CWE-74 CVE-2020-15011: GNU Mailman before 2.1.33 allows arbitrary content injection via the Cgi/private.py private archive
GNU Mailman before 2.1.33 allows arbitrary content injection via the Cgi/private.py private archive login page.
nvd
CVE-2017-9408P4MEDIUMCVSS 6.5v8.0v9.02017-06-02
CVE-2017-9408 [MEDIUM] CWE-772 CVE-2017-9408: In Poppler 0.54.0, a memory leak vulnerability was found in the function Object::initArray in Object
In Poppler 0.54.0, a memory leak vulnerability was found in the function Object::initArray in Object.cc, which allows attackers to cause a denial of service via a crafted file.
nvd
CVE-2011-2359P4MEDIUMCVSS 6.8v6.0v7.02011-08-03
CVE-2011-2359 [MEDIUM] CWE-20 CVE-2011-2359: Google Chrome before 13.0.782.107 does not properly track line boxes during rendering, which allows
Google Chrome before 13.0.782.107 does not properly track line boxes during rendering, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2015-2925P4MEDIUMCVSS 6.9v7.0v8.02015-11-16
CVE-2015-2925 [MEDIUM] CVE-2015-2925: The prepend_path function in fs/dcache.c in the Linux kernel before 4.2.4 does not properly handle r
The prepend_path function in fs/dcache.c in the Linux kernel before 4.2.4 does not properly handle rename actions inside a bind mount, which allows local users to bypass an intended container protection mechanism by renaming a directory, related to a "double-chroot attack."
nvd