cbcvebase.

Debian Linux vulnerabilities

9,955 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358

Vulnerabilities

Page 389 of 498
CVE-2019-17344P4MEDIUMCVSS 6.5v9.0v10.02019-10-08
CVE-2019-17344 [MEDIUM] CWE-662 CVE-2019-17344: An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of se An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service by leveraging a long-running operation that exists to support restartability of PTE updates.
nvd
CVE-2019-17345P4MEDIUMCVSS 6.5v9.0v10.02019-10-08
CVE-2019-17345 [MEDIUM] CVE-2019-17345: An issue was discovered in Xen 4.8.x through 4.11.x allowing x86 PV guest OS users to cause a denial An issue was discovered in Xen 4.8.x through 4.11.x allowing x86 PV guest OS users to cause a denial of service because mishandling of failed IOMMU operations causes a bug check during the cleanup of a crashed guest.
nvd
CVE-2019-17348P4MEDIUMCVSS 6.5v9.0v10.02019-10-08
CVE-2019-17348 [MEDIUM] CWE-20 CVE-2019-17348: An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of se An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service because of an incompatibility between Process Context Identifiers (PCID) and shadow-pagetable switching.
nvd
CVE-2022-33746P4MEDIUMCVSS 6.5v11.02022-10-11
CVE-2022-33746 [MEDIUM] CWE-404 CVE-2022-33746: P2M pool freeing may take excessively long The P2M pool backing second level address translation for P2M pool freeing may take excessively long The P2M pool backing second level address translation for guests may be of significant size. Therefore its freeing may take more time than is reasonable without intermediate preemption checks. Such checking for the need to preempt was so far missing.
nvd
CVE-2017-15571P4MEDIUMCVSS 6.1v9.02017-10-18
CVE-2017-15571 [MEDIUM] CWE-79 CVE-2017-15571: In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/views/issues/ In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/views/issues/_list.html.erb via crafted column data.
nvd
CVE-2017-8831P4MEDIUMCVSS 6.4v7.02017-05-08
CVE-2017-8831 [MEDIUM] CWE-125 CVE-2017-8831: The saa7164_bus_get function in drivers/media/pci/saa7164/saa7164-bus.c in the Linux kernel through The saa7164_bus_get function in drivers/media/pci/saa7164/saa7164-bus.c in the Linux kernel through 4.11.5 allows local users to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact by changing a certain sequence-number value, aka a "double fetch" vulnerability.
nvd
CVE-2017-0363P4MEDIUMCVSS 6.1v7.02018-04-13
CVE-2017-0363 [MEDIUM] CWE-601 CVE-2017-0363: Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 has a flaw where Special:UserLogin?returnto=interwiki:foo Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 has a flaw where Special:UserLogin?returnto=interwiki:foo will redirect to external sites.
nvd
CVE-2014-6054P4MEDIUMCVSS 4.3v7.02014-10-06
CVE-2014-6054 [MEDIUM] CWE-189 CVE-2014-6054: The rfbProcessClientNormalMessage function in libvncserver/rfbserver.c in LibVNCServer 0.9.9 and ear The rfbProcessClientNormalMessage function in libvncserver/rfbserver.c in LibVNCServer 0.9.9 and earlier allows remote attackers to cause a denial of service (divide-by-zero error and server crash) via a zero value in the scaling factor in a (1) PalmVNCSetScaleFactor or (2) SetScale message.
nvd
CVE-2018-14617P4MEDIUMCVSS 5.5v8.0v9.02018-07-27
CVE-2018-14617 [MEDIUM] CWE-476 CVE-2018-14617: An issue was discovered in the Linux kernel through 4.17.10. There is a NULL pointer dereference and An issue was discovered in the Linux kernel through 4.17.10. There is a NULL pointer dereference and panic in hfsplus_lookup() in fs/hfsplus/dir.c when opening a file (that is purportedly a hard link) in an hfs+ filesystem that has malformed catalog data, and is mounted read-only without a metadata directory.
nvd
CVE-2014-7815P4MEDIUMCVSS 5.0v7.02014-11-14
CVE-2014-7815 [MEDIUM] CWE-20 CVE-2014-7815: The set_pixel_format function in ui/vnc.c in QEMU allows remote attackers to cause a denial of servi The set_pixel_format function in ui/vnc.c in QEMU allows remote attackers to cause a denial of service (crash) via a small bytes_per_pixel value.
nvd
CVE-2010-3674P4MEDIUMCVSS 6.1v5.02019-11-05
CVE-2010-3674 [MEDIUM] CWE-79 CVE-2010-3674: TYPO3 before 4.4.1 allows XSS in the frontend search box. TYPO3 before 4.4.1 allows XSS in the frontend search box.
nvd
CVE-2017-15569P4MEDIUMCVSS 6.1v9.02017-10-18
CVE-2017-15569 [MEDIUM] CWE-79 CVE-2017-15569: In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/helpers/queri In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/helpers/queries_helper.rb via a multi-value field with a crafted value that is mishandled during rendering of an issue list.
nvd
CVE-2017-3291P4MEDIUMCVSS 6.3v8.02017-01-27
CVE-2017-3291 [MEDIUM] CVE-2017-3291: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Packaging). Suppo Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Packaging). Supported versions that are affected are 5.5.53 and earlier, 5.6.34 and earlier and 5.7.16 and earlier. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Succes
nvd
CVE-2017-15568P4MEDIUMCVSS 6.1v9.02017-10-18
CVE-2017-15568 [MEDIUM] CWE-79 CVE-2017-15568: In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/helpers/appli In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/helpers/application_helper.rb via a multi-value field with a crafted value that is mishandled during rendering of issue history.
nvd
CVE-2017-15427P4MEDIUMCVSS 6.1v9.02018-08-28
CVE-2017-15427 [MEDIUM] CWE-79 CVE-2017-15427: Insufficient policy enforcement in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a socially Insufficient policy enforcement in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a socially engineered user to XSS themselves by dragging and dropping a javascript: URL into the URL bar.
nvd
CVE-2013-4076P4MEDIUMCVSS 5.0v7.02013-06-09
CVE-2013-4076 [MEDIUM] CWE-119 CVE-2013-4076: Buffer overflow in the dissect_iphc_crtp_fh function in epan/dissectors/packet-ppp.c in the PPP diss Buffer overflow in the dissect_iphc_crtp_fh function in epan/dissectors/packet-ppp.c in the PPP dissector in Wireshark 1.8.x before 1.8.8 allows remote attackers to cause a denial of service (application crash) via a crafted packet.
nvd
CVE-2014-8483P4MEDIUMCVSS 5.0v7.02014-11-06
CVE-2014-8483 [MEDIUM] CWE-125 CVE-2014-8483: The blowfishECB function in core/cipher.cpp in Quassel IRC 0.10.0 allows remote attackers to cause a The blowfishECB function in core/cipher.cpp in Quassel IRC 0.10.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a malformed string.
nvd
CVE-2011-0544P4MEDIUMCVSS 6.1v8.02019-11-14
CVE-2011-0544 [MEDIUM] CWE-79 CVE-2011-0544: phpbb 3.0.x-3.0.6 has an XSS vulnerability via the [flash] BB tag. phpbb 3.0.x-3.0.6 has an XSS vulnerability via the [flash] BB tag.
nvd
CVE-2013-2175P4MEDIUMCVSS 5.0v6.02013-08-19
CVE-2013-2175 [MEDIUM] CWE-20 CVE-2013-2175: HAProxy 1.4 before 1.4.24 and 1.5 before 1.5-dev19, when configured to use hdr_ip or other "hdr_*" f HAProxy 1.4 before 1.4.24 and 1.5 before 1.5-dev19, when configured to use hdr_ip or other "hdr_*" functions with a negative occurrence count, allows remote attackers to cause a denial of service (negative array index usage and crash) via an HTTP header with a certain number of values, related to the MAX_HDR_HISTORY variable.
nvd
CVE-2020-16291P4MEDIUMCVSS 5.5v9.0v10.02020-08-13
CVE-2020-16291 [MEDIUM] CWE-787 CVE-2020-16291: A buffer overflow vulnerability in contrib/gdevdj9.c of Artifex Software GhostScript v9.18 to v9.50 A buffer overflow vulnerability in contrib/gdevdj9.c of Artifex Software GhostScript v9.18 to v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
nvd
Debian Linux vulnerabilities | cvebase