Debian Linux vulnerabilities
9,955 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358
Vulnerabilities
Page 393 of 498
CVE-2020-26519P4MEDIUMCVSS 5.5v9.0v10.02020-10-02
CVE-2020-26519 [MEDIUM] CWE-787 CVE-2020-26519: Artifex MuPDF before 1.18.0 has a heap based buffer over-write when parsing JBIG2 files allowing att
Artifex MuPDF before 1.18.0 has a heap based buffer over-write when parsing JBIG2 files allowing attackers to cause a denial of service.
nvd
CVE-2022-2078P4MEDIUMCVSS 5.5v11.02022-06-30
CVE-2022-2078 [MEDIUM] CWE-121 CVE-2022-2078: A vulnerability was found in the Linux kernel's nft_set_desc_concat_parse() function .This flaw allo
A vulnerability was found in the Linux kernel's nft_set_desc_concat_parse() function .This flaw allows an attacker to trigger a buffer overflow via nft_set_desc_concat_parse() , causing a denial of service and possibly to run code.
nvd
CVE-2021-3479P4MEDIUMCVSS 5.5v9.0v10.02021-03-31
CVE-2021-3479 [MEDIUM] CWE-400 CVE-2021-3479: There's a flaw in OpenEXR's Scanline API functionality in versions before 3.0.0-beta. An attacker wh
There's a flaw in OpenEXR's Scanline API functionality in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to be processed by OpenEXR could trigger excessive consumption of memory, resulting in an impact to system availability.
nvd
CVE-2016-2058P4MEDIUMCVSS 5.4v8.02016-04-13
CVE-2016-2058 [MEDIUM] CWE-79 CVE-2016-2058: Multiple cross-site scripting (XSS) vulnerabilities in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 a
Multiple cross-site scripting (XSS) vulnerabilities in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow (1) remote Xymon clients to inject arbitrary web script or HTML via a status-message, which is not properly handled in the "detailed status" page, or (2) remote authenticated users to inject arbitrary web script or HTML via an acknowledgement messag
nvd
CVE-2008-5510P4MEDIUMCVSS 5.0v4.0v5.02008-12-17
CVE-2008-5510 [MEDIUM] CVE-2008-5510: The CSS parser in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2
The CSS parser in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 ignores the '\0' escaped null character, which might allow remote attackers to bypass protection mechanisms such as sanitization routines.
nvd
CVE-2021-3566P4MEDIUMCVSS 5.5v9.02021-08-05
CVE-2021-3566 [MEDIUM] CWE-200 CVE-2021-3566: Prior to ffmpeg version 4.3, the tty demuxer did not have a 'read_probe' function assigned to it. By
Prior to ffmpeg version 4.3, the tty demuxer did not have a 'read_probe' function assigned to it. By crafting a legitimate "ffconcat" file that references an image, followed by a file the triggers the tty demuxer, the contents of the second file will be copied into the output file verbatim (as long as the `-vcodec copy` option is passed to ffmpeg).
nvd
CVE-2018-10061P4MEDIUMCVSS 5.4v9.02018-04-12
CVE-2018-10061 [MEDIUM] CWE-79 CVE-2018-10061: Cacti before 1.1.37 has XSS because it makes certain htmlspecialchars calls without the ENT_QUOTES f
Cacti before 1.1.37 has XSS because it makes certain htmlspecialchars calls without the ENT_QUOTES flag (these calls occur when the html_escape function in lib/html.php is not used).
nvd
CVE-2022-41218P4MEDIUMCVSS 5.5v11.02022-09-21
CVE-2022-41218 [MEDIUM] CWE-416 CVE-2022-41218: In drivers/media/dvb-core/dmxdev.c in the Linux kernel through 5.19.10, there is a use-after-free ca
In drivers/media/dvb-core/dmxdev.c in the Linux kernel through 5.19.10, there is a use-after-free caused by refcount races, affecting dvb_demux_open and dvb_dmxdev_release.
nvd
CVE-2020-16166P4LOWCVSS 3.7v9.02020-07-30
CVE-2020-16166 [LOW] CWE-330 CVE-2020-16166: The Linux kernel through 5.7.11 allows remote attackers to make observations that help to obtain sen
The Linux kernel through 5.7.11 allows remote attackers to make observations that help to obtain sensitive information about the internal state of the network RNG, aka CID-f227e3ec3b5c. This is related to drivers/char/random.c and kernel/time/timer.c.
nvd
CVE-2023-42883P4MEDIUMCVSS 5.5v11.0v12.02023-12-12
CVE-2023-42883 [MEDIUM] CVE-2023-42883: The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, macOS Son
The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, macOS Sonoma 14.2, iOS 17.2 and iPadOS 17.2, watchOS 10.2, tvOS 17.2, iOS 16.7.3 and iPadOS 16.7.3. Processing an image may lead to a denial-of-service.
nvd
CVE-2024-35884P4MEDIUMCVSS 5.5v10.02024-05-19
CVE-2024-35884 [MEDIUM] CWE-617 CVE-2024-35884: In the Linux kernel, the following vulnerability has been resolved: udp: do not accept non-tunnel G
In the Linux kernel, the following vulnerability has been resolved:
udp: do not accept non-tunnel GSO skbs landing in a tunnel
When rx-udp-gro-forwarding is enabled UDP packets might be GROed when
being forwarded. If such packets might land in a tunnel this can cause
various issues and udp_gro_receive makes sure this isn't the case by
looking for a
nvd
CVE-2013-1934P4MEDIUMCVSS 5.4v7.02019-10-31
CVE-2013-1934 [MEDIUM] CWE-79 CVE-2013-1934: A cross-site scripting (XSS) vulnerability in the configuration report page (adm_config_report.php)
A cross-site scripting (XSS) vulnerability in the configuration report page (adm_config_report.php) in MantisBT 1.2.0rc1 before 1.2.14 allows remote authenticated users to inject arbitrary web script or HTML via a complex value.
nvd
CVE-2021-43389P4MEDIUMCVSS 5.5v9.0v10.02021-11-04
CVE-2021-43389 [MEDIUM] CWE-125 CVE-2021-43389: An issue was discovered in the Linux kernel before 5.14.15. There is an array-index-out-of-bounds fl
An issue was discovered in the Linux kernel before 5.14.15. There is an array-index-out-of-bounds flaw in the detach_capi_ctr function in drivers/isdn/capi/kcapi.c.
nvd
CVE-2018-16468P4MEDIUMCVSS 5.4v9.02018-10-30
CVE-2018-16468 [MEDIUM] CWE-79 CVE-2018-16468: In the Loofah gem for Ruby, through v2.2.2, unsanitized JavaScript may occur in sanitized output whe
In the Loofah gem for Ruby, through v2.2.2, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.
nvd
CVE-2020-28928P4MEDIUMCVSS 5.5v9.02020-11-24
CVE-2020-28928 [MEDIUM] CWE-787 CVE-2020-28928: In musl libc through 1.2.1, wcsnrtombs mishandles particular combinations of destination buffer size
In musl libc through 1.2.1, wcsnrtombs mishandles particular combinations of destination buffer size and source character limit, as demonstrated by an invalid write access (buffer overflow).
nvd
CVE-2022-36280P4MEDIUMCVSS 5.5v11.02022-09-09
CVE-2022-36280 [MEDIUM] CWE-120 CVE-2022-36280: An out-of-bounds(OOB) memory access vulnerability was found in vmwgfx driver in drivers/gpu/vmxgfx/v
An out-of-bounds(OOB) memory access vulnerability was found in vmwgfx driver in drivers/gpu/vmxgfx/vmxgfx_kms.c in GPU component in the Linux kernel with device file '/dev/dri/renderD128 (or Dxxx)'. This flaw allows a local attacker with a user account on the system to gain privilege, causing a denial of service(DoS).
nvd
CVE-2022-42721P4MEDIUMCVSS 5.5v10.0v11.02022-10-14
CVE-2022-42721 [MEDIUM] CWE-835 CVE-2022-42721: A list management bug in BSS handling in the mac80211 stack in the Linux kernel 5.1 through 5.19.x b
A list management bug in BSS handling in the mac80211 stack in the Linux kernel 5.1 through 5.19.x before 5.19.16 could be used by local attackers (able to inject WLAN frames) to corrupt a linked list and, in turn, potentially execute code.
nvd
CVE-2014-3610P4MEDIUMCVSS 5.5v7.02014-11-10
CVE-2014-3610 [MEDIUM] CVE-2014-3610: The WRMSR processing functionality in the KVM subsystem in the Linux kernel through 3.17.2 does not
The WRMSR processing functionality in the KVM subsystem in the Linux kernel through 3.17.2 does not properly handle the writing of a non-canonical address to a model-specific register, which allows guest OS users to cause a denial of service (host OS crash) by leveraging guest OS privileges, related to the wrmsr_interception function in arch/x86/kvm/svm.c and
nvd
CVE-2015-2730P4MEDIUMCVSS 4.3v7.0v8.02015-07-06
CVE-2015-2730 [MEDIUM] CWE-310 CVE-2015-2730: Mozilla Network Security Services (NSS) before 3.19.1, as used in Mozilla Firefox before 39.0, Firef
Mozilla Network Security Services (NSS) before 3.19.1, as used in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and other products, does not properly perform Elliptical Curve Cryptography (ECC) multiplications, which makes it easier for remote attackers to spoof ECDSA signatures via unspecified vectors.
nvd
CVE-2019-15292P4MEDIUMCVSS 4.7v8.02019-08-21
CVE-2019-15292 [MEDIUM] CWE-416 CVE-2019-15292: An issue was discovered in the Linux kernel before 5.0.9. There is a use-after-free in atalk_proc_ex
An issue was discovered in the Linux kernel before 5.0.9. There is a use-after-free in atalk_proc_exit, related to net/appletalk/atalk_proc.c, net/appletalk/ddp.c, and net/appletalk/sysctl_net_atalk.c.
nvd