cbcvebase.

Debian Linux vulnerabilities

9,955 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358

Vulnerabilities

Page 394 of 498
CVE-2021-37996P4MEDIUMCVSS 5.5v10.0v11.02021-11-02
CVE-2021-37996 [MEDIUM] CWE-20 CVE-2021-37996: Insufficient validation of untrusted input Downloads in Google Chrome prior to 95.0.4638.54 allowed Insufficient validation of untrusted input Downloads in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to bypass navigation restrictions via a malicious file.
nvd
CVE-2018-15594P4MEDIUMCVSS 5.5v8.0v9.02018-08-20
CVE-2018-15594 [MEDIUM] CWE-200 CVE-2018-15594: arch/x86/kernel/paravirt.c in the Linux kernel before 4.18.1 mishandles certain indirect calls, whic arch/x86/kernel/paravirt.c in the Linux kernel before 4.18.1 mishandles certain indirect calls, which makes it easier for attackers to conduct Spectre-v2 attacks against paravirtual guests.
nvd
CVE-2018-17206P4MEDIUMCVSS 4.9v9.02018-09-19
CVE-2018-17206 [MEDIUM] CWE-125 CVE-2018-17206: An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6. The decode_bundle function inside An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6. The decode_bundle function inside lib/ofp-actions.c is affected by a buffer over-read issue during BUNDLE action decoding.
nvd
CVE-2021-26931P4MEDIUMCVSS 5.5v9.02021-02-17
CVE-2021-26931 [MEDIUM] CWE-770 CVE-2021-26931: An issue was discovered in the Linux kernel 2.6.39 through 5.10.16, as used in Xen. Block, net, and An issue was discovered in the Linux kernel 2.6.39 through 5.10.16, as used in Xen. Block, net, and SCSI backends consider certain errors a plain bug, deliberately causing a kernel crash. For errors potentially being at least under the influence of guests (such as out of memory conditions), it isn't correct to assume a plain bug. Memory allocations p
nvd
CVE-2021-3800P4MEDIUMCVSS 5.5v10.02022-08-23
CVE-2021-3800 [MEDIUM] CWE-200 CVE-2021-3800: A flaw was found in glib before version 2.63.6. Due to random charset alias, pkexec can leak content A flaw was found in glib before version 2.63.6. Due to random charset alias, pkexec can leak content from files owned by privileged users to unprivileged ones under the right condition.
nvd
CVE-2025-23145P4MEDIUMCVSS 5.5v11.02025-05-01
CVE-2025-23145 [MEDIUM] CWE-476 CVE-2025-23145: In the Linux kernel, the following vulnerability has been resolved: mptcp: fix NULL pointer in can_ In the Linux kernel, the following vulnerability has been resolved: mptcp: fix NULL pointer in can_accept_new_subflow When testing valkey benchmark tool with MPTCP, the kernel panics in 'mptcp_can_accept_new_subflow' because subflow_req->msk is NULL. Call trace: mptcp_can_accept_new_subflow (./net/mptcp/subflow.c:63 (discriminator 4)) (P) subflow
nvd
CVE-2018-10883P4MEDIUMCVSS 5.5v8.02018-07-30
CVE-2018-10883 [MEDIUM] CWE-787 CVE-2018-10883: A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bounds writ A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bounds write in jbd2_journal_dirty_metadata(), a denial of service, and a system crash by mounting and operating on a crafted ext4 filesystem image.
nvd
CVE-2013-4184P4MEDIUMCVSS 5.5v8.0v9.0+1 more2019-12-10
CVE-2013-4184 [MEDIUM] CWE-59 CVE-2013-4184: Perl module Data::UUID from CPAN version 1.219 vulnerable to symlink attacks Perl module Data::UUID from CPAN version 1.219 vulnerable to symlink attacks
nvd
CVE-2018-5750P4MEDIUMCVSS 5.5v7.0v8.0+1 more2018-01-26
CVE-2018-5750 [MEDIUM] CWE-200 CVE-2018-5750: The acpi_smbus_hc_add function in drivers/acpi/sbshc.c in the Linux kernel through 4.14.15 allows lo The acpi_smbus_hc_add function in drivers/acpi/sbshc.c in the Linux kernel through 4.14.15 allows local users to obtain sensitive address information by reading dmesg data from an SBS HC printk call.
nvd
CVE-2021-3564P4MEDIUMCVSS 5.5v9.02021-06-08
CVE-2021-3564 [MEDIUM] CWE-415 CVE-2021-3564: A flaw double-free memory corruption in the Linux kernel HCI device initialization subsystem was fou A flaw double-free memory corruption in the Linux kernel HCI device initialization subsystem was found in the way user attach malicious HCI TTY Bluetooth device. A local user could use this flaw to crash the system. This flaw affects all the Linux kernel versions starting from 3.13.
nvd
CVE-2025-38439P4MEDIUMCVSS 5.5v11.02025-07-25
CVE-2025-38439 [MEDIUM] CVE-2025-38439: In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Set DMA unmap len corr In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Set DMA unmap len correctly for XDP_REDIRECT When transmitting an XDP_REDIRECT packet, call dma_unmap_len_set() with the proper length instead of 0. This bug triggers this warning on a system with IOMMU enabled: WARNING: CPU: 36 PID: 0 at drivers/iommu/dma-iommu.c:842 __iommu_dma
nvd
CVE-2025-38067P4MEDIUMCVSS 5.5v11.02025-06-18
CVE-2025-38067 [MEDIUM] CVE-2025-38067: In the Linux kernel, the following vulnerability has been resolved: rseq: Fix segfault on registrat In the Linux kernel, the following vulnerability has been resolved: rseq: Fix segfault on registration when rseq_cs is non-zero The rseq_cs field is documented as being set to 0 by user-space prior to registration, however this is not currently enforced by the kernel. This can result in a segfault on return to user-space if the value stored in the rseq_cs
nvd
CVE-2025-38181P4MEDIUMCVSS 5.5v11.02025-07-04
CVE-2025-38181 [MEDIUM] CWE-476 CVE-2025-38181: In the Linux kernel, the following vulnerability has been resolved: calipso: Fix null-ptr-deref in In the Linux kernel, the following vulnerability has been resolved: calipso: Fix null-ptr-deref in calipso_req_{set,del}attr(). syzkaller reported a null-ptr-deref in sock_omalloc() while allocating a CALIPSO option. [0] The NULL is of struct sock, which was fetched by sk_to_full_sk() in calipso_req_setattr(). Since commit a1a5344ddbe8 ("tcp: avoi
nvd
CVE-2022-2153P4MEDIUMCVSS 5.5v10.02022-08-31
CVE-2022-2153 [MEDIUM] CWE-476 CVE-2022-2153: A flaw was found in the Linux kernel’s KVM when attempting to set a SynIC IRQ. This issue makes it p A flaw was found in the Linux kernel’s KVM when attempting to set a SynIC IRQ. This issue makes it possible for a misbehaving VMM to write to SYNIC/STIMER MSRs, causing a NULL pointer dereference. This flaw allows an unprivileged local attacker on the host to issue specific ioctl calls, causing a kernel oops condition that results in a denial of servi
nvd
CVE-2021-3468P4MEDIUMCVSS 5.5v9.02021-06-02
CVE-2021-3468 [MEDIUM] CWE-835 CVE-2021-3468: A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the client connection on the avahi Unix socket is not correctly handled in the client_work function, allowing a local attacker to trigger an infinite loop. The highest threat from this vulnerability is to the availability of the avahi service, which become
nvd
CVE-2018-20511P4MEDIUMCVSS 5.5v8.02018-12-27
CVE-2018-20511 [MEDIUM] CWE-200 CVE-2018-20511: An issue was discovered in the Linux kernel before 4.18.11. The ipddp_ioctl function in drivers/net/ An issue was discovered in the Linux kernel before 4.18.11. The ipddp_ioctl function in drivers/net/appletalk/ipddp.c allows local users to obtain sensitive kernel address information by leveraging CAP_NET_ADMIN to read the ipddp_route dev and next fields via an SIOCFINDIPDDPRT ioctl call.
nvd
CVE-2020-29566P4MEDIUMCVSS 5.5v10.02020-12-15
CVE-2020-29566 [MEDIUM] CWE-674 CVE-2020-29566: An issue was discovered in Xen through 4.14.x. When they require assistance from the device model, x An issue was discovered in Xen through 4.14.x. When they require assistance from the device model, x86 HVM guests must be temporarily de-scheduled. The device model will signal Xen when it has completed its operation, via an event channel, so that the relevant vCPU is rescheduled. If the device model were to signal Xen without having actually comple
nvd
CVE-2022-2318P4MEDIUMCVSS 5.5v10.0v11.02022-07-06
CVE-2022-2318 [MEDIUM] CWE-416 CVE-2022-2318: There are use-after-free vulnerabilities caused by timer handler in net/rose/rose_timer.c of linux t There are use-after-free vulnerabilities caused by timer handler in net/rose/rose_timer.c of linux that allow attackers to crash linux kernel without any privileges.
nvd
CVE-2017-6188P4MEDIUMCVSS 5.5v8.02017-02-22
CVE-2017-6188 [MEDIUM] CWE-20 CVE-2017-6188: Munin before 2.999.6 has a local file write vulnerability when CGI graphs are enabled. Setting multi Munin before 2.999.6 has a local file write vulnerability when CGI graphs are enabled. Setting multiple upper_limit GET parameters allows overwriting any file accessible to the www-data user.
nvd
CVE-2020-17490P4MEDIUMCVSS 5.5v9.0v10.02020-11-06
CVE-2020-17490 [MEDIUM] CWE-732 CVE-2020-17490: The TLS module within SaltStack Salt through 3002 creates certificates with weak file permissions. The TLS module within SaltStack Salt through 3002 creates certificates with weak file permissions.
nvd
Debian Linux vulnerabilities | cvebase