Debian Linux vulnerabilities
9,955 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358
Vulnerabilities
Page 397 of 498
CVE-2025-38683P4MEDIUMCVSS 5.5v11.02025-09-04
CVE-2025-38683 [MEDIUM] CWE-476 CVE-2025-38683: In the Linux kernel, the following vulnerability has been resolved: hv_netvsc: Fix panic during nam
In the Linux kernel, the following vulnerability has been resolved:
hv_netvsc: Fix panic during namespace deletion with VF
The existing code move the VF NIC to new namespace when NETDEV_REGISTER is
received on netvsc NIC. During deletion of the namespace,
default_device_exit_batch() >> default_device_exit_net() is called. When
netvsc NIC is moved b
nvd
CVE-2025-39724P4MEDIUMCVSS 5.5v11.02025-09-05
CVE-2025-39724 [MEDIUM] CVE-2025-39724: In the Linux kernel, the following vulnerability has been resolved: serial: 8250: fix panic due to
In the Linux kernel, the following vulnerability has been resolved:
serial: 8250: fix panic due to PSLVERR
When the PSLVERR_RESP_EN parameter is set to 1, the device generates
an error response if an attempt is made to read an empty RBR (Receive
Buffer Register) while the FIFO is enabled.
In serial8250_do_startup(), calling serial_port_out(port, UART_LCR,
nvd
CVE-2025-38478P4MEDIUMCVSS 5.5v11.02025-07-28
CVE-2025-38478 [MEDIUM] CWE-908 CVE-2025-38478: In the Linux kernel, the following vulnerability has been resolved: comedi: Fix initialization of d
In the Linux kernel, the following vulnerability has been resolved:
comedi: Fix initialization of data for instructions that write to subdevice
Some Comedi subdevice instruction handlers are known to access
instruction data elements beyond the first `insn->n` elements in some
cases. The `do_insn_ioctl()` and `do_insnlist_ioctl()` functions
allocate
nvd
CVE-2025-39756P4MEDIUMCVSS 5.5v11.02025-09-11
CVE-2025-39756 [MEDIUM] CWE-401 CVE-2025-39756: In the Linux kernel, the following vulnerability has been resolved: fs: Prevent file descriptor tab
In the Linux kernel, the following vulnerability has been resolved:
fs: Prevent file descriptor table allocations exceeding INT_MAX
When sysctl_nr_open is set to a very high value (for example, 1073741816
as set by systemd), processes attempting to use file descriptors near
the limit can trigger massive memory allocation attempts that exceed
INT_MA
nvd
CVE-2025-38061P4MEDIUMCVSS 5.5v11.02025-06-18
CVE-2025-38061 [MEDIUM] CVE-2025-38061: In the Linux kernel, the following vulnerability has been resolved: net: pktgen: fix access outside
In the Linux kernel, the following vulnerability has been resolved:
net: pktgen: fix access outside of user given buffer in pktgen_thread_write()
Honour the user given buffer size for the strn_len() calls (otherwise
strn_len() will access memory outside of the user given buffer).
nvd
CVE-2025-38457P4MEDIUMCVSS 5.5v11.02025-07-25
CVE-2025-38457 [MEDIUM] CVE-2025-38457: In the Linux kernel, the following vulnerability has been resolved: net/sched: Abort __tc_modify_qd
In the Linux kernel, the following vulnerability has been resolved:
net/sched: Abort __tc_modify_qdisc if parent class does not exist
Lion's patch [1] revealed an ancient bug in the qdisc API.
Whenever a user creates/modifies a qdisc specifying as a parent another
qdisc, the qdisc API will, during grafting, detect that the user is
not trying to attach to a
nvd
CVE-2025-38062P4MEDIUMCVSS 5.5v11.02025-06-18
CVE-2025-38062 [MEDIUM] CVE-2025-38062: In the Linux kernel, the following vulnerability has been resolved: genirq/msi: Store the IOMMU IOV
In the Linux kernel, the following vulnerability has been resolved:
genirq/msi: Store the IOMMU IOVA directly in msi_desc instead of iommu_cookie
The IOMMU translation for MSI message addresses has been a 2-step process,
separated in time:
1) iommu_dma_prepare_msi(): A cookie pointer containing the IOVA address
is stored in the MSI descriptor when an MSI
nvd
CVE-2025-39844P4MEDIUMCVSS 5.5v11.02025-09-19
CVE-2025-39844 [MEDIUM] CVE-2025-39844: In the Linux kernel, the following vulnerability has been resolved: mm: move page table sync declar
In the Linux kernel, the following vulnerability has been resolved:
mm: move page table sync declarations to linux/pgtable.h
During our internal testing, we started observing intermittent boot
failures when the machine uses 4-level paging and has a large amount of
persistent memory:
BUG: unable to handle page fault for address: ffffe70000000034
#PF: super
nvd
CVE-2013-2868P4MEDIUMCVSS 5.0v7.02013-07-10
CVE-2013-2868 [MEDIUM] CVE-2013-2868: common/extensions/sync_helper.cc in Google Chrome before 28.0.1500.71 proceeds with sync operations
common/extensions/sync_helper.cc in Google Chrome before 28.0.1500.71 proceeds with sync operations for NPAPI extensions without checking for a certain plugin permission setting, which might allow remote attackers to trigger unwanted extension changes via unspecified vectors.
nvd
CVE-2012-3986P4MEDIUMCVSS 4.3v6.02012-10-10
CVE-2012-3986 [MEDIUM] CWE-20 CVE-2012-3986: Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ES
Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 do not properly restrict calls to DOMWindowUtils (aka nsDOMWindowUtils) methods, which allows remote attackers to bypass intended access restrictions via crafted JavaScript code.
nvd
CVE-2019-2745P4MEDIUMCVSS 5.1v8.02019-07-23
CVE-2019-2745 [MEDIUM] CVE-2019-2745: Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Security). Supported version
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 7u221, 8u212 and 11.0.3. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Java SE executes to compromise Java SE. Successful attacks of this vulnerability can result in un
nvd
CVE-2018-3058P4MEDIUMCVSS 4.3v8.0v9.02018-07-18
CVE-2018-3058 [MEDIUM] CVE-2018-3058: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: MyISAM). Supported versio
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: MyISAM). Supported versions that are affected are 5.5.60 and prior, 5.6.40 and prior and 5.7.22 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can
nvd
CVE-2019-11281P4MEDIUMCVSS 4.8v9.02019-10-16
CVE-2019-11281 [MEDIUM] CWE-79 CVE-2019-11281: Pivotal RabbitMQ, versions prior to v3.7.18, and RabbitMQ for PCF, versions 1.15.x prior to 1.15.13,
Pivotal RabbitMQ, versions prior to v3.7.18, and RabbitMQ for PCF, versions 1.15.x prior to 1.15.13, versions 1.16.x prior to 1.16.6, and versions 1.17.x prior to 1.17.3, contain two components, the virtual host limits page, and the federation management UI, which do not properly sanitize user input. A remote authenticated malicious user with adminis
nvd
CVE-2020-25085P4MEDIUMCVSS 5.0v9.0v10.02020-09-25
CVE-2020-25085 [MEDIUM] CWE-787 CVE-2020-25085: QEMU 5.0.0 has a heap-based Buffer Overflow in flatview_read_continue in exec.c because hw/sd/sdhci.
QEMU 5.0.0 has a heap-based Buffer Overflow in flatview_read_continue in exec.c because hw/sd/sdhci.c mishandles a write operation in the SDHC_BLKSIZE case.
nvd
CVE-2014-9039P4MEDIUMCVSS 4.3v7.0v8.02014-11-25
CVE-2014-9039 [MEDIUM] CWE-254 CVE-2014-9039: wp-login.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1
wp-login.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to reset passwords by leveraging access to an e-mail account that received a password-reset message.
nvd
CVE-2017-6932P4MEDIUMCVSS 4.7v7.0v8.0+1 more2018-03-01
CVE-2017-6932 [MEDIUM] CWE-601 CVE-2017-6932: Drupal core 7.x versions before 7.57 has an external link injection vulnerability when the language
Drupal core 7.x versions before 7.57 has an external link injection vulnerability when the language switcher block is used. A similar vulnerability exists in various custom and contributed modules. This vulnerability could allow an attacker to trick users into unwillingly navigating to an external site.
nvd
CVE-2020-1733P4MEDIUMCVSS 5.0v8.0v10.02020-03-11
CVE-2020-1733 [MEDIUM] CWE-377 CVE-2020-1733: A race condition flaw was found in Ansible Engine 2.7.17 and prior, 2.8.9 and prior, 2.9.6 and prior
A race condition flaw was found in Ansible Engine 2.7.17 and prior, 2.8.9 and prior, 2.9.6 and prior when running a playbook with an unprivileged become user. When Ansible needs to run a module with become user, the temporary directory is created in /var/tmp. This directory is created with "umask 77 && mkdir -p "; this operation does not fail if the d
nvd
CVE-2019-16680P4MEDIUMCVSS 4.3v8.0v9.02019-09-21
CVE-2019-16680 [MEDIUM] CWE-22 CVE-2019-16680: An issue was discovered in GNOME file-roller before 3.29.91. It allows a single ./../ path traversal
An issue was discovered in GNOME file-roller before 3.29.91. It allows a single ./../ path traversal via a filename contained in a TAR archive, possibly overwriting a file during extraction.
nvd
CVE-2019-16711P4MEDIUMCVSS 6.5v10.02019-09-23
CVE-2019-16711 [MEDIUM] CWE-401 CVE-2019-16711: ImageMagick 7.0.8-40 has a memory leak in Huffman2DEncodeImage in coders/ps2.c.
ImageMagick 7.0.8-40 has a memory leak in Huffman2DEncodeImage in coders/ps2.c.
nvd
CVE-2024-21096P4MEDIUMCVSS 4.9v11.02024-04-16
CVE-2024-21096 [MEDIUM] CWE-829 CVE-2024-21096: Vulnerability in the MySQL Server product of Oracle MySQL (component: Client: mysqldump). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.0.36 and prior and 8.3.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attacks of this
nvd