Debian Linux vulnerabilities
9,955 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358
Vulnerabilities
Page 403 of 498
CVE-2015-5523P4MEDIUMCVSS 4.3v7.0v8.02015-08-11
CVE-2015-5523 [MEDIUM] CWE-119 CVE-2015-5523: The ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial o
The ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving multiple whitespace characters before an empty href, which triggers a large memory allocation.
nvd
CVE-2004-0583P4MEDIUMCVSS 5.0v3.02004-08-06
CVE-2004-0583 [MEDIUM] CVE-2004-0583: The account lockout functionality in (1) Webmin 1.140 and (2) Usermin 1.070 does not parse certain c
The account lockout functionality in (1) Webmin 1.140 and (2) Usermin 1.070 does not parse certain character strings, which allows remote attackers to conduct a brute force attack to guess user IDs and passwords.
nvd
CVE-2022-3524P4MEDIUMCVSS 5.5v10.02022-10-16
CVE-2022-3524 [MEDIUM] CWE-404 CVE-2022-3524: A vulnerability was found in Linux Kernel. It has been declared as problematic. Affected by this vul
A vulnerability was found in Linux Kernel. It has been declared as problematic. Affected by this vulnerability is the function ipv6_renew_options of the component IPv6 Handler. The manipulation leads to memory leak. The attack can be launched remotely. It is recommended to apply a patch to fix this issue. The identifier VDB-211021 was assigned to this
nvd
CVE-2019-15118P4MEDIUMCVSS 5.5v8.0v9.0+1 more2019-08-16
CVE-2019-15118 [MEDIUM] CWE-674 CVE-2019-15118: check_input_term in sound/usb/mixer.c in the Linux kernel through 5.2.9 mishandles recursion, leadin
check_input_term in sound/usb/mixer.c in the Linux kernel through 5.2.9 mishandles recursion, leading to kernel stack exhaustion.
nvd
CVE-2020-10029P4MEDIUMCVSS 5.5v10.02020-03-04
CVE-2020-10029 [MEDIUM] CWE-787 CVE-2020-10029: The GNU C Library (aka glibc or libc6) before 2.32 could overflow an on-stack buffer during range re
The GNU C Library (aka glibc or libc6) before 2.32 could overflow an on-stack buffer during range reduction if an input to an 80-bit long double function contains a non-canonical bit pattern, a seen when passing a 0x5d414141414141410000 value to sinl on x86 targets. This is related to sysdeps/ieee754/ldbl-96/e_rem_pio2l.c.
nvd
CVE-2024-26851P4MEDIUMCVSS 5.5v10.02024-04-17
CVE-2024-26851 [MEDIUM] CWE-787 CVE-2024-26851: In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: A
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_conntrack_h323: Add protection for bmp length out of range
UBSAN load reports an exception of BRK#5515 SHIFT_ISSUE:Bitwise shifts
that are out of bounds for their data type.
vmlinux get_bitmap(b=75) + 712
vmlinux decode_seq(bs=0xFFFFFFD008037000, f=0xFFFFFFD00803701
nvd
CVE-2021-3679P4MEDIUMCVSS 5.5v9.0v10.02021-08-05
CVE-2021-3679 [MEDIUM] CWE-400 CVE-2021-3679: A lack of CPU resource in the Linux kernel tracing module functionality in versions prior to 5.14-rc
A lack of CPU resource in the Linux kernel tracing module functionality in versions prior to 5.14-rc3 was found in the way user uses trace ring buffer in a specific way. Only privileged local users (with CAP_SYS_ADMIN capability) could use this flaw to starve the resources causing denial of service.
nvd
CVE-2024-26877P4MEDIUMCVSS 5.5v10.02024-04-17
CVE-2024-26877 [MEDIUM] CVE-2024-26877: In the Linux kernel, the following vulnerability has been resolved: crypto: xilinx - call finalize
In the Linux kernel, the following vulnerability has been resolved:
crypto: xilinx - call finalize with bh disabled
When calling crypto_finalize_request, BH should be disabled to avoid
triggering the following calltrace:
------------[ cut here ]------------
WARNING: CPU: 2 PID: 74 at crypto/crypto_engine.c:58 crypto_finalize_request+0xa0/0x118
Modules link
nvd
CVE-2015-0441P4MEDIUMCVSS 4.0v7.0v8.02015-04-16
CVE-2015-0441 [MEDIUM] CVE-2015-0441: Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows
Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Security : Encryption.
nvd
CVE-2024-26880P4MEDIUMCVSS 5.5v10.02024-04-17
CVE-2024-26880 [MEDIUM] CWE-476 CVE-2024-26880: In the Linux kernel, the following vulnerability has been resolved: dm: call the resume method on i
In the Linux kernel, the following vulnerability has been resolved:
dm: call the resume method on internal suspend
There is this reported crash when experimenting with the lvm2 testsuite.
The list corruption is caused by the fact that the postsuspend and resume
methods were not paired correctly; there were two consecutive calls to the
origin_postsu
nvd
CVE-2025-37871P4MEDIUMCVSS 5.5v11.02025-05-09
CVE-2025-37871 [MEDIUM] CVE-2025-37871: In the Linux kernel, the following vulnerability has been resolved: nfsd: decrease sc_count directl
In the Linux kernel, the following vulnerability has been resolved:
nfsd: decrease sc_count directly if fail to queue dl_recall
A deadlock warning occurred when invoking nfs4_put_stid following a failed
dl_recall queue operation:
T1 T2
nfs4_laundromat
nfs4_get_client_reaplist
nfs4_anylock_blockers
__break_lease
spin_lock // ctx->flc_lock
spin_lock // clp->
nvd
CVE-2024-56644P4MEDIUMCVSS 5.5v11.02024-12-27
CVE-2024-56644 [MEDIUM] CVE-2024-56644: In the Linux kernel, the following vulnerability has been resolved: net/ipv6: release expired excep
In the Linux kernel, the following vulnerability has been resolved:
net/ipv6: release expired exception dst cached in socket
Dst objects get leaked in ip6_negative_advice() when this function is
executed for an expired IPv6 route located in the exception table. There
are several conditions that must be fulfilled for the leak to occur:
* an ICMPv6 packet in
nvd
CVE-2016-1693P4MEDIUMCVSS 5.3v8.02016-06-05
CVE-2016-1693 [MEDIUM] CWE-284 CVE-2016-1693: browser/safe_browsing/srt_field_trial_win.cc in Google Chrome before 51.0.2704.63 does not use the H
browser/safe_browsing/srt_field_trial_win.cc in Google Chrome before 51.0.2704.63 does not use the HTTPS service on dl.google.com to obtain the Software Removal Tool, which allows remote attackers to spoof the chrome_cleanup_tool.exe (aka CCT) file via a man-in-the-middle attack on an HTTP session.
nvd
CVE-2021-37990P4MEDIUMCVSS 5.5v10.0v11.02021-11-02
CVE-2021-37990 [MEDIUM] CVE-2021-37990: Inappropriate implementation in WebView in Google Chrome on Android prior to 95.0.4638.54 allowed a
Inappropriate implementation in WebView in Google Chrome on Android prior to 95.0.4638.54 allowed a remote attacker to leak cross-origin data via a crafted app.
nvd
CVE-2020-0549P4MEDIUMCVSS 5.5v8.0v10.0+1 more2020-01-28
CVE-2020-0549 [MEDIUM] CWE-404 CVE-2020-0549: Cleanup errors in some data cache evictions for some Intel(R) Processors may allow an authenticated
Cleanup errors in some data cache evictions for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
nvd
CVE-2015-2643P4MEDIUMCVSS 4.0v7.0v8.02015-07-16
CVE-2015-2643 [MEDIUM] CVE-2015-2643: Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.24 and earlier allows re
Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.24 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Optimizer.
nvd
CVE-2024-26641P4MEDIUMCVSS 5.5v10.02024-03-18
CVE-2024-26641 [MEDIUM] CWE-908 CVE-2024-26641: In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: make sure to pull i
In the Linux kernel, the following vulnerability has been resolved:
ip6_tunnel: make sure to pull inner header in __ip6_tnl_rcv()
syzbot found __ip6_tnl_rcv() could access unitiliazed data [1].
Call pskb_inet_may_pull() to fix this, and initialize ipv6h
variable after this call as it can change skb->head.
[1]
BUG: KMSAN: uninit-value in __INET_EC
nvd
CVE-2024-35821P4MEDIUMCVSS 5.5v10.02024-05-17
CVE-2024-35821 [MEDIUM] CWE-772 CVE-2024-35821: In the Linux kernel, the following vulnerability has been resolved: ubifs: Set page uptodate in the
In the Linux kernel, the following vulnerability has been resolved:
ubifs: Set page uptodate in the correct place
Page cache reads are lockless, so setting the freshly allocated page
uptodate before we've overwritten it with the data it's supposed to have
in it will allow a simultaneous reader to see old data. Move the call
to SetPageUptodate into
nvd
CVE-2022-21427P4MEDIUMCVSS 4.9v10.02022-04-19
CVE-2022-21427 [MEDIUM] CVE-2022-21427: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: FTS). Supported versio
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: FTS). Supported versions that are affected are 5.7.37 and prior and 8.0.28 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unau
nvd
CVE-2016-0596P4MEDIUMCVSS 4.0v8.02016-01-21
CVE-2016-0596 [MEDIUM] CVE-2016-0596: Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier and 5.6.27 and earlier and MariaDB befo
Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier and 5.6.27 and earlier and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via vectors related to DML.
nvd