cbcvebase.

Debian Linux vulnerabilities

9,955 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358

Vulnerabilities

Page 404 of 498
CVE-2016-0597P4MEDIUMCVSS 4.0v8.02016-01-21
CVE-2016-0597 [MEDIUM] CVE-2016-0597: Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and Mari Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via unknown vectors related to Optimizer.
nvd
CVE-2018-10940P4MEDIUMCVSS 5.5v7.02018-05-09
CVE-2018-10940 [MEDIUM] CWE-119 CVE-2018-10940: The cdrom_ioctl_media_changed function in drivers/cdrom/cdrom.c in the Linux kernel before 4.16.6 al The cdrom_ioctl_media_changed function in drivers/cdrom/cdrom.c in the Linux kernel before 4.16.6 allows local attackers to use a incorrect bounds check in the CDROM driver CDROM_MEDIA_CHANGED ioctl to read out kernel memory.
nvd
CVE-2019-3882P4MEDIUMCVSS 5.5v8.0v9.0+1 more2019-04-24
CVE-2019-3882 [MEDIUM] CWE-770 CVE-2019-3882: A flaw was found in the Linux kernel's vfio interface implementation that permits violation of the u A flaw was found in the Linux kernel's vfio interface implementation that permits violation of the user's locked memory limit. If a device is bound to a vfio driver, such as vfio-pci, and the local attacker is administratively granted ownership of the device, it may cause a system memory exhaustion and thus a denial of service (DoS). Versions 3.10, 4.
nvd
CVE-2020-8698P4MEDIUMCVSS 5.5v9.02020-11-12
CVE-2020-8698 [MEDIUM] CWE-668 CVE-2020-8698: Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user t Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
nvd
CVE-2011-4915P4MEDIUMCVSS 5.5v8.0v9.0+1 more2020-02-20
CVE-2011-4915 [MEDIUM] CWE-200 CVE-2011-4915: fs/proc/base.c in the Linux kernel through 3.1 allows local users to obtain sensitive keystroke info fs/proc/base.c in the Linux kernel through 3.1 allows local users to obtain sensitive keystroke information via access to /proc/interrupts.
nvd
CVE-2025-38430P4MEDIUMCVSS 5.5v11.02025-07-25
CVE-2025-38430 [MEDIUM] CVE-2025-38430: In the Linux kernel, the following vulnerability has been resolved: nfsd: nfsd4_spo_must_allow() mu In the Linux kernel, the following vulnerability has been resolved: nfsd: nfsd4_spo_must_allow() must check this is a v4 compound request If the request being processed is not a v4 compound request, then examining the cstate can have undefined results. This patch adds a check that the rpc procedure being executed (rq_procinfo) is the NFSPROC4_COMPOUND pro
nvd
CVE-2025-38035P4MEDIUMCVSS 5.5v11.02025-06-18
CVE-2025-38035 [MEDIUM] CWE-476 CVE-2025-38035: In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: don't restore null s In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: don't restore null sk_state_change queue->state_change is set as part of nvmet_tcp_set_queue_sock(), but if the TCP connection isn't established when nvmet_tcp_set_queue_sock() is called then queue->state_change isn't set and sock->sk->sk_state_change isn't replaced. As
nvd
CVE-2020-28935P4MEDIUMCVSS 5.5v9.02020-12-07
CVE-2020-28935 [MEDIUM] CWE-59 CVE-2020-28935: NLnet Labs Unbound, up to and including version 1.12.0, and NLnet Labs NSD, up to and including vers NLnet Labs Unbound, up to and including version 1.12.0, and NLnet Labs NSD, up to and including version 4.3.3, contain a local vulnerability that would allow for a local symlink attack. When writing the PID file, Unbound and NSD create the file if it is not there, or open an existing file for writing. In case the file was already present, they would
nvd
CVE-2020-15306P4MEDIUMCVSS 5.5v9.0v10.02020-06-26
CVE-2020-15306 [MEDIUM] CWE-787 CVE-2020-15306: An issue was discovered in OpenEXR before v2.5.2. Invalid chunkCount attributes could cause a heap b An issue was discovered in OpenEXR before v2.5.2. Invalid chunkCount attributes could cause a heap buffer overflow in getChunkOffsetTableSize() in IlmImf/ImfMisc.cpp.
nvd
CVE-2022-3586P4MEDIUMCVSS 5.5v10.02022-10-19
CVE-2022-3586 [MEDIUM] CWE-416 CVE-2022-3586: A flaw was found in the Linux kernel’s networking code. A use-after-free was found in the way the sc A flaw was found in the Linux kernel’s networking code. A use-after-free was found in the way the sch_sfb enqueue function used the socket buffer (SKB) cb field after the same SKB had been enqueued (and freed) into a child qdisc. This flaw allows a local, unprivileged user to crash the system, causing a denial of service.
nvd
CVE-2017-2618P4MEDIUMCVSS 5.5v8.02018-07-27
CVE-2017-2618 [MEDIUM] CWE-193 CVE-2017-2618: A flaw was found in the Linux kernel's handling of clearing SELinux attributes on /proc/pid/attr fil A flaw was found in the Linux kernel's handling of clearing SELinux attributes on /proc/pid/attr files before 4.9.10. An empty (null) write to this file can crash the system by causing the system to attempt to access unmapped kernel memory.
nvd
CVE-2020-8696P4MEDIUMCVSS 5.5v9.02020-11-12
CVE-2020-8696 [MEDIUM] CWE-212 CVE-2020-8696: Improper removal of sensitive information before storage or transfer in some Intel(R) Processors may Improper removal of sensitive information before storage or transfer in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
nvd
CVE-2017-10806P4MEDIUMCVSS 5.5v8.0v9.02017-08-02
CVE-2017-10806 [MEDIUM] CWE-787 CVE-2017-10806: Stack-based buffer overflow in hw/usb/redirect.c in QEMU (aka Quick Emulator) allows local guest OS Stack-based buffer overflow in hw/usb/redirect.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (QEMU process crash) via vectors related to logging debug messages.
nvd
CVE-2020-25652P4MEDIUMCVSS 5.5v9.02020-11-26
CVE-2020-25652 [MEDIUM] CWE-770 CVE-2020-25652: A flaw was found in the spice-vdagentd daemon, where it did not properly handle client connections t A flaw was found in the spice-vdagentd daemon, where it did not properly handle client connections that can be established via the UNIX domain socket in `/run/spice-vdagentd/spice-vdagent-sock`. Any unprivileged local guest user could use this flaw to prevent legitimate agents from connecting to the spice-vdagentd daemon, resulting in a denial of se
nvd
CVE-2018-1071P4MEDIUMCVSS 5.5v7.02018-03-09
CVE-2018-1071 [MEDIUM] CWE-121 CVE-2018-1071: zsh through version 5.4.2 is vulnerable to a stack-based buffer overflow in the exec.c:hashcmd() fun zsh through version 5.4.2 is vulnerable to a stack-based buffer overflow in the exec.c:hashcmd() function. A local attacker could exploit this to cause a denial of service.
nvd
CVE-2012-0843P4MEDIUMCVSS 5.5v8.0v9.02019-11-19
CVE-2012-0843 [MEDIUM] CWE-200 CVE-2012-0843: uzbl: Information disclosure via world-readable cookies storage file uzbl: Information disclosure via world-readable cookies storage file
nvd
CVE-2021-3598P4MEDIUMCVSS 5.5v10.0v11.02021-07-06
CVE-2021-3598 [MEDIUM] CWE-119 CVE-2021-3598: There's a flaw in OpenEXR's ImfDeepScanLineInputFile functionality in versions prior to 3.0.5. An at There's a flaw in OpenEXR's ImfDeepScanLineInputFile functionality in versions prior to 3.0.5. An attacker who is able to submit a crafted file to an application linked with OpenEXR could cause an out-of-bounds read. The greatest risk from this flaw is to application availability.
nvd
CVE-2016-5337P4MEDIUMCVSS 5.5v8.02016-06-14
CVE-2016-5337 [MEDIUM] CVE-2016-5337: The megasas_ctrl_get_info function in hw/scsi/megasas.c in QEMU allows local guest OS administrators The megasas_ctrl_get_info function in hw/scsi/megasas.c in QEMU allows local guest OS administrators to obtain sensitive host memory information via vectors related to reading device control information.
nvd
CVE-2020-25600P4MEDIUMCVSS 5.5v10.02020-09-23
CVE-2020-25600 [MEDIUM] CWE-787 CVE-2020-25600: An issue was discovered in Xen through 4.14.x. Out of bounds event channels are available to 32-bit An issue was discovered in Xen through 4.14.x. Out of bounds event channels are available to 32-bit x86 domains. The so called 2-level event channel model imposes different limits on the number of usable event channels for 32-bit x86 domains vs 64-bit or Arm (either bitness) ones. 32-bit x86 domains can use only 1023 channels, due to limited space in
nvd
CVE-2020-25601P4MEDIUMCVSS 5.5v10.02020-09-23
CVE-2020-25601 [MEDIUM] CVE-2020-25601: An issue was discovered in Xen through 4.14.x. There is a lack of preemption in evtchn_reset() / evt An issue was discovered in Xen through 4.14.x. There is a lack of preemption in evtchn_reset() / evtchn_destroy(). In particular, the FIFO event channel model allows guests to have a large number of event channels active at a time. Closing all of these (when resetting all event channels or when cleaning up after the guest) may take extended periods of time.
nvd
Debian Linux vulnerabilities | cvebase