cbcvebase.

Debian Linux vulnerabilities

9,955 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358

Vulnerabilities

Page 405 of 498
CVE-2017-16611P4MEDIUMCVSS 5.5v8.0v9.02017-12-01
CVE-2017-16611 [MEDIUM] CWE-59 CVE-2017-16611: In libXfont before 1.5.4 and libXfont2 before 2.0.3, a local attacker can open (but not read) files In libXfont before 1.5.4 and libXfont2 before 2.0.3, a local attacker can open (but not read) files on the system as root, triggering tape rewinds, watchdogs, or similar mechanisms that can be triggered by opening files.
nvd
CVE-2020-8695P4MEDIUMCVSS 5.5v9.02020-11-12
CVE-2020-8695 [MEDIUM] CWE-203 CVE-2020-8695: Observable discrepancy in the RAPL interface for some Intel(R) Processors may allow a privileged use Observable discrepancy in the RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.
nvd
CVE-2015-4802P4MEDIUMCVSS 4.0v7.0v8.02015-10-21
CVE-2015-4802 [MEDIUM] CVE-2015-4802: Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows re Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Partition, a different vulnerability than CVE-2015-4792.
nvd
CVE-2018-5953P4MEDIUMCVSS 5.5v8.02018-08-07
CVE-2018-5953 [MEDIUM] CWE-200 CVE-2018-5953: The swiotlb_print_info function in lib/swiotlb.c in the Linux kernel through 4.14.14 allows local us The swiotlb_print_info function in lib/swiotlb.c in the Linux kernel through 4.14.14 allows local users to obtain sensitive address information by reading dmesg data from a "software IO TLB" printk call.
nvd
CVE-2020-29485P4MEDIUMCVSS 5.5v10.02020-12-15
CVE-2020-29485 [MEDIUM] CWE-401 CVE-2020-29485: An issue was discovered in Xen 4.6 through 4.14.x. When acting upon a guest XS_RESET_WATCHES request An issue was discovered in Xen 4.6 through 4.14.x. When acting upon a guest XS_RESET_WATCHES request, not all tracking information is freed. A guest can cause unbounded memory usage in oxenstored. This can lead to a system-wide DoS. Only systems using the Ocaml Xenstored implementation are vulnerable. Systems using the C Xenstored implementation are
nvd
CVE-2018-6147P4MEDIUMCVSS 5.5v9.02019-01-09
CVE-2018-6147 [MEDIUM] CWE-200 CVE-2018-6147: Lack of secure text entry mode in Browser UI in Google Chrome on Mac prior to 67.0.3396.62 allowed a Lack of secure text entry mode in Browser UI in Google Chrome on Mac prior to 67.0.3396.62 allowed a local attacker to obtain potentially sensitive information from process memory via a local process.
nvd
CVE-2012-5476P4MEDIUMCVSS 5.5v8.0v9.0+1 more2019-12-30
CVE-2012-5476 [MEDIUM] CWE-200 CVE-2012-5476: Within the RHOS Essex Preview (2012.2) of the OpenStack dashboard package, the file /etc/quantum/qua Within the RHOS Essex Preview (2012.2) of the OpenStack dashboard package, the file /etc/quantum/quantum.conf is world readable which exposes the admin password and token value.
nvd
CVE-2019-8354P4MEDIUMCVSS 5.0v8.02019-02-15
CVE-2019-8354 [MEDIUM] CWE-190 CVE-2019-8354: An issue was discovered in SoX 14.4.2. lsx_make_lpf in effect_i_dsp.c has an integer overflow on the An issue was discovered in SoX 14.4.2. lsx_make_lpf in effect_i_dsp.c has an integer overflow on the result of multiplication fed into malloc. When the buffer is allocated, it is smaller than expected, leading to a heap-based buffer overflow.
nvd
CVE-2016-0641P4MEDIUMCVSS 5.1v8.02016-04-21
CVE-2016-0641 [MEDIUM] CVE-2016-0641: Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and ear Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.48, 10.0.x before 10.0.24, and 10.1.x before 10.1.12 allows local users to affect confidentiality and availability via vectors related to MyISAM.
nvd
CVE-2025-38124P4MEDIUMCVSS 5.5v11.02025-07-03
CVE-2025-38124 [MEDIUM] CWE-401 CVE-2025-38124: In the Linux kernel, the following vulnerability has been resolved: net: fix udp gso skb_segment af In the Linux kernel, the following vulnerability has been resolved: net: fix udp gso skb_segment after pull from frag_list Commit a1e40ac5b5e9 ("net: gso: fix udp gso fraglist segmentation after pull from frag_list") detected invalid geometry in frag_list skbs and redirects them from skb_segment_list to more robust skb_segment. But some packets wit
nvd
CVE-2020-35530P4MEDIUMCVSS 5.5v10.02022-09-01
CVE-2020-35530 [MEDIUM] CWE-787 CVE-2020-35530: In LibRaw, there is an out-of-bounds write vulnerability within the "new_node()" function (libraw\sr In LibRaw, there is an out-of-bounds write vulnerability within the "new_node()" function (libraw\src\x3f\x3f_utils_patched.cpp) that can be triggered via a crafted X3F file.
nvd
CVE-2020-8632P4MEDIUMCVSS 5.5v8.02020-02-05
CVE-2020-8632 [MEDIUM] CWE-521 CVE-2020-8632: In cloud-init through 19.4, rand_user_password in cloudinit/config/cc_set_passwords.py has a small d In cloud-init through 19.4, rand_user_password in cloudinit/config/cc_set_passwords.py has a small default pwlen value, which makes it easier for attackers to guess passwords.
nvd
CVE-2020-14314P4MEDIUMCVSS 5.5v9.02020-09-15
CVE-2020-14314 [MEDIUM] CWE-125 CVE-2020-14314: A memory out-of-bounds read flaw was found in the Linux kernel before 5.9-rc2 with the ext3/ext4 fil A memory out-of-bounds read flaw was found in the Linux kernel before 5.9-rc2 with the ext3/ext4 file system, in the way it accesses a directory with broken indexing. This flaw allows a local user to crash the system if the directory exists. The highest threat from this vulnerability is to system availability.
nvd
CVE-2021-28699P4MEDIUMCVSS 5.5v11.02021-08-27
CVE-2021-28699 [MEDIUM] CVE-2021-28699: inadequate grant-v2 status frames array bounds check The v2 grant table interface separates grant at inadequate grant-v2 status frames array bounds check The v2 grant table interface separates grant attributes from grant status. That is, when operating in this mode, a guest has two tables. As a result, guests also need to be able to retrieve the addresses that the new status tracking table can be accessed through. For 32-bit guests on x86, translation of r
nvd
CVE-2022-21151P4MEDIUMCVSS 5.5v10.0v11.02022-05-12
CVE-2022-21151 [MEDIUM] CVE-2022-21151: Processor optimization removal or modification of security-critical code for some Intel(R) Processor Processor optimization removal or modification of security-critical code for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
nvd
CVE-2021-26932P4MEDIUMCVSS 5.5v9.02021-02-17
CVE-2021-26932 [MEDIUM] CVE-2021-26932: An issue was discovered in the Linux kernel 3.2 through 5.10.16, as used by Xen. Grant mapping opera An issue was discovered in the Linux kernel 3.2 through 5.10.16, as used by Xen. Grant mapping operations often occur in batch hypercalls, where a number of operations are done in a single hypercall, the success or failure of each one is reported to the backend driver, and the backend driver then loops over the results, performing follow-up actions based on
nvd
CVE-2018-8754P4MEDIUMCVSS 5.5v9.02018-03-18
CVE-2018-8754 [MEDIUM] CWE-125 CVE-2018-8754: The libevt_record_values_read_event() function in libevt_record_values.c in libevt before 2018-03-17 The libevt_record_values_read_event() function in libevt_record_values.c in libevt before 2018-03-17 does not properly check for out-of-bounds values of user SID data size, strings size, or data size. NOTE: the vendor has disputed this as described in libyal/libevt issue 5 on GitHub
nvd
CVE-2021-45095P4MEDIUMCVSS 5.5v9.0v10.0+1 more2021-12-16
CVE-2021-45095 [MEDIUM] CWE-200 CVE-2021-45095: pep_sock_accept in net/phonet/pep.c in the Linux kernel through 5.15.8 has a refcount leak. pep_sock_accept in net/phonet/pep.c in the Linux kernel through 5.15.8 has a refcount leak.
nvd
CVE-2012-5474P4MEDIUMCVSS 5.5v8.0v9.0+1 more2019-12-30
CVE-2012-5474 [MEDIUM] CWE-311 CVE-2012-5474: The file /etc/openstack-dashboard/local_settings within Red Hat OpenStack Platform 2.0 and RHOS Esse The file /etc/openstack-dashboard/local_settings within Red Hat OpenStack Platform 2.0 and RHOS Essex Release (python-django-horizon package before 2012.1.1) is world readable and exposes the secret key value.
nvd
CVE-2016-5293P4MEDIUMCVSS 5.5v8.02018-06-11
CVE-2016-5293 [MEDIUM] CWE-20 CVE-2016-5293: When the Mozilla Updater is run, if the Updater's log file in the working directory points to a hard When the Mozilla Updater is run, if the Updater's log file in the working directory points to a hardlink, data can be appended to an arbitrary local file. This vulnerability requires local system access. Note: this issue only affects Windows operating systems. This vulnerability affects Firefox ESR < 45.5 and Firefox < 50.
nvd
Debian Linux vulnerabilities | cvebase