Debian Linux vulnerabilities
9,955 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358
Vulnerabilities
Page 413 of 498
CVE-2015-8473P4MEDIUMCVSS 4.3v8.02016-04-12
CVE-2015-8473 [MEDIUM] CWE-200 CVE-2015-8473: The Issues API in Redmine before 2.6.8, 3.0.x before 3.0.6, and 3.1.x before 3.1.2 allows remote aut
The Issues API in Redmine before 2.6.8, 3.0.x before 3.0.6, and 3.1.x before 3.1.2 allows remote authenticated users to obtain sensitive information in changeset messages by leveraging permission to read issues with related changesets from other projects.
nvd
CVE-2015-1281P4MEDIUMCVSS 4.3v8.02015-07-23
CVE-2015-1281 [MEDIUM] CWE-254 CVE-2015-1281: core/loader/ImageLoader.cpp in Blink, as used in Google Chrome before 44.0.2403.89, does not properl
core/loader/ImageLoader.cpp in Blink, as used in Google Chrome before 44.0.2403.89, does not properly determine the V8 context of a microtask, which allows remote attackers to bypass Content Security Policy (CSP) restrictions by providing an image from an unintended source.
nvd
CVE-2005-0076P4HIGHCVSS 7.2v3.02005-05-02
CVE-2005-0076 [HIGH] CVE-2005-0076: Multiple buffer overflows in the XView library 3.2 may allow local users to execute arbitrary code v
Multiple buffer overflows in the XView library 3.2 may allow local users to execute arbitrary code via setuid applications that use the library.
nvd
CVE-1999-0341P4HIGHCVSS 7.2v1.3.11998-01-01
CVE-1999-0341 [HIGH] CVE-1999-0341: Buffer overflow in the Linux mail program "deliver" allows local users to gain root access.
Buffer overflow in the Linux mail program "deliver" allows local users to gain root access.
nvd
CVE-2006-1772P4HIGHCVSS 7.2v3.12006-04-13
CVE-2006-1772 [HIGH] CVE-2006-1772: debconf in Debian GNU/Linux, when configuring mnogosearch in the mnogosearch-common 3.2.31-1 package
debconf in Debian GNU/Linux, when configuring mnogosearch in the mnogosearch-common 3.2.31-1 package, uses the world-readable config.dat file instead of the restricted passwords.dat for storing the cleartext database administrator password in the mnogosearch-common/database_admin_pass record, which allows local users to view the password.
nvd
CVE-1999-0872P4HIGHCVSS 7.2v2.1v2.21999-08-25
CVE-1999-0872 [HIGH] CVE-1999-0872: Buffer overflow in Vixie cron allows local users to gain root access via a long MAILTO environment v
Buffer overflow in Vixie cron allows local users to gain root access via a long MAILTO environment variable in a crontab file.
nvd
CVE-2020-27170P4MEDIUMCVSS 4.7v9.02021-03-20
CVE-2020-27170 [MEDIUM] CWE-203 CVE-2020-27170: An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c performs undesirabl
An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c performs undesirable out-of-bounds speculation on pointer arithmetic, leading to side-channel attacks that defeat Spectre mitigations and obtain sensitive information from kernel memory, aka CID-f232326f6966. This affects pointer types that do not define a ptr_limit.
nvd
CVE-2020-6527P4MEDIUMCVSS 4.3v10.02020-07-22
CVE-2020-6527 [MEDIUM] CWE-276 CVE-2020-6527: Insufficient policy enforcement in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attac
Insufficient policy enforcement in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy via a crafted HTML page.
nvd
CVE-2018-16586P4MEDIUMCVSS 4.3v8.0v9.02018-09-28
CVE-2018-16586 [MEDIUM] CVE-2018-16586: In Open Ticket Request System (OTRS) 4.0.x before 4.0.32, 5.0.x before 5.0.30, and 6.0.x before 6.0.
In Open Ticket Request System (OTRS) 4.0.x before 4.0.32, 5.0.x before 5.0.30, and 6.0.x before 6.0.11, an attacker could send a malicious email to an OTRS system. If a logged in user opens it, the email could cause the browser to load external image or CSS resources.
nvd
CVE-2020-1740P4MEDIUMCVSS 4.7v8.0v10.02020-03-16
CVE-2020-1740 [MEDIUM] CWE-377 CVE-2020-1740: A flaw was found in Ansible Engine when using Ansible Vault for editing encrypted files. When a user
A flaw was found in Ansible Engine when using Ansible Vault for editing encrypted files. When a user executes "ansible-vault edit", another user on the same computer can read the old and new secret, as it is created in a temporary file with mkstemp and the returned file descriptor is closed and the method write_data is called to write the existing sec
nvd
CVE-2019-3901P4MEDIUMCVSS 4.7v8.02019-04-22
CVE-2019-3901 [MEDIUM] CWE-667 CVE-2019-3901: A race condition in perf_event_open() allows local attackers to leak sensitive data from setuid prog
A race condition in perf_event_open() allows local attackers to leak sensitive data from setuid programs. As no relevant locks (in particular the cred_guard_mutex) are held during the ptrace_may_access() call, it is possible for the specified target task to perform an execve() syscall with setuid execution before perf_event_alloc() actually attaches t
nvd
CVE-2011-1799P4MEDIUMCVSS 6.8v6.0v7.02011-05-16
CVE-2011-1799 [MEDIUM] CWE-704 CVE-2011-1799: Google Chrome before 11.0.696.68 does not properly perform casts of variables during interaction wit
Google Chrome before 11.0.696.68 does not properly perform casts of variables during interaction with the WebKit engine, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2019-5839P4MEDIUMCVSS 4.3v10.02019-06-27
CVE-2019-5839 [MEDIUM] CWE-20 CVE-2019-5839: Excessive data validation in URL parser in Google Chrome prior to 75.0.3770.80 allowed a remote atta
Excessive data validation in URL parser in Google Chrome prior to 75.0.3770.80 allowed a remote attacker who convinced a user to input a URL to bypass website URL validation via a crafted URL.
nvd
CVE-2021-30152P4MEDIUMCVSS 4.3v9.0v10.02021-04-09
CVE-2021-30152 [MEDIUM] CWE-269 CVE-2021-30152: An issue was discovered in MediaWiki before 1.31.13 and 1.32.x through 1.35.x before 1.35.2. When us
An issue was discovered in MediaWiki before 1.31.13 and 1.32.x through 1.35.x before 1.35.2. When using the MediaWiki API to "protect" a page, a user is currently able to protect to a higher level than they currently have permissions for.
nvd
CVE-2021-30155P4MEDIUMCVSS 4.3v9.0v10.02021-04-09
CVE-2021-30155 [MEDIUM] CWE-862 CVE-2021-30155: An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Content
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. ContentModelChange does not check if a user has correct permissions to create and set the content model of a nonexistent page.
nvd
CVE-2014-9713P4MEDIUMCVSS 4.0v7.02015-04-01
CVE-2014-9713 [MEDIUM] CWE-264 CVE-2014-9713: The default slapd configuration in the Debian openldap package 2.4.23-3 through 2.4.39-1.1 allows re
The default slapd configuration in the Debian openldap package 2.4.23-3 through 2.4.39-1.1 allows remote authenticated users to modify the user's permissions and other user attributes via unspecified vectors.
nvd
CVE-2020-9497P4MEDIUMCVSS 4.4v9.02020-07-02
CVE-2020-9497 [MEDIUM] CWE-20 CVE-2020-9497: Apache Guacamole 1.1.0 and older do not properly validate datareceived from RDP servers via static v
Apache Guacamole 1.1.0 and older do not properly validate datareceived from RDP servers via static virtual channels. If a userconnects to a malicious or compromised RDP server, specially-craftedPDUs could result in disclosure of information within the memory ofthe guacd process handling the connection.
nvd
CVE-2023-39418P4MEDIUMCVSS 4.3v12.02023-08-11
CVE-2023-39418 [MEDIUM] CWE-1220 CVE-2023-39418: A vulnerability was found in PostgreSQL with the use of the MERGE command, which fails to test new r
A vulnerability was found in PostgreSQL with the use of the MERGE command, which fails to test new rows against row security policies defined for UPDATE and SELECT. If UPDATE and SELECT policies forbid some rows that INSERT policies do not forbid, a user could store such rows.
nvd
CVE-2019-3701P4MEDIUMCVSS 4.4v8.02019-01-03
CVE-2019-3701 [MEDIUM] CWE-787 CVE-2019-3701: An issue was discovered in can_can_gw_rcv in net/can/gw.c in the Linux kernel through 4.19.13. The C
An issue was discovered in can_can_gw_rcv in net/can/gw.c in the Linux kernel through 4.19.13. The CAN frame modification rules allow bitwise logical operations that can be also applied to the can_dlc field. The privileged user "root" with CAP_NET_ADMIN can create a CAN frame modification rule that makes the data length code a higher value than the av
nvd
CVE-2015-8568P4MEDIUMCVSS 6.5v8.02017-04-11
CVE-2015-8568 [MEDIUM] CWE-772 CVE-2015-8568: Memory leak in QEMU, when built with a VMWARE VMXNET3 paravirtual NIC emulator support, allows local
Memory leak in QEMU, when built with a VMWARE VMXNET3 paravirtual NIC emulator support, allows local guest users to cause a denial of service (host memory consumption) by trying to activate the vmxnet3 device repeatedly.
nvd