Debian Linux vulnerabilities
9,955 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358
Vulnerabilities
Page 419 of 498
CVE-2020-14385P4MEDIUMCVSS 5.5v9.02020-09-15
CVE-2020-14385 [MEDIUM] CWE-131 CVE-2020-14385: A flaw was found in the Linux kernel before 5.9-rc4. A failure of the file system metadata validator
A flaw was found in the Linux kernel before 5.9-rc4. A failure of the file system metadata validator in XFS can cause an inode with a valid, user-creatable extended attribute to be flagged as corrupt. This can lead to the filesystem being shutdown, or otherwise rendered inaccessible until it is remounted, leading to a denial of service. The highest
nvd
CVE-2020-27673P4MEDIUMCVSS 5.5v9.02020-10-22
CVE-2020-27673 [MEDIUM] CVE-2020-27673: An issue was discovered in the Linux kernel through 5.9.1, as used with Xen through 4.14.x. Guest OS
An issue was discovered in the Linux kernel through 5.9.1, as used with Xen through 4.14.x. Guest OS users can cause a denial of service (host OS hang) via a high rate of events to dom0, aka CID-e99502f76271.
nvd
CVE-2025-38399P4MEDIUMCVSS 5.5v11.02025-07-25
CVE-2025-38399 [MEDIUM] CWE-476 CVE-2025-38399: In the Linux kernel, the following vulnerability has been resolved: scsi: target: Fix NULL pointer
In the Linux kernel, the following vulnerability has been resolved:
scsi: target: Fix NULL pointer dereference in core_scsi3_decode_spec_i_port()
The function core_scsi3_decode_spec_i_port(), in its error code path,
unconditionally calls core_scsi3_lunacl_undepend_item() passing the
dest_se_deve pointer, which may be NULL.
This can lead to a NULL p
nvd
CVE-2023-31084P4MEDIUMCVSS 5.5v10.0v11.0+1 more2023-04-24
CVE-2023-31084 [MEDIUM] CWE-833 CVE-2023-31084: An issue was discovered in drivers/media/dvb-core/dvb_frontend.c in the Linux kernel 6.2. There is a
An issue was discovered in drivers/media/dvb-core/dvb_frontend.c in the Linux kernel 6.2. There is a blocking operation when a task is in !TASK_RUNNING. In dvb_frontend_get_event, wait_event_interruptible is called; the condition is dvb_frontend_test_event(fepriv,events). In dvb_frontend_test_event, down(&fepriv->sem) is called. However, wait_event_
nvd
CVE-2025-38472P4MEDIUMCVSS 5.5v11.02025-07-28
CVE-2025-38472 [MEDIUM] CWE-908 CVE-2025-38472: In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack: fix cr
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_conntrack: fix crash due to removal of uninitialised entry
A crash in conntrack was reported while trying to unlink the conntrack
entry from the hash bucket list:
[exception RIP: __nf_ct_delete_from_lists+172]
[..]
#7 [ff539b5a2b043aa0] nf_ct_delete at ffffffffc124d42
nvd
CVE-2021-39257P4MEDIUMCVSS 5.5v9.0v10.0+1 more2021-09-07
CVE-2021-39257 [MEDIUM] CWE-674 CVE-2021-39257: A crafted NTFS image with an unallocated bitmap can lead to a endless recursive function call chain
A crafted NTFS image with an unallocated bitmap can lead to a endless recursive function call chain (starting from ntfs_attr_pwrite), causing stack consumption in NTFS-3G < 2021.8.22.
nvd
CVE-2022-20796P4MEDIUMCVSS 5.5v9.02022-05-04
CVE-2022-20796 [MEDIUM] CWE-822 CVE-2022-20796: On May 4, 2022, the following vulnerability in the ClamAV scanning library versions 0.103.5 and earl
On May 4, 2022, the following vulnerability in the ClamAV scanning library versions 0.103.5 and earlier and 0.104.2 and earlier was disclosed: A vulnerability in Clam AntiVirus (ClamAV) versions 0.103.4, 0.103.5, 0.104.1, and 0.104.2 could allow an authenticated, local attacker to cause a denial of service condition on an affected device. For a desc
nvd
CVE-2015-9267P4MEDIUMCVSS 5.5v8.02018-10-01
CVE-2015-9267 [MEDIUM] CWE-269 CVE-2015-9267: Nullsoft Scriptable Install System (NSIS) before 2.49 uses temporary folder locations that allow unp
Nullsoft Scriptable Install System (NSIS) before 2.49 uses temporary folder locations that allow unprivileged local users to overwrite files. This allows a local attack in which either a plugin or the uninstaller can be replaced by a Trojan horse program.
nvd
CVE-2025-37820P4MEDIUMCVSS 5.5v11.02025-05-08
CVE-2025-37820 [MEDIUM] CWE-476 CVE-2025-37820: In the Linux kernel, the following vulnerability has been resolved: xen-netfront: handle NULL retur
In the Linux kernel, the following vulnerability has been resolved:
xen-netfront: handle NULL returned by xdp_convert_buff_to_frame()
The function xdp_convert_buff_to_frame() may return NULL if it fails
to correctly convert the XDP buffer into an XDP frame due to memory
constraints, internal errors, or invalid data. Failing to check for NULL
may le
nvd
CVE-2017-9868P4MEDIUMCVSS 5.5v8.02017-06-25
CVE-2017-9868 [MEDIUM] CWE-200 CVE-2017-9868: In Mosquitto through 1.4.12, mosquitto.db (aka the persistence file) is world readable, which allows
In Mosquitto through 1.4.12, mosquitto.db (aka the persistence file) is world readable, which allows local users to obtain sensitive MQTT topic information.
nvd
CVE-2013-0326P4MEDIUMCVSS 5.5v8.0v9.0+1 more2019-12-05
CVE-2013-0326 [MEDIUM] CWE-732 CVE-2013-0326: OpenStack nova base images permissions are world readable
OpenStack nova base images permissions are world readable
nvd
CVE-2012-3425P4MEDIUMCVSS 4.3v6.02012-08-13
CVE-2012-3425 [MEDIUM] CWE-119 CVE-2012-3425: The png_push_read_zTXt function in pngpread.c in libpng 1.0.x before 1.0.58, 1.2.x before 1.2.48, 1.
The png_push_read_zTXt function in pngpread.c in libpng 1.0.x before 1.0.58, 1.2.x before 1.2.48, 1.4.x before 1.4.10, and 1.5.x before 1.5.10 allows remote attackers to cause a denial of service (out-of-bounds read) via a large avail_in field value in a PNG image.
nvd
CVE-2021-3759P4MEDIUMCVSS 5.5v10.02022-08-23
CVE-2021-3759 [MEDIUM] CWE-400 CVE-2021-3759: A memory overflow vulnerability was found in the Linux kernel’s ipc functionality of the memcg subsy
A memory overflow vulnerability was found in the Linux kernel’s ipc functionality of the memcg subsystem, in the way a user calls the semget function multiple times, creating semaphores. This flaw allows a local user to starve the resources, causing a denial of service. The highest threat from this vulnerability is to system availability.
nvd
CVE-2024-35811P4MEDIUMCVSS 5.5v10.02024-05-17
CVE-2024-35811 [MEDIUM] CVE-2024-35811: In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: Fix use-after-f
In the Linux kernel, the following vulnerability has been resolved:
wifi: brcmfmac: Fix use-after-free bug in brcmf_cfg80211_detach
This is the candidate patch of CVE-2023-47233 :
https://nvd.nist.gov/vuln/detail/CVE-2023-47233
In brcm80211 driver,it starts with the following invoking chain
to start init a timeout worker:
->brcmf_usb_probe
->brcmf_usb_pr
nvd
CVE-2020-25704P4MEDIUMCVSS 5.5v9.02020-12-02
CVE-2020-25704 [MEDIUM] CWE-401 CVE-2020-25704: A flaw memory leak in the Linux kernel performance monitoring subsystem was found in the way if usin
A flaw memory leak in the Linux kernel performance monitoring subsystem was found in the way if using PERF_EVENT_IOC_SET_FILTER. A local user could use this flaw to starve the resources causing denial of service.
nvd
CVE-2022-38863P4MEDIUMCVSS 5.5v10.02022-09-15
CVE-2022-38863 [MEDIUM] CWE-787 CVE-2022-38863: Certain The MPlayer Project products are vulnerable to Buffer Overflow via function mp_getbits() of
Certain The MPlayer Project products are vulnerable to Buffer Overflow via function mp_getbits() of libmpdemux/mpeg_hdr.c which affects mencoder and mplayer. This affects mecoder SVN-r38374-13.0.1 and mplayer SVN-r38374-13.0.1.
nvd
CVE-2022-38855P4MEDIUMCVSS 5.5v10.02022-09-15
CVE-2022-38855 [MEDIUM] CWE-787 CVE-2022-38855: Certain The MPlayer Project products are vulnerable to Buffer Overflow via function gen_sh_video ()
Certain The MPlayer Project products are vulnerable to Buffer Overflow via function gen_sh_video () of mplayer/libmpdemux/demux_mov.c. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.
nvd
CVE-2022-38858P4MEDIUMCVSS 5.5v10.02022-09-15
CVE-2022-38858 [MEDIUM] CWE-787 CVE-2022-38858: Certain The MPlayer Project products are vulnerable to Buffer Overflow via function mov_build_index(
Certain The MPlayer Project products are vulnerable to Buffer Overflow via function mov_build_index() of libmpdemux/demux_mov.c. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.
nvd
CVE-2022-38864P4MEDIUMCVSS 5.5v10.02022-09-15
CVE-2022-38864 [MEDIUM] CWE-787 CVE-2022-38864: Certain The MPlayer Project products are vulnerable to Buffer Overflow via the function mp_unescape0
Certain The MPlayer Project products are vulnerable to Buffer Overflow via the function mp_unescape03() of libmpdemux/mpeg_hdr.c. This affects mencoder SVN-r38374-13.0.1 and mplayer SVN-r38374-13.0.1.
nvd
CVE-2022-23034P4MEDIUMCVSS 5.5v9.0v11.02022-01-25
CVE-2022-23034 [MEDIUM] CWE-191 CVE-2022-23034: A PV guest could DoS Xen while unmapping a grant To address XSA-380, reference counting was introduc
A PV guest could DoS Xen while unmapping a grant To address XSA-380, reference counting was introduced for grant mappings for the case where a PV guest would have the IOMMU enabled. PV guests can request two forms of mappings. When both are in use for any individual mapping, unmapping of such a mapping can be requested in two steps. The reference co
nvd