cbcvebase.

Debian Linux vulnerabilities

9,955 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358

Vulnerabilities

Page 428 of 498
CVE-2014-0401P4MEDIUMCVSS 4.0v6.0v7.02014-01-15
CVE-2014-0401 [MEDIUM] CVE-2014-0401: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.72 and earlier, 5.5.34 a Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.72 and earlier, 5.5.34 and earlier, and 5.6.14 and earlier allows remote authenticated users to affect availability via unknown vectors.
nvd
CVE-2015-1240P4MEDIUMCVSS 5.0v8.02015-04-19
CVE-2015-1240 [MEDIUM] CWE-119 CVE-2015-1240: gpu/blink/webgraphicscontext3d_impl.cc in the WebGL implementation in Google Chrome before 42.0.2311 gpu/blink/webgraphicscontext3d_impl.cc in the WebGL implementation in Google Chrome before 42.0.2311.90 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WebGL program that triggers a state inconsistency.
nvd
CVE-2015-4815P4MEDIUMCVSS 4.0v7.0v8.02015-10-21
CVE-2015-4815 [MEDIUM] CVE-2015-4815: Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows re Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows remote authenticated users to affect availability via vectors related to Server : DDL.
nvd
CVE-2024-24858P4MEDIUMCVSS 5.3v10.02024-02-05
CVE-2024-24858 [MEDIUM] CWE-362 CVE-2024-24858: A race condition was found in the Linux kernel's net/bluetooth in {conn,adv}_{min,max}_interval_set( A race condition was found in the Linux kernel's net/bluetooth in {conn,adv}_{min,max}_interval_set() function. This can result in I2cap connection or broadcast abnormality issue, possibly leading to denial of service.
nvd
CVE-2014-8161P4MEDIUMCVSS 4.3v7.0v8.02020-01-27
CVE-2014-8161 [MEDIUM] CWE-209 CVE-2014-8161: PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x be PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to obtain sensitive column values by triggering constraint violation and then reading the error message.
nvd
CVE-2015-2776P4MEDIUMCVSS 4.3v7.02015-03-31
CVE-2015-2776 [MEDIUM] CWE-20 CVE-2015-2776: The parse_SST function in FreeXL before 1.0.0i allows remote attackers to cause a denial of service The parse_SST function in FreeXL before 1.0.0i allows remote attackers to cause a denial of service (memory consumption) via a crafted shared strings table in a workbook.
nvd
CVE-2020-25624P4MEDIUMCVSS 5.0v10.02020-11-30
CVE-2020-25624 [MEDIUM] CWE-125 CVE-2020-25624: hw/usb/hcd-ohci.c in QEMU 5.0.0 has a stack-based buffer over-read via values obtained from the host hw/usb/hcd-ohci.c in QEMU 5.0.0 has a stack-based buffer over-read via values obtained from the host controller driver.
nvd
CVE-2015-4826P4MEDIUMCVSS 4.0v7.0v8.02015-10-21
CVE-2015-4826 [MEDIUM] CVE-2015-4826: Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows re Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows remote authenticated users to affect confidentiality via unknown vectors related to Server : Types.
nvd
CVE-2002-0839P4HIGHCVSS 7.2v2.2v3.02002-10-11
CVE-2002-0839 [HIGH] CVE-2002-0839: The shared memory scoreboard in the HTTP daemon for Apache 1.3.x before 1.3.27 allows any user runni The shared memory scoreboard in the HTTP daemon for Apache 1.3.x before 1.3.27 allows any user running as the Apache UID to send a SIGUSR1 signal to any process as root, resulting in a denial of service (process kill) or possibly other behaviors that would not normally be allowed, by modifying the parent[].pid and parent[].last_rtime segments in the scoreboard.
nvd
CVE-2017-0365P4MEDIUMCVSS 4.7v7.02018-04-13
CVE-2017-0365 [MEDIUM] CWE-79 CVE-2017-0365: Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a XSS vulnerability in SearchHighlighter::highli Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a XSS vulnerability in SearchHighlighter::highlightText() with non-default configurations.
nvd
CVE-2020-14792P4MEDIUMCVSS 4.2v9.0v10.02020-10-21
CVE-2020-14792 [MEDIUM] CVE-2020-14792: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Hotspot). Suppo Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successfu
nvd
CVE-2018-17204P4MEDIUMCVSS 4.3v9.02018-09-19
CVE-2018-17204 [MEDIUM] CWE-617 CVE-2018-17204: An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting parse_group_prop_ntr_se An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting parse_group_prop_ntr_selection_method in lib/ofp-util.c. When decoding a group mod, it validates the group type and command after the whole group mod has been decoded. The OF1.5 decoder, however, tries to use the type and command earlier, when it might still be invalid. Thi
nvd
CVE-2005-1260P4MEDIUMCVSS 5.0v3.0v3.12005-05-19
CVE-2005-1260 [MEDIUM] CWE-400 CVE-2005-1260: bzip2 allows remote attackers to cause a denial of service (hard drive consumption) via a crafted bz bzip2 allows remote attackers to cause a denial of service (hard drive consumption) via a crafted bzip2 file that causes an infinite loop (a.k.a "decompression bomb").
nvd
CVE-2018-0495P4MEDIUMCVSS 4.7v8.0v9.02018-06-13
CVE-2018-0495 [MEDIUM] CWE-203 CVE-2018-0495: Libgcrypt before 1.7.10 and 1.8.x before 1.8.3 allows a memory-cache side-channel attack on ECDSA si Libgcrypt before 1.7.10 and 1.8.x before 1.8.3 allows a memory-cache side-channel attack on ECDSA signatures that can be mitigated through the use of blinding during the signing process in the _gcry_ecc_ecdsa_sign function in cipher/ecc-ecdsa.c, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access t
nvd
CVE-2000-0606P4HIGHCVSS 7.2v2.0v2.1+2 more2000-06-21
CVE-2000-0606 [HIGH] CVE-2000-0606: Buffer overflow in kon program in Kanji on Console (KON) package on Linux may allow local users to g Buffer overflow in kon program in Kanji on Console (KON) package on Linux may allow local users to gain root privileges via a long -StartupMessage parameter.
nvd
CVE-2016-5584P4MEDIUMCVSS 4.4v8.02016-10-25
CVE-2016-5584 [MEDIUM] CVE-2016-5584: Unspecified vulnerability in Oracle MySQL 5.5.52 and earlier, 5.6.33 and earlier, and 5.7.15 and ear Unspecified vulnerability in Oracle MySQL 5.5.52 and earlier, 5.6.33 and earlier, and 5.7.15 and earlier allows remote administrators to affect confidentiality via vectors related to Server: Security: Encryption.
nvd
CVE-2020-6396P4MEDIUMCVSS 4.3v9.0v10.02020-02-11
CVE-2020-6396 [MEDIUM] CVE-2020-6396: Inappropriate implementation in Skia in Google Chrome prior to 80.0.3987.87 allowed a remote attacke Inappropriate implementation in Skia in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2023-0458P4MEDIUMCVSS 4.7v10.02023-04-26
CVE-2023-0458 [MEDIUM] CWE-476 CVE-2023-0458: A speculative pointer dereference problem exists in the Linux Kernel on the do_prlimit() function. T A speculative pointer dereference problem exists in the Linux Kernel on the do_prlimit() function. The resource argument value is controlled and is used in pointer arithmetic for the 'rlim' variable and can be used to leak the contents. We recommend upgrading past version 6.1.8 or commit 739790605705ddcf18f21782b9c99ad7d53a8c11
nvd
CVE-2018-19985P4MEDIUMCVSS 4.6v8.02019-03-21
CVE-2018-19985 [MEDIUM] CWE-125 CVE-2018-19985: The function hso_get_config_data in drivers/net/usb/hso.c in the Linux kernel through 4.19.8 reads i The function hso_get_config_data in drivers/net/usb/hso.c in the Linux kernel through 4.19.8 reads if_num from the USB device (as a u8) and uses it to index a small array, resulting in an object out-of-bounds (OOB) read that potentially allows arbitrary read in the kernel address space.
nvd
CVE-2020-6432P4MEDIUMCVSS 4.3v9.0v10.02020-04-13
CVE-2020-6432 [MEDIUM] CVE-2020-6432: Insufficient policy enforcement in navigations in Google Chrome prior to 81.0.4044.92 allowed a remo Insufficient policy enforcement in navigations in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
Debian Linux vulnerabilities | cvebase