Debian Linux vulnerabilities
9,955 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358
Vulnerabilities
Page 429 of 498
CVE-2020-8166P4MEDIUMCVSS 4.3v10.02020-07-02
CVE-2020-8166 [MEDIUM] CWE-352 CVE-2020-8166: A CSRF forgery vulnerability exists in rails < 5.2.5, rails < 6.0.4 that makes it possible for an at
A CSRF forgery vulnerability exists in rails < 5.2.5, rails < 6.0.4 that makes it possible for an attacker to, given a global CSRF token such as the one present in the authenticity_token meta tag, forge a per-form CSRF token.
nvd
CVE-2001-0128P4HIGHCVSS 7.2v2.22001-03-12
CVE-2001-0128 [HIGH] CVE-2001-0128: Zope before 2.2.4 does not properly compute local roles, which could allow users to bypass specified
Zope before 2.2.4 does not properly compute local roles, which could allow users to bypass specified access restrictions and gain privileges.
nvd
CVE-2003-0308P4HIGHCVSS 7.2v3.02003-05-15
CVE-2003-0308 [HIGH] CVE-2003-0308: The Sendmail 8.12.3 package in Debian GNU/Linux 3.0 does not securely create temporary files, which
The Sendmail 8.12.3 package in Debian GNU/Linux 3.0 does not securely create temporary files, which could allow local users to gain additional privileges via (1) expn, (2) checksendmail, or (3) doublebounce.pl.
nvd
CVE-2020-6433P4MEDIUMCVSS 4.3v9.0v10.02020-04-13
CVE-2020-6433 [MEDIUM] CVE-2020-6433: Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed a remot
Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2020-6435P4MEDIUMCVSS 4.3v9.0v10.02020-04-13
CVE-2020-6435 [MEDIUM] CVE-2020-6435: Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed a remot
Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2020-6403P4MEDIUMCVSS 4.3v9.0v10.02020-02-11
CVE-2020-6403 [MEDIUM] CVE-2020-6403: Incorrect implementation in Omnibox in Google Chrome on iOS prior to 80.0.3987.87 allowed a remote a
Incorrect implementation in Omnibox in Google Chrome on iOS prior to 80.0.3987.87 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2019-13754P4MEDIUMCVSS 4.3v9.0v10.02019-12-10
CVE-2019-13754 [MEDIUM] CVE-2019-13754: Insufficient policy enforcement in extensions in Google Chrome prior to 79.0.3945.79 allowed a remot
Insufficient policy enforcement in extensions in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2010-3359P4MEDIUMCVSS 4.8v8.0v9.0+1 more2019-11-12
CVE-2010-3359 [MEDIUM] CWE-20 CVE-2010-3359: If LD_LIBRARY_PATH is undefined in gargoyle-free before 2009-08-25, the variable will point to the c
If LD_LIBRARY_PATH is undefined in gargoyle-free before 2009-08-25, the variable will point to the current directory. This can allow a local user to trick another user into running gargoyle in a directory with a cracked libgarglk.so and gain access to the user's account.
nvd
CVE-2020-6431P4MEDIUMCVSS 4.3v9.0v10.02020-04-13
CVE-2020-6431 [MEDIUM] CWE-276 CVE-2020-6431: Insufficient policy enforcement in full screen in Google Chrome prior to 81.0.4044.92 allowed a remo
Insufficient policy enforcement in full screen in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to spoof security UI via a crafted HTML page.
nvd
CVE-2020-6488P4MEDIUMCVSS 4.3v9.0v10.02020-05-21
CVE-2020-6488 [MEDIUM] CWE-276 CVE-2020-6488: Insufficient policy enforcement in downloads in Google Chrome prior to 83.0.4103.61 allowed a remote
Insufficient policy enforcement in downloads in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2018-14395P4MEDIUMCVSS 6.5v9.02018-07-19
CVE-2018-14395 [MEDIUM] CWE-369 CVE-2018-14395: libavformat/movenc.c in FFmpeg 3.2 and 4.0.2 allows attackers to cause a denial of service (applicat
libavformat/movenc.c in FFmpeg 3.2 and 4.0.2 allows attackers to cause a denial of service (application crash caused by a divide-by-zero error) with a user crafted audio file when converting to the MOV audio format.
nvd
CVE-2021-38508P4MEDIUMCVSS 4.3v9.0v10.0+1 more2021-12-08
CVE-2021-38508 [MEDIUM] CWE-1021 CVE-2021-38508: By displaying a form validity message in the correct location at the same time as a permission promp
By displaying a form validity message in the correct location at the same time as a permission prompt (such as for geolocation), the validity message could have obscured the prompt, resulting in the user potentially being tricked into granting the permission. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
nvd
CVE-2020-6528P4MEDIUMCVSS 4.3v10.02020-07-22
CVE-2020-6528 [MEDIUM] CVE-2020-6528: Incorrect security UI in basic auth in Google Chrome on iOS prior to 84.0.4147.89 allowed a remote a
Incorrect security UI in basic auth in Google Chrome on iOS prior to 84.0.4147.89 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2020-6392P4MEDIUMCVSS 4.3v9.0v10.02020-02-11
CVE-2020-6392 [MEDIUM] CWE-79 CVE-2020-6392: Insufficient policy enforcement in extensions in Google Chrome prior to 80.0.3987.87 allowed an atta
Insufficient policy enforcement in extensions in Google Chrome prior to 80.0.3987.87 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.
nvd
CVE-2021-21189P4MEDIUMCVSS 4.3v10.02021-03-09
CVE-2021-21189 [MEDIUM] CVE-2021-21189: Insufficient policy enforcement in payments in Google Chrome prior to 89.0.4389.72 allowed a remote
Insufficient policy enforcement in payments in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2020-6490P4MEDIUMCVSS 4.3v9.0v10.02020-05-21
CVE-2020-6490 [MEDIUM] CWE-668 CVE-2020-6490: Insufficient data validation in loader in Google Chrome prior to 83.0.4103.61 allowed a remote attac
Insufficient data validation in loader in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had been able to write to disk to leak cross-origin data via a crafted HTML page.
nvd
CVE-2021-21187P4MEDIUMCVSS 4.3v10.02021-03-09
CVE-2021-21187 [MEDIUM] CVE-2021-21187: Insufficient data validation in URL formatting in Google Chrome prior to 89.0.4389.72 allowed a remo
Insufficient data validation in URL formatting in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
nvd
CVE-2017-10295P4MEDIUMCVSS 4.0v7.0v8.0+1 more2017-10-19
CVE-2017-10295 [MEDIUM] CVE-2017-10295: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: N
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144; JRockit: R28.3.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Java SE, Java SE
nvd
CVE-2020-29129P4MEDIUMCVSS 4.3v10.02020-11-26
CVE-2020-29129 [MEDIUM] CWE-125 CVE-2020-29129: ncsi.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of
ncsi.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length.
nvd
CVE-2017-3313P4MEDIUMCVSS 4.7v8.02017-01-27
CVE-2017-3313 [MEDIUM] CVE-2017-3313: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: MyISAM). Supporte
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: MyISAM). Supported versions that are affected are 5.5.53 and earlier, 5.6.34 and earlier and 5.7.16 and earlier. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful
nvd