cbcvebase.

Debian Linux vulnerabilities

9,955 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358

Vulnerabilities

Page 431 of 498
CVE-2023-4901P4MEDIUMCVSS 4.3v11.0v12.02023-09-12
CVE-2023-4901 [MEDIUM] CVE-2023-4901: Inappropriate implementation in Prompts in Google Chrome prior to 117.0.5938.62 allowed a remote att Inappropriate implementation in Prompts in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to potentially spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-4905P4MEDIUMCVSS 4.3v11.0v12.02023-09-12
CVE-2023-4905 [MEDIUM] CVE-2023-4905: Inappropriate implementation in Prompts in Google Chrome prior to 117.0.5938.62 allowed a remote att Inappropriate implementation in Prompts in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-4902P4MEDIUMCVSS 4.3v11.0v12.02023-09-12
CVE-2023-4902 [MEDIUM] CVE-2023-4902: Inappropriate implementation in Input in Google Chrome prior to 117.0.5938.62 allowed a remote attac Inappropriate implementation in Input in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-4906P4MEDIUMCVSS 4.3v11.0v12.02023-09-12
CVE-2023-4906 [MEDIUM] CVE-2023-4906: Insufficient policy enforcement in Autofill in Google Chrome prior to 117.0.5938.62 allowed a remote Insufficient policy enforcement in Autofill in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2023-4904P4MEDIUMCVSS 4.3v11.0v12.02023-09-12
CVE-2023-4904 [MEDIUM] CVE-2023-4904: Insufficient policy enforcement in Downloads in Google Chrome prior to 117.0.5938.62 allowed a remot Insufficient policy enforcement in Downloads in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to bypass Enterprise policy restrictions via a crafted download. (Chromium security severity: Medium)
nvd
CVE-2023-5477P4MEDIUMCVSS 4.3v11.0v12.02023-10-11
CVE-2023-5477 [MEDIUM] CVE-2023-5477: Inappropriate implementation in Installer in Google Chrome prior to 118.0.5993.70 allowed a local at Inappropriate implementation in Installer in Google Chrome prior to 118.0.5993.70 allowed a local attacker to bypass discretionary access control via a crafted command. (Chromium security severity: Low)
nvd
CVE-2026-34757P4MEDIUMCVSS 4.4v11.02026-04-09
CVE-2026-34757 [MEDIUM] CWE-416 CVE-2026-34757: LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portabl LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.0.9 to before 1.6.57, passing a pointer obtained from png_get_PLTE, png_get_tRNS, or png_get_hIST back into the corresponding setter on the same png_struct/png_info pair causes the setter to read from fre
nvd
CVE-2017-17433P4LOWCVSS 3.7v7.0v8.0+1 more2017-12-06
CVE-2017-17433 [LOW] CWE-862 CVE-2017-17433: The recv_files function in receiver.c in the daemon in rsync 3.1.2, and 3.1.3-development before 201 The recv_files function in receiver.c in the daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, proceeds with certain file metadata updates before checking for a filename in the daemon_filter_list data structure, which allows remote attackers to bypass intended access restrictions.
nvd
CVE-2015-2749P4MEDIUMCVSS 6.1v8.0v9.02017-09-13
CVE-2015-2749 [MEDIUM] CWE-601 CVE-2015-2749: Open redirect vulnerability in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to Open redirect vulnerability in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destination parameter.
nvd
CVE-2017-17381P4MEDIUMCVSS 6.5v9.02017-12-07
CVE-2017-17381 [MEDIUM] CWE-369 CVE-2017-17381: The Virtio Vring implementation in QEMU allows local OS guest users to cause a denial of service (di The Virtio Vring implementation in QEMU allows local OS guest users to cause a denial of service (divide-by-zero error and QEMU process crash) by unsetting vring alignment while updating Virtio rings.
nvd
CVE-2023-3863P4MEDIUMCVSS 4.1v10.0v11.0+1 more2023-07-24
CVE-2023-3863 [MEDIUM] CWE-416 CVE-2023-3863: A use-after-free flaw was found in nfc_llcp_find_local in net/nfc/llcp_core.c in NFC in the Linux ke A use-after-free flaw was found in nfc_llcp_find_local in net/nfc/llcp_core.c in NFC in the Linux kernel. This flaw allows a local user with special privileges to impact a kernel information leak issue.
nvd
CVE-2015-3232P4MEDIUMCVSS 5.8v7.0v8.02015-06-22
CVE-2015-3232 [MEDIUM] CVE-2015-3232: Open redirect vulnerability in the Field UI module in Drupal 7.x before 7.38 allows remote attackers Open redirect vulnerability in the Field UI module in Drupal 7.x before 7.38 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destinations parameter.
nvd
CVE-2013-2485P4MEDIUMCVSS 6.1v7.02013-03-07
CVE-2013-2485 [MEDIUM] CVE-2013-2485: The FCSP dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 allows remote attackers t The FCSP dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (infinite loop) via a malformed packet.
nvd
CVE-2012-0248P4MEDIUMCVSS 5.5v6.0v7.02012-06-05
CVE-2012-0248 [MEDIUM] CWE-835 CVE-2012-0248: ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (infinite loop ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (infinite loop and hang) via a crafted image whose IFD contains IOP tags that all reference the beginning of the IDF.
nvd
CVE-2015-4757P4LOWCVSS 3.5v8.02015-07-16
CVE-2015-4757 [LOW] CVE-2015-4757: Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier and 5.6.23 and earlier allows re Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier and 5.6.23 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Optimizer.
nvd
CVE-2018-5683P4MEDIUMCVSS 6.0v8.0v9.02018-01-23
CVE-2018-5683 [MEDIUM] CWE-125 CVE-2018-5683: The vga_draw_text function in Qemu allows local OS guest privileged users to cause a denial of servi The vga_draw_text function in Qemu allows local OS guest privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) by leveraging improper memory address validation.
nvd
CVE-2012-1186P4MEDIUMCVSS 5.5v6.02012-06-05
CVE-2012-1186 [MEDIUM] CVE-2012-1186: Integer overflow in the SyncImageProfiles function in profile.c in ImageMagick 6.7.5-8 and earlier a Integer overflow in the SyncImageProfiles function in profile.c in ImageMagick 6.7.5-8 and earlier allows remote attackers to cause a denial of service (infinite loop) via crafted IOP tag offsets in the IFD in an image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0248.
nvd
CVE-2008-3913P4MEDIUMCVSS 5.0v4.02008-09-11
CVE-2008-3913 [MEDIUM] CWE-401 CVE-2008-3913: Multiple memory leaks in freshclam/manager.c in ClamAV before 0.94 might allow attackers to cause a Multiple memory leaks in freshclam/manager.c in ClamAV before 0.94 might allow attackers to cause a denial of service (memory consumption) via unspecified vectors related to "error handling logic".
nvd
CVE-2019-10649P4MEDIUMCVSS 5.5v10.02019-03-30
CVE-2019-10649 [MEDIUM] CWE-401 CVE-2019-10649: In ImageMagick 7.0.8-36 Q16, there is a memory leak in the function SVGKeyValuePairs of coders/svg.c In ImageMagick 7.0.8-36 Q16, there is a memory leak in the function SVGKeyValuePairs of coders/svg.c, which allows an attacker to cause a denial of service via a crafted image file.
nvd
CVE-2018-6616P4MEDIUMCVSS 5.5v8.0v9.02018-02-04
CVE-2018-6616 [MEDIUM] CWE-400 CVE-2018-6616: In OpenJPEG 2.3.0, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. In OpenJPEG 2.3.0, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file.
nvd
Debian Linux vulnerabilities | cvebase