Debian Linux vulnerabilities
9,955 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358
Vulnerabilities
Page 435 of 498
CVE-2011-0984P4MEDIUMCVSS 5.0v6.0v7.02011-02-10
CVE-2011-0984 [MEDIUM] CWE-125 CVE-2011-0984: Google Chrome before 9.0.597.94 does not properly handle plug-ins, which allows remote attackers to
Google Chrome before 9.0.597.94 does not properly handle plug-ins, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2017-9330P4MEDIUMCVSS 5.6v8.0v9.02017-06-08
CVE-2017-9330 [MEDIUM] CVE-2017-9330: QEMU (aka Quick Emulator) before 2.9.0, when built with the USB OHCI Emulation support, allows local
QEMU (aka Quick Emulator) before 2.9.0, when built with the USB OHCI Emulation support, allows local guest OS users to cause a denial of service (infinite loop) by leveraging an incorrect return value, a different vulnerability than CVE-2017-6505.
nvd
CVE-2018-7740P4MEDIUMCVSS 5.5v7.0v8.0+1 more2018-03-07
CVE-2018-7740 [MEDIUM] CWE-119 CVE-2018-7740: The resv_map_release function in mm/hugetlb.c in the Linux kernel through 4.15.7 allows local users
The resv_map_release function in mm/hugetlb.c in the Linux kernel through 4.15.7 allows local users to cause a denial of service (BUG) via a crafted application that makes mmap system calls and has a large pgoff argument to the remap_file_pages system call.
nvd
CVE-2014-3647P4MEDIUMCVSS 5.5v7.02014-11-10
CVE-2014-3647 [MEDIUM] CVE-2014-3647: arch/x86/kvm/emulate.c in the KVM subsystem in the Linux kernel through 3.17.2 does not properly per
arch/x86/kvm/emulate.c in the KVM subsystem in the Linux kernel through 3.17.2 does not properly perform RIP changes, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application.
nvd
CVE-2020-14392P4MEDIUMCVSS 5.5v9.02020-09-16
CVE-2020-14392 [MEDIUM] CWE-822 CVE-2020-14392: An untrusted pointer dereference flaw was found in Perl-DBI < 1.643. A local attacker who is able to
An untrusted pointer dereference flaw was found in Perl-DBI < 1.643. A local attacker who is able to manipulate calls to dbd_db_login6_sv() could cause memory corruption, affecting the service's availability.
nvd
CVE-2018-10124P4MEDIUMCVSS 5.5v8.02018-04-16
CVE-2018-10124 [MEDIUM] CWE-119 CVE-2018-10124: The kill_something_info function in kernel/signal.c in the Linux kernel before 4.13, when an unspeci
The kill_something_info function in kernel/signal.c in the Linux kernel before 4.13, when an unspecified architecture and compiler is used, might allow local users to cause a denial of service via an INT_MIN argument.
nvd
CVE-2020-13632P4MEDIUMCVSS 5.5v9.02020-05-27
CVE-2020-13632 [MEDIUM] CWE-476 CVE-2020-13632: ext/fts3/fts3_snippet.c in SQLite before 3.32.0 has a NULL pointer dereference via a crafted matchin
ext/fts3/fts3_snippet.c in SQLite before 3.32.0 has a NULL pointer dereference via a crafted matchinfo() query.
nvd
CVE-2022-1354P4MEDIUMCVSS 5.5v10.0v11.02022-08-31
CVE-2022-1354 [MEDIUM] CWE-125 CVE-2022-1354: A heap buffer overflow flaw was found in Libtiffs' tiffinfo.c in TIFFReadRawDataStriped() function.
A heap buffer overflow flaw was found in Libtiffs' tiffinfo.c in TIFFReadRawDataStriped() function. This flaw allows an attacker to pass a crafted TIFF file to the tiffinfo tool, triggering a heap buffer overflow issue and causing a crash that leads to a denial of service.
nvd
CVE-2000-0145P4HIGHCVSS 7.5v4.02000-02-05
CVE-2000-0145 [HIGH] CVE-2000-0145: The libguile.so library file used by gnucash in Debian GNU/Linux is installed with world-writable pe
The libguile.so library file used by gnucash in Debian GNU/Linux is installed with world-writable permissions.
nvd
CVE-2021-3744P4MEDIUMCVSS 5.5v9.0v10.02022-03-04
CVE-2021-3744 [MEDIUM] CVE-2021-3744: A memory leak flaw was found in the Linux kernel in the ccp_run_aes_gcm_cmd() function in drivers/cr
A memory leak flaw was found in the Linux kernel in the ccp_run_aes_gcm_cmd() function in drivers/crypto/ccp/ccp-ops.c, which allows attackers to cause a denial of service (memory consumption). This vulnerability is similar with the older CVE-2019-18808.
nvd
CVE-2018-19364P4MEDIUMCVSS 5.5v8.0v9.02018-12-13
CVE-2018-19364 [MEDIUM] CWE-416 CVE-2018-19364: hw/9pfs/cofile.c and hw/9pfs/9p.c in QEMU can modify an fid path while it is being accessed by a sec
hw/9pfs/cofile.c and hw/9pfs/9p.c in QEMU can modify an fid path while it is being accessed by a second thread, leading to (for example) a use-after-free outcome.
nvd
CVE-2017-7718P4MEDIUMCVSS 5.5v8.02017-04-20
CVE-2017-7718 [MEDIUM] CWE-125 CVE-2017-7718: hw/display/cirrus_vga_rop.h in QEMU (aka Quick Emulator) allows local guest OS privileged users to c
hw/display/cirrus_vga_rop.h in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) via vectors related to copying VGA data via the cirrus_bitblt_rop_fwd_transp_ and cirrus_bitblt_rop_fwd_ functions.
nvd
CVE-2018-16878P4MEDIUMCVSS 5.5v9.02019-04-18
CVE-2018-16878 [MEDIUM] CWE-400 CVE-2018-16878: A flaw was found in pacemaker up to and including version 2.0.1. An insufficient verification inflic
A flaw was found in pacemaker up to and including version 2.0.1. An insufficient verification inflicted preference of uncontrolled processes can lead to DoS
nvd
CVE-2017-17862P4MEDIUMCVSS 5.5v9.02017-12-27
CVE-2017-17862 [MEDIUM] CWE-20 CVE-2017-17862: kernel/bpf/verifier.c in the Linux kernel through 4.14.8 ignores unreachable code, even though it wo
kernel/bpf/verifier.c in the Linux kernel through 4.14.8 ignores unreachable code, even though it would still be processed by JIT compilers. This behavior, also considered an improper branch-pruning logic issue, could possibly be used by local users for denial of service.
nvd
CVE-2017-9375P4MEDIUMCVSS 5.5v8.0v9.02017-06-16
CVE-2017-9375 [MEDIUM] CWE-835 CVE-2017-9375: QEMU (aka Quick Emulator), when built with USB xHCI controller emulator support, allows local guest
QEMU (aka Quick Emulator), when built with USB xHCI controller emulator support, allows local guest OS privileged users to cause a denial of service (infinite recursive call) via vectors involving control transfer descriptors sequencing.
nvd
CVE-2025-37917P4MEDIUMCVSS 5.5v11.02025-05-20
CVE-2025-37917 [MEDIUM] CVE-2025-37917: In the Linux kernel, the following vulnerability has been resolved: net: ethernet: mtk-star-emac: f
In the Linux kernel, the following vulnerability has been resolved:
net: ethernet: mtk-star-emac: fix spinlock recursion issues on rx/tx poll
Use spin_lock_irqsave and spin_unlock_irqrestore instead of spin_lock
and spin_unlock in mtk_star_emac driver to avoid spinlock recursion
occurrence that can happen when enabling the DMA interrupts again in
rx/tx pol
nvd
CVE-2016-2198P4MEDIUMCVSS 5.5v8.02016-12-29
CVE-2016-2198 [MEDIUM] CWE-476 CVE-2016-2198: QEMU (aka Quick Emulator) built with the USB EHCI emulation support is vulnerable to a null pointer
QEMU (aka Quick Emulator) built with the USB EHCI emulation support is vulnerable to a null pointer dereference flaw. It could occur when an application attempts to write to EHCI capabilities registers. A privileged user inside quest could use this flaw to crash the QEMU process instance resulting in DoS.
nvd
CVE-2021-29650P4MEDIUMCVSS 5.5v9.02021-03-30
CVE-2021-29650 [MEDIUM] CVE-2021-29650: An issue was discovered in the Linux kernel before 5.11.11. The netfilter subsystem allows attackers
An issue was discovered in the Linux kernel before 5.11.11. The netfilter subsystem allows attackers to cause a denial of service (panic) because net/netfilter/x_tables.c and include/linux/netfilter/x_tables.h lack a full memory barrier upon the assignment of a new table value, aka CID-175e476b8cdf.
nvd
CVE-2015-8745P4MEDIUMCVSS 5.5v8.02016-12-29
CVE-2015-8745 [MEDIUM] CWE-617 CVE-2015-8745: QEMU (aka Quick Emulator) built with a VMWARE VMXNET3 paravirtual NIC emulator support is vulnerable
QEMU (aka Quick Emulator) built with a VMWARE VMXNET3 paravirtual NIC emulator support is vulnerable to crash issue. It could occur while reading Interrupt Mask Registers (IMR). A privileged (CAP_SYS_RAWIO) guest user could use this flaw to crash the QEMU process instance resulting in DoS.
nvd
CVE-2022-28388P4MEDIUMCVSS 5.5v10.0v11.02022-04-03
CVE-2022-28388 [MEDIUM] CWE-415 CVE-2022-28388: usb_8dev_start_xmit in drivers/net/can/usb/usb_8dev.c in the Linux kernel through 5.17.1 has a doubl
usb_8dev_start_xmit in drivers/net/can/usb/usb_8dev.c in the Linux kernel through 5.17.1 has a double free.
nvd