cbcvebase.

Debian Linux vulnerabilities

9,955 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358

Vulnerabilities

Page 436 of 498
CVE-2015-8744P4MEDIUMCVSS 5.5v8.02016-12-29
CVE-2015-8744 [MEDIUM] CWE-20 CVE-2015-8744: QEMU (aka Quick Emulator) built with a VMWARE VMXNET3 paravirtual NIC emulator support is vulnerable QEMU (aka Quick Emulator) built with a VMWARE VMXNET3 paravirtual NIC emulator support is vulnerable to crash issue. It occurs when a guest sends a Layer-2 packet smaller than 22 bytes. A privileged (CAP_SYS_RAWIO) guest user could use this flaw to crash the QEMU process instance resulting in DoS.
nvd
CVE-2017-18257P4MEDIUMCVSS 5.5v9.02018-04-04
CVE-2017-18257 [MEDIUM] CWE-190 CVE-2017-18257: The __get_data_block function in fs/f2fs/data.c in the Linux kernel before 4.11 allows local users t The __get_data_block function in fs/f2fs/data.c in the Linux kernel before 4.11 allows local users to cause a denial of service (integer overflow and loop) via crafted use of the open and fallocate system calls with an FS_IOC_FIEMAP ioctl.
nvd
CVE-2025-38018P4MEDIUMCVSS 5.5v11.02025-06-18
CVE-2025-38018 [MEDIUM] CWE-476 CVE-2025-38018: In the Linux kernel, the following vulnerability has been resolved: net/tls: fix kernel panic when In the Linux kernel, the following vulnerability has been resolved: net/tls: fix kernel panic when alloc_page failed We cannot set frag_list to NULL pointer when alloc_page failed. It will be used in tls_strp_check_queue_ok when the next time tls_strp_read_sock is called. This is because we don't reset full_len in tls_strp_flush_anchor_copy() so th
nvd
CVE-2021-28971P4MEDIUMCVSS 5.5v9.02021-03-22
CVE-2021-28971 [MEDIUM] CWE-755 CVE-2021-28971: In intel_pmu_drain_pebs_nhm in arch/x86/events/intel/ds.c in the Linux kernel through 5.11.8 on some In intel_pmu_drain_pebs_nhm in arch/x86/events/intel/ds.c in the Linux kernel through 5.11.8 on some Haswell CPUs, userspace applications (such as perf-fuzzer) can cause a system crash because the PEBS status in a PEBS record is mishandled, aka CID-d88d05a9e0b6.
nvd
CVE-2025-38075P4MEDIUMCVSS 5.5v11.02025-06-18
CVE-2025-38075 [MEDIUM] CWE-476 CVE-2025-38075: In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Fix timeou In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Fix timeout on deleted connection NOPIN response timer may expire on a deleted connection and crash with such logs: Did not receive response to NOPIN on CID: 0, failing connection for I_T Nexus (null),i,0x00023d000125,iqn.2017-01.com.iscsi.target,t,0x3d BUG:
nvd
CVE-2020-36322P4MEDIUMCVSS 5.5v9.0v10.02021-04-14
CVE-2020-36322 [MEDIUM] CWE-459 CVE-2020-36322: An issue was discovered in the FUSE filesystem implementation in the Linux kernel before 5.10.6, aka An issue was discovered in the FUSE filesystem implementation in the Linux kernel before 5.10.6, aka CID-5d069dbe8aaf. fuse_do_getattr() calls make_bad_inode() in inappropriate situations, causing a system crash. NOTE: the original fix for this vulnerability was incomplete, and its incompleteness is tracked as CVE-2021-28950.
nvd
CVE-2015-2697P4MEDIUMCVSS 4.0v7.0v8.0+1 more2015-11-09
CVE-2015-2697 [MEDIUM] CWE-125 CVE-2015-2697: The build_principal_va function in lib/krb5/krb/bld_princ.c in MIT Kerberos 5 (aka krb5) before 1.14 The build_principal_va function in lib/krb5/krb/bld_princ.c in MIT Kerberos 5 (aka krb5) before 1.14 allows remote authenticated users to cause a denial of service (out-of-bounds read and KDC crash) via an initial '\0' character in a long realm field within a TGS request.
nvd
CVE-2024-27416P4MEDIUMCVSS 5.5v10.02024-05-17
CVE-2024-27416 [MEDIUM] CVE-2024-27416: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: Fix handl In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: Fix handling of HCI_EV_IO_CAPA_REQUEST If we received HCI_EV_IO_CAPA_REQUEST while HCI_OP_READ_REMOTE_EXT_FEATURES is yet to be responded assume the remote does support SSP since otherwise this event shouldn't be generated.
nvd
CVE-2021-45480P4MEDIUMCVSS 5.5v9.0v10.0+1 more2021-12-24
CVE-2021-45480 [MEDIUM] CWE-401 CVE-2021-45480: An issue was discovered in the Linux kernel before 5.15.11. There is a memory leak in the __rds_conn An issue was discovered in the Linux kernel before 5.15.11. There is a memory leak in the __rds_conn_create() function in net/rds/connection.c in a certain combination of circumstances.
nvd
CVE-2021-28698P4MEDIUMCVSS 5.5v11.02021-08-27
CVE-2021-28698 [MEDIUM] CWE-835 CVE-2021-28698: long running loops in grant table handling In order to properly monitor resource use, Xen maintains long running loops in grant table handling In order to properly monitor resource use, Xen maintains information on the grant mappings a domain may create to map grants offered by other domains. In the process of carrying out certain actions, Xen would iterate over all such entries, including ones which aren't in use anymore and some which may have be
nvd
CVE-2021-28950P4MEDIUMCVSS 5.5v9.02021-03-20
CVE-2021-28950 [MEDIUM] CWE-834 CVE-2021-28950: An issue was discovered in fs/fuse/fuse_i.h in the Linux kernel before 5.11.8. A "stall on CPU" can An issue was discovered in fs/fuse/fuse_i.h in the Linux kernel before 5.11.8. A "stall on CPU" can occur because a retry loop continually finds the same bad inode, aka CID-775c5033a0d1.
nvd
CVE-2008-2079P4MEDIUMCVSS 4.6v4.02008-05-05
CVE-2008-2079 [MEDIUM] CWE-264 CVE-2008-2079: MySQL 4.1.x before 4.1.24, 5.0.x before 5.0.60, 5.1.x before 5.1.24, and 6.0.x before 6.0.5 allows l MySQL 4.1.x before 4.1.24, 5.0.x before 5.0.60, 5.1.x before 5.1.24, and 6.0.x before 6.0.5 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are within the MySQL home data directory, which can point to tables that are created in the fu
nvd
CVE-2019-18388P4MEDIUMCVSS 5.5v10.02019-12-23
CVE-2019-18388 [MEDIUM] CWE-476 CVE-2019-18388: A NULL pointer dereference in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users A NULL pointer dereference in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service via malformed commands.
nvd
CVE-2022-28389P4MEDIUMCVSS 5.5v10.0v11.02022-04-03
CVE-2022-28389 [MEDIUM] CWE-415 CVE-2022-28389: mcba_usb_start_xmit in drivers/net/can/usb/mcba_usb.c in the Linux kernel through 5.17.1 has a doubl mcba_usb_start_xmit in drivers/net/can/usb/mcba_usb.c in the Linux kernel through 5.17.1 has a double free.
nvd
CVE-2022-38851P4MEDIUMCVSS 5.5v10.02022-09-15
CVE-2022-38851 [MEDIUM] CWE-125 CVE-2022-38851: Certain The MPlayer Project products are vulnerable to Out-of-bounds Read via function read_meta_rec Certain The MPlayer Project products are vulnerable to Out-of-bounds Read via function read_meta_record() of mplayer/libmpdemux/asfheader.c. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.
nvd
CVE-2022-38860P4MEDIUMCVSS 5.5v10.02022-09-15
CVE-2022-38860 [MEDIUM] CWE-369 CVE-2022-38860: Certain The MPlayer Project products are vulnerable to Divide By Zero via function demux_open_avi() Certain The MPlayer Project products are vulnerable to Divide By Zero via function demux_open_avi() of libmpdemux/demux_avi.c which affects mencoder. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.
nvd
CVE-2022-36879P4MEDIUMCVSS 5.5v10.0v11.02022-07-27
CVE-2022-36879 [MEDIUM] CVE-2022-36879: An issue was discovered in the Linux kernel through 5.18.14. xfrm_expand_policies in net/xfrm/xfrm_p An issue was discovered in the Linux kernel through 5.18.14. xfrm_expand_policies in net/xfrm/xfrm_policy.c can cause a refcount to be dropped twice.
nvd
CVE-2024-26773P4MEDIUMCVSS 5.5v10.02024-04-03
CVE-2024-26773 [MEDIUM] CVE-2024-26773: In the Linux kernel, the following vulnerability has been resolved: ext4: avoid allocating blocks f In the Linux kernel, the following vulnerability has been resolved: ext4: avoid allocating blocks from corrupted group in ext4_mb_try_best_found() Determine if the group block bitmap is corrupted before using ac_b_ex in ext4_mb_try_best_found() to avoid allocating blocks from a group with a corrupted block bitmap in the following concurrency and making the
nvd
CVE-2023-23454P4MEDIUMCVSS 5.5v11.02023-01-12
CVE-2023-23454 [MEDIUM] CWE-843 CVE-2023-23454: cbq_classify in net/sched/sch_cbq.c in the Linux kernel through 6.1.4 allows attackers to cause a de cbq_classify in net/sched/sch_cbq.c in the Linux kernel through 6.1.4 allows attackers to cause a denial of service (slab-out-of-bounds read) because of type confusion (non-negative numbers can sometimes indicate a TC_ACT_SHOT condition rather than valid classification results).
nvd
CVE-2023-52656P4MEDIUMCVSS 5.5v10.02024-05-14
CVE-2023-52656 [MEDIUM] CVE-2023-52656: In the Linux kernel, the following vulnerability has been resolved: io_uring: drop any code related In the Linux kernel, the following vulnerability has been resolved: io_uring: drop any code related to SCM_RIGHTS This is dead code after we dropped support for passing io_uring fds over SCM_RIGHTS, get rid of it.
nvd
Debian Linux vulnerabilities | cvebase