cbcvebase.

Debian Linux vulnerabilities

9,955 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358

Vulnerabilities

Page 444 of 498
CVE-2013-2905P4MEDIUMCVSS 5.0v7.02013-08-21
CVE-2013-2905 [MEDIUM] CWE-264 CVE-2013-2905: The SharedMemory::Create function in memory/shared_memory_posix.cc in Google Chrome before 29.0.1547 The SharedMemory::Create function in memory/shared_memory_posix.cc in Google Chrome before 29.0.1547.57 uses weak permissions under /dev/shm/, which allows attackers to obtain sensitive information via direct access to a POSIX shared-memory file.
nvd
CVE-2014-0481P4MEDIUMCVSS 4.3v7.02014-08-26
CVE-2014-0481 [MEDIUM] CWE-399 CVE-2014-0481: The default configuration for the file upload handling system in Django before 1.4.14, 1.5.x before The default configuration for the file upload handling system in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 uses a sequential file name generation process when a file with a conflicting name is uploaded, which allows remote attackers to cause a denial of service (CPU consumption) by unloading a mult
nvd
CVE-2008-4098P4MEDIUMCVSS 4.6v5.02008-09-18
CVE-2008-4098 [MEDIUM] CWE-59 CVE-2008-4098: MySQL before 5.0.67 allows local users to bypass certain privilege checks by calling CREATE TABLE on MySQL before 5.0.67 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink t
nvd
CVE-2014-9035P4MEDIUMCVSS 4.3v7.0v8.02014-11-25
CVE-2014-9035 [MEDIUM] CWE-79 CVE-2014-9035: Cross-site scripting (XSS) vulnerability in Press This in WordPress before 3.7.5, 3.8.x before 3.8.5 Cross-site scripting (XSS) vulnerability in Press This in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2015-4652P4MEDIUMCVSS 4.3v8.02015-07-22
CVE-2015-4652 [MEDIUM] CWE-20 CVE-2015-4652: epan/dissectors/packet-gsm_a_dtap.c in the GSM DTAP dissector in Wireshark 1.12.x before 1.12.6 does epan/dissectors/packet-gsm_a_dtap.c in the GSM DTAP dissector in Wireshark 1.12.x before 1.12.6 does not properly validate digit characters, which allows remote attackers to cause a denial of service (application crash) via a crafted packet, related to the de_emerg_num_list and de_bcd_num functions.
nvd
CVE-2022-21248P4LOWCVSS 3.7v9.0v10.0+1 more2022-01-19
CVE-2022-21248 [LOW] CVE-2022-21248: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (co Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Serialization). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via mult
nvd
CVE-2008-5508P4MEDIUMCVSS 4.3v4.0v5.02008-12-17
CVE-2008-5508 [MEDIUM] CWE-20 CVE-2008-5508: Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMo Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 does not properly parse URLs with leading whitespace or control characters, which might allow remote attackers to misrepresent URLs and simplify phishing attacks.
nvd
CVE-2015-1241P4MEDIUMCVSS 4.3v8.02015-04-19
CVE-2015-1241 [MEDIUM] CWE-1021 CVE-2015-1241: Google Chrome before 42.0.2311.90 does not properly consider the interaction of page navigation with Google Chrome before 42.0.2311.90 does not properly consider the interaction of page navigation with the handling of touch events and gesture events, which allows remote attackers to trigger unintended UI actions via a crafted web site that conducts a "tapjacking" attack.
nvd
CVE-2018-12374P4MEDIUMCVSS 4.3v8.0v9.02018-10-18
CVE-2018-12374 [MEDIUM] CWE-200 CVE-2018-12374: Plaintext of decrypted emails can leak through by user submitting an embedded form by pressing enter Plaintext of decrypted emails can leak through by user submitting an embedded form by pressing enter key within a text input field. This vulnerability affects Thunderbird < 52.9.
nvd
CVE-2020-6442P4MEDIUMCVSS 4.3v10.02020-04-13
CVE-2020-6442 [MEDIUM] CWE-668 CVE-2020-6442: Inappropriate implementation in cache in Google Chrome prior to 81.0.4044.92 allowed a remote attack Inappropriate implementation in cache in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2015-1286P4MEDIUMCVSS 4.3v8.02015-07-23
CVE-2015-1286 [MEDIUM] CWE-79 CVE-2015-1286: Cross-site scripting (XSS) vulnerability in the V8ContextNativeHandler::GetModuleSystem function in Cross-site scripting (XSS) vulnerability in the V8ContextNativeHandler::GetModuleSystem function in extensions/renderer/v8_context_native_handler.cc in Google Chrome before 44.0.2403.89 allows remote attackers to inject arbitrary web script or HTML by leveraging the lack of a certain V8 context restriction, aka a Blink "Universal XSS (UXSS)."
nvd
CVE-2017-5103P4MEDIUMCVSS 4.3v9.02017-10-27
CVE-2017-5103 [MEDIUM] CWE-908 CVE-2017-5103: Use of an uninitialized value in Skia in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Use of an uninitialized value in Skia in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2017-5102P4MEDIUMCVSS 4.3v9.02017-10-27
CVE-2017-5102 [MEDIUM] CWE-908 CVE-2017-5102: Use of an uninitialized value in Skia in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux Use of an uninitialized value in Skia in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2015-1278P4MEDIUMCVSS 4.3v8.02015-07-23
CVE-2015-1278 [MEDIUM] CWE-254 CVE-2015-1278: content/browser/web_contents/web_contents_impl.cc in Google Chrome before 44.0.2403.89 does not ensu content/browser/web_contents/web_contents_impl.cc in Google Chrome before 44.0.2403.89 does not ensure that a PDF document's modal dialog is closed upon navigation to an interstitial page, which allows remote attackers to spoof URLs via a crafted document, as demonstrated by the alert_dialog.pdf document.
nvd
CVE-2017-5119P4MEDIUMCVSS 4.3v9.02017-10-27
CVE-2017-5119 [MEDIUM] CWE-119 CVE-2017-5119: Use of an uninitialized value in Skia in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and L Use of an uninitialized value in Skia in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.3163.81 for Android, allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2023-5380P4MEDIUMCVSS 4.7v11.0v12.02023-10-25
CVE-2023-5380 [MEDIUM] CWE-416 CVE-2023-5380: A use-after-free flaw was found in the xorg-x11-server. An X server crash may occur in a very specif A use-after-free flaw was found in the xorg-x11-server. An X server crash may occur in a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode) if the pointer is warped from within a window on one screen to the root window of the other screen and if the original window is destroyed follo
nvd
CVE-1999-0373P4HIGHCVSS 7.2v2.01999-02-01
CVE-1999-0373 [HIGH] CVE-1999-0373: Buffer overflow in the "Super" utility in Debian GNU/Linux, and other operating systems, allows loca Buffer overflow in the "Super" utility in Debian GNU/Linux, and other operating systems, allows local users to execute commands as root.
nvd
CVE-1999-1182P4HIGHCVSS 7.2v4.01997-07-17
CVE-1999-1182 [HIGH] CVE-1999-1182: Buffer overflow in run-time linkers (1) ld.so or (2) ld-linux.so for Linux systems allows local user Buffer overflow in run-time linkers (1) ld.so or (2) ld-linux.so for Linux systems allows local users to gain privileges by calling a setuid program with a long program name (argv[0]) and forcing ld.so/ld-linux.so to report an error.
nvd
CVE-2020-6489P4MEDIUMCVSS 4.3v9.0v10.02020-05-21
CVE-2020-6489 [MEDIUM] CWE-200 CVE-2020-6489: Inappropriate implementation in developer tools in Google Chrome prior to 83.0.4103.61 allowed a rem Inappropriate implementation in developer tools in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had convinced the user to take certain actions in developer tools to obtain potentially sensitive information from disk via a crafted HTML page.
nvd
CVE-2017-16804P4MEDIUMCVSS 4.3v9.02017-11-13
CVE-2017-16804 [MEDIUM] CWE-200 CVE-2017-16804: In Redmine before 3.2.7 and 3.3.x before 3.3.4, the reminders function in app/models/mailer.rb does In Redmine before 3.2.7 and 3.3.x before 3.3.4, the reminders function in app/models/mailer.rb does not check whether an issue is visible, which allows remote authenticated users to obtain sensitive information by reading e-mail reminder messages.
nvd
Debian Linux vulnerabilities | cvebase