Debian Linux vulnerabilities
9,955 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358
Vulnerabilities
Page 445 of 498
CVE-2018-6112P4MEDIUMCVSS 4.3v8.0v9.02019-01-09
CVE-2018-6112 [MEDIUM] CWE-706 CVE-2018-6112: Making URLs clickable and allowing them to be styled in DevTools in Google Chrome prior to 66.0.3359
Making URLs clickable and allowing them to be styled in DevTools in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2020-6531P4MEDIUMCVSS 4.3v10.02020-07-22
CVE-2020-6531 [MEDIUM] CWE-203 CVE-2020-6531: Side-channel information leakage in scroll to text in Google Chrome prior to 84.0.4147.89 allowed a
Side-channel information leakage in scroll to text in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2014-6276P4MEDIUMCVSS 4.3v7.0v8.02016-04-13
CVE-2014-6276 [MEDIUM] CWE-264 CVE-2014-6276: schema.py in Roundup before 1.5.1 does not properly limit attributes included in default user permis
schema.py in Roundup before 1.5.1 does not properly limit attributes included in default user permissions, which might allow remote authenticated users to obtain sensitive user information by viewing user details.
nvd
CVE-2018-0503P4MEDIUMCVSS 4.3v9.02018-10-04
CVE-2018-0503 [MEDIUM] CWE-269 CVE-2018-0503: Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains a flaw where contrary to the docume
Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains a flaw where contrary to the documentation, $wgRateLimits entry for 'user' overrides that for 'newbie'.
nvd
CVE-2014-3166P4MEDIUMCVSS 4.3v7.0v8.02014-08-13
CVE-2014-3166 [MEDIUM] CVE-2014-3166: The Public Key Pinning (PKP) implementation in Google Chrome before 36.0.1985.143 on Windows, OS X,
The Public Key Pinning (PKP) implementation in Google Chrome before 36.0.1985.143 on Windows, OS X, and Linux, and before 36.0.1985.135 on Android, does not correctly consider the properties of SPDY connections, which allows remote attackers to obtain sensitive information by leveraging the use of multiple domain names.
nvd
CVE-2015-1236P4MEDIUMCVSS 4.3v8.02015-04-19
CVE-2015-1236 [MEDIUM] CWE-264 CVE-2015-1236: The MediaElementAudioSourceNode::process function in modules/webaudio/MediaElementAudioSourceNode.cp
The MediaElementAudioSourceNode::process function in modules/webaudio/MediaElementAudioSourceNode.cpp in the Web Audio API implementation in Blink, as used in Google Chrome before 42.0.2311.90, allows remote attackers to bypass the Same Origin Policy and obtain sensitive audio sample values via a crafted web site containing a media element.
nvd
CVE-2017-5033P4MEDIUMCVSS 4.3v8.0v9.02017-04-24
CVE-2017-5033 [MEDIUM] CWE-281 CVE-2017-5033: Blink in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Andro
Blink in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android failed to correctly propagate CSP restrictions to local scheme pages, which allowed a remote attacker to bypass content security policy via a crafted HTML page, related to the unsafe-inline keyword.
nvd
CVE-2021-38506P4MEDIUMCVSS 4.3v9.0v10.0+1 more2021-12-08
CVE-2021-38506 [MEDIUM] CWE-1021 CVE-2021-38506: Through a series of navigations, Firefox could have entered fullscreen mode without notification or
Through a series of navigations, Firefox could have entered fullscreen mode without notification or warning to the user. This could lead to spoofing attacks on the browser UI including phishing. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
nvd
CVE-2018-1116P4MEDIUMCVSS 4.4v8.02018-07-10
CVE-2018-1116 [MEDIUM] CWE-285 CVE-2018-1116: A flaw was found in polkit before version 0.116. The implementation of the polkit_backend_interactiv
A flaw was found in polkit before version 0.116. The implementation of the polkit_backend_interactive_authority_check_authorization function in polkitd allows to test for authentication and trigger authentication of unrelated processes owned by other users. This may result in a local DoS and information disclosure.
nvd
CVE-2004-0689P4HIGHCVSS 7.1v3.02004-09-28
CVE-2004-0689 [HIGH] CWE-59 CVE-2004-0689: KDE before 3.3.0 does not properly handle when certain symbolic links point to "stale" locations, wh
KDE before 3.3.0 does not properly handle when certain symbolic links point to "stale" locations, which could allow local users to create or truncate arbitrary files.
nvd
CVE-2016-1657P4MEDIUMCVSS 4.3v8.02016-04-18
CVE-2016-1657 [MEDIUM] CWE-254 CVE-2016-1657: The WebContentsImpl::FocusLocationBarByDefault function in content/browser/web_contents/web_contents
The WebContentsImpl::FocusLocationBarByDefault function in content/browser/web_contents/web_contents_impl.cc in Google Chrome before 50.0.2661.75 mishandles focus for certain about:blank pages, which allows remote attackers to spoof the address bar via a crafted URL.
nvd
CVE-2016-1658P4MEDIUMCVSS 4.3v8.02016-04-18
CVE-2016-1658 [MEDIUM] CWE-200 CVE-2016-1658: The Extensions subsystem in Google Chrome before 50.0.2661.75 incorrectly relies on GetOrigin method
The Extensions subsystem in Google Chrome before 50.0.2661.75 incorrectly relies on GetOrigin method calls for origin comparisons, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted extension.
nvd
CVE-2021-22898P4LOWCVSS 3.1v9.02021-06-11
CVE-2021-22898 [LOW] CWE-200 CVE-2021-22898: curl 7.7 through 7.76.1 suffers from an information disclosure when the `-t` command line option, kn
curl 7.7 through 7.76.1 suffers from an information disclosure when the `-t` command line option, known as `CURLOPT_TELNETOPTIONS` in libcurl, is used to send variable=content pairs to TELNET servers. Due to a flaw in the option parser for sending NEW_ENV variables, libcurl could be made to pass on uninitialized data from a stack based buffer to the se
nvd
CVE-2018-0498P4MEDIUMCVSS 4.7v8.0v9.02018-07-28
CVE-2018-0498 [MEDIUM] CVE-2018-0498: ARM mbed TLS before 2.12.0, before 2.7.5, and before 2.1.14 allows local users to achieve partial pl
ARM mbed TLS before 2.12.0, before 2.7.5, and before 2.1.14 allows local users to achieve partial plaintext recovery (for a CBC based ciphersuite) via a cache-based side-channel attack.
nvd
CVE-2020-36424P4MEDIUMCVSS 4.7v10.02021-07-19
CVE-2020-36424 [MEDIUM] CWE-203 CVE-2020-36424: An issue was discovered in Arm Mbed TLS before 2.24.0. An attacker can recover a private key (for RS
An issue was discovered in Arm Mbed TLS before 2.24.0. An attacker can recover a private key (for RSA or static Diffie-Hellman) via a side-channel attack against generation of base blinding/unblinding values.
nvd
CVE-2020-15966P4MEDIUMCVSS 4.3v10.02020-09-21
CVE-2020-15966 [MEDIUM] CVE-2020-15966: Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.4183.121 allowed an att
Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information via a crafted Chrome Extension.
nvd
CVE-2020-6391P4MEDIUMCVSS 4.3v9.0v10.02020-02-11
CVE-2020-6391 [MEDIUM] CWE-79 CVE-2020-6391: Insufficient validation of untrusted input in Blink in Google Chrome prior to 80.0.3987.87 allowed a
Insufficient validation of untrusted input in Blink in Google Chrome prior to 80.0.3987.87 allowed a local attacker to bypass content security policy via a crafted HTML page.
nvd
CVE-2018-6041P4MEDIUMCVSS 4.3v8.0v9.02018-09-25
CVE-2018-6041 [MEDIUM] CWE-20 CVE-2018-6041: Incorrect security UI in navigation in Google Chrome prior to 64.0.3282.119 allowed a remote attacke
Incorrect security UI in navigation in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2006-2935P4MEDIUMCVSS 4.6v3.12006-07-05
CVE-2006-2935 [MEDIUM] CWE-120 CVE-2006-2935: The dvd_read_bca function in the DVD handling code in drivers/cdrom/cdrom.c in Linux kernel 2.2.16,
The dvd_read_bca function in the DVD handling code in drivers/cdrom/cdrom.c in Linux kernel 2.2.16, and later versions, assigns the wrong value to a length variable, which allows local users to execute arbitrary code via a crafted USB Storage device that triggers a buffer overflow.
nvd
CVE-2021-21185P4MEDIUMCVSS 4.3v10.02021-03-09
CVE-2021-21185 [MEDIUM] CVE-2021-21185: Insufficient policy enforcement in extensions in Google Chrome prior to 89.0.4389.72 allowed an atta
Insufficient policy enforcement in extensions in Google Chrome prior to 89.0.4389.72 allowed an attacker who convinced a user to install a malicious extension to obtain sensitive information via a crafted Chrome Extension.
nvd