cbcvebase.

Debian Linux vulnerabilities

9,955 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358

Vulnerabilities

Page 446 of 498
CVE-2020-6571P4MEDIUMCVSS 4.3v10.02020-09-21
CVE-2020-6571 [MEDIUM] CWE-20 CVE-2020-6571: Insufficient data validation in Omnibox in Google Chrome prior to 85.0.4183.83 allowed a remote atta Insufficient data validation in Omnibox in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
nvd
CVE-2020-6529P4MEDIUMCVSS 4.3v10.02020-07-22
CVE-2020-6529 [MEDIUM] CWE-295 CVE-2020-6529: Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to leak cross-origin data via a crafted HTML page.
nvd
CVE-2017-9079P4MEDIUMCVSS 4.7v8.02017-05-19
CVE-2017-9079 [MEDIUM] CWE-732 CVE-2017-9079: Dropbear before 2017.75 might allow local users to read certain files as root, if the file has the a Dropbear before 2017.75 might allow local users to read certain files as root, if the file has the authorized_keys file format with a command= option. This occurs because ~/.ssh/authorized_keys is read with root privileges and symlinks are followed.
nvd
CVE-2019-13759P4MEDIUMCVSS 4.3v9.0v10.02019-12-10
CVE-2019-13759 [MEDIUM] CVE-2019-13759: Incorrect security UI in interstitials in Google Chrome prior to 79.0.3945.79 allowed a remote attac Incorrect security UI in interstitials in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
nvd
CVE-2019-13756P4MEDIUMCVSS 4.3v9.0v10.02019-12-10
CVE-2019-13756 [MEDIUM] CVE-2019-13756: Incorrect security UI in printing in Google Chrome prior to 79.0.3945.79 allowed a remote attacker t Incorrect security UI in printing in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
nvd
CVE-2021-37968P4MEDIUMCVSS 4.3v10.0v11.02021-10-08
CVE-2021-37968 [MEDIUM] CWE-203 CVE-2021-37968: Inappropriate implementation in Background Fetch API in Google Chrome prior to 94.0.4606.54 allowed Inappropriate implementation in Background Fetch API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2019-13758P4MEDIUMCVSS 4.3v9.0v10.02019-12-10
CVE-2019-13758 [MEDIUM] CVE-2019-13758: Insufficient policy enforcement in navigation in Google Chrome on Android prior to 79.0.3945.79 allo Insufficient policy enforcement in navigation in Google Chrome on Android prior to 79.0.3945.79 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2019-13755P4MEDIUMCVSS 4.3v9.0v10.02019-12-10
CVE-2019-13755 [MEDIUM] CVE-2019-13755: Insufficient policy enforcement in extensions in Google Chrome prior to 79.0.3945.79 allowed a remot Insufficient policy enforcement in extensions in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to disable extensions via a crafted HTML page.
nvd
CVE-2021-37965P4MEDIUMCVSS 4.3v10.0v11.02021-10-08
CVE-2021-37965 [MEDIUM] CVE-2021-37965: Inappropriate implementation in Background Fetch API in Google Chrome prior to 94.0.4606.54 allowed Inappropriate implementation in Background Fetch API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2018-6102P4MEDIUMCVSS 4.3v8.0v9.02018-12-04
CVE-2018-6102 [MEDIUM] CWE-20 CVE-2018-6102: Missing confusable characters in Internationalization in Google Chrome prior to 66.0.3359.117 allowe Missing confusable characters in Internationalization in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
nvd
CVE-2010-0291P4MEDIUMCVSS 4.6v4.0v5.02010-02-15
CVE-2010-0291 [MEDIUM] CWE-264 CVE-2010-0291: The Linux kernel before 2.6.32.4 allows local users to gain privileges or cause a denial of service The Linux kernel before 2.6.32.4 allows local users to gain privileges or cause a denial of service (panic) by calling the (1) mmap or (2) mremap function, aka the "do_mremap() mess" or "mremap/mmap mess."
nvd
CVE-2021-43538P4MEDIUMCVSS 4.3v9.0v10.0+1 more2021-12-08
CVE-2021-43538 [MEDIUM] CWE-362 CVE-2021-43538: By misusing a race in our notification code, an attacker could have forcefully hidden the notificati By misusing a race in our notification code, an attacker could have forcefully hidden the notification for pages that had received full screen and pointer lock access, which could have been used for spoofing attacks. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
nvd
CVE-2021-37963P4MEDIUMCVSS 4.3v10.0v11.02021-10-08
CVE-2021-37963 [MEDIUM] CVE-2021-37963: Side-channel information leakage in DevTools in Google Chrome prior to 94.0.4606.54 allowed a remote Side-channel information leakage in DevTools in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to bypass site isolation via a crafted HTML page.
nvd
CVE-2016-1000236P4MEDIUMCVSS 4.4v8.0v9.02019-11-19
CVE-2016-1000236 [MEDIUM] CWE-362 CVE-2016-1000236: Node-cookie-signature before 1.0.6 is affected by a timing attack due to the type of comparison used Node-cookie-signature before 1.0.6 is affected by a timing attack due to the type of comparison used.
nvd
CVE-2018-18357P4MEDIUMCVSS 4.3v9.02018-12-11
CVE-2018-18357 [MEDIUM] CVE-2018-18357: Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 71.0.3578.80 Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
nvd
CVE-2018-18355P4MEDIUMCVSS 4.3v9.02018-12-11
CVE-2018-18355 [MEDIUM] CVE-2018-18355: Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 71.0.3578.80 Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
nvd
CVE-2025-39713P4MEDIUMCVSS 4.7v11.02025-09-05
CVE-2025-39713 [MEDIUM] CWE-367 CVE-2025-39713: In the Linux kernel, the following vulnerability has been resolved: media: rainshadow-cec: fix TOCT In the Linux kernel, the following vulnerability has been resolved: media: rainshadow-cec: fix TOCTOU race condition in rain_interrupt() In the interrupt handler rain_interrupt(), the buffer full check on rain->buf_len is performed before acquiring rain->buf_lock. This creates a Time-of-Check to Time-of-Use (TOCTOU) race condition, as rain->buf_len
nvd
CVE-2015-0374P4LOWCVSS 3.5v7.02015-01-21
CVE-2015-0374 [LOW] CVE-2015-0374: Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows re Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows remote authenticated users to affect confidentiality via unknown vectors related to Server : Security : Privileges : Foreign Key.
nvd
CVE-2019-13761P4MEDIUMCVSS 4.3v9.0v10.02019-12-10
CVE-2019-13761 [MEDIUM] CVE-2019-13761: Incorrect security UI in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to Incorrect security UI in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
nvd
CVE-2021-21228P4MEDIUMCVSS 4.3v10.02021-04-30
CVE-2021-21228 [MEDIUM] CWE-863 CVE-2021-21228: Insufficient policy enforcement in extensions in Google Chrome prior to 90.0.4430.93 allowed an atta Insufficient policy enforcement in extensions in Google Chrome prior to 90.0.4430.93 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.
nvd
Debian Linux vulnerabilities | cvebase