cbcvebase.

Debian Linux vulnerabilities

9,955 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358

Vulnerabilities

Page 447 of 498
CVE-2013-1811P4MEDIUMCVSS 4.3v6.0v7.02019-11-07
CVE-2013-1811 [MEDIUM] CWE-20 CVE-2013-1811: An access control issue in MantisBT before 1.2.13 allows users with "Reporter" permissions to change An access control issue in MantisBT before 1.2.13 allows users with "Reporter" permissions to change any issue to "New".
nvd
CVE-2020-11494P4MEDIUMCVSS 4.4v8.0v9.02020-04-02
CVE-2020-11494 [MEDIUM] CWE-908 CVE-2020-11494: An issue was discovered in slc_bump in drivers/net/can/slcan.c in the Linux kernel 3.16 through 5.6. An issue was discovered in slc_bump in drivers/net/can/slcan.c in the Linux kernel 3.16 through 5.6.2. It allows attackers to read uninitialized can_frame data, potentially containing sensitive information from kernel stack memory, if the configuration lacks CONFIG_INIT_STACK_ALL, aka CID-b9258a2cece4.
nvd
CVE-2023-5851P4MEDIUMCVSS 4.3v11.0v12.02023-11-01
CVE-2023-5851 [MEDIUM] CWE-346 CVE-2023-5851: Inappropriate implementation in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote Inappropriate implementation in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2018-6178P4MEDIUMCVSS 4.3v9.02019-01-09
CVE-2018-6178 [MEDIUM] CWE-1021 CVE-2018-6178: Eliding from the wrong side in an infobar in DevTools in Google Chrome prior to 68.0.3440.75 allowed Eliding from the wrong side in an infobar in DevTools in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced a user to install a malicious extension to Hide Chrome Security UI via a crafted Chrome Extension.
nvd
CVE-2023-6511P4MEDIUMCVSS 4.3v11.0v12.02023-12-06
CVE-2023-6511 [MEDIUM] CVE-2023-6511: Inappropriate implementation in Autofill in Google Chrome prior to 120.0.6099.62 allowed a remote at Inappropriate implementation in Autofill in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2016-4323P4LOWCVSS 3.7v8.02017-01-06
CVE-2016-4323 [LOW] CWE-22 CVE-2016-4323: A directory traversal exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT A directory traversal exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent from the server could potentially result in an overwrite of files. A malicious server or someone with access to the network traffic can provide an invalid filename for a splash image triggering the vulnerability.
nvd
CVE-2023-2466P4MEDIUMCVSS 4.3v11.02023-05-03
CVE-2023-2466 [MEDIUM] CVE-2023-2466: Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 allowed a remote att Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to spoof the contents of the security UI via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2023-5721P4MEDIUMCVSS 4.3v10.0v11.02023-10-25
CVE-2023-5721 [MEDIUM] CWE-1021 CVE-2023-5721: It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to an insufficient activation-delay. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
nvd
CVE-2019-5838P4MEDIUMCVSS 4.3v10.02019-06-27
CVE-2019-5838 [MEDIUM] CWE-863 CVE-2019-5838: Insufficient policy enforcement in extensions API in Google Chrome prior to 75.0.3770.80 allowed an Insufficient policy enforcement in extensions API in Google Chrome prior to 75.0.3770.80 allowed an attacker who convinced a user to install a malicious extension to bypass restrictions on file URIs via a crafted Chrome Extension.
nvd
CVE-2023-5478P4MEDIUMCVSS 4.3v11.0v12.02023-10-11
CVE-2023-5478 [MEDIUM] CVE-2023-5478: Inappropriate implementation in Autofill in Google Chrome prior to 118.0.5993.70 allowed a remote at Inappropriate implementation in Autofill in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2023-5486P4MEDIUMCVSS 4.3v11.0v12.02023-10-11
CVE-2023-5486 [MEDIUM] CVE-2023-5486: Inappropriate implementation in Input in Google Chrome prior to 118.0.5993.70 allowed a remote attac Inappropriate implementation in Input in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2023-5485P4MEDIUMCVSS 4.3v11.0v12.02023-10-11
CVE-2023-5485 [MEDIUM] CWE-79 CVE-2023-5485: Inappropriate implementation in Autofill in Google Chrome prior to 118.0.5993.70 allowed a remote at Inappropriate implementation in Autofill in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to bypass autofill restrictions via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2020-25685P4LOWCVSS 3.7v10.02021-01-20
CVE-2020-25685 [LOW] CVE-2020-25685: A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmas A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmasq checks in forward.c:reply_query(), which is the forwarded query that matches the reply, by only using a weak hash of the query name. Due to the weak hash (CRC32 when dnsmasq is compiled without DNSSEC, SHA-1 when it is) this flaw allows an off-path attacker to
nvd
CVE-2023-4907P4MEDIUMCVSS 4.3v11.0v12.02023-09-12
CVE-2023-4907 [MEDIUM] CVE-2023-4907: Inappropriate implementation in Intents in Google Chrome on Android prior to 117.0.5938.62 allowed a Inappropriate implementation in Intents in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2023-4900P4MEDIUMCVSS 4.3v11.0v12.02023-09-12
CVE-2023-4900 [MEDIUM] CVE-2023-4900: Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 117.0.5938.62 allow Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to obfuscate a permission prompt via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-4903P4MEDIUMCVSS 4.3v11.0v12.02023-09-12
CVE-2023-4903 [MEDIUM] CVE-2023-4903: Inappropriate implementation in Custom Mobile Tabs in Google Chrome on Android prior to 117.0.5938.6 Inappropriate implementation in Custom Mobile Tabs in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-4364P4MEDIUMCVSS 4.3v11.0v12.02023-08-15
CVE-2023-4364 [MEDIUM] CVE-2023-4364: Inappropriate implementation in Permission Prompts in Google Chrome prior to 116.0.5845.96 allowed a Inappropriate implementation in Permission Prompts in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-4365P4MEDIUMCVSS 4.3v11.0v12.02023-08-15
CVE-2023-4365 [MEDIUM] CVE-2023-4365: Inappropriate implementation in Fullscreen in Google Chrome prior to 116.0.5845.96 allowed a remote Inappropriate implementation in Fullscreen in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-4360P4MEDIUMCVSS 4.3v11.0v12.02023-08-15
CVE-2023-4360 [MEDIUM] CVE-2023-4360: Inappropriate implementation in Color in Google Chrome prior to 116.0.5845.96 allowed a remote attac Inappropriate implementation in Color in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2020-28368P4MEDIUMCVSS 4.4v10.02020-11-10
CVE-2020-28368 [MEDIUM] CWE-862 CVE-2020-28368: Xen through 4.14.x allows guest OS administrators to obtain sensitive information (such as AES keys Xen through 4.14.x allows guest OS administrators to obtain sensitive information (such as AES keys from outside the guest) via a side-channel attack on a power/energy monitoring interface, aka a "Platypus" attack. NOTE: there is only one logically independent fix: to change the access control for each such interface in Xen.
nvd
Debian Linux vulnerabilities | cvebase