cbcvebase.

Debian Linux vulnerabilities

9,955 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358

Vulnerabilities

Page 448 of 498
CVE-2023-5858P4MEDIUMCVSS 4.3v11.0v12.02023-11-01
CVE-2023-5858 [MEDIUM] CWE-346 CVE-2023-5858: Inappropriate implementation in WebApp Provider in Google Chrome prior to 119.0.6045.105 allowed a r Inappropriate implementation in WebApp Provider in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2023-5853P4MEDIUMCVSS 4.3v11.0v12.02023-11-01
CVE-2023-5853 [MEDIUM] CWE-346 CVE-2023-5853: Incorrect security UI in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacke Incorrect security UI in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-2464P4MEDIUMCVSS 4.3v11.02023-05-03
CVE-2023-2464 [MEDIUM] CVE-2023-2464: Inappropriate implementation in PictureInPicture in Google Chrome prior to 113.0.5672.63 allowed an Inappropriate implementation in PictureInPicture in Google Chrome prior to 113.0.5672.63 allowed an attacker who convinced a user to install a malicious extension to perform an origin spoof in the security UI via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-5859P4MEDIUMCVSS 4.3v11.0v12.02023-11-01
CVE-2023-5859 [MEDIUM] CWE-346 CVE-2023-5859: Incorrect security UI in Picture In Picture in Google Chrome prior to 119.0.6045.105 allowed a remot Incorrect security UI in Picture In Picture in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform domain spoofing via a crafted local HTML page. (Chromium security severity: Low)
nvd
CVE-2023-4908P4MEDIUMCVSS 4.3v11.0v12.02023-09-12
CVE-2023-4908 [MEDIUM] CVE-2023-4908: Inappropriate implementation in Picture in Picture in Google Chrome prior to 117.0.5938.62 allowed a Inappropriate implementation in Picture in Picture in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2023-4909P4MEDIUMCVSS 4.3v11.0v12.02023-09-12
CVE-2023-4909 [MEDIUM] CVE-2023-4909: Inappropriate implementation in Interstitials in Google Chrome prior to 117.0.5938.62 allowed a remo Inappropriate implementation in Interstitials in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2019-10732P4MEDIUMCVSS 4.3v8.02019-04-07
CVE-2019-10732 [MEDIUM] CWE-319 CVE-2019-10732: In KDE KMail 5.2.3, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub In KDE KMail 5.2.3, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This modified multipart email can be re-sent by the attacker to the intended receiver. If the receiver replies to this (be
nvd
CVE-2020-25656P4MEDIUMCVSS 4.1v9.02020-12-02
CVE-2020-25656 [MEDIUM] CWE-416 CVE-2020-25656: A flaw was found in the Linux kernel. A use-after-free was found in the way the console subsystem wa A flaw was found in the Linux kernel. A use-after-free was found in the way the console subsystem was using ioctls KDGKBSENT and KDSKBSENT. A local user could use this flaw to get read memory access out of bounds. The highest threat from this vulnerability is to data confidentiality.
nvd
CVE-2015-8345P4MEDIUMCVSS 6.5v7.0v8.02017-04-13
CVE-2015-8345 [MEDIUM] CWE-399 CVE-2015-8345: The eepro100 emulator in QEMU qemu-kvm blank allows local guest users to cause a denial of service ( The eepro100 emulator in QEMU qemu-kvm blank allows local guest users to cause a denial of service (application crash and infinite loop) via vectors involving the command block list.
nvd
CVE-2018-19841P4MEDIUMCVSS 5.5v9.02018-12-04
CVE-2018-19841 [MEDIUM] CWE-125 CVE-2018-19841: The function WavpackVerifySingleBlock in open_utils.c in libwavpack.a in WavPack through 5.1.0 allow The function WavpackVerifySingleBlock in open_utils.c in libwavpack.a in WavPack through 5.1.0 allows attackers to cause a denial-of-service (out-of-bounds read and application crash) via a crafted WavPack Lossless Audio file, as demonstrated by wvunpack.
nvd
CVE-2014-7154P4MEDIUMCVSS 6.1v7.02014-10-02
CVE-2014-7154 [MEDIUM] CWE-362 CVE-2014-7154: Race condition in HVMOP_track_dirty_vram in Xen 4.0.0 through 4.4.x does not ensure possession of th Race condition in HVMOP_track_dirty_vram in Xen 4.0.0 through 4.4.x does not ensure possession of the guarding lock for dirty video RAM tracking, which allows certain local guest domains to cause a denial of service via unspecified vectors.
nvd
CVE-2017-6312P4MEDIUMCVSS 5.5v8.02017-03-10
CVE-2017-6312 [MEDIUM] CWE-190 CVE-2017-6312: Integer overflow in io-ico.c in gdk-pixbuf allows context-dependent attackers to cause a denial of s Integer overflow in io-ico.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (segmentation fault and application crash) via a crafted image entry offset in an ICO file, which triggers an out-of-bounds read, related to compiler optimizations.
nvd
CVE-2013-6892P4LOWCVSS 3.5v7.02015-01-21
CVE-2013-6892 [LOW] CWE-200 CVE-2013-6892: WebSVN 2.3.3 allows remote authenticated users to read arbitrary files via a symlink attack in a com WebSVN 2.3.3 allows remote authenticated users to read arbitrary files via a symlink attack in a commit.
nvd
CVE-2017-18267P4MEDIUMCVSS 5.5v8.02018-05-10
CVE-2017-18267 [MEDIUM] CWE-835 CVE-2017-18267: The FoFiType1C::cvtGlyph function in fofi/FoFiType1C.cc in Poppler through 0.64.0 allows remote atta The FoFiType1C::cvtGlyph function in fofi/FoFiType1C.cc in Poppler through 0.64.0 allows remote attackers to cause a denial of service (infinite recursion) via a crafted PDF file, as demonstrated by pdftops.
nvd
CVE-2017-6314P4MEDIUMCVSS 5.5v8.02017-03-10
CVE-2017-6314 [MEDIUM] CWE-835 CVE-2017-6314: The make_available_at_least function in io-tiff.c in gdk-pixbuf allows context-dependent attackers t The make_available_at_least function in io-tiff.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (infinite loop) via a large TIFF file.
nvd
CVE-2019-15144P4MEDIUMCVSS 5.5v8.0v9.0+2 more2019-08-18
CVE-2019-15144 [MEDIUM] CWE-674 CVE-2019-15144: In DjVuLibre 3.5.27, the sorting functionality (aka GArrayTemplate<TYPE>::sort) allows attackers to In DjVuLibre 3.5.27, the sorting functionality (aka GArrayTemplate::sort) allows attackers to cause a denial-of-service (application crash due to an Uncontrolled Recursion) by crafting a PBM image file that is mishandled in libdjvu/GContainer.h.
nvd
CVE-2007-3998P4MEDIUMCVSS 5.0v3.1v4.02007-09-04
CVE-2007-3998 [MEDIUM] CWE-20 CVE-2007-3998: The wordwrap function in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, does not properly use the break The wordwrap function in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, does not properly use the breakcharlen variable, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash, or infinite loop) via certain arguments, as demonstrated by a 'chr(0), 0, ""' argument set.
nvd
CVE-2016-5107P4MEDIUMCVSS 6.0v8.02016-09-02
CVE-2016-5107 [MEDIUM] CWE-125 CVE-2016-5107: The megasas_lookup_frame function in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emu The megasas_lookup_frame function in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds read and crash) via unspecified vectors.
nvd
CVE-2016-10155P4MEDIUMCVSS 6.0v8.02017-03-15
CVE-2016-10155 [MEDIUM] CWE-401 CVE-2016-10155: Memory leak in hw/watchdog/wdt_i6300esb.c in QEMU (aka Quick Emulator) allows local guest OS privile Memory leak in hw/watchdog/wdt_i6300esb.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption and QEMU process crash) via a large number of device unplug operations.
nvd
CVE-2016-9106P4MEDIUMCVSS 6.0v8.02016-12-09
CVE-2016-9106 [MEDIUM] CWE-772 CVE-2016-9106: Memory leak in the v9fs_write function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local gue Memory leak in the v9fs_write function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption) by leveraging failure to free an IO vector.
nvd
Debian Linux vulnerabilities | cvebase