Debian Linux vulnerabilities
9,955 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358
Vulnerabilities
Page 452 of 498
CVE-2018-1130P4MEDIUMCVSS 5.5v7.0v8.02018-05-10
CVE-2018-1130 [MEDIUM] CWE-476 CVE-2018-1130: Linux kernel before version 4.16-rc7 is vulnerable to a null pointer dereference in dccp_write_xmit(
Linux kernel before version 4.16-rc7 is vulnerable to a null pointer dereference in dccp_write_xmit() function in net/dccp/output.c in that allows a local user to cause a denial of service by a number of certain crafted system calls.
nvd
CVE-2015-8558P4MEDIUMCVSS 5.5v7.0v8.02016-05-23
CVE-2015-8558 [MEDIUM] CWE-835 CVE-2015-8558: The ehci_process_itd function in hw/usb/hcd-ehci.c in QEMU allows local guest OS administrators to c
The ehci_process_itd function in hw/usb/hcd-ehci.c in QEMU allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) via a circular isochronous transfer descriptor (iTD) list.
nvd
CVE-2011-1488P4MEDIUMCVSS 5.5v8.0v9.0+1 more2019-11-14
CVE-2011-1488 [MEDIUM] CWE-772 CVE-2011-1488: A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged
A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when $RepeatedMsgReduction was enabled. A local attacker could use this flaw to cause a denial of the rsyslogd daemon service by crashing the service via a sequence of repeated log messages sent within short periods of time.
nvd
CVE-2014-9671P4MEDIUMCVSS 4.3v7.02015-02-08
CVE-2014-9671 [MEDIUM] CVE-2014-9671: Off-by-one error in the pcf_get_properties function in pcf/pcfread.c in FreeType before 2.5.4 allows
Off-by-one error in the pcf_get_properties function in pcf/pcfread.c in FreeType before 2.5.4 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PCF file with a 0xffffffff size value that is improperly incremented.
nvd
CVE-2012-0879P4MEDIUMCVSS 5.5v6.02012-05-17
CVE-2012-0879 [MEDIUM] CWE-400 CVE-2012-0879: The I/O implementation for block devices in the Linux kernel before 2.6.33 does not properly handle
The I/O implementation for block devices in the Linux kernel before 2.6.33 does not properly handle the CLONE_IO feature, which allows local users to cause a denial of service (I/O instability) by starting multiple processes that share an I/O context.
nvd
CVE-2018-10087P4MEDIUMCVSS 5.5v8.02018-04-13
CVE-2018-10087 [MEDIUM] CWE-20 CVE-2018-10087: The kernel_wait4 function in kernel/exit.c in the Linux kernel before 4.13, when an unspecified arch
The kernel_wait4 function in kernel/exit.c in the Linux kernel before 4.13, when an unspecified architecture and compiler is used, might allow local users to cause a denial of service by triggering an attempted use of the -INT_MIN value.
nvd
CVE-2019-19462P4MEDIUMCVSS 5.5v8.0v9.0+1 more2019-11-30
CVE-2019-19462 [MEDIUM] CWE-476 CVE-2019-19462: relay_open in kernel/relay.c in the Linux kernel through 5.4.1 allows local users to cause a denial
relay_open in kernel/relay.c in the Linux kernel through 5.4.1 allows local users to cause a denial of service (such as relay blockage) by triggering a NULL alloc_percpu result.
nvd
CVE-2017-5973P4MEDIUMCVSS 5.5v8.02017-03-27
CVE-2017-5973 [MEDIUM] CWE-835 CVE-2017-5973: The xhci_kick_epctx function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator) allows local guest OS
The xhci_kick_epctx function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (infinite loop and QEMU process crash) via vectors related to control transfer descriptor sequence.
nvd
CVE-2023-38559P4MEDIUMCVSS 5.5v10.02023-08-01
CVE-2023-38559 [MEDIUM] CWE-125 CVE-2023-38559: A buffer overflow flaw was found in base/gdevdevn.c:1973 in devn_pcx_write_rle() in ghostscript. Thi
A buffer overflow flaw was found in base/gdevdevn.c:1973 in devn_pcx_write_rle() in ghostscript. This issue may allow a local attacker to cause a denial of service via outputting a crafted PDF file for a DEVN device with gs.
nvd
CVE-2025-38120P4MEDIUMCVSS 5.5v11.02025-07-03
CVE-2025-38120 [MEDIUM] CVE-2025-38120: In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_set_pipapo_avx2:
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_set_pipapo_avx2: fix initial map fill
If the first field doesn't cover the entire start map, then we must zero
out the remainder, else we leak those bits into the next match round map.
The early fix was incomplete and did only fix up the generic C
implementation.
A followup
nvd
CVE-2020-15393P4MEDIUMCVSS 5.5v9.02020-06-29
CVE-2020-15393 [MEDIUM] CWE-401 CVE-2020-15393: In the Linux kernel 4.4 through 5.7.6, usbtest_disconnect in drivers/usb/misc/usbtest.c has a memory
In the Linux kernel 4.4 through 5.7.6, usbtest_disconnect in drivers/usb/misc/usbtest.c has a memory leak, aka CID-28ebeb8db770.
nvd
CVE-2014-3646P4MEDIUMCVSS 5.5v7.02014-11-10
CVE-2014-3646 [MEDIUM] CVE-2014-3646: arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel through 3.17.2 does not have an exit han
arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel through 3.17.2 does not have an exit handler for the INVVPID instruction, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application.
nvd
CVE-2017-9373P4MEDIUMCVSS 5.5v8.0v9.02017-06-16
CVE-2017-9373 [MEDIUM] CWE-401 CVE-2017-9373: Memory leak in QEMU (aka Quick Emulator), when built with IDE AHCI Emulation support, allows local g
Memory leak in QEMU (aka Quick Emulator), when built with IDE AHCI Emulation support, allows local guest OS privileged users to cause a denial of service (memory consumption) by repeatedly hot-unplugging the AHCI device.
nvd
CVE-2017-8925P4MEDIUMCVSS 5.5v8.0v9.02017-05-12
CVE-2017-8925 [MEDIUM] CWE-404 CVE-2017-8925: The omninet_open function in drivers/usb/serial/omninet.c in the Linux kernel before 4.10.4 allows l
The omninet_open function in drivers/usb/serial/omninet.c in the Linux kernel before 4.10.4 allows local users to cause a denial of service (tty exhaustion) by leveraging reference count mishandling.
nvd
CVE-2004-1093P4MEDIUMCVSS 5.0v3.02005-04-14
CVE-2004-1093 [MEDIUM] CVE-2004-1093: Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service via
Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service via "use of already freed memory."
nvd
CVE-2004-1092P4MEDIUMCVSS 5.0v3.02005-04-14
CVE-2004-1092 [MEDIUM] CVE-2004-1092: Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service by c
Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service by causing mc to free unallocated memory.
nvd
CVE-2021-1095P4MEDIUMCVSS 5.5v9.02021-07-22
CVE-2021-1095 [MEDIUM] CWE-476 CVE-2021-1095: NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (n
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handlers for all control calls with embedded parameters where dereferencing an untrusted pointer may lead to denial of service.
nvd
CVE-2017-18241P4MEDIUMCVSS 5.5v8.0v9.02018-03-21
CVE-2017-18241 [MEDIUM] CWE-476 CVE-2017-18241: fs/f2fs/segment.c in the Linux kernel before 4.13 allows local users to cause a denial of service (N
fs/f2fs/segment.c in the Linux kernel before 4.13 allows local users to cause a denial of service (NULL pointer dereference and panic) by using a noflush_merge option that triggers a NULL value for a flush_cmd_control data structure.
nvd
CVE-2017-11434P4MEDIUMCVSS 5.5v8.0v9.02017-07-25
CVE-2017-11434 [MEDIUM] CWE-125 CVE-2017-11434: The dhcp_decode function in slirp/bootp.c in QEMU (aka Quick Emulator) allows local guest OS users t
The dhcp_decode function in slirp/bootp.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) via a crafted DHCP options string.
nvd
CVE-2023-42755P4MEDIUMCVSS 5.5v10.02023-10-05
CVE-2023-42755 [MEDIUM] CWE-125 CVE-2023-42755: A flaw was found in the IPv4 Resource Reservation Protocol (RSVP) classifier in the Linux kernel. Th
A flaw was found in the IPv4 Resource Reservation Protocol (RSVP) classifier in the Linux kernel. The xprt pointer may go beyond the linear part of the skb, leading to an out-of-bounds read in the `rsvp_classify` function. This issue may allow a local user to crash the system and cause a denial of service.
nvd