cbcvebase.

Debian Linux vulnerabilities

9,955 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358

Vulnerabilities

Page 459 of 498
CVE-2013-3839P4MEDIUMCVSS 4.0v6.0v7.02013-10-16
CVE-2013-3839 [MEDIUM] CVE-2013-3839: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.70 and earlier, 5.5.32 a Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.70 and earlier, 5.5.32 and earlier, and 5.6.12 and earlier allows remote authenticated users to affect availability via unknown vectors related to Optimizer.
nvd
CVE-2014-9036P4MEDIUMCVSS 4.3v7.0v8.02014-11-25
CVE-2014-9036 [MEDIUM] CWE-79 CVE-2014-9036: Cross-site scripting (XSS) vulnerability in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before Cross-site scripting (XSS) vulnerability in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted Cascading Style Sheets (CSS) token sequence in a post.
nvd
CVE-2012-6684P4MEDIUMCVSS 4.3v7.02015-01-08
CVE-2012-6684 [MEDIUM] CWE-79 CVE-2012-6684: Cross-site scripting (XSS) vulnerability in the RedCloth library 4.2.9 for Ruby and earlier allows r Cross-site scripting (XSS) vulnerability in the RedCloth library 4.2.9 for Ruby and earlier allows remote attackers to inject arbitrary web script or HTML via a javascript: URI.
nvd
CVE-2013-3804P4MEDIUMCVSS 4.0v7.02013-07-17
CVE-2013-3804 [MEDIUM] CVE-2013-3804: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.69 and earlier, 5.5.31 a Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.69 and earlier, 5.5.31 and earlier, and 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.
nvd
CVE-2015-3012P4MEDIUMCVSS 4.3v7.02015-05-08
CVE-2015-3012 [MEDIUM] CWE-79 CVE-2015-3012: Multiple cross-site scripting (XSS) vulnerabilities in WebODF before 0.5.5, as used in ownCloud, all Multiple cross-site scripting (XSS) vulnerabilities in WebODF before 0.5.5, as used in ownCloud, allow remote attackers to inject arbitrary web script or HTML via a (1) style or (2) font name or (3) javascript or (4) data URI.
nvd
CVE-2019-18281P4MEDIUMCVSS 4.3v9.0v10.02019-10-23
CVE-2019-18281 [MEDIUM] CWE-119 CVE-2019-18281: An out-of-bounds memory access in the generateDirectionalRuns() function in qtextengine.cpp in Qt qt An out-of-bounds memory access in the generateDirectionalRuns() function in qtextengine.cpp in Qt qtbase 5.11.x and 5.12.x before 5.12.5 allows attackers to cause a denial of service by crashing an application via a text file containing many directional characters.
nvd
CVE-2013-6422P4MEDIUMCVSS 4.0v7.02013-12-23
CVE-2013-6422 [MEDIUM] CWE-20 CVE-2013-6422: The GnuTLS backend in libcurl 7.21.4 through 7.33.0, when disabling digital signature verification ( The GnuTLS backend in libcurl 7.21.4 through 7.33.0, when disabling digital signature verification (CURLOPT_SSL_VERIFYPEER), also disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it easier for remote attackers to spoof servers and conduct man-in-the-middle (MITM) attacks.
nvd
CVE-2014-9272P4MEDIUMCVSS 4.3v7.02015-01-09
CVE-2014-9272 [MEDIUM] CWE-79 CVE-2014-9272: The string_insert_href function in MantisBT 1.2.0a1 through 1.2.x before 1.2.18 does not properly va The string_insert_href function in MantisBT 1.2.0a1 through 1.2.x before 1.2.18 does not properly validate the URL protocol, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the javascript:// protocol.
nvd
CVE-2018-12367P4MEDIUMCVSS 4.3v8.0v9.02018-10-18
CVE-2018-12367 [MEDIUM] CWE-20 CVE-2018-12367: In the previous mitigations for Spectre, the resolution or precision of various methods was reduced In the previous mitigations for Spectre, the resolution or precision of various methods was reduced to counteract the ability to measure precise time intervals. In that work PerformanceNavigationTiming was not adjusted but it was found that it could be used as a precision timer. This vulnerability affects Thunderbird < 60, Firefox ESR < 60.1, and Fire
nvd
CVE-2019-9495P4LOWCVSS 3.7v8.02019-04-17
CVE-2019-9495 [LOW] CWE-524 CVE-2019-9495: The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks as a result of cache access patterns. All versions of hostapd and wpa_supplicant with EAP-PWD support are vulnerable. The ability to install and execute applications is necessary for a successful attack. Memory access patterns are visible in a shared cache.
nvd
CVE-2012-4430P4MEDIUMCVSS 4.0v6.0v7.02012-10-10
CVE-2012-4430 [MEDIUM] CWE-264 CVE-2012-4430: The dump_resource function in dird/dird_conf.c in Bacula before 5.2.11 does not properly enforce ACL The dump_resource function in dird/dird_conf.c in Bacula before 5.2.11 does not properly enforce ACL rules, which allows remote authenticated users to obtain resource dump information via unspecified vectors.
nvd
CVE-2017-2826P4LOWCVSS 3.7v8.02018-04-09
CVE-2017-2826 [LOW] CWE-200 CVE-2017-2826: An information disclosure vulnerability exists in the iConfig proxy request of Zabbix server 2.4.X. An information disclosure vulnerability exists in the iConfig proxy request of Zabbix server 2.4.X. A specially crafted iConfig proxy request can cause the Zabbix server to send the configuration information of any Zabbix proxy, resulting in information disclosure. An attacker can make requests from an active Zabbix proxy to trigger this vulnerability.
nvd
CVE-2020-14573P4LOWCVSS 3.7v10.02020-07-15
CVE-2020-14573 [LOW] CVE-2020-14573: Vulnerability in the Java SE product of Oracle Java SE (component: Hotspot). Supported versions that Vulnerability in the Java SE product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Java SE: 11.0.7 and 14.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized update, insert
nvd
CVE-2016-0606P4LOWCVSS 3.5v8.02016-01-21
CVE-2016-0606 [LOW] CVE-2016-0606: Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and Mari Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect integrity via unknown vectors related to encryption.
nvd
CVE-2015-4737P4LOWCVSS 3.5v8.02015-07-16
CVE-2015-4737 [LOW] CVE-2015-4737: Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier, and 5.6.23 and earlier, allows Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier, and 5.6.23 and earlier, allows remote authenticated users to affect confidentiality via unknown vectors related to Server : Pluggable Auth.
nvd
CVE-2017-15418P4MEDIUMCVSS 4.3v9.02018-08-28
CVE-2017-15418 [MEDIUM] CWE-119 CVE-2017-15418: Use of uninitialized memory in Skia in Google Chrome prior to 63.0.3239.84 allowed a remote attacker Use of uninitialized memory in Skia in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2015-4913P4LOWCVSS 3.5v7.0v8.02015-10-22
CVE-2015-4913 [LOW] CVE-2015-4913: Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows re Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows remote authenticated users to affect availability via vectors related to Server : DML, a different vulnerability than CVE-2015-4858.
nvd
CVE-2019-15220P4MEDIUMCVSS 4.6v8.02019-08-19
CVE-2019-15220 [MEDIUM] CWE-416 CVE-2019-15220: An issue was discovered in the Linux kernel before 5.2.1. There is a use-after-free caused by a mali An issue was discovered in the Linux kernel before 5.2.1. There is a use-after-free caused by a malicious USB device in the drivers/net/wireless/intersil/p54/p54usb.c driver.
nvd
CVE-2019-15211P4MEDIUMCVSS 4.6v8.02019-08-19
CVE-2019-15211 [MEDIUM] CWE-416 CVE-2019-15211: An issue was discovered in the Linux kernel before 5.2.6. There is a use-after-free caused by a mali An issue was discovered in the Linux kernel before 5.2.6. There is a use-after-free caused by a malicious USB device in the drivers/media/v4l2-core/v4l2-dev.c driver because drivers/media/radio/radio-raremono.c does not properly allocate memory.
nvd
CVE-2019-19524P4MEDIUMCVSS 4.6v8.02019-12-03
CVE-2019-19524 [MEDIUM] CWE-416 CVE-2019-19524: In the Linux kernel before 5.3.12, there is a use-after-free bug that can be caused by a malicious U In the Linux kernel before 5.3.12, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/input/ff-memless.c driver, aka CID-fa3a5a1880c9.
nvd
Debian Linux vulnerabilities | cvebase