Debian Linux vulnerabilities
9,955 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,955
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4168MEDIUM4296LOW358
Vulnerabilities
Page 460 of 498
CVE-2015-1287P4MEDIUMCVSS 4.3v8.02015-07-23
CVE-2015-1287 [MEDIUM] CWE-17 CVE-2015-1287: Blink, as used in Google Chrome before 44.0.2403.89, enables a quirks-mode exception that limits the
Blink, as used in Google Chrome before 44.0.2403.89, enables a quirks-mode exception that limits the cases in which a Cascading Style Sheets (CSS) document is required to have the text/css content type, which allows remote attackers to bypass the Same Origin Policy via a crafted web site, related to core/fetch/CSSStyleSheetResource.cpp.
nvd
CVE-2015-3334P4MEDIUMCVSS 4.3v7.0v8.02015-04-19
CVE-2015-3334 [MEDIUM] CWE-17 CVE-2015-3334: browser/ui/website_settings/website_settings.cc in Google Chrome before 42.0.2311.90 does not always
browser/ui/website_settings/website_settings.cc in Google Chrome before 42.0.2311.90 does not always display "Media: Allowed by you" in a Permissions table after the user has granted camera permission to a web site, which might make it easier for user-assisted remote attackers to obtain sensitive video data from a device's physical environment via a cr
nvd
CVE-2018-17467P4MEDIUMCVSS 4.3v9.02018-11-14
CVE-2018-17467 [MEDIUM] CWE-459 CVE-2018-17467: Insufficiently quick clearing of stale rendered content in Navigation in Google Chrome prior to 70.0
Insufficiently quick clearing of stale rendered content in Navigation in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2021-43546P4MEDIUMCVSS 4.3v9.0v10.0+1 more2021-12-08
CVE-2021-43546 [MEDIUM] CWE-1021 CVE-2021-43546: It was possible to recreate previous cursor spoofing attacks against users with a zoomed native curs
It was possible to recreate previous cursor spoofing attacks against users with a zoomed native cursor. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
nvd
CVE-2018-17471P4MEDIUMCVSS 4.3v9.02018-11-14
CVE-2018-17471 [MEDIUM] CVE-2018-17471: Incorrect dialog placement in WebContents in Google Chrome prior to 70.0.3538.67 allowed a remote at
Incorrect dialog placement in WebContents in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to obscure the full screen warning via a crafted HTML page.
nvd
CVE-2015-7810P4MEDIUMCVSS 4.7v8.0v9.0+1 more2019-11-22
CVE-2015-7810 [MEDIUM] CWE-367 CVE-2015-7810: libbluray MountManager class has a time-of-check time-of-use (TOCTOU) race when expanding JAR files
libbluray MountManager class has a time-of-check time-of-use (TOCTOU) race when expanding JAR files
nvd
CVE-2018-17476P4MEDIUMCVSS 4.3v9.02018-11-14
CVE-2018-17476 [MEDIUM] CVE-2018-17476: Incorrect dialog placement in Cast UI in Google Chrome prior to 70.0.3538.67 allowed a remote attack
Incorrect dialog placement in Cast UI in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to obscure the full screen warning via a crafted HTML page.
nvd
CVE-2019-18222P4MEDIUMCVSS 4.7v10.02020-01-23
CVE-2019-18222 [MEDIUM] CWE-203 CVE-2019-18222: The ECDSA signature implementation in ecdsa.c in Arm Mbed Crypto 2.1 and Mbed TLS through 2.19.1 doe
The ECDSA signature implementation in ecdsa.c in Arm Mbed Crypto 2.1 and Mbed TLS through 2.19.1 does not reduce the blinded scalar before computing the inverse, which allows a local attacker to recover the private key via side-channel attacks.
nvd
CVE-2018-17464P4MEDIUMCVSS 4.3v9.02018-11-14
CVE-2018-17464 [MEDIUM] CVE-2018-17464: Incorrect handling of history on iOS in Navigation in Google Chrome prior to 70.0.3538.67 allowed a
Incorrect handling of history on iOS in Navigation in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2013-4235P4MEDIUMCVSS 4.7v8.0v9.0+1 more2019-12-03
CVE-2013-4235 [MEDIUM] CWE-367 CVE-2013-4235: shadow: TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees
shadow: TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees
nvd
CVE-2018-7995P4MEDIUMCVSS 4.7v7.02018-03-09
CVE-2018-7995 [MEDIUM] CWE-362 CVE-2018-7995: Race condition in the store_int_with_restart() function in arch/x86/kernel/cpu/mcheck/mce.c in the L
Race condition in the store_int_with_restart() function in arch/x86/kernel/cpu/mcheck/mce.c in the Linux kernel through 4.15.7 allows local users to cause a denial of service (panic) by leveraging root access to write to the check_interval file in a /sys/devices/system/machinecheck/machinecheck directory. NOTE: a third party has indicated that this re
nvd
CVE-2023-52489P4MEDIUMCVSS 4.7v10.02024-03-11
CVE-2023-52489 [MEDIUM] CWE-362 CVE-2023-52489: In the Linux kernel, the following vulnerability has been resolved: mm/sparsemem: fix race in acces
In the Linux kernel, the following vulnerability has been resolved:
mm/sparsemem: fix race in accessing memory_section->usage
The below race is observed on a PFN which falls into the device memory
region with the system memory configuration where PFN's are such that
[ZONE_NORMAL ZONE_DEVICE ZONE_NORMAL]. Since normal zone start and end
pfn contains
nvd
CVE-2020-6438P4MEDIUMCVSS 4.3v9.0v10.02020-04-13
CVE-2020-6438 [MEDIUM] CWE-209 CVE-2020-6438: Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed an atta
Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory via a crafted Chrome Extension.
nvd
CVE-2017-2616P4MEDIUMCVSS 4.7v8.02018-07-27
CVE-2017-2616 [MEDIUM] CWE-267 CVE-2017-2616: A race condition was found in util-linux before 2.32.1 in the way su handled the management of child
A race condition was found in util-linux before 2.32.1 in the way su handled the management of child processes. A local authenticated attacker could use this flaw to kill other processes with root privileges under specific conditions.
nvd
CVE-2020-27675P4MEDIUMCVSS 4.7v9.02020-10-22
CVE-2020-27675 [MEDIUM] CWE-362 CVE-2020-27675: An issue was discovered in the Linux kernel through 5.9.1, as used with Xen through 4.14.x. drivers/
An issue was discovered in the Linux kernel through 5.9.1, as used with Xen through 4.14.x. drivers/xen/events/events_base.c allows event-channel removal during the event-handling loop (a race condition). This can cause a use-after-free or NULL pointer dereference, as demonstrated by a dom0 crash via events for an in-reconfiguration paravirtualized
nvd
CVE-2016-6130P4MEDIUMCVSS 4.7v8.02016-07-03
CVE-2016-6130 [MEDIUM] CWE-362 CVE-2016-6130: Race condition in the sclp_ctl_ioctl_sccb function in drivers/s390/char/sclp_ctl.c in the Linux kern
Race condition in the sclp_ctl_ioctl_sccb function in drivers/s390/char/sclp_ctl.c in the Linux kernel before 4.6 allows local users to obtain sensitive information from kernel memory by changing a certain length value, aka a "double fetch" vulnerability.
nvd
CVE-2017-5109P4MEDIUMCVSS 4.3v9.02017-10-27
CVE-2017-5109 [MEDIUM] CWE-20 CVE-2017-5109: Inappropriate implementation of unload handler handling in permission prompts in Google Chrome prior
Inappropriate implementation of unload handler handling in permission prompts in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed a remote attacker to display UI on a non attacker controlled tab via a crafted HTML page.
nvd
CVE-2020-1735P4MEDIUMCVSS 4.6v10.02020-03-16
CVE-2020-1735 [MEDIUM] CWE-22 CVE-2020-1735: A flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept th
A flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept the module, inject a new path, and then choose a new destination path on the controller node. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.
nvd
CVE-2020-15959P4MEDIUMCVSS 4.3v10.02020-09-21
CVE-2020-15959 [MEDIUM] CVE-2020-15959: Insufficient policy enforcement in networking in Google Chrome prior to 85.0.4183.102 allowed an att
Insufficient policy enforcement in networking in Google Chrome prior to 85.0.4183.102 allowed an attacker who convinced the user to enable logging to obtain potentially sensitive information from process memory via social engineering.
nvd
CVE-2018-6042P4MEDIUMCVSS 4.3v8.0v9.02018-09-25
CVE-2018-6042 [MEDIUM] CWE-20 CVE-2018-6042: Incorrect security UI in Omnibox in Google Chrome prior to 64.0.3282.119 allowed a remote attacker t
Incorrect security UI in Omnibox in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd