Debian Linux vulnerabilities
9,956 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,956
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4169MEDIUM4296LOW358
Vulnerabilities
Page 469 of 498
CVE-2016-0600P4LOWCVSS 3.5v8.02016-01-21
CVE-2016-0600 [LOW] CVE-2016-0600: Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and Mari
Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via unknown vectors related to InnoDB.
nvd
CVE-2019-19966P4MEDIUMCVSS 4.6v8.02019-12-25
CVE-2019-19966 [MEDIUM] CWE-416 CVE-2019-19966: In the Linux kernel before 5.1.6, there is a use-after-free in cpia2_exit() in drivers/media/usb/cpi
In the Linux kernel before 5.1.6, there is a use-after-free in cpia2_exit() in drivers/media/usb/cpia2/cpia2_v4l.c that will cause denial of service, aka CID-dea37a972655.
nvd
CVE-2017-13721P4MEDIUMCVSS 4.7v8.0v9.02017-10-10
CVE-2017-13721 [MEDIUM] CWE-269 CVE-2017-13721: In X.Org Server (aka xserver and xorg-server) before 1.19.4, an attacker authenticated to an X serve
In X.Org Server (aka xserver and xorg-server) before 1.19.4, an attacker authenticated to an X server with the X shared memory extension enabled can cause aborts of the X server or replace shared memory segments of other X clients in the same session.
nvd
CVE-2010-4493P4MEDIUMCVSS 4.3v6.0v7.02010-12-07
CVE-2010-4493 [MEDIUM] CWE-416 CVE-2010-4493: Use-after-free vulnerability in Google Chrome before 8.0.552.215 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 8.0.552.215 allows remote attackers to cause a denial of service via vectors related to the handling of mouse dragging events.
nvd
CVE-2018-6052P4MEDIUMCVSS 4.3v8.0v9.02018-09-25
CVE-2018-6052 [MEDIUM] CWE-200 CVE-2018-6052: Lack of support for a non standard no-referrer policy value in Blink in Google Chrome prior to 64.0.
Lack of support for a non standard no-referrer policy value in Blink in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to obtain referrer details from a web page that had thought it had opted out of sending referrer data.
nvd
CVE-2017-5046P4MEDIUMCVSS 4.3v8.0v9.02017-04-24
CVE-2017-5046 [MEDIUM] CVE-2017-5046: V8 in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android
V8 in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android had insufficient policy enforcement, which allowed a remote attacker to spoof the location object via a crafted HTML page, related to Blink information disclosure.
nvd
CVE-2012-0049P4MEDIUMCVSS 4.3v6.0v8.0+2 more2019-11-07
CVE-2012-0049 [MEDIUM] CWE-400 CVE-2012-0049: OpenTTD before 1.1.5 contains a Denial of Service (slow read attack) that prevents users from joinin
OpenTTD before 1.1.5 contains a Denial of Service (slow read attack) that prevents users from joining the server.
nvd
CVE-2016-1626P4MEDIUMCVSS 4.3v8.02016-02-14
CVE-2016-1626 [MEDIUM] CWE-119 CVE-2016-1626: The opj_pi_update_decode_poc function in pi.c in OpenJPEG, as used in PDFium in Google Chrome before
The opj_pi_update_decode_poc function in pi.c in OpenJPEG, as used in PDFium in Google Chrome before 48.0.2564.109, miscalculates a certain layer index value, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PDF document.
nvd
CVE-2022-33744P4MEDIUMCVSS 4.7v10.0v11.02022-07-05
CVE-2022-33744 [MEDIUM] CVE-2022-33744: Arm guests can cause Dom0 DoS via PV devices When mapping pages of guests on Arm, dom0 is using an r
Arm guests can cause Dom0 DoS via PV devices When mapping pages of guests on Arm, dom0 is using an rbtree to keep track of the foreign mappings. Updating of that rbtree is not always done completely with the related lock held, resulting in a small race window, which can be used by unprivileged guests via PV devices to cause inconsistencies of the rbtree. Th
nvd
CVE-2022-3303P4MEDIUMCVSS 4.7v10.0v11.02022-09-27
CVE-2022-3303 [MEDIUM] CWE-667 CVE-2022-3303: A race condition flaw was found in the Linux kernel sound subsystem due to improper locking. It coul
A race condition flaw was found in the Linux kernel sound subsystem due to improper locking. It could lead to a NULL pointer dereference while handling the SNDCTL_DSP_SYNC ioctl. A privileged local user (root or member of the audio group) could use this flaw to crash the system, resulting in a denial of service condition
nvd
CVE-2025-39673P4MEDIUMCVSS 4.7v11.02025-09-05
CVE-2025-39673 [MEDIUM] CWE-362 CVE-2025-39673: In the Linux kernel, the following vulnerability has been resolved: ppp: fix race conditions in ppp
In the Linux kernel, the following vulnerability has been resolved:
ppp: fix race conditions in ppp_fill_forward_path
ppp_fill_forward_path() has two race conditions:
1. The ppp->channels list can change between list_empty() and
list_first_entry(), as ppp_lock() is not held. If the only channel
is deleted in ppp_disconnect_channel(), list_first_en
nvd
CVE-2014-3611P4MEDIUMCVSS 4.7v7.02014-11-10
CVE-2014-3611 [MEDIUM] CWE-362 CVE-2014-3611: Race condition in the __kvm_migrate_pit_timer function in arch/x86/kvm/i8254.c in the KVM subsystem
Race condition in the __kvm_migrate_pit_timer function in arch/x86/kvm/i8254.c in the KVM subsystem in the Linux kernel through 3.17.2 allows guest OS users to cause a denial of service (host OS crash) by leveraging incorrect PIT emulation.
nvd
CVE-2018-6051P4MEDIUMCVSS 4.3v8.0v9.02018-09-25
CVE-2018-6051 [MEDIUM] CWE-79 CVE-2018-6051: XSS Auditor in Google Chrome prior to 64.0.3282.119, did not ensure the reporting URL was in the sam
XSS Auditor in Google Chrome prior to 64.0.3282.119, did not ensure the reporting URL was in the same origin as the page it was on, which allowed a remote attacker to obtain referrer details via a crafted HTML page.
nvd
CVE-2018-6048P4MEDIUMCVSS 4.3v8.0v9.02018-09-25
CVE-2018-6048 [MEDIUM] CWE-20 CVE-2018-6048: Insufficient policy enforcement in Blink in Google Chrome prior to 64.0.3282.119 allowed a remote at
Insufficient policy enforcement in Blink in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak referrer information via a crafted HTML page.
nvd
CVE-2025-38365P4MEDIUMCVSS 4.7v11.02025-07-25
CVE-2025-38365 [MEDIUM] CWE-362 CVE-2025-38365: In the Linux kernel, the following vulnerability has been resolved: btrfs: fix a race between renam
In the Linux kernel, the following vulnerability has been resolved:
btrfs: fix a race between renames and directory logging
We have a race between a rename and directory inode logging that if it
happens and we crash/power fail before the rename completes, the next time
the filesystem is mounted, the log replay code will end up deleting the
file tha
nvd
CVE-2023-42756P4MEDIUMCVSS 4.7v10.02023-09-28
CVE-2023-42756 [MEDIUM] CWE-362 CVE-2023-42756: A flaw was found in the Netfilter subsystem of the Linux kernel. A race condition between IPSET_CMD_
A flaw was found in the Netfilter subsystem of the Linux kernel. A race condition between IPSET_CMD_ADD and IPSET_CMD_SWAP can lead to a kernel panic due to the invocation of `__ip_set_put` on a wrong `set`. This issue may allow a local user to crash the system.
nvd
CVE-2021-28964P4MEDIUMCVSS 4.7v9.02021-03-22
CVE-2021-28964 [MEDIUM] CWE-362 CVE-2021-28964: A race condition was discovered in get_old_root in fs/btrfs/ctree.c in the Linux kernel through 5.11
A race condition was discovered in get_old_root in fs/btrfs/ctree.c in the Linux kernel through 5.11.8. It allows attackers to cause a denial of service (BUG) because of a lack of locking on an extent buffer before a cloning operation, aka CID-dbcc7d57bffc.
nvd
CVE-2019-19947P4MEDIUMCVSS 4.6v8.02019-12-24
CVE-2019-19947 [MEDIUM] CWE-908 CVE-2019-19947: In the Linux kernel through 5.4.6, there are information leaks of uninitialized memory to a USB devi
In the Linux kernel through 5.4.6, there are information leaks of uninitialized memory to a USB device in the drivers/net/can/usb/kvaser_usb/kvaser_usb_leaf.c driver, aka CID-da2311a6385c.
nvd
CVE-2017-8924P4MEDIUMCVSS 4.6v8.0v9.02017-05-12
CVE-2017-8924 [MEDIUM] CWE-191 CVE-2017-8924: The edge_bulk_in_callback function in drivers/usb/serial/io_ti.c in the Linux kernel before 4.10.4 a
The edge_bulk_in_callback function in drivers/usb/serial/io_ti.c in the Linux kernel before 4.10.4 allows local users to obtain sensitive information (in the dmesg ringbuffer and syslog) from uninitialized kernel memory by using a crafted USB device (posing as an io_ti USB serial device) to trigger an integer underflow.
nvd
CVE-2022-39188P4MEDIUMCVSS 4.7v10.0v11.02022-09-02
CVE-2022-39188 [MEDIUM] CWE-362 CVE-2022-39188: An issue was discovered in include/asm-generic/tlb.h in the Linux kernel before 5.19. Because of a r
An issue was discovered in include/asm-generic/tlb.h in the Linux kernel before 5.19. Because of a race condition (unmap_mapping_range versus munmap), a device driver can free a page while it still has stale TLB entries. This only occurs in situations with VM_PFNMAP VMAs.
nvd