cbcvebase.

Debian Linux vulnerabilities

9,956 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,956
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4169MEDIUM4296LOW358

Vulnerabilities

Page 471 of 498
CVE-2021-21184P4MEDIUMCVSS 4.3v10.02021-03-09
CVE-2021-21184 [MEDIUM] CWE-346 CVE-2021-21184: Inappropriate implementation in performance APIs in Google Chrome prior to 89.0.4389.72 allowed a re Inappropriate implementation in performance APIs in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2021-21183P4MEDIUMCVSS 4.3v10.02021-03-09
CVE-2021-21183 [MEDIUM] CWE-346 CVE-2021-21183: Inappropriate implementation in performance APIs in Google Chrome prior to 89.0.4389.72 allowed a re Inappropriate implementation in performance APIs in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2020-12863P4MEDIUMCVSS 4.3v9.02020-06-24
CVE-2020-12863 [MEDIUM] CWE-125 CVE-2020-12863: An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the s An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-083.
nvd
CVE-2018-5730P4LOWCVSS 3.8v8.0v9.02018-03-06
CVE-2018-5730 [LOW] CWE-90 CVE-2018-5730: MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Ke MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to circumvent a DN containership check by supplying both a "linkdn" and "containerdn" database argument, or by supplying a DN string which is a left extension of a container DN string but is not hierarchically within the container DN.
nvd
CVE-2019-5833P4MEDIUMCVSS 4.3v10.02019-06-27
CVE-2019-5833 [MEDIUM] CVE-2019-5833: Incorrect dialog box scoping in browser in Google Chrome on Android prior to 75.0.3770.80 allowed a Incorrect dialog box scoping in browser in Google Chrome on Android prior to 75.0.3770.80 allowed a remote attacker to display misleading security UI via a crafted HTML page.
nvd
CVE-2015-3231P4MEDIUMCVSS 4.0v7.0v8.02015-06-22
CVE-2015-3231 [MEDIUM] CWE-200 CVE-2015-3231: The Render cache system in Drupal 7.x before 7.38, when used to cache content by user role, allows r The Render cache system in Drupal 7.x before 7.38, when used to cache content by user role, allows remote authenticated users to obtain private content viewed by user 1 by reading the cache.
nvd
CVE-2020-12399P4MEDIUMCVSS 4.4v9.02020-07-09
CVE-2020-12399 [MEDIUM] CWE-203 CVE-2020-12399: NSS has shown timing differences when performing DSA signatures, which was exploitable and could eve NSS has shown timing differences when performing DSA signatures, which was exploitable and could eventually leak private keys. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.
nvd
CVE-2019-19318P4MEDIUMCVSS 4.4v9.02019-11-28
CVE-2019-19318 [MEDIUM] CWE-416 CVE-2019-19318: In the Linux kernel 5.3.11, mounting a crafted btrfs image twice can cause an rwsem_down_write_slowp In the Linux kernel 5.3.11, mounting a crafted btrfs image twice can cause an rwsem_down_write_slowpath use-after-free because (in rwsem_can_spin_on_owner in kernel/locking/rwsem.c) rwsem_owner_flags returns an already freed pointer,
nvd
CVE-2022-2787P4MEDIUMCVSS 4.3v10.0v11.02022-08-27
CVE-2022-2787 [MEDIUM] CWE-281 CVE-2022-2787: Schroot before 1.6.13 had too permissive rules on chroot or session names, allowing a denial of serv Schroot before 1.6.13 had too permissive rules on chroot or session names, allowing a denial of service on the schroot service for all users that may start a schroot session.
nvd
CVE-2021-38004P4MEDIUMCVSS 4.3v10.0v11.02021-11-23
CVE-2021-38004 [MEDIUM] CWE-668 CVE-2021-38004: Insufficient policy enforcement in Autofill in Google Chrome prior to 95.0.4638.69 allowed a remote Insufficient policy enforcement in Autofill in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2013-4134P4MEDIUMCVSS 4.3v7.02013-11-05
CVE-2013-4134 [MEDIUM] CWE-310 CVE-2013-4134: OpenAFS before 1.4.15, 1.6.x before 1.6.5, and 1.7.x before 1.7.26 uses weak encryption (DES) for Ke OpenAFS before 1.4.15, 1.6.x before 1.6.5, and 1.7.x before 1.7.26 uses weak encryption (DES) for Kerberos keys, which makes it easier for remote attackers to obtain the service key.
nvd
CVE-2022-46877P4MEDIUMCVSS 4.3v10.0v11.02022-12-22
CVE-2022-46877 [MEDIUM] CWE-79 CVE-2022-46877: By confusing the browser, the fullscreen notification could have been delayed or suppressed, resulti By confusing the browser, the fullscreen notification could have been delayed or suppressed, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox < 108.
nvd
CVE-2023-50762P4MEDIUMCVSS 4.3v11.0v12.02023-12-19
CVE-2023-50762 [MEDIUM] CVE-2023-50762: When processing a PGP/MIME payload that contains digitally signed text, the first paragraph of the t When processing a PGP/MIME payload that contains digitally signed text, the first paragraph of the text was never shown to the user. This is because the text was interpreted as a MIME message and the first paragraph was always treated as an email header section. A digitally signed text from a different context, such as a signed GIT commit, could be used to
nvd
CVE-2023-50761P4MEDIUMCVSS 4.3v11.0v12.02023-12-19
CVE-2023-50761 [MEDIUM] CVE-2023-50761: The signature of a digitally signed S/MIME email message may optionally specify the signature creati The signature of a digitally signed S/MIME email message may optionally specify the signature creation date and time. If present, Thunderbird did not compare the signature creation date with the message date and time, and displayed a valid signature despite a date or time mismatch. This could be used to give recipients the impression that a message was sent
nvd
CVE-2020-12402P4MEDIUMCVSS 4.4v9.02020-07-09
CVE-2020-12402 [MEDIUM] CWE-203 CVE-2020-12402: During RSA key generation, bignum implementations used a variation of the Binary Extended Euclidean During RSA key generation, bignum implementations used a variation of the Binary Extended Euclidean Algorithm which entailed significantly input-dependent flow. This allowed an attacker able to perform electromagnetic-based side channel attacks to record traces leading to the recovery of the secret primes. *Note:* An unmodified Firefox browser does n
nvd
CVE-2009-1962P4MEDIUMCVSS 4.4v4.0v5.02009-06-08
CVE-2009-1962 [MEDIUM] CWE-59 CVE-2009-1962: Xfig, possibly 3.2.5, allows local users to read and write arbitrary files via a symlink attack on t Xfig, possibly 3.2.5, allows local users to read and write arbitrary files via a symlink attack on the (1) xfig-eps[PID], (2) xfig-pic[PID].pix, (3) xfig-pic[PID].err, (4) xfig-pcx[PID].pix, (5) xfig-xfigrc[PID], (6) xfig[PID], (7) xfig-print[PID], (8) xfig-export[PID].err, (9) xfig-batch[PID], (10) xfig-exp[PID], or (11) xfig-spell.[PID] temporary fil
nvd
CVE-2014-2398P4LOWCVSS 3.5v6.0v7.0+1 more2014-04-16
CVE-2014-2398 [LOW] CVE-2014-2398: Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JavaFX 2.2.51; and JRockit R2 Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JavaFX 2.2.51; and JRockit R27.8.1 and R28.3.1 allows remote authenticated users to affect integrity via unknown vectors related to Javadoc.
nvd
CVE-2019-9445P4MEDIUMCVSS 4.4v9.02019-09-06
CVE-2019-9445 [MEDIUM] CWE-125 CVE-2019-9445: In the Android kernel in F2FS driver there is a possible out of bounds read due to a missing bounds In the Android kernel in F2FS driver there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with system execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2021-4159P4MEDIUMCVSS 4.4v10.02022-08-24
CVE-2021-4159 [MEDIUM] CWE-202 CVE-2021-4159: A vulnerability was found in the Linux kernel's EBPF verifier when handling internal data structures A vulnerability was found in the Linux kernel's EBPF verifier when handling internal data structures. Internal memory locations could be returned to userspace. A local attacker with the permissions to insert eBPF code to the kernel can use this to leak internal kernel memory details defeating some of the exploit mitigations in place for the kernel.
nvd
CVE-2021-43980P4LOWCVSS 3.7v10.0v11.02022-09-28
CVE-2021-43980 [LOW] CWE-362 CVE-2021-43980: The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back-ported t The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back-ported to Tomcat 9.0.47 onwards exposed a long standing (but extremely hard to trigger) concurrency bug in Apache Tomcat 10.1.0 to 10.1.0-M12, 10.0.0-M1 to 10.0.18, 9.0.0-M1 to 9.0.60 and 8.5.0 to 8.5.77 that could cause client connections to share an Http11Proc
nvd
Debian Linux vulnerabilities | cvebase