Debian Linux vulnerabilities
9,956 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,956
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4169MEDIUM4296LOW358
Vulnerabilities
Page 475 of 498
CVE-2020-2773P4LOWCVSS 3.7v8.0v9.0+1 more2020-04-15
CVE-2020-2773 [LOW] CVE-2020-2773: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Security). Supp
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Security). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful at
nvd
CVE-2011-2694P4LOWCVSS 2.6v5.0v6.0+1 more2011-07-29
CVE-2011-2694 [LOW] CWE-79 CVE-2011-2694: Cross-site scripting (XSS) vulnerability in the chg_passwd function in web/swat.c in the Samba Web A
Cross-site scripting (XSS) vulnerability in the chg_passwd function in web/swat.c in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allows remote authenticated administrators to inject arbitrary web script or HTML via the username parameter to the passwd program (aka the user field to the Change Password page).
nvd
CVE-2014-8867P4MEDIUMCVSS 4.9v7.02014-12-01
CVE-2014-8867 [MEDIUM] CWE-17 CVE-2014-8867: The acceleration support for the "REP MOVS" instruction in Xen 4.4.x, 3.2.x, and earlier lacks prope
The acceleration support for the "REP MOVS" instruction in Xen 4.4.x, 3.2.x, and earlier lacks properly bounds checking for memory mapped I/O (MMIO) emulated in the hypervisor, which allows local HVM guests to cause a denial of service (host crash) via unspecified vectors.
nvd
CVE-2015-2756P4MEDIUMCVSS 4.9v7.0v8.02015-04-01
CVE-2015-2756 [MEDIUM] CWE-264 CVE-2015-2756: QEMU, as used in Xen 3.3.x through 4.5.x, does not properly restrict access to PCI command registers
QEMU, as used in Xen 3.3.x through 4.5.x, does not properly restrict access to PCI command registers, which might allow local HVM guest users to cause a denial of service (non-maskable interrupt and host crash) by disabling the (1) memory or (2) I/O decoding for a PCI Express device and then accessing the device, which triggers an Unsupported Request
nvd
CVE-2014-9718P4MEDIUMCVSS 4.9v8.02015-04-21
CVE-2014-9718 [MEDIUM] CWE-399 CVE-2014-9718: The (1) BMDMA and (2) AHCI HBA interfaces in the IDE functionality in QEMU 1.0 through 2.1.3 have mu
The (1) BMDMA and (2) AHCI HBA interfaces in the IDE functionality in QEMU 1.0 through 2.1.3 have multiple interpretations of a function's return value, which allows guest OS users to cause a host OS denial of service (memory consumption or infinite loop, and system crash) via a PRDT with zero complete sectors, related to the bmdma_prepare_buf and ahc
nvd
CVE-2011-0482P4MEDIUMCVSS 4.3v6.0v7.02011-01-14
CVE-2011-0482 [MEDIUM] CWE-704 CVE-2011-0482: Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly perform a cast of
Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly perform a cast of an unspecified variable during handling of anchors, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted HTML document.
nvd
CVE-2012-3954P4LOWCVSS 3.3v6.0v7.02012-07-25
CVE-2012-3954 [LOW] CWE-399 CVE-2012-3954: Multiple memory leaks in ISC DHCP 4.1.x and 4.2.x before 4.2.4-P1 and 4.1-ESV before 4.1-ESV-R6 allo
Multiple memory leaks in ISC DHCP 4.1.x and 4.2.x before 4.2.4-P1 and 4.1-ESV before 4.1-ESV-R6 allow remote attackers to cause a denial of service (memory consumption) by sending many requests.
nvd
CVE-2019-2894P4LOWCVSS 3.7v8.0v9.02019-10-16
CVE-2019-2894 [LOW] CVE-2019-2894: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Security). Supp
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Security). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful at
nvd
CVE-2000-0112P4HIGHCVSS 7.2v2.0v2.1+1 more2000-02-02
CVE-2000-0112 [HIGH] CVE-2000-0112: The default installation of Debian GNU/Linux uses an insecure Master Boot Record (MBR) which allows
The default installation of Debian GNU/Linux uses an insecure Master Boot Record (MBR) which allows a local user to boot from a floppy disk during the installation.
nvd
CVE-2019-19062P4MEDIUMCVSS 4.7v8.02019-11-18
CVE-2019-19062 [MEDIUM] CWE-401 CVE-2019-19062: A memory leak in the crypto_report() function in crypto/crypto_user_base.c in the Linux kernel throu
A memory leak in the crypto_report() function in crypto/crypto_user_base.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering crypto_report_alg() failures, aka CID-ffdde5932042.
nvd
CVE-2014-4721P4LOWCVSS 2.6v7.0v8.02014-07-06
CVE-2014-4721 [LOW] CWE-200 CVE-2014-4721: The phpinfo implementation in ext/standard/info.c in PHP before 5.4.30 and 5.5.x before 5.5.14 does
The phpinfo implementation in ext/standard/info.c in PHP before 5.4.30 and 5.5.x before 5.5.14 does not ensure use of the string data type for the PHP_AUTH_PW, PHP_AUTH_TYPE, PHP_AUTH_USER, and PHP_SELF variables, which might allow context-dependent attackers to obtain sensitive information from process memory by using the integer data type with crafted v
nvd
CVE-2015-4861P4LOWCVSS 3.5v7.0v8.02015-10-21
CVE-2015-4861 [LOW] CVE-2015-4861: Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : InnoDB.
nvd
CVE-2019-15212P4MEDIUMCVSS 4.6v8.02019-08-19
CVE-2019-15212 [MEDIUM] CWE-415 CVE-2019-15212: An issue was discovered in the Linux kernel before 5.1.8. There is a double-free caused by a malicio
An issue was discovered in the Linux kernel before 5.1.8. There is a double-free caused by a malicious USB device in the drivers/usb/misc/rio500.c driver.
nvd
CVE-2019-20919P4MEDIUMCVSS 4.7v9.02020-09-17
CVE-2019-20919 [MEDIUM] CWE-476 CVE-2019-20919: An issue was discovered in the DBI module before 1.643 for Perl. The hv_fetch() documentation requir
An issue was discovered in the DBI module before 1.643 for Perl. The hv_fetch() documentation requires checking for NULL and the code does that. But, shortly thereafter, it calls SvOK(profile), causing a NULL pointer dereference.
nvd
CVE-2019-15221P4MEDIUMCVSS 4.6v8.02019-08-19
CVE-2019-15221 [MEDIUM] CWE-476 CVE-2019-15221: An issue was discovered in the Linux kernel before 5.1.17. There is a NULL pointer dereference cause
An issue was discovered in the Linux kernel before 5.1.17. There is a NULL pointer dereference caused by a malicious USB device in the sound/usb/line6/pcm.c driver.
nvd
CVE-2019-15216P4MEDIUMCVSS 4.6v8.02019-08-19
CVE-2019-15216 [MEDIUM] CWE-476 CVE-2019-15216: An issue was discovered in the Linux kernel before 5.0.14. There is a NULL pointer dereference cause
An issue was discovered in the Linux kernel before 5.0.14. There is a NULL pointer dereference caused by a malicious USB device in the drivers/usb/misc/yurex.c driver.
nvd
CVE-2015-4167P4MEDIUMCVSS 4.7v7.02015-08-05
CVE-2015-4167 [MEDIUM] CWE-189 CVE-2015-4167: The udf_read_inode function in fs/udf/inode.c in the Linux kernel before 3.19.1 does not validate ce
The udf_read_inode function in fs/udf/inode.c in the Linux kernel before 3.19.1 does not validate certain length values, which allows local users to cause a denial of service (incorrect data representation or integer overflow, and OOPS) via a crafted UDF filesystem.
nvd
CVE-2025-38561P4MEDIUMCVSS 4.7v11.02025-08-19
CVE-2025-38561 [MEDIUM] CWE-362 CVE-2025-38561: In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix Preauh_HashValue rac
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix Preauh_HashValue race condition
If client send multiple session setup requests to ksmbd,
Preauh_HashValue race condition could happen.
There is no need to free sess->Preauh_HashValue at session setup phase.
It can be freed together with session at connection termination
nvd
CVE-2021-43976P4MEDIUMCVSS 4.6v9.0v10.0+1 more2021-11-17
CVE-2021-43976 [MEDIUM] CVE-2021-43976: In the Linux kernel through 5.15.2, mwifiex_usb_recv in drivers/net/wireless/marvell/mwifiex/usb.c a
In the Linux kernel through 5.15.2, mwifiex_usb_recv in drivers/net/wireless/marvell/mwifiex/usb.c allows an attacker (who can connect a crafted USB device) to cause a denial of service (skb_over_panic).
nvd
CVE-2018-3136P4LOWCVSS 3.4v8.0v9.02018-10-17
CVE-2018-3136 [LOW] CVE-2018-3136: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security).
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u201, 7u191, 8u182 and 11; Java SE Embedded: 8u181. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successfu
nvd