Debian Linux vulnerabilities
9,956 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,956
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4169MEDIUM4296LOW358
Vulnerabilities
Page 477 of 498
CVE-2022-23035P4MEDIUMCVSS 4.6v11.02022-01-25
CVE-2022-23035 [MEDIUM] CWE-459 CVE-2022-23035: Insufficient cleanup of passed-through device IRQs The management of IRQs associated with physical d
Insufficient cleanup of passed-through device IRQs The management of IRQs associated with physical devices exposed to x86 HVM guests involves an iterative operation in particular when cleaning up after the guest's use of the device. In the case where an interrupt is not quiescent yet at the time this cleanup gets invoked, the cleanup attempt may be
nvd
CVE-2017-3533P4LOWCVSS 3.7v8.02017-04-24
CVE-2017-3533 [LOW] CVE-2017-3533: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: N
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u141, 7u131 and 8u121; Java SE Embedded: 8u121; JRockit: R28.3.13. Difficult to exploit vulnerability allows unauthenticated attacker with network access via FTP to compromise Java SE, Java SE Embedded
nvd
CVE-2018-6068P4MEDIUMCVSS 4.3v9.02018-11-14
CVE-2018-6068 [MEDIUM] CWE-20 CVE-2018-6068: Object lifecycle issue in Chrome Custom Tab in Google Chrome prior to 65.0.3325.146 allowed a remote
Object lifecycle issue in Chrome Custom Tab in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2013-2869P4MEDIUMCVSS 4.3v7.02013-07-10
CVE-2013-2869 [MEDIUM] CWE-119 CVE-2013-2869: Google Chrome before 28.0.1500.71 allows remote attackers to cause a denial of service (out-of-bound
Google Chrome before 28.0.1500.71 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted JPEG2000 image.
nvd
CVE-2021-25284P4MEDIUMCVSS 4.4v9.0v10.0+1 more2021-02-27
CVE-2021-25284 [MEDIUM] CWE-522 CVE-2021-25284: An issue was discovered in through SaltStack Salt before 3002.5. salt.modules.cmdmod can log credent
An issue was discovered in through SaltStack Salt before 3002.5. salt.modules.cmdmod can log credentials to the info or error log level.
nvd
CVE-2020-14782P4LOWCVSS 3.7v9.0v10.02020-10-21
CVE-2020-14782 [LOW] CVE-2020-14782: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Sup
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful
nvd
CVE-2019-8905P4MEDIUMCVSS 4.4v8.02019-02-18
CVE-2019-8905 [MEDIUM] CVE-2019-8905: do_core_note in readelf.c in libmagic.a in file 5.35 has a stack-based buffer over-read, related to
do_core_note in readelf.c in libmagic.a in file 5.35 has a stack-based buffer over-read, related to file_printable, a different vulnerability than CVE-2018-10360.
nvd
CVE-2020-14797P4LOWCVSS 3.7v9.0v10.02020-10-21
CVE-2020-14797 [LOW] CVE-2020-14797: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Sup
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful
nvd
CVE-2015-8552P4MEDIUMCVSS 4.4v6.02016-04-13
CVE-2015-8552 [MEDIUM] CWE-20 CVE-2015-8552: The PCI backend driver in Xen, when running on an x86 system and using Linux 3.1.x through 4.3.x as
The PCI backend driver in Xen, when running on an x86 system and using Linux 3.1.x through 4.3.x as the driver domain, allows local guest administrators to generate a continuous stream of WARN messages and cause a denial of service (disk consumption) by leveraging a system with access to a passed-through MSI or MSI-X capable physical PCI device and XEN_
nvd
CVE-2012-2736P4MEDIUMCVSS 4.4v8.0v9.0+1 more2019-12-26
CVE-2012-2736 [MEDIUM] CWE-306 CVE-2012-2736: In NetworkManager 0.9.2.0, when a new wireless network was created with WPA/WPA2 security in AdHoc m
In NetworkManager 0.9.2.0, when a new wireless network was created with WPA/WPA2 security in AdHoc mode, it created an open/insecure network.
nvd
CVE-2016-0610P4LOWCVSS 3.5v8.02016-01-21
CVE-2016-0610 [LOW] CVE-2016-0610: Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and MariaDB before 10.0.22 and 10.1.x b
Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and MariaDB before 10.0.22 and 10.1.x before 10.1.9 allows remote authenticated users to affect availability via unknown vectors related to InnoDB.
nvd
CVE-2023-23908P4MEDIUMCVSS 4.4v10.0v11.0+1 more2023-08-11
CVE-2023-23908 [MEDIUM] CWE-284 CVE-2023-23908: Improper access control in some 3rd Generation Intel(R) Xeon(R) Scalable processors may allow a priv
Improper access control in some 3rd Generation Intel(R) Xeon(R) Scalable processors may allow a privileged user to potentially enable information disclosure via local access.
nvd
CVE-2022-35252P4LOWCVSS 3.7v10.02022-09-23
CVE-2022-35252 [LOW] CWE-20 CVE-2022-35252: When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using contr
When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a"sister site" to deny service to all siblings.
nvd
CVE-2017-10268P4MEDIUMCVSS 4.1v8.0v9.02017-10-19
CVE-2017-10268 [MEDIUM] CVE-2017-10268: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Sup
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 5.5.57 and earlier, 5.6.37 and earlier and 5.7.19 and earlier. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Su
nvd
CVE-2020-11810P4LOWCVSS 3.7v8.0v9.0+1 more2020-04-27
CVE-2020-11810 [LOW] CWE-362 CVE-2020-11810: An issue was discovered in OpenVPN 2.4.x before 2.4.9. An attacker can inject a data channel v2 (P_D
An issue was discovered in OpenVPN 2.4.x before 2.4.9. An attacker can inject a data channel v2 (P_DATA_V2) packet using a victim's peer-id. Normally such packets are dropped, but if this packet arrives before the data channel crypto parameters have been initialized, the victim's connection will be dropped. This requires careful timing due to the small
nvd
CVE-2018-16738P4LOWCVSS 3.7v9.02018-10-10
CVE-2018-16738 [LOW] CWE-287 CVE-2018-16738: tinc 1.0.30 through 1.0.34 has a broken authentication protocol, although there is a partial mitigat
tinc 1.0.30 through 1.0.34 has a broken authentication protocol, although there is a partial mitigation. This is fixed in 1.1.
nvd
CVE-2020-25284P4MEDIUMCVSS 4.1v9.02020-09-13
CVE-2020-25284 [MEDIUM] CWE-863 CVE-2020-25284: The rbd block device driver in drivers/block/rbd.c in the Linux kernel through 5.8.9 used incomplete
The rbd block device driver in drivers/block/rbd.c in the Linux kernel through 5.8.9 used incomplete permission checking for access to rbd devices, which could be leveraged by local attackers to map or unmap rbd block devices, aka CID-f44d04e696fe.
nvd
CVE-2021-41136P4LOWCVSS 3.7v10.0v11.02021-10-12
CVE-2021-41136 [LOW] CWE-444 CVE-2021-41136: Puma is a HTTP 1.1 server for Ruby/Rack applications. Prior to versions 5.5.1 and 4.3.9, using `puma
Puma is a HTTP 1.1 server for Ruby/Rack applications. Prior to versions 5.5.1 and 4.3.9, using `puma` with a proxy which forwards HTTP header values which contain the LF character could allow HTTP request smugggling. A client could smuggle a request through a proxy, causing the proxy to send a response back to another unknown client. The only proxy whi
nvd
CVE-2023-52597P4MEDIUMCVSS 4.0v10.02024-03-06
CVE-2023-52597 [MEDIUM] CVE-2023-52597: In the Linux kernel, the following vulnerability has been resolved: KVM: s390: fix setting of fpc r
In the Linux kernel, the following vulnerability has been resolved:
KVM: s390: fix setting of fpc register
kvm_arch_vcpu_ioctl_set_fpu() allows to set the floating point control
(fpc) register of a guest cpu. The new value is tested for validity by
temporarily loading it into the fpc register.
This may lead to corruption of the fpc register of the host pr
nvd
CVE-2020-15103P4LOWCVSS 3.5v10.02020-07-27
CVE-2020-15103 [LOW] CWE-680 CVE-2020-15103: In FreeRDP less than or equal to 2.1.2, an integer overflow exists due to missing input sanitation i
In FreeRDP less than or equal to 2.1.2, an integer overflow exists due to missing input sanitation in rdpegfx channel. All FreeRDP clients are affected. The input rectangles from the server are not checked against local surface coordinates and blindly accepted. A malicious server can send data that will crash the client later on (invalid length argumen
nvd