cbcvebase.

Debian Linux vulnerabilities

9,956 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,956
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4169MEDIUM4296LOW358

Vulnerabilities

Page 480 of 498
CVE-2011-2800P4MEDIUMCVSS 4.3v6.0v7.02011-08-03
CVE-2011-2800 [MEDIUM] CWE-200 CVE-2011-2800: Google Chrome before 13.0.782.107 allows remote attackers to obtain potentially sensitive informatio Google Chrome before 13.0.782.107 allows remote attackers to obtain potentially sensitive information about client-side redirect targets via a crafted web site.
nvd
CVE-2018-19489P4MEDIUMCVSS 4.7v8.0v9.02018-12-13
CVE-2018-19489 [MEDIUM] CWE-362 CVE-2018-19489: v9fs_wstat in hw/9pfs/9p.c in QEMU allows guest OS users to cause a denial of service (crash) becaus v9fs_wstat in hw/9pfs/9p.c in QEMU allows guest OS users to cause a denial of service (crash) because of a race condition during file renaming.
nvd
CVE-2010-3442P4MEDIUMCVSS 4.7v5.02010-10-04
CVE-2010-3442 [MEDIUM] CWE-190 CVE-2010-3442: Multiple integer overflows in the snd_ctl_new function in sound/core/control.c in the Linux kernel b Multiple integer overflows in the snd_ctl_new function in sound/core/control.c in the Linux kernel before 2.6.36-rc5-next-20100929 allow local users to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted (1) SNDRV_CTL_IOCTL_ELEM_ADD or (2) SNDRV_CTL_IOCTL_ELEM_REPLACE ioctl call.
nvd
CVE-2025-38393P4MEDIUMCVSS 4.7v11.02025-07-25
CVE-2025-38393 [MEDIUM] CWE-362 CVE-2025-38393: In the Linux kernel, the following vulnerability has been resolved: NFSv4/pNFS: Fix a race to wake In the Linux kernel, the following vulnerability has been resolved: NFSv4/pNFS: Fix a race to wake on NFS_LAYOUT_DRAIN We found a few different systems hung up in writeback waiting on the same page lock, and one task waiting on the NFS_LAYOUT_DRAIN bit in pnfs_update_layout(), however the pnfs_layout_hdr's plh_outstanding count was zero. It seems m
nvd
CVE-2020-25604P4MEDIUMCVSS 4.7v10.02020-09-23
CVE-2020-25604 [MEDIUM] CWE-362 CVE-2020-25604: An issue was discovered in Xen through 4.14.x. There is a race condition when migrating timers betwe An issue was discovered in Xen through 4.14.x. There is a race condition when migrating timers between x86 HVM vCPUs. When migrating timers of x86 HVM guests between its vCPUs, the locking model used allows for a second vCPU of the same guest (also operating on the timers) to release a lock that it didn't acquire. The most likely effect of the issue
nvd
CVE-2015-5707P4MEDIUMCVSS 4.6v7.0v8.02015-10-19
CVE-2015-5707 [MEDIUM] CWE-190 CVE-2015-5707: Integer overflow in the sg_start_req function in drivers/scsi/sg.c in the Linux kernel 2.6.x through Integer overflow in the sg_start_req function in drivers/scsi/sg.c in the Linux kernel 2.6.x through 4.x before 4.1 allows local users to cause a denial of service or possibly have unspecified other impact via a large iov_count value in a write request.
nvd
CVE-2024-26874P4MEDIUMCVSS 4.7v10.02024-04-17
CVE-2024-26874 [MEDIUM] CWE-476 CVE-2024-26874: In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: Fix a null pointe In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: Fix a null pointer crash in mtk_drm_crtc_finish_page_flip It's possible that mtk_crtc->event is NULL in mtk_drm_crtc_finish_page_flip(). pending_needs_vblank value is set by mtk_crtc->event, but in mtk_drm_crtc_atomic_flush(), it's is not guarded by the same lock in
nvd
CVE-2021-2341P4LOWCVSS 3.1v9.0v10.02021-07-21
CVE-2021-2341 [LOW] CVE-2021-2341: Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u301, 8u291, 11.0.11, 16.0.1; Oracle GraalVM Enterprise Edition: 20.3.2 and 21.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to c
nvd
CVE-2022-21443P4LOWCVSS 3.7v9.0v10.0+1 more2022-04-19
CVE-2022-21443 [LOW] CVE-2022-21443: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (co Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle GraalVM Enterprise Edition: 20.3.5, 21.3.1 and 22.0.0.2. Difficult to exploit vulnerability allows unauthenticated attacker with network acces
nvd
CVE-2023-2898P4MEDIUMCVSS 4.7v10.0v11.0+1 more2023-05-26
CVE-2023-2898 [MEDIUM] CWE-476 CVE-2023-2898: There is a null-pointer-dereference flaw found in f2fs_write_end_io in fs/f2fs/data.c in the Linux k There is a null-pointer-dereference flaw found in f2fs_write_end_io in fs/f2fs/data.c in the Linux kernel. This flaw allows a local privileged user to cause a denial of service problem.
nvd
CVE-2024-27419P4MEDIUMCVSS 4.7v10.02024-05-17
CVE-2024-27419 [MEDIUM] CWE-362 CVE-2024-27419: In the Linux kernel, the following vulnerability has been resolved: netrom: Fix data-races around s In the Linux kernel, the following vulnerability has been resolved: netrom: Fix data-races around sysctl_net_busy_read We need to protect the reader reading the sysctl value because the value can be changed concurrently.
nvd
CVE-2024-26878P4MEDIUMCVSS 4.7v10.02024-04-17
CVE-2024-26878 [MEDIUM] CWE-362 CVE-2024-26878: In the Linux kernel, the following vulnerability has been resolved: quota: Fix potential NULL point In the Linux kernel, the following vulnerability has been resolved: quota: Fix potential NULL pointer dereference Below race may cause NULL pointer dereference P1 P2 dquot_free_inode quota_off drop_dquot_ref remove_dquot_ref dquots = i_dquot(inode) dquots = i_dquot(inode) srcu_read_lock dquots[cnt]) != NULL (1) dquots[type] = NULL (2) spin_lock(&d
nvd
CVE-2015-2684P4MEDIUMCVSS 4.0v7.02015-03-31
CVE-2015-2684 [MEDIUM] CWE-20 CVE-2015-2684: Shibboleth Service Provider (SP) before 2.5.4 allows remote authenticated users to cause a denial of Shibboleth Service Provider (SP) before 2.5.4 allows remote authenticated users to cause a denial of service (crash) via a crafted SAML message.
nvd
CVE-2019-19523P4MEDIUMCVSS 4.6v8.02019-12-03
CVE-2019-19523 [MEDIUM] CWE-416 CVE-2019-19523: In the Linux kernel before 5.3.7, there is a use-after-free bug that can be caused by a malicious US In the Linux kernel before 5.3.7, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/usb/misc/adutux.c driver, aka CID-44efc269db79.
nvd
CVE-2025-38112P4MEDIUMCVSS 4.7v11.02025-07-03
CVE-2025-38112 [MEDIUM] CWE-367 CVE-2025-38112: In the Linux kernel, the following vulnerability has been resolved: net: Fix TOCTOU issue in sk_is_ In the Linux kernel, the following vulnerability has been resolved: net: Fix TOCTOU issue in sk_is_readable() sk->sk_prot->sock_is_readable is a valid function pointer when sk resides in a sockmap. After the last sk_psock_put() (which usually happens when socket is removed from sockmap), sk->sk_prot gets restored and sk->sk_prot->sock_is_readable b
nvd
CVE-2025-38461P4MEDIUMCVSS 4.7v11.02025-07-25
CVE-2025-38461 [MEDIUM] CWE-367 CVE-2025-38461: In the Linux kernel, the following vulnerability has been resolved: vsock: Fix transport_* TOCTOU In the Linux kernel, the following vulnerability has been resolved: vsock: Fix transport_* TOCTOU Transport assignment may race with module unload. Protect new_transport from becoming a stale pointer. This also takes care of an insecure call in vsock_use_local_transport(); add a lockdep assert. BUG: unable to handle page fault for address: fffffbff
nvd
CVE-2025-38462P4MEDIUMCVSS 4.7v11.02025-07-25
CVE-2025-38462 [MEDIUM] CWE-367 CVE-2025-38462: In the Linux kernel, the following vulnerability has been resolved: vsock: Fix transport_{g2h,h2g} In the Linux kernel, the following vulnerability has been resolved: vsock: Fix transport_{g2h,h2g} TOCTOU vsock_find_cid() and vsock_dev_do_ioctl() may race with module unload. transport_{g2h,h2g} may become NULL after the NULL check. Introduce vsock_transport_local_cid() to protect from a potential null-ptr-deref. KASAN: null-ptr-deref in range [
nvd
CVE-2020-14781P4LOWCVSS 3.7v9.0v10.02020-10-21
CVE-2020-14781 [LOW] CVE-2020-14781: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JNDI). Supporte Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JNDI). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful atta
nvd
CVE-2020-2778P4LOWCVSS 3.7v10.02020-04-15
CVE-2020-2778 [LOW] CVE-2020-2778: Vulnerability in the Java SE product of Oracle Java SE (component: JSSE). Supported versions that ar Vulnerability in the Java SE product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 11.0.6 and 14. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE ac
nvd
CVE-2017-11334P4MEDIUMCVSS 4.4v9.02017-08-02
CVE-2017-11334 [MEDIUM] CWE-125 CVE-2017-11334: The address_space_write_continue function in exec.c in QEMU (aka Quick Emulator) allows local guest The address_space_write_continue function in exec.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (out-of-bounds access and guest instance crash) by leveraging use of qemu_map_ram_ptr to access guest ram block area.
nvd
Debian Linux vulnerabilities | cvebase