cbcvebase.

Debian Linux vulnerabilities

9,956 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,956
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4169MEDIUM4296LOW358

Vulnerabilities

Page 482 of 498
CVE-2023-21938P4LOWCVSS 3.7v10.0v11.0+1 more2023-04-18
CVE-2023-21938 [LOW] CVE-2023-21938: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (co Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6, 20; Oracle GraalVM Enterprise Edition: 20.3.8, 21.3.4 and 22.3.0. Difficult to exploit vulnerability allows unauthenticated attacker with network ac
nvd
CVE-2023-21937P4LOWCVSS 3.7v10.0v11.0+1 more2023-04-18
CVE-2023-21937 [LOW] CVE-2023-21937: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (co Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6, 20; Oracle GraalVM Enterprise Edition: 20.3.9, 21.3.5 and 22.3.1. Difficult to exploit vulnerability allows unauthenticated attacker with network a
nvd
CVE-2024-3861P4MEDIUMCVSS 4.0v10.02024-04-16
CVE-2024-3861 [MEDIUM] CWE-416 CVE-2024-3861: If an AlignedBuffer were assigned to itself, the subsequent self-move could result in an incorrect r If an AlignedBuffer were assigned to itself, the subsequent self-move could result in an incorrect reference count and later use-after-free. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
nvd
CVE-2024-21012P4LOWCVSS 3.7v10.02024-04-16
CVE-2024-21012 [LOW] CWE-276 CVE-2024-21012: Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition produ Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 11.0.22, 17.0.10, 21.0.2, 22; Oracle GraalVM for JDK: 17.0.10, 21.0.2, 22; Oracle GraalVM Enterprise Edition: 20.3.13 and 21.3.9. Difficult to exploit
nvd
CVE-2020-1739P4LOWCVSS 3.9v8.0v10.02020-03-12
CVE-2020-1739 [LOW] CWE-200 CVE-2020-1739: A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password i A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument "password" of svn module, it is used on svn command line, disclosing to other users within the same node. An attacker could take advantage by reading the cmdline file from that particular PID on the procfs.
nvd
CVE-2024-21094P4LOWCVSS 3.7v10.02024-04-16
CVE-2024-21094 [LOW] CWE-349 CVE-2024-21094: Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition produ Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u401, 8u401-perf, 11.0.22, 17.0.10, 21.0.2, 22; Oracle GraalVM for JDK: 17.0.10, 21.0.2, 22; Oracle GraalVM Enterprise Edition: 20.3.13 and 21.3.9. Diffi
nvd
CVE-2020-24654P4LOWCVSS 3.3v10.0v9.02020-09-02
CVE-2020-24654 [LOW] CWE-59 CVE-2020-24654: In KDE Ark before 20.08.1, a crafted TAR archive with symlinks can install files outside the extract In KDE Ark before 20.08.1, a crafted TAR archive with symlinks can install files outside the extraction directory, as demonstrated by a write operation to a user's home directory.
nvd
CVE-2025-32728P4LOWCVSS 3.8v11.02025-04-10
CVE-2025-32728 [LOW] CWE-440 CVE-2025-32728: In sshd in OpenSSH before 10.0, the DisableForwarding directive does not adhere to the documentation In sshd in OpenSSH before 10.0, the DisableForwarding directive does not adhere to the documentation stating that it disables X11 and agent forwarding.
nvd
CVE-2018-18310P4MEDIUMCVSS 5.5v8.0v9.02018-10-15
CVE-2018-18310 [MEDIUM] CWE-119 CVE-2018-18310: An invalid memory address dereference was discovered in dwfl_segment_report_module.c in libdwfl in e An invalid memory address dereference was discovered in dwfl_segment_report_module.c in libdwfl in elfutils through v0.174. The vulnerability allows attackers to cause a denial of service (application crash) with a crafted ELF file, as demonstrated by consider_notes.
nvd
CVE-2020-4050P4LOWCVSS 3.1v8.0v9.0+1 more2020-06-12
CVE-2020-4050 [LOW] CWE-288 CVE-2020-4050: In affected versions of WordPress, misuse of the `set-screen-option` filter's return value allows ar In affected versions of WordPress, misuse of the `set-screen-option` filter's return value allows arbitrary user meta fields to be saved. It does require an admin to install a plugin that would misuse the filter. Once installed, it can be leveraged by low privileged users. This has been patched in version 5.4.2, along with all the previously affected ver
nvd
CVE-2020-24587P4LOWCVSS 2.6v9.02021-05-11
CVE-2020-24587 [LOW] CWE-327 CVE-2020-24587: The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that all fragments of a frame are encrypted under the same key. An adversary can abuse this to decrypt selected fragments when another device sends fragmented frames and the WEP, CCMP, or GCMP encryption key is periodically
nvd
CVE-2018-20360P4MEDIUMCVSS 5.5v8.0v9.0+1 more2018-12-22
CVE-2018-20360 [MEDIUM] CWE-119 CVE-2018-20360: An invalid memory address dereference was discovered in the sbr_process_channel function of libfaad/ An invalid memory address dereference was discovered in the sbr_process_channel function of libfaad/sbr_dec.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.
nvd
CVE-2020-21530P4MEDIUMCVSS 5.5v9.02021-09-16
CVE-2020-21530 [MEDIUM] CVE-2020-21530: fig2dev 3.2.7b contains a segmentation fault in the read_objects function in read.c. fig2dev 3.2.7b contains a segmentation fault in the read_objects function in read.c.
nvd
CVE-2000-0510P4MEDIUMCVSS 5.0v2.2v2.32000-06-21
CVE-2000-0510 [MEDIUM] CVE-2000-0510: CUPS (Common Unix Printing System) 1.04 and earlier allows remote attackers to cause a denial of ser CUPS (Common Unix Printing System) 1.04 and earlier allows remote attackers to cause a denial of service via a malformed IPP request.
nvd
CVE-2005-1916P4MEDIUMCVSS 5.5v3.12005-07-06
CVE-2005-1916 [MEDIUM] CWE-59 CVE-2005-1916: linki.py in ekg 2005-06-05 and earlier allows local users to overwrite or create arbitrary files via linki.py in ekg 2005-06-05 and earlier allows local users to overwrite or create arbitrary files via a symlink attack on temporary files.
nvd
CVE-2023-24755P4MEDIUMCVSS 5.5v10.02023-03-01
CVE-2023-24755 [MEDIUM] CWE-476 CVE-2023-24755: libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the put_weighted_pred_8_fal libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the put_weighted_pred_8_fallback function at fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.
nvd
CVE-2023-24754P4MEDIUMCVSS 5.5v10.02023-03-01
CVE-2023-24754 [MEDIUM] CWE-476 CVE-2023-24754: libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_weighted_pr libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_weighted_pred_avg_8_sse function at sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.
nvd
CVE-2023-24757P4MEDIUMCVSS 5.5v10.02023-03-01
CVE-2023-24757 [MEDIUM] CWE-476 CVE-2023-24757: libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the put_unweighted_pred_16_ libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the put_unweighted_pred_16_fallback function at fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.
nvd
CVE-2023-24752P4MEDIUMCVSS 5.5v10.02023-03-01
CVE-2023-24752 [MEDIUM] CWE-476 CVE-2023-24752: libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_hevc_epel_p libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_hevc_epel_pixels_8_sse function at sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.
nvd
CVE-2023-24758P4MEDIUMCVSS 5.5v10.02023-03-01
CVE-2023-24758 [MEDIUM] CWE-476 CVE-2023-24758: libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_weighted_pr libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_weighted_pred_avg_8_sse function at sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.
nvd
Debian Linux vulnerabilities | cvebase