cbcvebase.

Debian Linux vulnerabilities

9,956 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,956
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4169MEDIUM4296LOW358

Vulnerabilities

Page 484 of 498
CVE-2013-7421P4LOWCVSS 2.1v7.0v8.02015-03-02
CVE-2013-7421 [LOW] CWE-269 CVE-2013-7421: The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a module name in the salg_name field, a different vulnerability than CVE-2014-9644.
nvd
CVE-2025-37985P4MEDIUMCVSS 4.7v11.02025-05-20
CVE-2025-37985 [MEDIUM] CWE-362 CVE-2025-37985: In the Linux kernel, the following vulnerability has been resolved: USB: wdm: close race between wd In the Linux kernel, the following vulnerability has been resolved: USB: wdm: close race between wdm_open and wdm_wwan_port_stop Clearing WDM_WWAN_IN_USE must be the last action or we can open a chardev whose URBs are still poisoned
nvd
CVE-2016-0668P4MEDIUMCVSS 4.1v8.02016-04-21
CVE-2016-0668 [MEDIUM] CVE-2016-0668: Unspecified vulnerability in Oracle MySQL 5.6.28 and earlier and 5.7.10 and earlier and MariaDB 10.0 Unspecified vulnerability in Oracle MySQL 5.6.28 and earlier and 5.7.10 and earlier and MariaDB 10.0.x before 10.0.24 and 10.1.x before 10.1.12 allows local users to affect availability via vectors related to InnoDB.
nvd
CVE-2015-4895P4LOWCVSS 3.5v8.02015-10-21
CVE-2015-4895 [LOW] CVE-2015-4895: Unspecified vulnerability in Oracle MySQL Server 5.6.25 and earlier allows remote authenticated user Unspecified vulnerability in Oracle MySQL Server 5.6.25 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : InnoDB.
nvd
CVE-2016-1000346P4LOWCVSS 3.7v8.02018-06-04
CVE-2016-1000346 [LOW] CWE-320 CVE-2016-1000346: In the Bouncy Castle JCE Provider version 1.55 and earlier the other party DH public key is not full In the Bouncy Castle JCE Provider version 1.55 and earlier the other party DH public key is not fully validated. This can cause issues as invalid keys can be used to reveal details about the other party's private key where static Diffie-Hellman is in use. As of release 1.56 the key parameters are checked on agreement calculation.
nvd
CVE-2013-3812P4LOWCVSS 3.5v7.02013-07-17
CVE-2013-3812 [LOW] CVE-2013-3812: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.31 and earlier and 5.6.1 Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.31 and earlier and 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Replication.
nvd
CVE-2019-3819P4MEDIUMCVSS 4.4v8.02019-01-25
CVE-2019-3819 [MEDIUM] CWE-835 CVE-2019-3819: A flaw was found in the Linux kernel in the function hid_debug_events_read() in drivers/hid/hid-debu A flaw was found in the Linux kernel in the function hid_debug_events_read() in drivers/hid/hid-debug.c file which may enter an infinite loop with certain parameters passed from a userspace. A local privileged user ("root") can cause a system lock up and a denial of service. Versions from v4.18 and newer are vulnerable.
nvd
CVE-2016-5238P4MEDIUMCVSS 4.4v8.02016-06-14
CVE-2016-5238 [MEDIUM] CWE-787 CVE-2016-5238: The get_cmd function in hw/scsi/esp.c in QEMU might allow local guest OS administrators to cause a d The get_cmd function in hw/scsi/esp.c in QEMU might allow local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) via vectors related to reading from the information transfer buffer in non-DMA mode.
nvd
CVE-2016-7908P4MEDIUMCVSS 4.4v8.02016-10-05
CVE-2016-7908 [MEDIUM] CWE-835 CVE-2016-7908: The mcf_fec_do_tx function in hw/net/mcf_fec.c in QEMU (aka Quick Emulator) does not properly limit The mcf_fec_do_tx function in hw/net/mcf_fec.c in QEMU (aka Quick Emulator) does not properly limit the buffer descriptor count when transmitting packets, which allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via vectors involving a buffer descriptor with a length of 0 and crafted values in bd.fl
nvd
CVE-2012-0216P4MEDIUMCVSS 4.4v6.0v7.02012-04-22
CVE-2012-0216 [MEDIUM] CVE-2012-0216: The default configuration of the apache2 package in Debian GNU/Linux squeeze before 2.2.16-6+squeeze The default configuration of the apache2 package in Debian GNU/Linux squeeze before 2.2.16-6+squeeze7, wheezy before 2.2.22-4, and sid before 2.2.22-4, when mod_php or mod_rivet is used, provides example scripts under the doc/ URI, which might allow local users to conduct cross-site scripting (XSS) attacks, gain privileges, or obtain sensitive information via
nvd
CVE-2020-35505P4MEDIUMCVSS 4.4v10.02021-05-28
CVE-2020-35505 [MEDIUM] CWE-476 CVE-2020-35505: A NULL pointer dereference flaw was found in the am53c974 SCSI host bus adapter emulation of QEMU in A NULL pointer dereference flaw was found in the am53c974 SCSI host bus adapter emulation of QEMU in versions before 6.0.0. This issue occurs while handling the 'Information Transfer' command. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. The highest threat from this vulnerability i
nvd
CVE-2023-52492P4MEDIUMCVSS 4.4v10.02024-03-11
CVE-2023-52492 [MEDIUM] CWE-476 CVE-2023-52492: In the Linux kernel, the following vulnerability has been resolved: dmaengine: fix NULL pointer in In the Linux kernel, the following vulnerability has been resolved: dmaengine: fix NULL pointer in channel unregistration function __dma_async_device_channel_register() can fail. In case of failure, chan->local is freed (with free_percpu()), and chan->local is nullified. When dma_async_device_unregister() is called (because of managed API or intenti
nvd
CVE-2024-36950P4MEDIUMCVSS 4.4v10.02024-05-30
CVE-2024-36950 [MEDIUM] CVE-2024-36950: In the Linux kernel, the following vulnerability has been resolved: firewire: ohci: mask bus reset In the Linux kernel, the following vulnerability has been resolved: firewire: ohci: mask bus reset interrupts between ISR and bottom half In the FireWire OHCI interrupt handler, if a bus reset interrupt has occurred, mask bus reset interrupts until bus_reset_work has serviced and cleared the interrupt. Normally, we always leave bus reset interrupts masked.
nvd
CVE-2023-52617P4MEDIUMCVSS 4.4v10.02024-03-18
CVE-2023-52617 [MEDIUM] CWE-459 CVE-2023-52617: In the Linux kernel, the following vulnerability has been resolved: PCI: switchtec: Fix stdev_relea In the Linux kernel, the following vulnerability has been resolved: PCI: switchtec: Fix stdev_release() crash after surprise hot remove A PCI device hot removal may occur while stdev->cdev is held open. The call to stdev_release() then happens during close or exit, at a point way past switchtec_pci_remove(). Otherwise the last ref would vanish with
nvd
CVE-2023-2269P4MEDIUMCVSS 4.4v10.0v11.0+1 more2023-04-25
CVE-2023-2269 [MEDIUM] CWE-413 CVE-2023-2269: A denial of service problem was found, due to a possible recursive locking scenario, resulting in a A denial of service problem was found, due to a possible recursive locking scenario, resulting in a deadlock in table_clear in drivers/md/dm-ioctl.c in the Linux Kernel Device Mapper-Multipathing sub-component.
nvd
CVE-2021-3735P4MEDIUMCVSS 4.4v10.0v11.02022-08-26
CVE-2021-3735 [MEDIUM] CWE-667 CVE-2021-3735: A deadlock issue was found in the AHCI controller device of QEMU. It occurs on a software reset (ahc A deadlock issue was found in the AHCI controller device of QEMU. It occurs on a software reset (ahci_reset_port) while handling a host-to-device Register FIS (Frame Information Structure) packet from the guest. A privileged user inside the guest could use this flaw to hang the QEMU process on the host, resulting in a denial of service condition. The
nvd
CVE-2022-41849P4MEDIUMCVSS 4.2v10.02022-09-30
CVE-2022-41849 [MEDIUM] CWE-362 CVE-2022-41849: drivers/video/fbdev/smscufx.c in the Linux kernel through 5.19.12 has a race condition and resultant drivers/video/fbdev/smscufx.c in the Linux kernel through 5.19.12 has a race condition and resultant use-after-free if a physically proximate attacker removes a USB device while calling open(), aka a race condition between ufx_ops_open and ufx_usb_disconnect.
nvd
CVE-2024-21011P4LOWCVSS 3.7v10.02024-04-16
CVE-2024-21011 [LOW] CWE-770 CVE-2024-21011: Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition produ Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u401, 8u401-perf, 11.0.22, 17.0.10, 21.0.2, 22; Oracle GraalVM for JDK: 17.0.10, 21.0.2, 22; Oracle GraalVM Enterprise Edition: 20.3.13 and 21.3.9. Diffi
nvd
CVE-2023-22044P4LOWCVSS 3.7v11.0v12.02023-07-18
CVE-2023-22044 [LOW] CVE-2023-22044: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK produ Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u371-perf, 17.0.7, 20.0.1; Oracle GraalVM Enterprise Edition: 21.3.6, 22.3.2; Oracle GraalVM for JDK: 17.0.7 and 20.0.1. Difficult to exploit vulnerability allow
nvd
CVE-2023-22045P4LOWCVSS 3.7v10.0v11.0+1 more2023-07-18
CVE-2023-22045 [LOW] CVE-2023-22045: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK produ Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u371, 8u371-perf, 11.0.19, 17.0.7, 20.0.1; Oracle GraalVM Enterprise Edition: 20.3.10, 21.3.6, 22.3.2; Oracle GraalVM for JDK: 17.0.7 and 20.0.1. Difficult to ex
nvd
Debian Linux vulnerabilities | cvebase