Debian Linux vulnerabilities
9,956 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,956
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4169MEDIUM4296LOW358
Vulnerabilities
Page 485 of 498
CVE-2014-5025P4LOWCVSS 3.5v7.02014-10-20
CVE-2014-5025 [LOW] CWE-79 CVE-2014-5025: Cross-site scripting (XSS) vulnerability in data_sources.php in Cacti 0.8.8b allows remote authentic
Cross-site scripting (XSS) vulnerability in data_sources.php in Cacti 0.8.8b allows remote authenticated users with console access to inject arbitrary web script or HTML via the name_cache parameter in a ds_edit action.
nvd
CVE-2023-22036P4LOWCVSS 3.7v10.0v11.0+1 more2023-07-18
CVE-2023-22036 [LOW] CVE-2023-22036: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK produ
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK product of Oracle Java SE (component: Utility). Supported versions that are affected are Oracle Java SE: 11.0.19, 17.0.7, 20.0.1; Oracle GraalVM Enterprise Edition: 20.3.10, 21.3.6, 22.3.2; Oracle GraalVM for JDK: 17.0.7 and 20.0.1. Difficult to exploit vulnerability
nvd
CVE-2020-11085P4LOWCVSS 3.5v10.02020-05-29
CVE-2020-11085 [LOW] CWE-125 CVE-2020-11085: In FreeRDP before 2.1.0, there is an out-of-bounds read in cliprdr_read_format_list. Clipboard forma
In FreeRDP before 2.1.0, there is an out-of-bounds read in cliprdr_read_format_list. Clipboard format data read (by client or server) might read data out-of-bounds. This has been fixed in 2.1.0.
nvd
CVE-2017-3318P4MEDIUMCVSS 4.0v8.02017-01-27
CVE-2017-3318 [MEDIUM] CVE-2017-3318: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Error Handling).
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Error Handling). Supported versions that are affected are 5.5.53 and earlier, 5.6.34 and earlier and 5.7.16 and earlier. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Su
nvd
CVE-2010-3874P4MEDIUMCVSS 4.0v5.02010-12-29
CVE-2010-3874 [MEDIUM] CWE-787 CVE-2010-3874: Heap-based buffer overflow in the bcm_connect function in net/can/bcm.c (aka the Broadcast Manager)
Heap-based buffer overflow in the bcm_connect function in net/can/bcm.c (aka the Broadcast Manager) in the Controller Area Network (CAN) implementation in the Linux kernel before 2.6.36.2 on 64-bit platforms might allow local users to cause a denial of service (memory corruption) via a connect operation.
nvd
CVE-2023-21968P4LOWCVSS 3.7v10.0v11.0+1 more2023-04-18
CVE-2023-21968 [LOW] CWE-284 CVE-2023-21968: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (co
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6, 20; Oracle GraalVM Enterprise Edition: 20.3.9, 21.3.5 and 22.3.1. Difficult to exploit vulnerability allows unauthenticated attacker with ne
nvd
CVE-2020-13361P4LOWCVSS 3.9v8.0v9.0+1 more2020-05-28
CVE-2020-13361 [LOW] CWE-787 CVE-2020-13361: In QEMU 5.0.0 and earlier, es1370_transfer_audio in hw/audio/es1370.c does not properly validate the
In QEMU 5.0.0 and earlier, es1370_transfer_audio in hw/audio/es1370.c does not properly validate the frame count, which allows guest OS users to trigger an out-of-bounds access during an es1370_write() operation.
nvd
CVE-2025-4215P4LOWCVSS 3.7v11.02025-05-02
CVE-2025-4215 [LOW] CWE-400 CVE-2025-4215: A vulnerability was found in gorhill uBlock Origin up to 1.63.3b16. It has been classified as proble
A vulnerability was found in gorhill uBlock Origin up to 1.63.3b16. It has been classified as problematic. Affected is the function currentStateChanged of the file src/js/1p-filters.js of the component UI. The manipulation leads to inefficient regular expression complexity. It is possible to launch the attack remotely. The complexity of an attack is rath
nvd
CVE-2020-16092P4LOWCVSS 3.8v9.0v10.02020-08-11
CVE-2020-16092 [LOW] CWE-617 CVE-2020-16092: In QEMU through 5.0.0, an assertion failure can occur in the network packet processing. This issue a
In QEMU through 5.0.0, an assertion failure can occur in the network packet processing. This issue affects the e1000e and vmxnet3 network devices. A malicious guest user/process could use this flaw to abort the QEMU process on the host, resulting in a denial of service condition in net_tx_pkt_add_raw_fragment in hw/net/net_tx_pkt.c.
nvd
CVE-2021-3593P4LOWCVSS 3.8v9.02021-06-15
CVE-2021-3593 [LOW] CWE-824 CVE-2021-3593: An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. Th
An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the udp6_input() function and could occur while processing a udp packet that is smaller than the size of the 'udphdr' structure. This issue may lead to out-of-bounds read access or indirect host memory disclosure to the guest. The highest
nvd
CVE-2021-3594P4LOWCVSS 3.8v9.02021-06-15
CVE-2021-3594 [LOW] CWE-824 CVE-2021-3594: An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. Th
An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the udp_input() function and could occur while processing a udp packet that is smaller than the size of the 'udphdr' structure. This issue may lead to out-of-bounds read access or indirect host memory disclosure to the guest. The highest t
nvd
CVE-2021-3592P4LOWCVSS 3.8v9.02021-06-15
CVE-2021-3592 [LOW] CWE-824 CVE-2021-3592: An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. Th
An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the bootp_input() function and could occur while processing a udp packet that is smaller than the size of the 'bootp_t' structure. A malicious guest could use this flaw to leak 10 bytes of uninitialized heap memory from the host. The highe
nvd
CVE-2021-3595P4LOWCVSS 3.8v9.02021-06-15
CVE-2021-3595 [LOW] CWE-824 CVE-2021-3595: An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. Th
An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the tftp_input() function and could occur while processing a udp packet that is smaller than the size of the 'tftp_t' structure. This issue may lead to out-of-bounds read access or indirect host memory disclosure to the guest. The highest
nvd
CVE-2023-45145P4LOWCVSS 3.6v10.02023-10-18
CVE-2023-45145 [LOW] CWE-668 CVE-2023-45145: Redis is an in-memory database that persists on disk. On startup, Redis begins listening on a Unix s
Redis is an in-memory database that persists on disk. On startup, Redis begins listening on a Unix socket before adjusting its permissions to the user-provided configuration. If a permissive umask(2) is used, this creates a race condition that enables, during a short period of time, another process to establish an otherwise unauthorized connection. Thi
nvd
CVE-2020-29374P4LOWCVSS 3.6v9.0v10.02020-11-28
CVE-2020-29374 [LOW] CWE-362 CVE-2020-29374: An issue was discovered in the Linux kernel before 5.7.3, related to mm/gup.c and mm/huge_memory.c.
An issue was discovered in the Linux kernel before 5.7.3, related to mm/gup.c and mm/huge_memory.c. The get_user_pages (aka gup) implementation, when used for a copy-on-write page, does not properly consider the semantics of read operations and therefore can grant unintended write access, aka CID-17839856fd58.
nvd
CVE-2001-0738P4MEDIUMCVSS 5.0v1.3v2.22001-10-18
CVE-2001-0738 [MEDIUM] CVE-2001-0738: LogLine function in klogd in sysklogd 1.3 in various Linux distributions allows an attacker to cause
LogLine function in klogd in sysklogd 1.3 in various Linux distributions allows an attacker to cause a denial of service (hang) by causing null bytes to be placed in log messages.
nvd
CVE-2004-1139P4MEDIUMCVSS 5.0v3.02004-12-15
CVE-2004-1139 [MEDIUM] CVE-2004-1139: Unknown vulnerability in the DICOM dissector in Ethereal 0.10.4 through 0.10.7 allows remote attacke
Unknown vulnerability in the DICOM dissector in Ethereal 0.10.4 through 0.10.7 allows remote attackers to cause a denial of service (application crash).
nvd
CVE-2023-36479P4LOWCVSS 3.1v10.0v11.0+1 more2023-09-15
CVE-2023-36479 [LOW] CWE-149 CVE-2023-36479: Eclipse Jetty Canonical Repository is the canonical repository for the Jetty project. Users of the C
Eclipse Jetty Canonical Repository is the canonical repository for the Jetty project. Users of the CgiServlet with a very specific command structure may have the wrong command executed. If a user sends a request to a org.eclipse.jetty.servlets.CGI Servlet for a binary with a space in its name, the servlet will escape the command by wrapping it in quota
nvd
CVE-2002-2185P4MEDIUMCVSS 4.9v2.22002-12-31
CVE-2002-2185 [MEDIUM] CVE-2002-2185: The Internet Group Management Protocol (IGMP) allows local users to cause a denial of service via an
The Internet Group Management Protocol (IGMP) allows local users to cause a denial of service via an IGMP membership report to a target's Ethernet address instead of the Multicast group address, which causes the target to stop sending reports to the router and effectively disconnect the group from the network.
nvd
CVE-2000-0315P4MEDIUMCVSS 5.0v2.0.342001-03-12
CVE-2000-0315 [MEDIUM] CVE-2000-0315: traceroute in NetBSD 1.3.3 and Linux systems allows local unprivileged users to modify the source ad
traceroute in NetBSD 1.3.3 and Linux systems allows local unprivileged users to modify the source address of the packets, which could be used in spoofing attacks.
nvd