cbcvebase.

Debian Linux vulnerabilities

9,956 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,956
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4169MEDIUM4296LOW358

Vulnerabilities

Page 486 of 498
CVE-2008-3534P4MEDIUMCVSS 4.9v4.02008-08-08
CVE-2008-3534 [MEDIUM] CWE-400 CVE-2008-3534: The shmem_delete_inode function in mm/shmem.c in the tmpfs implementation in the Linux kernel before The shmem_delete_inode function in mm/shmem.c in the tmpfs implementation in the Linux kernel before 2.6.26.1 allows local users to cause a denial of service (system crash) via a certain sequence of file create, remove, and overwrite operations, as demonstrated by the insserv program, related to allocation of "useless pages" and improper maintenance o
nvd
CVE-2010-3067P4MEDIUMCVSS 4.9v5.02010-09-21
CVE-2010-3067 [MEDIUM] CWE-190 CVE-2010-3067: Integer overflow in the do_io_submit function in fs/aio.c in the Linux kernel before 2.6.36-rc4-next Integer overflow in the do_io_submit function in fs/aio.c in the Linux kernel before 2.6.36-rc4-next-20100915 allows local users to cause a denial of service or possibly have unspecified other impact via crafted use of the io_submit system call.
nvd
CVE-2005-0004P4MEDIUMCVSS 4.6v3.02005-04-14
CVE-2005-0004 [MEDIUM] CWE-59 CVE-2005-0004: The mysqlaccess script in MySQL 4.0.23 and earlier, 4.1.x before 4.1.10, 5.0.x before 5.0.3, and oth The mysqlaccess script in MySQL 4.0.23 and earlier, 4.1.x before 4.1.10, 5.0.x before 5.0.3, and other versions including 3.x, allows local users to overwrite arbitrary files or read temporary files via a symlink attack on temporary files.
nvd
CVE-2005-2555P4MEDIUMCVSS 4.6v3.12005-08-16
CVE-2005-2555 [MEDIUM] CWE-264 CVE-2005-2555: Linux kernel 2.6.x does not properly restrict socket policy access to users with the CAP_NET_ADMIN c Linux kernel 2.6.x does not properly restrict socket policy access to users with the CAP_NET_ADMIN capability, which could allow local users to conduct unauthorized activities via (1) ipv4/ip_sockglue.c and (2) ipv6/ipv6_sockglue.c.
nvd
CVE-2005-0159P4MEDIUMCVSS 4.6v3.02005-04-27
CVE-2005-0159 [MEDIUM] CVE-2005-0159: The tpkg-* scripts in the toolchain-source 3.0.4 package on Debian GNU/Linux 3.0 allow local users t The tpkg-* scripts in the toolchain-source 3.0.4 package on Debian GNU/Linux 3.0 allow local users to overwrite arbitrary files via a symlink attack on temporary files.
nvd
CVE-2014-9644P4LOWCVSS 2.1v7.0v8.02015-03-02
CVE-2014-9644 [LOW] CVE-2014-9644: The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a parenthesized module template expression in the salg_name field, as demonstrated by the vfat(aes) expression, a different vulnerability than CVE-2013-7421.
nvd
CVE-2008-1945P4LOWCVSS 2.1v4.0v5.02008-08-08
CVE-2008-1945 [LOW] CVE-2008-1945: QEMU 0.9.0 does not properly handle changes to removable media, which allows guest OS users to read QEMU 0.9.0 does not properly handle changes to removable media, which allows guest OS users to read arbitrary files on the host OS by using the diskformat: parameter in the -usbdevice option to modify the disk-image header to identify a different format, a related issue to CVE-2008-2004.
nvd
CVE-2017-7519P4MEDIUMCVSS 4.4v10.02018-07-27
CVE-2017-7519 [MEDIUM] CWE-134 CVE-2017-7519: In Ceph, a format string flaw was found in the way libradosstriper parses input from user. A user co In Ceph, a format string flaw was found in the way libradosstriper parses input from user. A user could crash an application or service using the libradosstriper library.
nvd
CVE-2012-3167P4LOWCVSS 3.5v6.0v7.02012-10-17
CVE-2012-3167 [LOW] CVE-2012-3167: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.63 and earlier, and 5.5. Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.63 and earlier, and 5.5.25 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Full Text Search.
nvd
CVE-2016-7909P4MEDIUMCVSS 4.4v8.02016-10-05
CVE-2016-7909 [MEDIUM] CWE-835 CVE-2016-7909: The pcnet_rdra_addr function in hw/net/pcnet.c in QEMU (aka Quick Emulator) allows local guest OS ad The pcnet_rdra_addr function in hw/net/pcnet.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by setting the (1) receive or (2) transmit descriptor ring length to 0.
nvd
CVE-2016-4453P4MEDIUMCVSS 4.4v8.02016-06-01
CVE-2016-4453 [MEDIUM] CWE-835 CVE-2016-4453: The vmsvga_fifo_run function in hw/display/vmware_vga.c in QEMU allows local guest OS administrators The vmsvga_fifo_run function in hw/display/vmware_vga.c in QEMU allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via a VGA command.
nvd
CVE-2016-7421P4MEDIUMCVSS 4.4v8.02016-12-10
CVE-2016-7421 [MEDIUM] CWE-834 CVE-2016-7421: The pvscsi_ring_pop_req_descr function in hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows l The pvscsi_ring_pop_req_descr function in hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by leveraging failure to limit process IO loop to the ring size.
nvd
CVE-2004-0837P4LOWCVSS 2.6v3.02004-11-03
CVE-2004-0837 [LOW] CVE-2004-0837: MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows attackers to cause a denial of service (cras MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows attackers to cause a denial of service (crash or hang) via multiple threads that simultaneously alter MERGE table UNIONs.
nvd
CVE-2016-7156P4MEDIUMCVSS 4.4v8.02016-12-10
CVE-2016-7156 [MEDIUM] CWE-704 CVE-2016-7156: The pvscsi_convert_sglist function in hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local The pvscsi_convert_sglist function in hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by leveraging an incorrect cast.
nvd
CVE-2016-7155P4MEDIUMCVSS 4.4v8.02016-12-10
CVE-2016-7155 [MEDIUM] CVE-2016-7155: hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a de hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (out-of-bounds access or infinite loop, and QEMU process crash) via a crafted page count for descriptor rings.
nvd
CVE-2016-6834P4MEDIUMCVSS 4.4v8.02016-12-10
CVE-2016-6834 [MEDIUM] CWE-120 CVE-2016-6834: The net_tx_pkt_do_sw_fragmentation function in hw/net/net_tx_pkt.c in QEMU (aka Quick Emulator) allo The net_tx_pkt_do_sw_fragmentation function in hw/net/net_tx_pkt.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via a zero length for the current fragment length.
nvd
CVE-2017-18030P4MEDIUMCVSS 4.4v8.02018-01-23
CVE-2017-18030 [MEDIUM] CWE-125 CVE-2017-18030: The cirrus_invalidate_region function in hw/display/cirrus_vga.c in Qemu allows local OS guest privi The cirrus_invalidate_region function in hw/display/cirrus_vga.c in Qemu allows local OS guest privileged users to cause a denial of service (out-of-bounds array access and QEMU process crash) via vectors related to negative pitch.
nvd
CVE-2016-6833P4MEDIUMCVSS 4.4v8.02016-12-10
CVE-2016-6833 [MEDIUM] CWE-416 CVE-2016-6833: Use-after-free vulnerability in the vmxnet3_io_bar0_write function in hw/net/vmxnet3.c in QEMU (aka Use-after-free vulnerability in the vmxnet3_io_bar0_write function in hw/net/vmxnet3.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (QEMU instance crash) by leveraging failure to check if the device is active.
nvd
CVE-2021-35588P4LOWCVSS 3.1v9.02021-10-20
CVE-2021-35588 [LOW] CVE-2021-35588: Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Java SE: 7u311, 8u301; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE,
nvd
CVE-2014-0393P4LOWCVSS 3.3v6.0v7.02014-01-15
CVE-2014-0393 [LOW] CVE-2014-0393: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.71 and earlier, 5.5.33 a Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.71 and earlier, 5.5.33 and earlier, and 5.6.13 and earlier allows remote authenticated users to affect integrity via unknown vectors related to InnoDB.
nvd
Debian Linux vulnerabilities | cvebase