Debian Linux vulnerabilities
9,956 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,956
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4169MEDIUM4296LOW358
Vulnerabilities
Page 488 of 498
CVE-2008-3535P4MEDIUMCVSS 4.9v4.02008-08-08
CVE-2008-3535 [MEDIUM] CWE-193 CVE-2008-3535: Off-by-one error in the iov_iter_advance function in mm/filemap.c in the Linux kernel before 2.6.27-
Off-by-one error in the iov_iter_advance function in mm/filemap.c in the Linux kernel before 2.6.27-rc2 allows local users to cause a denial of service (system crash) via a certain sequence of file I/O operations with readv and writev, as demonstrated by testcases/kernel/fs/ftest/ftest03 from the Linux Test Project.
nvd
CVE-2014-8866P4MEDIUMCVSS 4.7v7.02014-12-01
CVE-2014-8866 [MEDIUM] CWE-17 CVE-2014-8866: The compatibility mode hypercall argument translation in Xen 3.3.x through 4.4.x, when running on a
The compatibility mode hypercall argument translation in Xen 3.3.x through 4.4.x, when running on a 64-bit hypervisor, allows local 32-bit HVM guests to cause a denial of service (host crash) via vectors involving altering the high halves of registers while in 64-bit mode.
nvd
CVE-2007-2172P4MEDIUMCVSS 4.7v3.1v4.02007-04-22
CVE-2007-2172 [MEDIUM] CWE-20 CVE-2007-2172: A typo in Linux kernel 2.6 before 2.6.21-rc6 and 2.4 before 2.4.35 causes RTA_MAX to be used as an a
A typo in Linux kernel 2.6 before 2.6.21-rc6 and 2.4 before 2.4.35 causes RTA_MAX to be used as an array size instead of RTN_MAX, which leads to an "out of bound access" by the (1) dn_fib_props (dn_fib.c, DECNet) and (2) fib_props (fib_semantics.c, IPv4) functions.
nvd
CVE-2008-5701P4MEDIUMCVSS 4.7v4.02008-12-22
CVE-2008-5701 [MEDIUM] CWE-189 CVE-2008-5701: Array index error in arch/mips/kernel/scall64-o32.S in the Linux kernel before 2.6.28-rc8 on 64-bit
Array index error in arch/mips/kernel/scall64-o32.S in the Linux kernel before 2.6.28-rc8 on 64-bit MIPS platforms allows local users to cause a denial of service (system crash) via an o32 syscall with a small syscall number, which leads to an attempted read operation outside the bounds of the syscall table.
nvd
CVE-2005-3274P4MEDIUMCVSS 4.7v3.12005-10-21
CVE-2005-3274 [MEDIUM] CWE-476 CVE-2005-3274: Race condition in ip_vs_conn_flush in Linux 2.6 before 2.6.13 and 2.4 before 2.4.32-pre2, when runni
Race condition in ip_vs_conn_flush in Linux 2.6 before 2.6.13 and 2.4 before 2.4.32-pre2, when running on SMP systems, allows local users to cause a denial of service (null dereference) by causing a connection timer to expire while the connection table is being flushed before the appropriate lock is acquired.
nvd
CVE-2006-1566P4MEDIUMCVSS 4.6v3.12006-03-31
CVE-2006-1566 [MEDIUM] CVE-2006-1566: Untrusted search path vulnerability in libtunepimp-perl 0.4.2-1 in Debian GNU/Linux includes an RPAT
Untrusted search path vulnerability in libtunepimp-perl 0.4.2-1 in Debian GNU/Linux includes an RPATH value under the /tmp/buildd directory for the tunepimp.so module, which might allow local users to gain privileges by installing malicious libraries in that directory.
nvd
CVE-2019-18809P4MEDIUMCVSS 4.6v8.02019-11-07
CVE-2019-18809 [MEDIUM] CWE-401 CVE-2019-18809: A memory leak in the af9005_identify_state() function in drivers/media/usb/dvb-usb/af9005.c in the L
A memory leak in the af9005_identify_state() function in drivers/media/usb/dvb-usb/af9005.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption), aka CID-2289adbfa559.
nvd
CVE-2006-1565P4MEDIUMCVSS 4.6v3.12006-03-31
CVE-2006-1565 [MEDIUM] CVE-2006-1565: Untrusted search path vulnerability in libgpib-perl 3.2.06-2 in Debian GNU/Linux includes an RPATH v
Untrusted search path vulnerability in libgpib-perl 3.2.06-2 in Debian GNU/Linux includes an RPATH value under the /tmp/buildd directory for the LinuxGpib.so module, which might allow local users to gain privileges by installing malicious libraries in that directory.
nvd
CVE-2006-1564P4MEDIUMCVSS 4.6v3.12006-03-31
CVE-2006-1564 [MEDIUM] CVE-2006-1564: Untrusted search path vulnerability in libapache2-svn 1.3.0-4 for Subversion in Debian GNU/Linux inc
Untrusted search path vulnerability in libapache2-svn 1.3.0-4 for Subversion in Debian GNU/Linux includes RPATH values under the /tmp/svn directory for the (1) mod_authz_svn.so and (2) mod_dav_svn.so modules, which might allow local users to gain privileges by installing malicious libraries in that directory.
nvd
CVE-2019-19068P4MEDIUMCVSS 4.6v8.02019-11-18
CVE-2019-19068 [MEDIUM] CWE-401 CVE-2019-19068: A memory leak in the rtl8xxxu_submit_int_urb() function in drivers/net/wireless/realtek/rtl8xxxu/rtl
A memory leak in the rtl8xxxu_submit_int_urb() function in drivers/net/wireless/realtek/rtl8xxxu/rtl8xxxu_core.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering usb_submit_urb() failures, aka CID-a2cdd07488e6.
nvd
CVE-2003-0382P4MEDIUMCVSS 4.6v2.3v3.02003-07-02
CVE-2003-0382 [MEDIUM] CVE-2003-0382: Buffer overflow in Eterm 0.9.2 allows local users to gain privileges via a long ETERMPATH environmen
Buffer overflow in Eterm 0.9.2 allows local users to gain privileges via a long ETERMPATH environment variable.
nvd
CVE-2012-3197P4LOWCVSS 3.5v6.0v7.02012-10-17
CVE-2012-3197 [LOW] CVE-2012-3197: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.64 and earlier, and 5.5.
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.64 and earlier, and 5.5.26 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Replication.
nvd
CVE-2008-2137P4MEDIUMCVSS 4.4v4.02008-05-29
CVE-2008-2137 [MEDIUM] CWE-264 CVE-2008-2137: The (1) sparc_mmap_check function in arch/sparc/kernel/sys_sparc.c and the (2) sparc64_mmap_check fu
The (1) sparc_mmap_check function in arch/sparc/kernel/sys_sparc.c and the (2) sparc64_mmap_check function in arch/sparc64/kernel/sys_sparc.c, in the Linux kernel 2.4 before 2.4.36.5 and 2.6 before 2.6.25.3, omit some virtual-address range (aka span) checks when the mmap MAP_FIXED bit is not set, which allows local users to cause a denial of service (
nvd
CVE-2022-28201P4MEDIUMCVSS 4.4v10.0v11.02022-09-19
CVE-2022-28201 [MEDIUM] CWE-674 CVE-2022-28201: An issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2.
An issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. Users with the editinterface permission can trigger infinite recursion, because a bare local interwiki is mishandled for the mainpage message.
nvd
CVE-2016-9104P4MEDIUMCVSS 4.4v8.02016-12-09
CVE-2016-9104 [MEDIUM] CWE-190 CVE-2016-9104: Multiple integer overflows in the (1) v9fs_xattr_read and (2) v9fs_xattr_write functions in hw/9pfs/
Multiple integer overflows in the (1) v9fs_xattr_read and (2) v9fs_xattr_write functions in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allow local guest OS administrators to cause a denial of service (QEMU process crash) via a crafted offset, which triggers an out-of-bounds access.
nvd
CVE-2016-6888P4MEDIUMCVSS 4.4v8.02016-12-10
CVE-2016-6888 [MEDIUM] CWE-190 CVE-2016-6888: Integer overflow in the net_tx_pkt_init function in hw/net/net_tx_pkt.c in QEMU (aka Quick Emulator)
Integer overflow in the net_tx_pkt_init function in hw/net/net_tx_pkt.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (QEMU process crash) via the maximum fragmentation count, which triggers an unchecked multiplication and NULL pointer dereference.
nvd
CVE-2019-2945P4LOWCVSS 3.1v8.0v9.0+1 more2019-10-16
CVE-2019-2945 [LOW] CVE-2019-2945: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Su
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful
nvd
CVE-2019-9942P4LOWCVSS 3.7v9.02019-03-23
CVE-2019-9942 [LOW] CVE-2019-9942: A sandbox information disclosure exists in Twig before 1.38.0 and 2.x before 2.7.0 because, under so
A sandbox information disclosure exists in Twig before 1.38.0 and 2.x before 2.7.0 because, under some circumstances, it is possible to call the __toString() method on an object even if not allowed by the security policy in place.
nvd
CVE-2020-14798P4LOWCVSS 3.1v9.0v10.02020-10-21
CVE-2020-14798 [LOW] CVE-2020-14798: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Sup
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful
nvd
CVE-2020-29443P4LOWCVSS 3.9v9.0v10.02021-01-26
CVE-2020-29443 [LOW] CWE-125 CVE-2020-29443: ide_atapi_cmd_reply_end in hw/ide/atapi.c in QEMU 5.1.0 allows out-of-bounds read access because a b
ide_atapi_cmd_reply_end in hw/ide/atapi.c in QEMU 5.1.0 allows out-of-bounds read access because a buffer index is not validated.
nvd