Debian Linux vulnerabilities
9,956 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,956
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4169MEDIUM4296LOW358
Vulnerabilities
Page 489 of 498
CVE-2016-3159P4LOWCVSS 3.8v8.02016-04-13
CVE-2016-3159 [LOW] CVE-2016-3159: The fpu_fxrstor function in arch/x86/i387.c in Xen 4.x does not properly handle writes to the hardwa
The fpu_fxrstor function in arch/x86/i387.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content information from another guest by leveraging pending exception and mask bits. NOTE: this vulnerability exists because of an incorrect fix for CVE
nvd
CVE-2017-3539P4LOWCVSS 3.1v8.02017-04-24
CVE-2017-3539 [LOW] CVE-2017-3539: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security).
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u141, 7u131 and 8u121; Java SE Embedded: 8u121. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful at
nvd
CVE-2021-34428P4LOWCVSS 3.5v10.02021-06-22
CVE-2021-34428 [LOW] CWE-613 CVE-2021-34428: For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the Sessi
For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments with clustered sessions and multiple contexts this can result in a session not being invalidated. This can result in an application use
nvd
CVE-2016-2380P4LOWCVSS 3.1v8.02017-01-06
CVE-2016-2380 [LOW] CWE-125 CVE-2016-2380: An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT da
An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent to the server could potentially result in an out-of-bounds read. A user could be convinced to enter a particular string which would then get converted incorrectly and could lead to a potential out-of-bounds read.
nvd
CVE-2018-16866P4LOWCVSS 3.3v9.02019-01-11
CVE-2018-16866 [LOW] CWE-125 CVE-2018-16866: An out of bounds read was discovered in systemd-journald in the way it parses log messages that term
An out of bounds read was discovered in systemd-journald in the way it parses log messages that terminate with a colon ':'. A local attacker can use this flaw to disclose process memory data. Versions from v221 to v239 are vulnerable.
nvd
CVE-2018-2767P4LOWCVSS 3.1v8.0v9.02018-07-18
CVE-2018-2767 [LOW] CVE-2018-2767: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Encrypt
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Encryption). Supported versions that are affected are 5.5.60 and prior, 5.6.40 and prior and 5.7.22 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of t
nvd
CVE-2020-15005P4LOWCVSS 3.1v9.0v10.02020-06-24
CVE-2020-15005 [LOW] CVE-2020-15005: In MediaWiki before 1.31.8, 1.32.x and 1.33.x before 1.33.4, and 1.34.x before 1.34.2, private wikis
In MediaWiki before 1.31.8, 1.32.x and 1.33.x before 1.33.4, and 1.34.x before 1.34.2, private wikis behind a caching server using the img_auth.php image authorization security feature may have had their files cached publicly, so any unauthorized user could view them. This occurs because Cache-Control and Vary headers were mishandled.
nvd
CVE-2019-19057P4LOWCVSS 3.3v8.02019-11-18
CVE-2019-19057 [LOW] CWE-401 CVE-2019-19057: Two memory leaks in the mwifiex_pcie_init_evt_ring() function in drivers/net/wireless/marvell/mwifie
Two memory leaks in the mwifiex_pcie_init_evt_ring() function in drivers/net/wireless/marvell/mwifiex/pcie.c in the Linux kernel through 5.3.11 allow attackers to cause a denial of service (memory consumption) by triggering mwifiex_map_pci_memory() failures, aka CID-d10dcb615c8e.
nvd
CVE-2022-33981P4LOWCVSS 3.3v9.0v10.02022-06-18
CVE-2022-33981 [LOW] CWE-416 CVE-2022-33981: drivers/block/floppy.c in the Linux kernel before 5.17.6 is vulnerable to a denial of service, becau
drivers/block/floppy.c in the Linux kernel before 5.17.6 is vulnerable to a denial of service, because of a concurrency use-after-free flaw after deallocating raw_cmd in the raw_cmd_ioctl function.
nvd
CVE-2019-17055P4LOWCVSS 3.3v8.02019-10-01
CVE-2019-17055 [LOW] CWE-862 CVE-2019-17055: base_sock_create in drivers/isdn/mISDN/socket.c in the AF_ISDN network module in the Linux kernel th
base_sock_create in drivers/isdn/mISDN/socket.c in the AF_ISDN network module in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means that unprivileged users can create a raw socket, aka CID-b91ee4aa2a21.
nvd
CVE-2015-0858P4LOWCVSS 3.3v8.02016-05-06
CVE-2015-0858 [LOW] CWE-59 CVE-2015-0858: Cool Projects TarDiff allows local users to write to arbitrary files via a symlink attack on a pathn
Cool Projects TarDiff allows local users to write to arbitrary files via a symlink attack on a pathname in a /tmp/tardiff-$$ temporary directory.
nvd
CVE-2019-13033P4LOWCVSS 3.3v8.0v9.02020-06-18
CVE-2019-13033 [LOW] CWE-200 CVE-2019-13033: In CISOfy Lynis 2.x through 2.7.5, the license key can be obtained by looking at the process list wh
In CISOfy Lynis 2.x through 2.7.5, the license key can be obtained by looking at the process list when a data upload is being performed. This license can be used to upload data to a central Lynis server. Although no data can be extracted by knowing the license key, it may be possible to upload the data of additional scans.
nvd
CVE-2009-3614P4LOWCVSS 3.3v8.0v9.0+1 more2019-11-09
CVE-2009-3614 [LOW] CWE-20 CVE-2009-3614: liboping 1.3.2 allows users reading arbitrary files upon the local system.
liboping 1.3.2 allows users reading arbitrary files upon the local system.
nvd
CVE-2020-4049P4LOWCVSS 2.4v8.0v9.0+1 more2020-06-12
CVE-2020-4049 [LOW] CWE-80 CVE-2020-4049: In affected versions of WordPress, when uploading themes, the name of the theme folder can be crafte
In affected versions of WordPress, when uploading themes, the name of the theme folder can be crafted in a way that could lead to JavaScript execution in /wp-admin on the themes page. This does require an admin to upload the theme, and is low severity self-XSS. This has been patched in version 5.4.2, along with all the previously affected versions via a m
nvd
CVE-2014-5240P4LOWCVSS 2.1v7.02014-08-18
CVE-2014-5240 [LOW] CWE-79 CVE-2014-5240: Cross-site scripting (XSS) vulnerability in wp-includes/pluggable.php in WordPress before 3.9.2, whe
Cross-site scripting (XSS) vulnerability in wp-includes/pluggable.php in WordPress before 3.9.2, when Multisite is enabled, allows remote authenticated administrators to inject arbitrary web script or HTML, and obtain Super Admin privileges, via a crafted avatar URL.
nvd
CVE-2020-11044P4LOWCVSS 2.2v10.02020-05-07
CVE-2020-11044 [LOW] CWE-415 CVE-2020-11044: In FreeRDP greater than 1.2 and before 2.0.0, a double free in update_read_cache_bitmap_v3_order cra
In FreeRDP greater than 1.2 and before 2.0.0, a double free in update_read_cache_bitmap_v3_order crashes the client application if corrupted data from a manipulated server is parsed. This has been patched in 2.0.0.
nvd
CVE-2021-23239P4LOWCVSS 2.5v10.02021-01-12
CVE-2021-23239 [LOW] CWE-59 CVE-2021-23239: The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitra
The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existence tests by winning a sudo_edit.c race condition in replacing a user-controlled directory by a symlink to an arbitrary path.
nvd
CVE-2006-4093P4MEDIUMCVSS 4.9v3.12006-08-21
CVE-2006-4093 [MEDIUM] CVE-2006-4093: Linux kernel 2.x.6 before 2.6.17.9 and 2.4.x before 2.4.33.1 on PowerPC PPC970 systems allows local
Linux kernel 2.x.6 before 2.6.17.9 and 2.4.x before 2.4.33.1 on PowerPC PPC970 systems allows local users to cause a denial of service (crash) related to the "HID0 attention enable on PPC970 at boot time."
nvd
CVE-2009-4895P4MEDIUMCVSS 4.7v5.02010-09-08
CVE-2009-4895 [MEDIUM] CWE-362 CVE-2009-4895: Race condition in the tty_fasync function in drivers/char/tty_io.c in the Linux kernel before 2.6.32
Race condition in the tty_fasync function in drivers/char/tty_io.c in the Linux kernel before 2.6.32.6 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via unknown vectors, related to the put_tty_queue and __f_setown functions. NOTE: the vulnerability was addressed in
nvd
CVE-2011-0783P4MEDIUMCVSS 4.3v6.0v7.02011-02-04
CVE-2011-0783 [MEDIUM] CVE-2011-0783: Unspecified vulnerability in Google Chrome before 9.0.597.84 allows user-assisted remote attackers t
Unspecified vulnerability in Google Chrome before 9.0.597.84 allows user-assisted remote attackers to cause a denial of service (application crash) via vectors involving a "bad volume setting."
nvd