cbcvebase.

Debian Linux vulnerabilities

9,956 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,956
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4169MEDIUM4296LOW358

Vulnerabilities

Page 491 of 498
CVE-2023-22006P4LOWCVSS 3.1v10.0v11.0+1 more2023-07-18
CVE-2023-22006 [LOW] CVE-2023-22006: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK produ Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 11.0.19, 17.0.7, 20.0.1; Oracle GraalVM Enterprise Edition: 20.3.10, 21.3.6, 22.3.2; Oracle GraalVM for JDK: 17.0.7 and 20.0.1. Difficult to exploit vulnerabil
nvd
CVE-2019-19126P4LOWCVSS 3.3v10.02019-11-19
CVE-2019-19126 [LOW] CWE-665 CVE-2019-19126: On the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to ignore the LD_PREFER_ On the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to ignore the LD_PREFER_MAP_32BIT_EXEC environment variable during program execution after a security transition, allowing local attackers to restrict the possible mapping addresses for loaded libraries and thus bypass ASLR for a setuid program.
nvd
CVE-2022-24448P4LOWCVSS 3.3v9.0v10.0+1 more2022-02-04
CVE-2022-24448 [LOW] CWE-755 CVE-2022-24448: An issue was discovered in fs/nfs/dir.c in the Linux kernel before 5.16.5. If an application sets th An issue was discovered in fs/nfs/dir.c in the Linux kernel before 5.16.5. If an application sets the O_DIRECTORY flag, and tries to open a regular file, nfs_atomic_open() performs a regular lookup. If a regular file is found, ENOTDIR should occur, but the server instead returns uninitialized data in the file descriptor.
nvd
CVE-2021-3655P4LOWCVSS 3.3v9.02021-08-05
CVE-2021-3655 [LOW] CWE-909 CVE-2021-3655: A vulnerability was found in the Linux kernel in versions prior to v5.14-rc1. Missing size validatio A vulnerability was found in the Linux kernel in versions prior to v5.14-rc1. Missing size validations on inbound SCTP packets may allow the kernel to read uninitialized memory.
nvd
CVE-2014-9269P4LOWCVSS 2.6v7.02015-01-09
CVE-2014-9269 [LOW] CWE-79 CVE-2014-9269: Cross-site scripting (XSS) vulnerability in helper_api.php in MantisBT 1.1.0a1 through 1.2.x before Cross-site scripting (XSS) vulnerability in helper_api.php in MantisBT 1.1.0a1 through 1.2.x before 1.2.18, when Extended project browser is enabled, allows remote attackers to inject arbitrary web script or HTML via the project cookie.
nvd
CVE-2020-13362P4LOWCVSS 3.2v8.0v9.0+1 more2020-05-28
CVE-2020-13362 [LOW] CWE-125 CVE-2020-13362: In QEMU 5.0.0 and earlier, megasas_lookup_frame in hw/scsi/megasas.c has an out-of-bounds read via a In QEMU 5.0.0 and earlier, megasas_lookup_frame in hw/scsi/megasas.c has an out-of-bounds read via a crafted reply_queue_head field from a guest OS user.
nvd
CVE-2020-11041P4LOWCVSS 2.7v10.02020-05-29
CVE-2020-11041 [LOW] CWE-129 CVE-2020-11041: In FreeRDP less than or equal to 2.0.0, an outside controlled array index is used unchecked for data In FreeRDP less than or equal to 2.0.0, an outside controlled array index is used unchecked for data used as configuration for sound backend (alsa, oss, pulse, ...). The most likely outcome is a crash of the client instance followed by no or distorted sound or a session disconnect. If a user cannot upgrade to the patched version, a workaround is to dis
nvd
CVE-2011-1499P4LOWCVSS 2.6v6.02011-04-29
CVE-2011-1499 [LOW] CWE-16 CVE-2011-1499: acl.c in Tinyproxy before 1.8.3, when an Allow configuration setting specifies a CIDR block, permits acl.c in Tinyproxy before 1.8.3, when an Allow configuration setting specifies a CIDR block, permits TCP connections from all IP addresses, which makes it easier for remote attackers to hide the origin of web traffic by leveraging the open HTTP proxy server.
nvd
CVE-2015-3340P4LOWCVSS 2.9v7.0v8.02015-04-28
CVE-2015-3340 [LOW] CWE-200 CVE-2015-3340: Xen 4.2.x through 4.5.x does not initialize certain fields, which allows certain remote service doma Xen 4.2.x through 4.5.x does not initialize certain fields, which allows certain remote service domains to obtain sensitive information from memory via a (1) XEN_DOMCTL_gettscinfo or (2) XEN_SYSCTL_getdomaininfolist request.
nvd
CVE-2021-29473P4LOWCVSS 2.5v9.0v10.02021-04-26
CVE-2021-29473 [LOW] CWE-125 CVE-2021-29473: Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds read was found in Exiv2 versions v0.27.3 and earlier. Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. The out-of-bounds read is triggered w
nvd
CVE-2022-2047P4LOWCVSS 2.7v10.0v11.02022-07-07
CVE-2022-2047 [LOW] CWE-20 CVE-2022-2047: In Eclipse Jetty versions 9.4.0 thru 9.4.46, and 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions In Eclipse Jetty versions 9.4.0 thru 9.4.46, and 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, the parsing of the authority segment of an http scheme URI, the Jetty HttpURI class improperly detects an invalid input as a hostname. This can lead to failures in a Proxy scenario.
nvd
CVE-1999-0939P4MEDIUMCVSS 5.0v2.1v2.21999-08-26
CVE-1999-0939 [MEDIUM] CVE-1999-0939: Denial of service in Debian IRC Epic/epic4 client via a long string. Denial of service in Debian IRC Epic/epic4 client via a long string.
nvd
CVE-2020-11526P4LOWCVSS 2.2v9.02020-05-15
CVE-2020-11526 [LOW] CWE-125 CVE-2020-11526: libfreerdp/core/update.c in FreeRDP versions > 1.1 through 2.0.0-rc4 has an Out-of-bounds Read. libfreerdp/core/update.c in FreeRDP versions > 1.1 through 2.0.0-rc4 has an Out-of-bounds Read.
nvd
CVE-2020-11058P4LOWCVSS 2.2v9.0v10.02020-05-12
CVE-2020-11058 [LOW] CWE-119 CVE-2020-11058: In FreeRDP after 1.1 and before 2.0.0, a stream out-of-bounds seek in rdp_read_font_capability_set c In FreeRDP after 1.1 and before 2.0.0, a stream out-of-bounds seek in rdp_read_font_capability_set could lead to a later out-of-bounds read. As a result, a manipulated client or server might force a disconnect due to an invalid data read. This has been fixed in 2.0.0.
nvd
CVE-2005-3106P4MEDIUMCVSS 4.7v3.12005-09-30
CVE-2005-3106 [MEDIUM] CWE-667 CVE-2005-3106: Race condition in Linux 2.6, when threads are sharing memory mapping via CLONE_VM (such as linuxthre Race condition in Linux 2.6, when threads are sharing memory mapping via CLONE_VM (such as linuxthreads and vfork), might allow local users to cause a denial of service (deadlock) by triggering a core dump while waiting for a thread that has just performed an exec.
nvd
CVE-2010-1451P4LOWCVSS 2.1v5.02010-05-07
CVE-2010-1451 [LOW] CWE-787 CVE-2010-1451: The TSB I-TLB load implementation in arch/sparc/kernel/tsb.S in the Linux kernel before 2.6.33 on th The TSB I-TLB load implementation in arch/sparc/kernel/tsb.S in the Linux kernel before 2.6.33 on the SPARC platform does not properly obtain the value of a certain _PAGE_EXEC_4U bit and consequently does not properly implement a non-executable stack, which makes it easier for context-dependent attackers to exploit stack-based buffer overflows via a craf
nvd
CVE-2004-0564P4LOWCVSS 2.1v3.02004-12-23
CVE-2004-0564 [LOW] CVE-2004-0564: Roaring Penguin pppoe (rp-ppoe), if installed or configured to run setuid root contrary to its desig Roaring Penguin pppoe (rp-ppoe), if installed or configured to run setuid root contrary to its design, allows local users to overwrite arbitrary files. NOTE: the developer has publicly disputed the claim that this is a vulnerability because pppoe "is NOT designed to run setuid-root." Therefore this identifier applies *only* to those configurations and installati
nvd
CVE-2015-0377P4MEDIUMCVSS 4.4v7.02015-01-21
CVE-2015-0377 [MEDIUM] CVE-2015-0377: Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.26, 4.0.28, 4.1.36, and 4.2.28 allows local users to affect availability via unknown vectors related to Core, a different vulnerability than CVE-2015-0418.
nvd
CVE-2014-8595P4LOWCVSS 1.9v7.02014-11-19
CVE-2014-8595 [LOW] CWE-17 CVE-2014-8595: arch/x86/x86_emulate/x86_emulate.c in Xen 3.2.1 through 4.4.x does not properly check privileges, wh arch/x86/x86_emulate/x86_emulate.c in Xen 3.2.1 through 4.4.x does not properly check privileges, which allows local HVM guest users to gain privileges or cause a denial of service (crash) via a crafted (1) CALL, (2) JMP, (3) RETF, (4) LCALL, (5) LJMP, or (6) LRET far branch instruction.
nvd
CVE-2017-10345P4LOWCVSS 3.1v7.0v8.0+1 more2017-10-19
CVE-2017-10345 [LOW] CVE-2017-10345: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: S Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144; JRockit: R28.3.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Ja
nvd
Debian Linux vulnerabilities | cvebase