cbcvebase.

Debian Linux vulnerabilities

9,956 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,956
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4169MEDIUM4296LOW358

Vulnerabilities

Page 493 of 498
CVE-2017-5081P4LOWCVSS 3.3v9.02017-10-27
CVE-2017-5081 [LOW] CWE-20 CVE-2017-5081: Lack of verification of an extension's locale folder in Google Chrome prior to 59.0.3071.86 for Mac, Lack of verification of an extension's locale folder in Google Chrome prior to 59.0.3071.86 for Mac, Windows, and Linux, and 59.0.3071.92 for Android, allowed an attacker with local write access to modify extensions by modifying extension files.
nvd
CVE-2021-38205P4LOWCVSS 3.3v9.02021-08-08
CVE-2021-38205 [LOW] CWE-824 CVE-2021-38205: drivers/net/ethernet/xilinx/xilinx_emaclite.c in the Linux kernel before 5.13.3 makes it easier for drivers/net/ethernet/xilinx/xilinx_emaclite.c in the Linux kernel before 5.13.3 makes it easier for attackers to defeat an ASLR protection mechanism because it prints a kernel pointer (i.e., the real IOMEM pointer).
nvd
CVE-2024-26764P4LOWCVSS 3.3v10.02024-04-03
CVE-2024-26764 [LOW] CVE-2024-26764: In the Linux kernel, the following vulnerability has been resolved: fs/aio: Restrict kiocb_set_canc In the Linux kernel, the following vulnerability has been resolved: fs/aio: Restrict kiocb_set_cancel_fn() to I/O submitted via libaio If kiocb_set_cancel_fn() is called for I/O submitted via io_uring, the following kernel warning appears: WARNING: CPU: 3 PID: 368 at fs/aio.c:598 kiocb_set_cancel_fn+0x9c/0xa8 Call trace: kiocb_set_cancel_fn+0x9c/0xa8 ffs_epf
nvd
CVE-2021-3392P4LOWCVSS 3.2v9.0v10.02021-03-23
CVE-2021-3392 [LOW] CWE-416 CVE-2021-3392: A use-after-free flaw was found in the MegaRAID emulator of QEMU. This issue occurs while processing A use-after-free flaw was found in the MegaRAID emulator of QEMU. This issue occurs while processing SCSI I/O requests in the case of an error mptsas_free_request() that does not dequeue the request object 'req' from a pending requests queue. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service.
nvd
CVE-2019-13762P4LOWCVSS 3.3v9.0v10.02019-12-10
CVE-2019-13762 [LOW] CWE-667 CVE-2019-13762: Insufficient policy enforcement in downloads in Google Chrome on Windows prior to 79.0.3945.79 allow Insufficient policy enforcement in downloads in Google Chrome on Windows prior to 79.0.3945.79 allowed a local attacker to spoof downloaded files via local code.
nvd
CVE-2020-11040P4LOWCVSS 2.7v10.02020-05-29
CVE-2020-11040 [LOW] CWE-125 CVE-2020-11040: In FreeRDP less than or equal to 2.0.0, there is an out-of-bound data read from memory in clear_deco In FreeRDP less than or equal to 2.0.0, there is an out-of-bound data read from memory in clear_decompress_subcode_rlex, visualized on screen as color. This has been patched in 2.1.0.
nvd
CVE-2024-30204P4LOWCVSS 2.8v10.02024-03-25
CVE-2024-30204 [LOW] CWE-276 CVE-2024-30204: In Emacs before 29.3, LaTeX preview is enabled by default for e-mail attachments. In Emacs before 29.3, LaTeX preview is enabled by default for e-mail attachments.
nvd
CVE-2020-11048P4LOWCVSS 2.2v9.0v10.02020-05-07
CVE-2020-11048 [LOW] CWE-125 CVE-2020-11048: In FreeRDP after 1.0 and before 2.0.0, there is an out-of-bounds read. It only allows to abort a ses In FreeRDP after 1.0 and before 2.0.0, there is an out-of-bounds read. It only allows to abort a session. No data extraction is possible. This has been fixed in 2.0.0.
nvd
CVE-2020-11525P4LOWCVSS 2.2v9.02020-05-15
CVE-2020-11525 [LOW] CWE-125 CVE-2020-11525: libfreerdp/cache/bitmap.c in FreeRDP versions > 1.0 through 2.0.0-rc4 has an Out of bounds read. libfreerdp/cache/bitmap.c in FreeRDP versions > 1.0 through 2.0.0-rc4 has an Out of bounds read.
nvd
CVE-2020-11049P4LOWCVSS 2.2v10.02020-05-07
CVE-2020-11049 [LOW] CWE-125 CVE-2020-11049: In FreeRDP after 1.1 and before 2.0.0, there is an out-of-bound read of client memory that is then p In FreeRDP after 1.1 and before 2.0.0, there is an out-of-bound read of client memory that is then passed on to the protocol parser. This has been patched in 2.0.0.
nvd
CVE-2005-0078P4MEDIUMCVSS 4.6v3.02005-05-02
CVE-2005-0078 [MEDIUM] CVE-2005-0078: The KDE screen saver in KDE before 3.0.5 does not properly check the return value from a certain fun The KDE screen saver in KDE before 3.0.5 does not properly check the return value from a certain function call, which allows attackers with physical access to cause a crash and access the desktop session.
nvd
CVE-1999-1565P4MEDIUMCVSS 4.6v4.01999-08-20
CVE-1999-1565 [MEDIUM] CVE-1999-1565: Man2html 2.1 and earlier allows local users to overwrite arbitrary files via a symlink attack on a t Man2html 2.1 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file.
nvd
CVE-2005-3055P4LOWCVSS 2.1v3.12005-09-26
CVE-2005-3055 [LOW] CWE-20 CVE-2005-3055: Linux kernel 2.6.8 to 2.6.14-rc2 allows local users to cause a denial of service (kernel OOPS) via a Linux kernel 2.6.8 to 2.6.14-rc2 allows local users to cause a denial of service (kernel OOPS) via a userspace process that issues a USB Request Block (URB) to a USB device and terminates before the URB is finished, which leads to a stale pointer reference.
nvd
CVE-2005-2960P4LOWCVSS 2.1v3.12005-10-05
CVE-2005-2960 [LOW] CVE-2005-2960: cfengine 1.6.5 and 2.1.16 allows local users to overwrite arbitrary files via a symlink attack on te cfengine 1.6.5 and 2.1.16 allows local users to overwrite arbitrary files via a symlink attack on temporary files used by vicf.in, a different vulnerability than CVE-2005-3137.
nvd
CVE-2017-3317P4MEDIUMCVSS 4.0v8.02017-01-27
CVE-2017-3317 [MEDIUM] CVE-2017-3317: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Logging). Supported versi Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Logging). Supported versions that are affected are 5.5.53 and earlier, 5.6.34 and earlier and 5.7.16 and earlier. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attac
nvd
CVE-2018-0361P4LOWCVSS 3.3v8.02018-07-16
CVE-2018-0361 [LOW] CWE-20 CVE-2018-0361: ClamAV before 0.100.1 lacks a PDF object length check, resulting in an unreasonably long time to par ClamAV before 0.100.1 lacks a PDF object length check, resulting in an unreasonably long time to parse a relatively small file.
nvd
CVE-2020-27818P4LOWCVSS 3.3v9.02020-12-08
CVE-2020-27818 [LOW] CWE-120 CVE-2020-27818: A flaw was found in the check_chunk_name() function of pngcheck-2.4.0. An attacker able to pass a ma A flaw was found in the check_chunk_name() function of pngcheck-2.4.0. An attacker able to pass a malicious file to be processed by pngcheck could cause a temporary denial of service, posing a low risk to application availability.
nvd
CVE-2018-6053P4LOWCVSS 3.3v8.0v9.02018-09-25
CVE-2018-6053 [LOW] CWE-200 CVE-2018-6053: Inappropriate implementation in New Tab Page in Google Chrome prior to 64.0.3282.119 allowed a local Inappropriate implementation in New Tab Page in Google Chrome prior to 64.0.3282.119 allowed a local attacker to view website thumbnail images after clearing browser data via a crafted HTML page.
nvd
CVE-2019-13232P4LOWCVSS 3.3v8.02019-07-04
CVE-2019-13232 [LOW] CWE-400 CVE-2019-13232: Info-ZIP UnZip 6.0 mishandles the overlapping of files inside a ZIP container, leading to denial of Info-ZIP UnZip 6.0 mishandles the overlapping of files inside a ZIP container, leading to denial of service (resource consumption), aka a "better zip bomb" issue.
nvd
CVE-2023-2602P4LOWCVSS 3.3v10.0v11.0+1 more2023-06-06
CVE-2023-2602 [LOW] CWE-401 CVE-2023-2602: A vulnerability was found in the pthread_create() function in libcap. This issue may allow a malicio A vulnerability was found in the pthread_create() function in libcap. This issue may allow a malicious actor to use cause __real_pthread_create() to return an error, which can exhaust the process memory.
nvd
Debian Linux vulnerabilities | cvebase