Debian Linux vulnerabilities
9,956 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,956
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4169MEDIUM4296LOW358
Vulnerabilities
Page 494 of 498
CVE-2024-35935P4LOWCVSS 3.3v10.02024-05-19
CVE-2024-35935 [LOW] CWE-209 CVE-2024-35935: In the Linux kernel, the following vulnerability has been resolved: btrfs: send: handle path ref un
In the Linux kernel, the following vulnerability has been resolved:
btrfs: send: handle path ref underflow in header iterate_inode_ref()
Change BUG_ON to proper error handling if building the path buffer
fails. The pointers are not printed so we don't accidentally leak kernel
addresses.
nvd
CVE-2020-25723P4LOWCVSS 3.2v10.02020-12-02
CVE-2020-25723 [LOW] CWE-617 CVE-2020-25723: A reachable assertion issue was found in the USB EHCI emulation code of QEMU. It could occur while p
A reachable assertion issue was found in the USB EHCI emulation code of QEMU. It could occur while processing USB requests due to missing handling of DMA memory map failure. A malicious privileged user within the guest may abuse this flaw to send bogus USB requests and crash the QEMU process on the host, resulting in a denial of service.
nvd
CVE-2020-25084P4LOWCVSS 3.2v9.0v10.02020-09-25
CVE-2020-25084 [LOW] CWE-416 CVE-2020-25084: QEMU 5.0.0 has a use-after-free in hw/usb/hcd-xhci.c because the usb_packet_map return value is not
QEMU 5.0.0 has a use-after-free in hw/usb/hcd-xhci.c because the usb_packet_map return value is not checked.
nvd
CVE-2013-2481P4LOWCVSS 2.9v6.02013-03-07
CVE-2013-2481 [LOW] CWE-189 CVE-2013-2481: Integer signedness error in the dissect_mount_dirpath_call function in epan/dissectors/packet-mount.
Integer signedness error in the dissect_mount_dirpath_call function in epan/dissectors/packet-mount.c in the Mount dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6, when nfs_file_name_snooping is enabled, allows remote attackers to cause a denial of service (application crash) via a negative length value.
nvd
CVE-2020-11046P4LOWCVSS 2.2v9.0v10.02020-05-07
CVE-2020-11046 [LOW] CWE-119 CVE-2020-11046: In FreeRDP after 1.0 and before 2.0.0, there is a stream out-of-bounds seek in update_read_synchroni
In FreeRDP after 1.0 and before 2.0.0, there is a stream out-of-bounds seek in update_read_synchronize that could lead to a later out-of-bounds read.
nvd
CVE-1999-1330P4MEDIUMCVSS 4.6v4.01999-12-31
CVE-1999-1330 [MEDIUM] CVE-1999-1330: The snprintf function in the db library 1.85.4 ignores the size parameter, which could allow attacke
The snprintf function in the db library 1.85.4 ignores the size parameter, which could allow attackers to exploit buffer overflows that would be prevented by a properly implemented snprintf.
nvd
CVE-2005-3181P4LOWCVSS 2.1v3.12005-10-12
CVE-2005-3181 [LOW] CWE-401 CVE-2005-3181: The audit system in Linux kernel 2.6.6, and other versions before 2.6.13.4, when CONFIG_AUDITSYSCALL
The audit system in Linux kernel 2.6.6, and other versions before 2.6.13.4, when CONFIG_AUDITSYSCALL is enabled, uses an incorrect function to free names_cache memory, which prevents the memory from being tracked by AUDITSYSCALL code and leads to a memory leak that allows attackers to cause a denial of service (memory consumption).
nvd
CVE-2013-4969P4LOWCVSS 2.1v6.0v7.0+1 more2014-01-07
CVE-2013-4969 [LOW] CWE-59 CVE-2013-4969: Puppet before 3.3.3 and 3.4 before 3.4.1 and Puppet Enterprise (PE) before 2.8.4 and 3.1 before 3.1.
Puppet before 3.3.3 and 3.4 before 3.4.1 and Puppet Enterprise (PE) before 2.8.4 and 3.1 before 3.1.1 allows local users to overwrite arbitrary files via a symlink attack on unspecified files.
nvd
CVE-2000-0366P4LOWCVSS 2.1v2.11999-12-02
CVE-2000-0366 [LOW] CVE-2000-0366: dump in Debian GNU/Linux 2.1 does not properly restore symlinks, which allows a local user to modify
dump in Debian GNU/Linux 2.1 does not properly restore symlinks, which allows a local user to modify the ownership of arbitrary files.
nvd
CVE-2004-0770P4LOWCVSS 2.1v3.02005-01-10
CVE-2004-0770 [LOW] CVE-2004-0770: romload.c in DGen Emulator 1.23 and earlier allows local users to overwrite arbitrary files via a sy
romload.c in DGen Emulator 1.23 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files during decompression of (1) gzip or (2) bzip ROM files.
nvd
CVE-2012-4048P4LOWCVSS 3.3v6.02012-07-24
CVE-2012-4048 [LOW] CWE-94 CVE-2012-4048: The PPP dissector in Wireshark 1.4.x before 1.4.14, 1.6.x before 1.6.9, and 1.8.x before 1.8.1 allow
The PPP dissector in Wireshark 1.4.x before 1.4.14, 1.6.x before 1.6.9, and 1.8.x before 1.8.1 allows remote attackers to cause a denial of service (invalid pointer dereference and application crash) via a crafted packet, as demonstrated by a usbmon dump.
nvd
CVE-2006-1753P4LOWCVSS 3.6v3.12006-04-18
CVE-2006-1753 [LOW] CVE-2006-1753: A cron job in fcheck before 2.7.59 allows local users to overwrite arbitrary files via a symlink att
A cron job in fcheck before 2.7.59 allows local users to overwrite arbitrary files via a symlink attack on a temporary file.
nvd
CVE-2013-2483P4LOWCVSS 3.3v7.02013-03-07
CVE-2013-2483 [LOW] CWE-189 CVE-2013-2483: The acn_add_dmp_data function in epan/dissectors/packet-acn.c in the ACN dissector in Wireshark 1.6.
The acn_add_dmp_data function in epan/dissectors/packet-acn.c in the ACN dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via an invalid count value in ACN_DMP_ADT_D_RE DMP data.
nvd
CVE-2001-1331P4LOWCVSS 1.2v2.22001-05-03
CVE-2001-1331 [LOW] CVE-2001-1331: mandb in the man-db package before 2.3.16-3 allows local users to overwrite arbitrary files via the
mandb in the man-db package before 2.3.16-3 allows local users to overwrite arbitrary files via the command line options (1) -u or (2) -c, which do not drop privileges and follow symlinks.
nvd
CVE-2012-6655P4LOWCVSS 3.3v8.0v9.0+1 more2019-11-27
CVE-2012-6655 [LOW] CWE-732 CVE-2012-6655: An issue exists AccountService 0.6.37 in the user_change_password_authorized_cb() function in user.c
An issue exists AccountService 0.6.37 in the user_change_password_authorized_cb() function in user.c which could let a local users obtain encrypted passwords.
nvd
CVE-2017-17864P4LOWCVSS 3.3v9.02017-12-27
CVE-2017-17864 [LOW] CWE-200 CVE-2017-17864: kernel/bpf/verifier.c in the Linux kernel through 4.14.8 mishandles states_equal comparisons between
kernel/bpf/verifier.c in the Linux kernel through 4.14.8 mishandles states_equal comparisons between the pointer data type and the UNKNOWN_VALUE data type, which allows local users to obtain potentially sensitive address information, aka a "pointer leak."
nvd
CVE-2020-24512P4LOWCVSS 3.3v10.02021-06-09
CVE-2020-24512 [LOW] CWE-203 CVE-2020-24512: Observable timing discrepancy in some Intel(R) Processors may allow an authenticated user to potenti
Observable timing discrepancy in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
nvd
CVE-2022-3629P4LOWCVSS 3.3v10.02022-10-21
CVE-2022-3629 [LOW] CWE-401 CVE-2022-3629: A vulnerability was found in Linux Kernel. It has been declared as problematic. This vulnerability a
A vulnerability was found in Linux Kernel. It has been declared as problematic. This vulnerability affects the function vsock_connect of the file net/vmw_vsock/af_vsock.c. The manipulation leads to memory leak. The complexity of an attack is rather high. The exploitation appears to be difficult. It is recommended to apply a patch to fix this issue. VDB-2
nvd
CVE-2022-26354P4LOWCVSS 3.2v9.0v10.02022-03-16
CVE-2022-26354 [LOW] CWE-772 CVE-2022-26354: A flaw was found in the vhost-vsock device of QEMU. In case of error, an invalid element was not det
A flaw was found in the vhost-vsock device of QEMU. In case of error, an invalid element was not detached from the virtqueue before freeing its memory, leading to memory leakage and other unexpected results. Affected QEMU versions <= 6.2.0.
nvd
CVE-2020-29480P4LOWCVSS 2.3v10.02020-12-15
CVE-2020-29480 [LOW] CWE-862 CVE-2020-29480: An issue was discovered in Xen through 4.14.x. Neither xenstore implementation does any permission c
An issue was discovered in Xen through 4.14.x. Neither xenstore implementation does any permission checks when reporting a xenstore watch event. A guest administrator can watch the root xenstored node, which will cause notifications for every created, modified, and deleted key. A guest administrator can also use the special watches, which will cause a
nvd