cbcvebase.

Debian Linux vulnerabilities

9,956 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,956
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4169MEDIUM4296LOW358

Vulnerabilities

Page 495 of 498
CVE-2014-7824P4LOWCVSS 2.1v7.0v8.02014-11-18
CVE-2014-7824 [LOW] CVE-2014-7824: D-Bus 1.3.0 through 1.6.x before 1.6.26, 1.8.x before 1.8.10, and 1.9.x before 1.9.2 allows local us D-Bus 1.3.0 through 1.6.x before 1.6.26, 1.8.x before 1.8.10, and 1.9.x before 1.9.2 allows local users to cause a denial of service (prevention of new connections and connection drop) by queuing the maximum number of file descriptors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-3636.1.
nvd
CVE-2014-9585P4LOWCVSS 2.1v7.0v8.02015-01-09
CVE-2014-9585 [LOW] CVE-2014-9585: The vdso_addr function in arch/x86/vdso/vma.c in the Linux kernel through 3.18.2 does not properly c The vdso_addr function in arch/x86/vdso/vma.c in the Linux kernel through 3.18.2 does not properly choose memory locations for the vDSO area, which makes it easier for local users to bypass the ASLR protection mechanism by guessing a location at the end of a PMD.
nvd
CVE-2009-1186P4LOWCVSS 2.1v4.0v5.02009-04-17
CVE-2009-1186 [LOW] CWE-120 CVE-2009-1186: Buffer overflow in the util_path_encode function in udev/lib/libudev-util.c in udev before 1.4.1 all Buffer overflow in the util_path_encode function in udev/lib/libudev-util.c in udev before 1.4.1 allows local users to cause a denial of service (service outage) via vectors that trigger a call with crafted arguments.
nvd
CVE-2014-5270P4LOWCVSS 2.1v7.02014-10-10
CVE-2014-5270 [LOW] CVE-2014-5270: Libgcrypt before 1.5.4, as used in GnuPG and other products, does not properly perform ciphertext no Libgcrypt before 1.5.4, as used in GnuPG and other products, does not properly perform ciphertext normalization and ciphertext randomization, which makes it easier for physically proximate attackers to conduct key-extraction attacks by leveraging the ability to collect voltage data from exposed metal, a different vector than CVE-2013-4576.
nvd
CVE-2014-3532P4LOWCVSS 2.1v7.02014-07-19
CVE-2014-3532 [LOW] CWE-20 CVE-2014-3532: dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6, when running on Linux 2.6.37-rc4 or later, allows l dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6, when running on Linux 2.6.37-rc4 or later, allows local users to cause a denial of service (system-bus disconnect of other services or applications) by sending a message containing a file descriptor, then exceeding the maximum recursion depth before the initial message is forwarded.
nvd
CVE-2003-0367P4LOWCVSS 2.1v2.2v3.02003-07-02
CVE-2003-0367 [LOW] CWE-20 CVE-2003-0367: znew in the gzip package allows local users to overwrite arbitrary files via a symlink attack on tem znew in the gzip package allows local users to overwrite arbitrary files via a symlink attack on temporary files.
nvd
CVE-2014-3533P4LOWCVSS 2.1v7.02014-07-19
CVE-2014-3533 [LOW] CWE-20 CVE-2014-3533: dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6 allows local users to cause a denial of service (dis dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6 allows local users to cause a denial of service (disconnect) via a certain sequence of crafted messages that cause the dbus-daemon to forward a message containing an invalid file descriptor.
nvd
CVE-2005-0077P4LOWCVSS 2.1v3.02005-05-02
CVE-2005-0077 [LOW] CVE-2005-0077: The DBI library (libdbi-perl) for Perl allows local users to overwrite arbitrary files via a symlink The DBI library (libdbi-perl) for Perl allows local users to overwrite arbitrary files via a symlink attack on a temporary PID file.
nvd
CVE-2015-2830P4LOWCVSS 1.9v7.0v8.02015-05-27
CVE-2015-2830 [LOW] CWE-264 CVE-2015-2830: arch/x86/kernel/entry_64.S in the Linux kernel before 3.19.2 does not prevent the TS_COMPAT flag fro arch/x86/kernel/entry_64.S in the Linux kernel before 3.19.2 does not prevent the TS_COMPAT flag from reaching a user-mode task, which might allow local users to bypass the seccomp or audit protection mechanism via a crafted application that uses the (1) fork or (2) close system call, as demonstrated by an attack against seccomp before 3.16.
nvd
CVE-2010-3310P4LOWCVSS 1.9v5.02010-09-29
CVE-2010-3310 [LOW] CWE-189 CVE-2010-3310: Multiple integer signedness errors in net/rose/af_rose.c in the Linux kernel before 2.6.36-rc5-next- Multiple integer signedness errors in net/rose/af_rose.c in the Linux kernel before 2.6.36-rc5-next-20100923 allow local users to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a rose_getname function call, related to the rose_bind and rose_connect functions.
nvd
CVE-2002-0044P4LOWCVSS 3.6v2.22002-01-31
CVE-2002-0044 [LOW] CVE-2002-0044: GNU Enscript 1.6.1 and earlier allows local users to overwrite arbitrary files of the Enscript user GNU Enscript 1.6.1 and earlier allows local users to overwrite arbitrary files of the Enscript user via a symlink attack on temporary files.
nvd
CVE-2001-0139P4LOWCVSS 1.2v2.22001-03-12
CVE-2001-0139 [LOW] CVE-2001-0139: inn 2.2.3 allows local users to overwrite arbitrary files via a symlink attack in some configuration inn 2.2.3 allows local users to overwrite arbitrary files via a symlink attack in some configurations.
nvd
CVE-2001-0125P4LOWCVSS 1.2v2.22001-03-12
CVE-2001-0125 [LOW] CVE-2001-0125: exmh 2.2 and earlier allows local users to overwrite arbitrary files via a symlink attack on the exm exmh 2.2 and earlier allows local users to overwrite arbitrary files via a symlink attack on the exmhErrorMsg temporary file.
nvd
CVE-2013-2484P4LOWCVSS 3.3v7.02013-03-07
CVE-2013-2484 [LOW] CVE-2013-2484: The CIMD dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 allows remote attackers t The CIMD dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (application crash) via a malformed packet.
nvd
CVE-2001-0138P4LOWCVSS 1.2v2.22001-03-12
CVE-2001-0138 [LOW] CVE-2001-0138: privatepw program in wu-ftpd before 2.6.1-6 allows local users to overwrite arbitrary files via a sy privatepw program in wu-ftpd before 2.6.1-6 allows local users to overwrite arbitrary files via a symlink attack.
nvd
CVE-2013-7458P4LOWCVSS 3.3v8.02016-08-10
CVE-2013-7458 [LOW] CWE-200 CVE-2013-7458: linenoise, as used in Redis before 3.2.3, uses world-readable permissions for .rediscli_history, whi linenoise, as used in Redis before 3.2.3, uses world-readable permissions for .rediscli_history, which allows local users to obtain sensitive information by reading the file.
nvd
CVE-2022-3633P4LOWCVSS 3.3v10.02022-10-21
CVE-2022-3633 [LOW] CWE-401 CVE-2022-3633: A vulnerability classified as problematic has been found in Linux Kernel. Affected is the function j A vulnerability classified as problematic has been found in Linux Kernel. Affected is the function j1939_session_destroy of the file net/can/j1939/transport.c. The manipulation leads to memory leak. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211932.
nvd
CVE-2020-2933P4LOWCVSS 2.2v8.0v9.02020-04-15
CVE-2020-2933 [LOW] CVE-2020-2933: Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported ve Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 5.1.48 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized ability
nvd
CVE-2019-19534P4LOWCVSS 2.4v8.02019-12-03
CVE-2019-19534 [LOW] CWE-909 CVE-2019-19534: In the Linux kernel before 5.3.11, there is an info-leak bug that can be caused by a malicious USB d In the Linux kernel before 5.3.11, there is an info-leak bug that can be caused by a malicious USB device in the drivers/net/can/usb/peak_usb/pcan_usb_core.c driver, aka CID-f7a1337f0d29.
nvd
CVE-2000-1135P4MEDIUMCVSS 4.6v2.1v2.22001-01-09
CVE-2000-1135 [MEDIUM] CVE-2000-1135: fshd (fsh daemon) in Debian GNU/Linux allows local users to overwrite files of other users via a sym fshd (fsh daemon) in Debian GNU/Linux allows local users to overwrite files of other users via a symlink attack.
nvd
Debian Linux vulnerabilities | cvebase