Debian Linux vulnerabilities
9,956 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,956
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4169MEDIUM4296LOW358
Vulnerabilities
Page 496 of 498
CVE-2014-9496P4LOWCVSS 2.1v9.02015-01-16
CVE-2014-9496 [LOW] CVE-2014-9496: The sd2_parse_rsrc_fork function in sd2.c in libsndfile allows attackers to have unspecified impact
The sd2_parse_rsrc_fork function in sd2.c in libsndfile allows attackers to have unspecified impact via vectors related to a (1) map offset or (2) rsrc marker, which triggers an out-of-bounds read.
nvd
CVE-2014-1738P4LOWCVSS 2.1v6.0v7.02014-05-11
CVE-2014-1738 [LOW] CWE-200 CVE-2014-1738: The raw_cmd_copyout function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not p
The raw_cmd_copyout function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly restrict access to certain pointers during processing of an FDRAWCMD ioctl call, which allows local users to obtain sensitive information from kernel heap memory by leveraging write access to a /dev/fd device.
nvd
CVE-2014-9584P4LOWCVSS 2.1v7.0v8.02015-01-09
CVE-2014-9584 [LOW] CWE-20 CVE-2014-9584: The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel before 3.18.2 do
The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel before 3.18.2 does not validate a length value in the Extensions Reference (ER) System Use Field, which allows local users to obtain sensitive information from kernel memory via a crafted iso9660 image.
nvd
CVE-2014-3640P4LOWCVSS 2.1v7.02014-11-07
CVE-2014-3640 [LOW] CWE-476 CVE-2014-3640: The sosendto function in slirp/udp.c in QEMU before 2.1.2 allows local users to cause a denial of se
The sosendto function in slirp/udp.c in QEMU before 2.1.2 allows local users to cause a denial of service (NULL pointer dereference) by sending a udp packet with a value of 0 in the source port and address, which triggers access of an uninitialized socket.
nvd
CVE-2001-0069P4LOWCVSS 2.1v2.22001-02-12
CVE-2001-0069 [LOW] CVE-2001-0069: dialog before 0.9a-20000118-3bis in Debian GNU/Linux allows local users to overwrite arbitrary files
dialog before 0.9a-20000118-3bis in Debian GNU/Linux allows local users to overwrite arbitrary files via a symlink attack.
nvd
CVE-2006-1376P4LOWCVSS 2.1v3.12006-03-24
CVE-2006-1376 [LOW] CVE-2006-1376: The installation of Debian GNU/Linux 3.1r1 from the network install CD creates /var/log/debian-insta
The installation of Debian GNU/Linux 3.1r1 from the network install CD creates /var/log/debian-installer/cdebconf with world writable permissions, which allows local users to cause a denial of service (disk consumption).
nvd
CVE-2005-1855P4LOWCVSS 2.1v3.12005-08-30
CVE-2005-1855 [LOW] CVE-2005-1855: Backup Manager (backup-manager) before 0.5.8 creates backup files with world-readable default permis
Backup Manager (backup-manager) before 0.5.8 creates backup files with world-readable default permissions, which allows local users to obtain sensitive information.
nvd
CVE-2003-0618P4LOWCVSS 2.1v3.02004-05-04
CVE-2003-0618 [LOW] CVE-2003-0618: Multiple vulnerabilities in suidperl 5.6.1 and earlier allow a local user to obtain sensitive inform
Multiple vulnerabilities in suidperl 5.6.1 and earlier allow a local user to obtain sensitive information about files for which the user does not have appropriate permissions.
nvd
CVE-1999-0732P4LOWCVSS 2.1v4.01999-08-19
CVE-1999-0732 [LOW] CVE-1999-0732: The logging facility of the Debian smtp-refuser package allows local users to delete arbitrary files
The logging facility of the Debian smtp-refuser package allows local users to delete arbitrary files using symbolic links.
nvd
CVE-2015-7511P4LOWCVSS 2.0v7.0v8.02016-04-19
CVE-2015-7511 [LOW] CWE-200 CVE-2015-7511: Libgcrypt before 1.6.5 does not properly perform elliptic-point curve multiplication during decrypti
Libgcrypt before 1.6.5 does not properly perform elliptic-point curve multiplication during decryption, which makes it easier for physically proximate attackers to extract ECDH keys by measuring electromagnetic emanations.
nvd
CVE-2013-4242P4LOWCVSS 1.9v6.0v7.02013-08-19
CVE-2013-4242 [LOW] CWE-200 CVE-2013-4242: GnuPG before 1.4.14, and Libgcrypt before 1.5.3 as used in GnuPG 2.0.x and possibly other products,
GnuPG before 1.4.14, and Libgcrypt before 1.5.3 as used in GnuPG 2.0.x and possibly other products, allows local users to obtain private RSA keys via a cache side-channel attack involving the L3 cache, aka Flush+Reload.
nvd
CVE-2006-6614P4LOWCVSS 1.9v3.12006-12-18
CVE-2006-6614 [LOW] CVE-2006-6614: The save_log_local function in Fully Automatic Installation (FAI) 2.10.1, and possibly 3.1.2, when v
The save_log_local function in Fully Automatic Installation (FAI) 2.10.1, and possibly 3.1.2, when verbose mode is enabled, stores the root password hash in /var/log/fai/current/fai.log, whose file permissions allow it to be copied to other hosts when fai-savelog is called and allows attackers to obtain the hash.
nvd
CVE-2010-3876P4LOWCVSS 1.9v5.02011-01-03
CVE-2010-3876 [LOW] CWE-909 CVE-2010-3876: net/packet/af_packet.c in the Linux kernel before 2.6.37-rc2 does not properly initialize certain st
net/packet/af_packet.c in the Linux kernel before 2.6.37-rc2 does not properly initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel stack memory by leveraging the CAP_NET_RAW capability to read copies of the applicable structures.
nvd
CVE-2015-1420P4LOWCVSS 1.9v7.02015-03-16
CVE-2015-1420 [LOW] CWE-362 CVE-2015-1420: Race condition in the handle_to_path function in fs/fhandle.c in the Linux kernel through 3.19.1 all
Race condition in the handle_to_path function in fs/fhandle.c in the Linux kernel through 3.19.1 allows local users to bypass intended size restrictions and trigger read operations on additional memory locations by changing the handle_bytes value of a file handle during the execution of this function.
nvd
CVE-2001-0430P4LOWCVSS 3.6≤ 3.2.4v2.22001-07-02
CVE-2001-0430 [LOW] CVE-2001-0430: Vulnerability in exuberant-ctags before 3.2.4-0.1 insecurely creates temporary files.
Vulnerability in exuberant-ctags before 3.2.4-0.1 insecurely creates temporary files.
nvd
CVE-2006-0050P4LOWCVSS 1.2v3.0v3.12006-03-23
CVE-2006-0050 [LOW] CVE-2006-0050: snmptrapfmt in Debian 3.0 allows local users to overwrite arbitrary files via a symlink attack on a
snmptrapfmt in Debian 3.0 allows local users to overwrite arbitrary files via a symlink attack on a temporary log file.
nvd
CVE-2013-2480P4LOWCVSS 3.3v6.02013-03-07
CVE-2013-2480 [LOW] CVE-2013-2480: The RTPS and RTPS2 dissectors in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 allow remote a
The RTPS and RTPS2 dissectors in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 allow remote attackers to cause a denial of service (application crash) via a malformed packet.
nvd
CVE-2020-13659P4LOWCVSS 2.5v9.0v10.02020-06-02
CVE-2020-13659 [LOW] CWE-476 CVE-2020-13659: address_space_map in exec.c in QEMU 4.2.0 can trigger a NULL pointer dereference related to BounceBu
address_space_map in exec.c in QEMU 4.2.0 can trigger a NULL pointer dereference related to BounceBuffer.
nvd
CVE-2021-27645P4LOWCVSS 2.5v10.02021-02-24
CVE-2021-27645 [LOW] CWE-415 CVE-2021-27645: The nameserver caching daemon (nscd) in the GNU C Library (aka glibc or libc6) 2.29 through 2.33, wh
The nameserver caching daemon (nscd) in the GNU C Library (aka glibc or libc6) 2.29 through 2.33, when processing a request for netgroup lookup, may crash due to a double-free, potentially resulting in degraded service or Denial of Service on the local system. This is related to netgroupcache.c.
nvd
CVE-2022-3521P4LOWCVSS 2.5v10.02022-10-16
CVE-2022-3521 [LOW] CWE-362 CVE-2022-3521: A vulnerability has been found in Linux Kernel and classified as problematic. This vulnerability aff
A vulnerability has been found in Linux Kernel and classified as problematic. This vulnerability affects the function kcm_tx_work of the file net/kcm/kcmsock.c of the component kcm. The manipulation leads to race condition. It is recommended to apply a patch to fix this issue. VDB-211018 is the identifier assigned to this vulnerability.
nvd