Debian Linux vulnerabilities
9,956 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,956
CISA KEV
121
actively exploited
Public exploits
461
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4169MEDIUM4296LOW358
Vulnerabilities
Page 497 of 498
CVE-2020-15469P4LOWCVSS 2.3v9.0v10.02020-07-02
CVE-2020-15469 [LOW] CWE-476 CVE-2020-15469: In QEMU 4.2.0, a MemoryRegionOps object may lack read/write callback methods, leading to a NULL poin
In QEMU 4.2.0, a MemoryRegionOps object may lack read/write callback methods, leading to a NULL pointer dereference.
nvd
CVE-1999-1572P4LOWCVSS 2.1v3.01996-07-16
CVE-1999-1572 [LOW] CVE-1999-1572: cpio on FreeBSD 2.1.0, Debian GNU/Linux 3.0, and possibly other operating systems, uses a 0 umask wh
cpio on FreeBSD 2.1.0, Debian GNU/Linux 3.0, and possibly other operating systems, uses a 0 umask when creating files using the -O (archive) or -F options, which creates the files with mode 0666 and allows local users to read or overwrite those files.
nvd
CVE-1999-1496P4LOWCVSS 2.1v2.11999-06-08
CVE-1999-1496 [LOW] CVE-1999-1496: Sudo 1.5 in Debian Linux 2.1 and Red Hat 6.0 allows local users to determine the existence of arbitr
Sudo 1.5 in Debian Linux 2.1 and Red Hat 6.0 allows local users to determine the existence of arbitrary files by attempting to execute the target filename as a program, which generates a different error message when the file does not exist.
nvd
CVE-2014-3615P4LOWCVSS 2.1v7.02014-11-01
CVE-2014-3615 [LOW] CWE-200 CVE-2014-3615: The VGA emulator in QEMU allows local guest users to read host memory by setting the display to a hi
The VGA emulator in QEMU allows local guest users to read host memory by setting the display to a high resolution.
nvd
CVE-2015-4813P4LOWCVSS 2.1v7.0v8.0+1 more2015-10-21
CVE-2015-4813 [LOW] CVE-2015-4813: Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 4.0.34, 4.1.42, 4.2.34, 4.3.32, and 5.0.8, when using a Windows guest, allows local users to affect availability via unknown vectors related to Core.
nvd
CVE-2007-2875P4LOWCVSS 2.1v3.12007-06-11
CVE-2007-2875 [LOW] CWE-189 CVE-2007-2875: Integer underflow in the cpuset_tasks_read function in the Linux kernel before 2.6.20.13, and 2.6.21
Integer underflow in the cpuset_tasks_read function in the Linux kernel before 2.6.20.13, and 2.6.21.x before 2.6.21.4, when the cpuset filesystem is mounted, allows local users to obtain kernel memory contents by using a large offset when reading the /dev/cpuset/tasks file.
nvd
CVE-2010-2226P4LOWCVSS 2.1v5.02010-09-03
CVE-2010-2226 [LOW] CWE-200 CVE-2010-2226: The xfs_swapext function in fs/xfs/xfs_dfrag.c in the Linux kernel before 2.6.35 does not properly c
The xfs_swapext function in fs/xfs/xfs_dfrag.c in the Linux kernel before 2.6.35 does not properly check the file descriptors passed to the SWAPEXT ioctl, which allows local users to leverage write access and obtain read access by swapping one file into another file.
nvd
CVE-2010-3296P4LOWCVSS 2.1v5.02010-09-30
CVE-2010-3296 [LOW] CWE-200 CVE-2010-3296: The cxgb_extension_ioctl function in drivers/net/cxgb3/cxgb3_main.c in the Linux kernel before 2.6.3
The cxgb_extension_ioctl function in drivers/net/cxgb3/cxgb3_main.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via a CHELSIO_GET_QSET_NUM ioctl call.
nvd
CVE-2007-6206P4LOWCVSS 2.1v3.1v4.02007-12-04
CVE-2007-6206 [LOW] CWE-200 CVE-2007-6206: The do_coredump function in fs/exec.c in Linux kernel 2.4.x and 2.6.x up to 2.6.24-rc3, and possibly
The do_coredump function in fs/exec.c in Linux kernel 2.4.x and 2.6.x up to 2.6.24-rc3, and possibly other versions, does not change the UID of a core dump file if it exists before a root process creates a core dump in the same location, which might allow local users to obtain sensitive information.
nvd
CVE-2010-4080P4LOWCVSS 2.1v5.02010-11-30
CVE-2010-4080 [LOW] CWE-200 CVE-2010-4080: The snd_hdsp_hwdep_ioctl function in sound/pci/rme9652/hdsp.c in the Linux kernel before 2.6.36-rc6
The snd_hdsp_hwdep_ioctl function in sound/pci/rme9652/hdsp.c in the Linux kernel before 2.6.36-rc6 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory via an SNDRV_HDSP_IOCTL_GET_CONFIG_INFO ioctl call.
nvd
CVE-2010-3297P4LOWCVSS 2.1v5.02010-09-30
CVE-2010-3297 [LOW] CWE-909 CVE-2010-3297: The eql_g_master_cfg function in drivers/net/eql.c in the Linux kernel before 2.6.36-rc5 does not pr
The eql_g_master_cfg function in drivers/net/eql.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via an EQL_GETMASTRCFG ioctl call.
nvd
CVE-2010-3298P4LOWCVSS 2.1v5.02010-09-30
CVE-2010-3298 [LOW] CWE-200 CVE-2010-3298: The hso_get_count function in drivers/net/usb/hso.c in the Linux kernel before 2.6.36-rc5 does not p
The hso_get_count function in drivers/net/usb/hso.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via a TIOCGICOUNT ioctl call.
nvd
CVE-2010-3477P4LOWCVSS 2.1v5.02010-09-21
CVE-2010-3477 [LOW] CVE-2010-3477: The tcf_act_police_dump function in net/sched/act_police.c in the actions implementation in the netw
The tcf_act_police_dump function in net/sched/act_police.c in the actions implementation in the network queueing functionality in the Linux kernel before 2.6.36-rc4 does not properly initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel memory via vectors involving a dump operation. NOTE: this vuln
nvd
CVE-2004-1340P4LOWCVSS 2.1v3.02005-01-26
CVE-2004-1340 [LOW] CVE-2004-1340: Debian GNU/Linux 3.0 installs the libpam-radius-auth package with the pam_radius_auth.conf set to be
Debian GNU/Linux 3.0 installs the libpam-radius-auth package with the pam_radius_auth.conf set to be world-readable, which allows local users to obtain sensitive information.
nvd
CVE-2010-2803P4LOWCVSS 1.9v5.02010-09-08
CVE-2010-2803 [LOW] CWE-200 CVE-2010-2803: The drm_ioctl function in drivers/gpu/drm/drm_drv.c in the Direct Rendering Manager (DRM) subsystem
The drm_ioctl function in drivers/gpu/drm/drm_drv.c in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 2.6.27.53, 2.6.32.x before 2.6.32.21, 2.6.34.x before 2.6.34.6, and 2.6.35.x before 2.6.35.4 allows local users to obtain potentially sensitive information from kernel memory by requesting a large memory-allocation amount.
nvd
CVE-2010-4081P4LOWCVSS 1.9v5.02010-11-30
CVE-2010-4081 [LOW] CWE-909 CVE-2010-4081: The snd_hdspm_hwdep_ioctl function in sound/pci/rme9652/hdspm.c in the Linux kernel before 2.6.36-rc
The snd_hdspm_hwdep_ioctl function in sound/pci/rme9652/hdspm.c in the Linux kernel before 2.6.36-rc6 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory via an SNDRV_HDSPM_IOCTL_GET_CONFIG_INFO ioctl call.
nvd
CVE-2010-4083P4LOWCVSS 1.9v5.02010-11-30
CVE-2010-4083 [LOW] CWE-909 CVE-2010-4083: The copy_semid_to_user function in ipc/sem.c in the Linux kernel before 2.6.36 does not initialize a
The copy_semid_to_user function in ipc/sem.c in the Linux kernel before 2.6.36 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory via a (1) IPC_INFO, (2) SEM_INFO, (3) IPC_STAT, or (4) SEM_STAT command in a semctl system call.
nvd
CVE-2010-4072P4LOWCVSS 1.9v5.02010-11-29
CVE-2010-4072 [LOW] CWE-200 CVE-2010-4072: The copy_shmid_to_user function in ipc/shm.c in the Linux kernel before 2.6.37-rc1 does not initiali
The copy_shmid_to_user function in ipc/shm.c in the Linux kernel before 2.6.37-rc1 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory via vectors related to the shmctl system call and the "old shm interface."
nvd
CVE-2010-4074P4LOWCVSS 1.9v5.02010-11-29
CVE-2010-4074 [LOW] CWE-200 CVE-2010-4074: The USB subsystem in the Linux kernel before 2.6.36-rc5 does not properly initialize certain structu
The USB subsystem in the Linux kernel before 2.6.36-rc5 does not properly initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel stack memory via vectors related to TIOCGICOUNT ioctl calls, and the (1) mos7720_ioctl function in drivers/usb/serial/mos7720.c and (2) mos7840_ioctl function in d
nvd
CVE-2010-4078P4LOWCVSS 1.9v5.02010-11-29
CVE-2010-4078 [LOW] CWE-909 CVE-2010-4078: The sisfb_ioctl function in drivers/video/sis/sis_main.c in the Linux kernel before 2.6.36-rc6 does
The sisfb_ioctl function in drivers/video/sis/sis_main.c in the Linux kernel before 2.6.36-rc6 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via an FBIOGET_VBLANK ioctl call.
nvd