Debian Linux vulnerabilities
9,952 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,952
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4311LOW358
Vulnerabilities
Page 5 of 498
CVE-2020-35730P1MEDIUMCVSS 6.1KEVPoCv9.02020-12-28
CVE-2020-35730 [MEDIUM] CWE-79 CVE-2020-35730: An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x befor
An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in a link reference element that is mishandled by linkref_addindex in rcube_string_replacer.php.
nvd
CVE-2023-0386P1HIGHCVSS 7.8KEVPoCv10.02023-03-22
CVE-2023-0386 [HIGH] CWE-282 CVE-2023-0386: A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.
nvd
CVE-2021-22600P1HIGHCVSS 7.0KEVPoCv9.0v10.02022-01-26
CVE-2021-22600 [HIGH] CWE-415 CVE-2021-22600: A double free bug in packet_set_ring() in net/packet/af_packet.c can be exploited by a local user th
A double free bug in packet_set_ring() in net/packet/af_packet.c can be exploited by a local user through crafted syscalls to escalate privileges or deny service. We recommend upgrading kernel past the effected versions or rebuilding past ec6af094ea28f0f2dda1a6a33b14cd57e36a9755
nvd
CVE-2014-0196P1MEDIUMCVSS 5.5KEVPoCv6.0v7.02014-05-07
CVE-2014-0196 [MEDIUM] CWE-362 CVE-2014-0196: The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly
The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users to cause a denial of service (memory corruption and system crash) or gain privileges by triggering a race condition involving read and write operations with long strings.
nvd
CVE-2020-36193P1HIGHCVSS 7.5KEVRansomwarev9.0v10.02021-01-18
CVE-2020-36193 [HIGH] CWE-22 CVE-2020-36193: Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadeq
Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.
nvd
CVE-2025-48384P1HIGHCVSS 8.0KEVPoCv11.02025-07-08
CVE-2025-48384 [HIGH] CWE-59 CVE-2025-48384: Git is a fast, scalable, distributed revision control system with an unusually rich command set that
Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When reading a config value, Git strips any trailing carriage return and line feed (CRLF). When writing a config entry, values with a trailing CR are not quoted, causing the CR to be lost
nvd
CVE-2024-9680P1CRITICALCVSS 9.8KEVRansomwarev11.02024-10-09
CVE-2024-9680 [CRITICAL] CWE-416 CVE-2024-9680: An attacker was able to achieve code execution in the content process by exploiting a use-after-free
An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability affects Firefox < 131.0.2, Firefox ESR < 128.3.1, Firefox ESR < 115.16.1, Thunderbird < 131.0.1, Thunderbird < 128.3.1, and Thunderbird
nvd
CVE-2025-38352P2HIGHCVSS 7.4KEVPoCv11.02025-07-22
CVE-2025-38352 [HIGH] CWE-367 CVE-2025-38352: In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: fix race betw
In the Linux kernel, the following vulnerability has been resolved:
posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()
If an exiting non-autoreaping task has already passed exit_notify() and
calls handle_posix_cpu_timers() from IRQ, it can be reaped by its parent
or debugger right after unlock_task_sighand().
If a
nvd
CVE-2020-16009P1HIGHCVSS 8.8KEVv10.02020-11-03
CVE-2020-16009 [HIGH] CWE-787 CVE-2020-16009: Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker
Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2015-2590P1CRITICALCVSS 9.8KEVv7.0v8.02015-07-16
CVE-2015-2590 [CRITICAL] CVE-2015-2590: Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33
Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2015-4732.
nvd
CVE-2020-13965P1MEDIUMCVSS 6.1KEVv9.0v10.02020-06-09
CVE-2020-13965 [MEDIUM] CWE-79 CVE-2020-13965: An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via
An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview.
nvd
CVE-2023-6345P1CRITICALCVSS 9.6KEVv11.0v12.02023-11-29
CVE-2023-6345 [CRITICAL] CWE-190 CVE-2023-6345: Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had
Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
nvd
CVE-2019-16928P1CRITICALCVSS 9.8KEVv10.02019-09-27
CVE-2019-16928 [CRITICAL] CVE-2019-16928: Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846
Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846. There is a heap-based buffer overflow in string_vformat in string.c involving a long EHLO command.
nvd
CVE-2023-5631P1MEDIUMCVSS 5.4KEVv10.0v11.0+1 more2023-10-18
CVE-2023-5631 [MEDIUM] CWE-79 CVE-2023-5631: Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-
Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attacker
to load arbitrary JavaScript code.
nvd
CVE-2021-37975P1HIGHCVSS 8.8KEVv10.0v11.02021-10-08
CVE-2021-37975 [HIGH] CWE-416 CVE-2021-37975: Use after free in V8 in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to potentially
Use after free in V8 in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2018-17480P1HIGHCVSS 8.8KEVv9.02018-12-11
CVE-2018-17480 [HIGH] CWE-787 CVE-2018-17480: Execution of user supplied Javascript during array deserialization leading to an out of bounds write
Execution of user supplied Javascript during array deserialization leading to an out of bounds write in V8 in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
nvd
CVE-2022-32893P1HIGHCVSS 8.8KEVv10.0v11.02022-08-24
CVE-2022-32893 [HIGH] CWE-787 CVE-2022-32893: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1, Safari 15.6.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
nvd
CVE-2021-21166P1HIGHCVSS 8.8KEVv10.02021-03-09
CVE-2021-21166 [HIGH] CWE-362 CVE-2021-21166: Data race in audio in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially e
Data race in audio in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2017-5030P1HIGHCVSS 8.8KEVv8.0v9.02017-04-24
CVE-2017-5030 [HIGH] CWE-125 CVE-2017-5030: Incorrect handling of complex species in V8 in Google Chrome prior to 57.0.2987.98 for Linux, Window
Incorrect handling of complex species in V8 in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac and 57.0.2987.108 for Android allowed a remote attacker to execute arbitrary code via a crafted HTML page.
nvd
CVE-2023-42917P1HIGHCVSS 8.8KEVv11.0v12.02023-11-30
CVE-2023-42917 [HIGH] CWE-787 CVE-2023-42917: A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 17
A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1.
nvd