cbcvebase.

Debian Linux vulnerabilities

9,952 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,952
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4311LOW358

Vulnerabilities

Page 6 of 498
CVE-2021-37973P1CRITICALCVSS 9.6KEVv10.0v11.02021-10-08
CVE-2021-37973 [CRITICAL] CWE-416 CVE-2021-37973: Use after free in Portals in Google Chrome prior to 94.0.4606.61 allowed a remote attacker who had c Use after free in Portals in Google Chrome prior to 94.0.4606.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2021-21148P1HIGHCVSS 8.8KEVv10.02021-02-09
CVE-2021-21148 [HIGH] CWE-787 CVE-2021-21148: Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.150 allowed a remote attacker to pote Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.150 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2023-2136P1CRITICALCVSS 9.6KEVv11.02023-04-19
CVE-2023-2136 [CRITICAL] CWE-190 CVE-2023-2136: Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2021-1871P1CRITICALCVSS 9.8KEVv10.02021-04-02
CVE-2021-1871 [CRITICAL] CVE-2021-1871: A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, S A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
nvd
CVE-2016-1646P2HIGHCVSS 8.8KEVv8.0v9.02016-03-29
CVE-2016-1646 [HIGH] CWE-125 CVE-2016-1646: The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome befo The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly consider element data types, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via crafted JavaScript code.
nvd
CVE-2023-7024P1HIGHCVSS 8.8KEVv11.0v12.02023-12-21
CVE-2023-7024 [HIGH] CWE-787 CVE-2023-7024: Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2021-30952P1HIGHCVSS 7.8KEVv10.0v11.02021-08-24
CVE-2021-30952 [HIGH] CWE-190 CVE-2021-30952: An integer overflow was addressed with improved input validation. This issue is fixed in tvOS 15.2, An integer overflow was addressed with improved input validation. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2021-21193P1HIGHCVSS 8.8KEVv10.02021-03-16
CVE-2021-21193 [HIGH] CWE-416 CVE-2021-21193: Use after free in Blink in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentia Use after free in Blink in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2024-44309P1MEDIUMCVSS 6.3KEVv11.02024-11-20
CVE-2024-44309 [MEDIUM] CWE-79 CVE-2024-44309: A cookie management issue was addressed with improved state management. This issue is fixed in Safar A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS Sequoia 15.1.1, visionOS 2.1.1. Processing maliciously crafted web content may lead to a cross site scripting attack. Apple is aware of a report that this issue may have been a
nvd
CVE-2023-42916P1MEDIUMCVSS 6.5KEVv11.0v12.02023-11-30
CVE-2023-42916 [MEDIUM] CWE-125 CVE-2023-42916: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1. An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may disclose sensitive information. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1.
nvd
CVE-2023-0266P1HIGHCVSS 7.0KEVv10.02023-01-30
CVE-2023-0266 [HIGH] CWE-416 CVE-2023-0266: A use after free vulnerability exists in the ALSA PCM package in the Linux Kernel. SNDRV_CTL_IOCTL_E A use after free vulnerability exists in the ALSA PCM package in the Linux Kernel. SNDRV_CTL_IOCTL_ELEM_{READ|WRITE}32 is missing locks that can be used in a use-after-free that can result in a priviledge escalation to gain ring0 access from the system user. We recommend upgrading past commit 56b88b50565cd8b946a2d00b0c83927b7ebb055e
nvd
CVE-2021-37976P2MEDIUMCVSS 6.5KEVv10.0v11.02021-10-08
CVE-2021-37976 [MEDIUM] CWE-862 CVE-2021-37976: Inappropriate implementation in Memory in Google Chrome prior to 94.0.4606.71 allowed a remote attac Inappropriate implementation in Memory in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2024-53104P1HIGHCVSS 7.8KEVv11.02024-12-02
CVE-2024-53104 [HIGH] CWE-787 CVE-2024-53104: In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Skip parsing f In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format This can lead to out of bounds writes since frames of this type were not taken into account when calculating the size of the frames buffer in uvc_parse_streaming.
nvd
CVE-2024-36971P2HIGHCVSS 7.8KEVv10.02024-06-10
CVE-2024-36971 [HIGH] CWE-416 CVE-2024-36971: In the Linux kernel, the following vulnerability has been resolved: net: fix __dst_negative_advice( In the Linux kernel, the following vulnerability has been resolved: net: fix __dst_negative_advice() race __dst_negative_advice() does not enforce proper RCU rules when sk->dst_cache must be cleared, leading to possible UAF. RCU rules are that we must first clear sk->sk_dst_cache, then call dst_release(old_dst). Note that sk_dst_reset(sk) is implem
nvd
CVE-2024-53150P2HIGHCVSS 7.1KEVv11.02024-12-24
CVE-2024-53150 [HIGH] CWE-125 CVE-2024-53150: In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix out of bou In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix out of bounds reads when finding clock sources The current USB-audio driver code doesn't check bLength of each descriptor at traversing for clock descriptors. That is, when a device provides a bogus descriptor with a shorter bLength, the driver might hit out-of-b
nvd
CVE-2023-20867P1LOWCVSS 3.9KEVRansomwarev10.0v11.0+1 more2023-06-13
CVE-2023-20867 [LOW] CWE-287 CVE-2023-20867: A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operation A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine.
nvd
CVE-2024-53197P2HIGHCVSS 7.8KEVv11.02024-12-27
CVE-2024-53197 [HIGH] CWE-787 CVE-2024-53197: In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix potential In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices A bogus device can provide a bNumConfigurations value that exceeds the initial value used in usb_get_configuration for allocating dev->config. This can lead to out-of-bounds accesses later, e.g. in usb_d
nvd
CVE-2021-0920P2MEDIUMCVSS 6.4KEVv9.02021-12-15
CVE-2021-0920 [MEDIUM] CWE-362 CVE-2021-0920: In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition. Thi In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-196926917References: Upstream kernel
nvd
CVE-2024-50302P2MEDIUMCVSS 5.5KEVv11.02024-11-19
CVE-2024-50302 [MEDIUM] CWE-908 CVE-2024-50302: In the Linux kernel, the following vulnerability has been resolved: HID: core: zero-initialize the In the Linux kernel, the following vulnerability has been resolved: HID: core: zero-initialize the report buffer Since the report buffer is used by all kinds of drivers in various ways, let's zero-initialize it during allocation to make sure that it can't be ever used to leak kernel memory via specially-crafted report.
nvd
CVE-2021-38000P2MEDIUMCVSS 6.1KEVv10.0v11.02021-11-23
CVE-2021-38000 [MEDIUM] CWE-601 CVE-2021-38000: Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638 Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitrarily browser to a malicious URL via a crafted HTML page.
nvd
Debian Linux vulnerabilities | cvebase