Debian Linux vulnerabilities

9,911 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,911
CISA KEV
119
actively exploited
Public exploits
429
Exploited in wild
132
Severity breakdown
CRITICAL1128HIGH4110MEDIUM4311LOW362

Vulnerabilities

Page 60 of 496
CVE-2023-6860MEDIUMCVSS 6.5v10.0v11.0+1 more2023-12-19
CVE-2023-6860 [MEDIUM] CVE-2023-6860: The `VideoBridge` allowed any content process to use textures produced by remote decoders. This cou The `VideoBridge` allowed any content process to use textures produced by remote decoders. This could be abused to escape the sandbox. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
nvd
CVE-2023-5115MEDIUMCVSS 6.3v10.02023-12-18
CVE-2023-5115 [MEDIUM] CWE-36 CVE-2023-5115: An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an att An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a malicious Ansible role and make the victim execute the role. A symlink can be used to overwrite a file outside of the extraction path.
nvd
CVE-2023-51385MEDIUMCVSS 6.5v10.0v11.0+1 more2023-12-18
CVE-2023-51385 [MEDIUM] CWE-78 CVE-2023-51385: In ssh in OpenSSH before 9.6, OS command injection might occur if a user name or host name has shell In ssh in OpenSSH before 9.6, OS command injection might occur if a user name or host name has shell metacharacters, and this name is referenced by an expansion token in certain situations. For example, an untrusted Git repository can have a submodule with shell metacharacters in a user name or host name.
nvd
CVE-2023-48795MEDIUMCVSS 5.9PoCv10.02023-12-18
CVE-2023-48795 [MEDIUM] CWE-354 CVE-2023-48795: The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other pr The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some security features have been downgr
nvd
CVE-2023-51384MEDIUMCVSS 5.5v11.0v12.02023-12-18
CVE-2023-51384 [MEDIUM] CVE-2023-51384: In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. Whe In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are specified during addition of PKCS#11-hosted private keys, these constraints are only applied to the first key, even if a PKCS#11 token returns multiple keys.
nvd
CVE-2023-6478HIGHCVSS 7.5v10.0v11.0+1 more2023-12-13
CVE-2023-6478 [HIGH] CWE-190 CVE-2023-6478: A flaw was found in xorg-server. A specially crafted request to RRChangeProviderProperty or RRChange A flaw was found in xorg-server. A specially crafted request to RRChangeProviderProperty or RRChangeOutputProperty can trigger an integer overflow which may lead to a disclosure of sensitive information.
nvd
CVE-2023-6377HIGHCVSS 7.8v10.0v11.0+1 more2023-12-13
CVE-2023-6377 [HIGH] CWE-125 CVE-2023-6377: A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touch A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory reads and writes. This may allow local privilege escalation or possible remote code execution in cases where X11 forwarding is involved.
nvd
CVE-2023-42883MEDIUMCVSS 5.5v11.0v12.02023-12-12
CVE-2023-42883 [MEDIUM] CVE-2023-42883: The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, macOS Son The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, macOS Sonoma 14.2, iOS 17.2 and iPadOS 17.2, watchOS 10.2, tvOS 17.2, iOS 16.7.3 and iPadOS 16.7.3. Processing an image may lead to a denial-of-service.
nvd
CVE-2023-6185HIGHCVSS 8.8v11.0v12.02023-12-11
CVE-2023-6185 [HIGH] CVE-2023-6185: Improper Input Validation vulnerability in GStreamer integration of The Document Foundation LibreOff Improper Input Validation vulnerability in GStreamer integration of The Document Foundation LibreOffice allows an attacker to execute arbitrary GStreamer plugins. In affected versions the filename of the embedded video is not sufficiently escaped when passed to GStreamer enabling an attacker to run arbitrary gstreamer plugins depending on what plugins are inst
nvd
CVE-2023-6186HIGHCVSS 8.8v11.0v12.02023-12-11
CVE-2023-6186 [HIGH] CWE-281 CVE-2023-6186: Insufficient macro permission validation of The Document Foundation LibreOffice allows an attacker t Insufficient macro permission validation of The Document Foundation LibreOffice allows an attacker to execute built-in macros without warning. In affected versions LibreOffice supports hyperlinks with macro or similar built-in command targets that can be executed when activated without warning the user.
nvd
CVE-2023-45866MEDIUMCVSS 6.3v10.02023-12-08
CVE-2023-45866 [MEDIUM] CVE-2023-45866: Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate an Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example affected package is bluez 5.64-0ubuntu1 in Ub
nvd
CVE-2023-6508HIGHCVSS 8.8v11.0v12.02023-12-06
CVE-2023-6508 [HIGH] CWE-416 CVE-2023-6508: Use after free in Media Stream in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to Use after free in Media Stream in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-6510HIGHCVSS 8.8v11.0v12.02023-12-06
CVE-2023-6510 [HIGH] CWE-416 CVE-2023-6510: Use after free in Media Capture in Google Chrome prior to 120.0.6099.62 allowed a remote attacker wh Use after free in Media Capture in Google Chrome prior to 120.0.6099.62 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via specific UI interaction. (Chromium security severity: Medium)
nvd
CVE-2023-6509HIGHCVSS 8.8v11.0v12.02023-12-06
CVE-2023-6509 [HIGH] CWE-416 CVE-2023-6509: Use after free in Side Panel Search in Google Chrome prior to 120.0.6099.62 allowed a remote attacke Use after free in Side Panel Search in Google Chrome prior to 120.0.6099.62 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via specific UI interaction. (Chromium security severity: High)
nvd
CVE-2023-6512MEDIUMCVSS 6.5v11.0v12.02023-12-06
CVE-2023-6512 [MEDIUM] CWE-838 CVE-2023-6512: Inappropriate implementation in Web Browser UI in Google Chrome prior to 120.0.6099.62 allowed a rem Inappropriate implementation in Web Browser UI in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to potentially spoof the contents of an iframe dialog context menu via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2023-6511MEDIUMCVSS 4.3v11.0v12.02023-12-06
CVE-2023-6511 [MEDIUM] CVE-2023-6511: Inappropriate implementation in Autofill in Google Chrome prior to 120.0.6099.62 allowed a remote at Inappropriate implementation in Autofill in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2023-40462HIGHCVSS 7.5v10.02023-12-04
CVE-2023-40462 [HIGH] CWE-617 CVE-2023-40462: The ACEManager component of ALEOS 4.16 and earlier does not perform input sanitization during aut The ACEManager component of ALEOS 4.16 and earlier does not perform input sanitization during authentication, which could potentially result in a Denial of Service (DoS) condition for ACEManager without impairing other router functions. ACEManager recovers from the DoS condition by restarting within ten seconds of becoming unavailable.
nvd
CVE-2023-42917HIGHCVSS 8.8KEVv11.0v12.02023-11-30
CVE-2023-42917 [HIGH] CWE-787 CVE-2023-42917: A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 17 A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1.
nvd
CVE-2023-42916MEDIUMCVSS 6.5KEVv11.0v12.02023-11-30
CVE-2023-42916 [MEDIUM] CWE-125 CVE-2023-42916: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1. An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may disclose sensitive information. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1.
nvd
CVE-2023-6345CRITICALCVSS 9.6KEVv11.0v12.02023-11-29
CVE-2023-6345 [CRITICAL] CWE-190 CVE-2023-6345: Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
nvd