Debian Linux vulnerabilities
9,911 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,911
CISA KEV
119
actively exploited
Public exploits
429
Exploited in wild
132
Severity breakdown
CRITICAL1128HIGH4110MEDIUM4311LOW362
Vulnerabilities
Page 63 of 496
CVE-2023-5728HIGHCVSS 7.5v10.0v11.02023-10-25
CVE-2023-5728 [HIGH] CWE-416 CVE-2023-5728: During garbage collection extra operations were performed on a object that should not be. This could
During garbage collection extra operations were performed on a object that should not be. This could have led to a potentially exploitable crash. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
nvd
CVE-2023-5363HIGHCVSS 7.5v12.02023-10-25
CVE-2023-5363 [HIGH] CWE-684 CVE-2023-5363: Issue summary: A bug has been identified in the processing of key and
initialisation vector (IV) len
Issue summary: A bug has been identified in the processing of key and
initialisation vector (IV) lengths. This can lead to potential truncation
or overruns during the initialisation of some symmetric ciphers.
Impact summary: A truncation in the IV can result in non-uniqueness,
which could result in loss of confidentiality for some cipher modes.
When c
nvd
CVE-2023-42852HIGHCVSS 8.8v11.0v12.02023-10-25
CVE-2023-42852 [HIGH] CVE-2023-42852: A logic issue was addressed with improved checks. This issue is fixed in iOS 17.1 and iPadOS 17.1, w
A logic issue was addressed with improved checks. This issue is fixed in iOS 17.1 and iPadOS 17.1, watchOS 10.1, iOS 16.7.2 and iPadOS 16.7.2, macOS Sonoma 14.1, Safari 17.1, tvOS 17.1. Processing web content may lead to arbitrary code execution.
nvd
CVE-2023-5367HIGHCVSS 7.8v11.0v12.02023-10-25
CVE-2023-5367 [HIGH] CWE-787 CVE-2023-5367: A out-of-bounds write flaw was found in the xorg-x11-server. This issue occurs due to an incorrect c
A out-of-bounds write flaw was found in the xorg-x11-server. This issue occurs due to an incorrect calculation of a buffer offset when copying data stored in the heap in the XIChangeDeviceProperty function in Xi/xiproperty.c and in RRChangeOutputProperty function in randr/rrproperty.c, allowing for possible escalation of privileges or denial of service.
nvd
CVE-2023-5724HIGHCVSS 7.5v10.0v11.02023-10-25
CVE-2023-5724 [HIGH] CWE-400 CVE-2023-5724: Drivers are not always robust to extremely large draw calls and in some cases this scenario could ha
Drivers are not always robust to extremely large draw calls and in some cases this scenario could have led to a crash. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
nvd
CVE-2023-46316MEDIUMCVSS 5.5v10.0v11.0+1 more2023-10-25
CVE-2023-46316 [MEDIUM] CWE-234 CVE-2023-46316: In buc Traceroute 2.0.12 through 2.1.2 before 2.1.3, the wrapper scripts do not properly parse comma
In buc Traceroute 2.0.12 through 2.1.2 before 2.1.3, the wrapper scripts do not properly parse command lines.
nvd
CVE-2023-41983MEDIUMCVSS 6.5v11.0v12.02023-10-25
CVE-2023-41983 [MEDIUM] CWE-119 CVE-2023-41983: The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.1, Saf
The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.1, Safari 17.1, iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1. Processing web content may lead to a denial-of-service.
nvd
CVE-2023-5725MEDIUMCVSS 4.3v10.0v11.02023-10-25
CVE-2023-5725 [MEDIUM] CVE-2023-5725: A malicious installed WebExtension could open arbitrary URLs, which under the right circumstance cou
A malicious installed WebExtension could open arbitrary URLs, which under the right circumstance could be leveraged to collect sensitive user data. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
nvd
CVE-2023-5380MEDIUMCVSS 4.7v11.0v12.02023-10-25
CVE-2023-5380 [MEDIUM] CWE-416 CVE-2023-5380: A use-after-free flaw was found in the xorg-x11-server. An X server crash may occur in a very specif
A use-after-free flaw was found in the xorg-x11-server. An X server crash may occur in a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode) if the pointer is warped from within a window on one screen to the root window of the other screen and if the original window is destroyed follo
nvd
CVE-2023-5732MEDIUMCVSS 6.5v10.0v11.02023-10-25
CVE-2023-5732 [MEDIUM] CVE-2023-5732: An attacker could have created a malicious link using bidirectional characters to spoof the location
An attacker could have created a malicious link using bidirectional characters to spoof the location in the address bar when visited. This vulnerability affects Firefox < 117, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
nvd
CVE-2023-5721MEDIUMCVSS 4.3v10.0v11.02023-10-25
CVE-2023-5721 [MEDIUM] CWE-1021 CVE-2023-5721: It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally
It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to an insufficient activation-delay. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
nvd
CVE-2023-31122HIGHCVSS 7.5v10.02023-10-23
CVE-2023-31122 [HIGH] CWE-125 CVE-2023-31122: Out-of-bounds Read vulnerability in mod_macro of Apache HTTP Server.This issue affects Apache HTTP S
Out-of-bounds Read vulnerability in mod_macro of Apache HTTP Server.This issue affects Apache HTTP Server: through 2.4.57.
nvd
CVE-2023-45802MEDIUMCVSS 5.9v10.02023-10-23
CVE-2023-45802 [MEDIUM] CVE-2023-45802: When a HTTP/2 stream was reset (RST frame) by a client, there was a time window were the request's m
When a HTTP/2 stream was reset (RST frame) by a client, there was a time window were the request's memory resources were not reclaimed immediately. Instead, de-allocation was deferred to connection close. A client could send new requests and resets, keeping the connection busy and open and causing the memory footprint to keep on growing. On connection close
nvd
CVE-2023-5631MEDIUMCVSS 5.4KEVv10.0v11.0+1 more2023-10-18
CVE-2023-5631 [MEDIUM] CWE-79 CVE-2023-5631: Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-
Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attacker
to load arbitrary JavaScript code.
nvd
CVE-2023-45145LOWCVSS 3.6v10.02023-10-18
CVE-2023-45145 [LOW] CWE-668 CVE-2023-45145: Redis is an in-memory database that persists on disk. On startup, Redis begins listening on a Unix s
Redis is an in-memory database that persists on disk. On startup, Redis begins listening on a Unix socket before adjusting its permissions to the user-provided configuration. If a permissive umask(2) is used, this creates a race condition that enables, during a short period of time, another process to establish an otherwise unauthorized connection. Thi
nvd
CVE-2023-45871HIGHCVSS 7.5v10.02023-10-15
CVE-2023-45871 [HIGH] CWE-131 CVE-2023-45871: An issue was discovered in drivers/net/ethernet/intel/igb/igb_main.c in the IGB driver in the Linux
An issue was discovered in drivers/net/ethernet/intel/igb/igb_main.c in the IGB driver in the Linux kernel before 6.5.3. A buffer size may not be adequate for frames larger than the MTU.
nvd
CVE-2023-45133HIGHCVSS 8.8v10.0v11.0+1 more2023-10-12
CVE-2023-45133 [HIGH] CWE-184 CVE-2023-45133: Babel is a compiler for writingJavaScript. In `@babel/traverse` prior to versions 7.23.2 and 8.0.0-a
Babel is a compiler for writingJavaScript. In `@babel/traverse` prior to versions 7.23.2 and 8.0.0-alpha.4 and all versions of `babel-traverse`, using Babel to compile code that was specifically crafted by an attacker can lead to arbitrary code execution during compilation, when using plugins that rely on the `path.evaluate()`or `path.evaluateTruthy()
nvd
CVE-2023-44981CRITICALCVSS 9.1v10.0v11.0+1 more2023-10-11
CVE-2023-44981 [CRITICAL] CWE-639 CVE-2023-44981: Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper. If SASL Quorum P
Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper. If SASL Quorum Peer authentication is enabled in ZooKeeper (quorum.auth.enableSasl=true), the authorization is done by verifying that the instance part in SASL authentication ID is listed in zoo.cfg server list. The instance part in SASL auth ID is optional and if
nvd
CVE-2023-5476HIGHCVSS 8.8v11.0v12.02023-10-11
CVE-2023-5476 [HIGH] CWE-416 CVE-2023-5476: Use after free in Blink History in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to
Use after free in Blink History in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-5474HIGHCVSS 8.8v11.0v12.02023-10-11
CVE-2023-5474 [HIGH] CWE-787 CVE-2023-5474: Heap buffer overflow in PDF in Google Chrome prior to 118.0.5993.70 allowed a remote attacker who co
Heap buffer overflow in PDF in Google Chrome prior to 118.0.5993.70 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Medium)
nvd