Debian Linux vulnerabilities

9,911 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,911
CISA KEV
119
actively exploited
Public exploits
429
Exploited in wild
132
Severity breakdown
CRITICAL1128HIGH4110MEDIUM4311LOW362

Vulnerabilities

Page 76 of 496
CVE-2023-2602LOWCVSS 3.3v10.0v11.0+1 more2023-06-06
CVE-2023-2602 [LOW] CWE-401 CVE-2023-2602: A vulnerability was found in the pthread_create() function in libcap. This issue may allow a malicio A vulnerability was found in the pthread_create() function in libcap. This issue may allow a malicious actor to use cause __real_pthread_create() to return an error, which can exhaust the process memory.
nvd
CVE-2023-3079HIGHCVSS 8.8KEVv11.0v12.02023-06-05
CVE-2023-3079 [HIGH] CWE-843 CVE-2023-3079: Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potential Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-3111HIGHCVSS 7.8v10.0v11.02023-06-05
CVE-2023-3111 [HIGH] CWE-416 CVE-2023-3111: A use after free vulnerability was found in prepare_to_relocate in fs/btrfs/relocation.c in btrfs in A use after free vulnerability was found in prepare_to_relocate in fs/btrfs/relocation.c in btrfs in the Linux Kernel. This possible flaw can be triggered by calling btrfs_ioctl_balance() before calling btrfs_ioctl_defrag().
nvd
CVE-2023-34410MEDIUMCVSS 5.3v10.02023-06-05
CVE-2023-34410 [MEDIUM] CWE-295 CVE-2023-34410: An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2 An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2. Certificate validation for TLS does not always consider whether the root of a chain is a configured CA certificate.
nvd
CVE-2023-32324MEDIUMCVSS 5.5v10.02023-06-01
CVE-2023-32324 [MEDIUM] CWE-122 CVE-2023-32324: OpenPrinting CUPS is an open source printing system. In versions 2.4.2 and prior, a heap buffer over OpenPrinting CUPS is an open source printing system. In versions 2.4.2 and prior, a heap buffer overflow vulnerability would allow a remote attacker to launch a denial of service (DoS) attack. A buffer overflow vulnerability in the function `format_log_line` could allow remote attackers to cause a DoS on the affected system. Exploitation of the vuln
nvd
CVE-2023-34256MEDIUMCVSS 5.5v10.02023-05-31
CVE-2023-34256 [MEDIUM] CWE-125 CVE-2023-34256: An issue was discovered in the Linux kernel before 6.3.3. There is an out-of-bounds read in crc16 in An issue was discovered in the Linux kernel before 6.3.3. There is an out-of-bounds read in crc16 in lib/crc16.c when called from fs/ext4/super.c because ext4_group_desc_csum does not properly check an offset. NOTE: this is disputed by third parties because the kernel is not intended to defend against attackers with the stated "When modifying the bl
nvd
CVE-2023-2650MEDIUMCVSS 6.5v10.0v11.02023-05-30
CVE-2023-2650 [MEDIUM] CWE-770 CVE-2023-2650: Issue summary: Processing some specially crafted ASN.1 object identifiers or data containing them ma Issue summary: Processing some specially crafted ASN.1 object identifiers or data containing them may be very slow. Impact summary: Applications that use OBJ_obj2txt() directly, or use any of the OpenSSL subsystems OCSP, PKCS7/SMIME, CMS, CMP/CRMF or TS with no message size limit may experience notable to very long delays when processing those messag
nvd
CVE-2023-2952MEDIUMCVSS 6.5v10.0v12.02023-05-30
CVE-2023-2952 [MEDIUM] CWE-835 CVE-2023-2952: XRA dissector infinite loop in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service XRA dissector infinite loop in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via packet injection or crafted capture file
nvd
CVE-2023-34151MEDIUMCVSS 5.5v10.02023-05-30
CVE-2023-34151 [MEDIUM] CVE-2023-34151: A vulnerability was found in ImageMagick. This security flaw ouccers as an undefined behaviors of ca A vulnerability was found in ImageMagick. This security flaw ouccers as an undefined behaviors of casting double to size_t in svg, mvg and other coders (recurring bugs of CVE-2022-32546).
nvd
CVE-2023-32762MEDIUMCVSS 5.3v10.02023-05-28
CVE-2023-32762 [MEDIUM] CVE-2023-32762: An issue was discovered in Qt before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1 An issue was discovered in Qt before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. Qt Network incorrectly parses the strict-transport-security (HSTS) header, allowing unencrypted connections to be established, even when explicitly prohibited by the server. This happens if the case used for this header does not exactly match.
nvd
CVE-2023-32307HIGHCVSS 7.5v10.02023-05-26
CVE-2023-32307 [HIGH] CWE-122 CVE-2023-32307: Sofia-SIP is an open-source SIP User-Agent library, compliant with the IETF RFC3261 specification. R Sofia-SIP is an open-source SIP User-Agent library, compliant with the IETF RFC3261 specification. Referring to [GHSA-8599-x7rq-fr54](https://github.com/freeswitch/sofia-sip/security/advisories/GHSA-8599-x7rq-fr54), several other potential heap-over-flow and integer-overflow in stun_parse_attr_error_code and stun_parse_attr_uint32 were found because t
nvd
CVE-2023-2879HIGHCVSS 7.5v10.0v12.02023-05-26
CVE-2023-2879 [HIGH] CWE-835 CVE-2023-2879: GDSDB infinite loop in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via pac GDSDB infinite loop in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via packet injection or crafted capture file
nvd
CVE-2023-2854MEDIUMCVSS 6.5v12.02023-05-26
CVE-2023-2854 [MEDIUM] CWE-787 CVE-2023-2854: BLF file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via c BLF file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file
nvd
CVE-2023-2856MEDIUMCVSS 6.5v10.0v12.02023-05-26
CVE-2023-2856 [MEDIUM] CWE-787 CVE-2023-2856: VMS TCPIPtrace file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of se VMS TCPIPtrace file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file
nvd
CVE-2023-2898MEDIUMCVSS 4.7v10.0v11.0+1 more2023-05-26
CVE-2023-2898 [MEDIUM] CWE-476 CVE-2023-2898: There is a null-pointer-dereference flaw found in f2fs_write_end_io in fs/f2fs/data.c in the Linux k There is a null-pointer-dereference flaw found in f2fs_write_end_io in fs/f2fs/data.c in the Linux kernel. This flaw allows a local privileged user to cause a denial of service problem.
nvd
CVE-2023-2855MEDIUMCVSS 6.5v12.02023-05-26
CVE-2023-2855 [MEDIUM] CWE-787 CVE-2023-2855: Candump log parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service vi Candump log parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file
nvd
CVE-2023-2858MEDIUMCVSS 6.5v10.0v12.02023-05-26
CVE-2023-2858 [MEDIUM] CWE-787 CVE-2023-2858: NetScaler file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service NetScaler file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file
nvd
CVE-2023-1667MEDIUMCVSS 6.5v10.02023-05-26
CVE-2023-1667 [MEDIUM] CWE-476 CVE-2023-1667: A NULL pointer dereference was found In libssh during re-keying with algorithm guessing. This issue A NULL pointer dereference was found In libssh during re-keying with algorithm guessing. This issue may allow an authenticated client to cause a denial of service.
nvd
CVE-2023-2857MEDIUMCVSS 6.5v12.02023-05-26
CVE-2023-2857 [MEDIUM] CWE-787 CVE-2023-2857: BLF file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via c BLF file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file
nvd
CVE-2023-28321MEDIUMCVSS 5.9v10.02023-05-26
CVE-2023-28321 [MEDIUM] CWE-295 CVE-2023-28321: An improper certificate validation vulnerability exists in curl <v8.1.0 in the way it supports match An improper certificate validation vulnerability exists in curl <v8.1.0 in the way it supports matching of wildcard patterns when listed as "Subject Alternative Name" in TLS server certificates. curl can be built to use its own name matching function for TLS rather than one provided by a TLS library. This private wildcard matching function would mat
nvd