Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 99 of 498
CVE-2021-21214P3HIGHCVSS 8.8v10.02021-04-26
CVE-2021-21214 [HIGH] CWE-416 CVE-2021-21214: Use after free in Network API in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to po
Use after free in Network API in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to potentially exploit heap corruption via a crafted Chrome Extension.
nvd
CVE-2022-42719P3HIGHCVSS 8.8v10.0v11.02022-10-13
CVE-2022-42719 [HIGH] CWE-416 CVE-2022-42719: A use-after-free in the mac80211 stack when parsing a multi-BSSID element in the Linux kernel 5.2 th
A use-after-free in the mac80211 stack when parsing a multi-BSSID element in the Linux kernel 5.2 through 5.19.x before 5.19.16 could be used by attackers (able to inject WLAN frames) to crash the kernel and potentially execute code.
nvd
CVE-2023-5849P3HIGHCVSS 8.8v11.0v12.02023-11-01
CVE-2023-5849 [HIGH] CWE-190 CVE-2023-5849: Integer overflow in USB in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to potent
Integer overflow in USB in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-5856P3HIGHCVSS 8.8v11.0v12.02023-11-01
CVE-2023-5856 [HIGH] CWE-416 CVE-2023-5856: Use after free in Side Panel in Google Chrome prior to 119.0.6045.105 allowed a remote attacker who
Use after free in Side Panel in Google Chrome prior to 119.0.6045.105 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2016-4450P3HIGHCVSS 7.5v8.02016-06-07
CVE-2016-4450 [HIGH] CWE-476 CVE-2016-4450: os/unix/ngx_files.c in nginx before 1.10.1 and 1.11.x before 1.11.1 allows remote attackers to cause
os/unix/ngx_files.c in nginx before 1.10.1 and 1.11.x before 1.11.1 allows remote attackers to cause a denial of service (NULL pointer dereference and worker process crash) via a crafted request, involving writing a client request body to a temporary file.
nvd
CVE-2019-16789P3HIGHCVSS 8.2v9.02019-12-26
CVE-2019-16789 [HIGH] CWE-444 CVE-2019-16789: In Waitress through version 1.4.0, if a proxy server is used in front of waitress, an invalid reques
In Waitress through version 1.4.0, if a proxy server is used in front of waitress, an invalid request may be sent by an attacker that bypasses the front-end and is parsed differently by waitress leading to a potential for HTTP request smuggling. Specially crafted requests containing special whitespace characters in the Transfer-Encoding header would g
nvd
CVE-2023-6347P3HIGHCVSS 8.8v11.0v12.02023-11-29
CVE-2023-6347 [HIGH] CWE-416 CVE-2023-6347: Use after free in Mojo in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potenti
Use after free in Mojo in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-6508P3HIGHCVSS 8.8v11.0v12.02023-12-06
CVE-2023-6508 [HIGH] CWE-416 CVE-2023-6508: Use after free in Media Stream in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to
Use after free in Media Stream in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2016-9928P3HIGHCVSS 7.4v8.02020-02-06
CVE-2016-9928 [HIGH] CWE-269 CVE-2016-9928: MCabber before 1.0.4 is vulnerable to roster push attacks, which allows remote attackers to intercep
MCabber before 1.0.4 is vulnerable to roster push attacks, which allows remote attackers to intercept communications, or add themselves as an entity on a 3rd party's roster as another user, which will also garner associated privileges, via crafted XMPP packets.
nvd
CVE-2023-6348P3HIGHCVSS 8.8v11.0v12.02023-11-29
CVE-2023-6348 [HIGH] CWE-843 CVE-2023-6348: Type Confusion in Spellcheck in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who
Type Confusion in Spellcheck in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-26314P3HIGHCVSS 8.8v10.02023-02-22
CVE-2023-26314 [HIGH] CVE-2023-26314: The mono package before 6.8.0.105+dfsg-3.3 for Debian allows arbitrary code execution because the ap
The mono package before 6.8.0.105+dfsg-3.3 for Debian allows arbitrary code execution because the application/x-ms-dos-executable MIME type is associated with an un-sandboxed Mono CLR interpreter.
nvd
CVE-2017-1000257P3CRITICALCVSS 9.1v8.0v9.02017-10-31
CVE-2017-1000257 [CRITICAL] CWE-119 CVE-2017-1000257: An IMAP FETCH response line indicates the size of the returned data, in number of bytes. When that r
An IMAP FETCH response line indicates the size of the returned data, in number of bytes. When that response says the data is zero bytes, libcurl would pass on that (non-existing) data with a pointer and the size (zero) to the deliver-data function. libcurl's deliver-data function treats zero as a magic number and invokes strlen() on the data t
nvd
CVE-2023-5186P3HIGHCVSS 8.8v11.0v12.02023-09-28
CVE-2023-5186 [HIGH] CWE-416 CVE-2023-5186: Use after free in Passwords in Google Chrome prior to 117.0.5938.132 allowed a remote attacker who c
Use after free in Passwords in Google Chrome prior to 117.0.5938.132 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via crafted UI interaction. (Chromium security severity: High)
nvd
CVE-2023-4429P3HIGHCVSS 8.8v11.0v12.02023-08-23
CVE-2023-4429 [HIGH] CWE-416 CVE-2023-4429: Use after free in Loader in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to poten
Use after free in Loader in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-3216P3HIGHCVSS 8.8v11.0v12.02023-06-13
CVE-2023-3216 [HIGH] CWE-843 CVE-2023-3216: Type confusion in V8 in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potential
Type confusion in V8 in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-4572P3HIGHCVSS 8.8v11.0v12.02023-08-29
CVE-2023-4572 [HIGH] CWE-416 CVE-2023-4572: Use after free in MediaStream in Google Chrome prior to 116.0.5845.140 allowed a remote attacker to
Use after free in MediaStream in Google Chrome prior to 116.0.5845.140 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-5476P3HIGHCVSS 8.8v11.0v12.02023-10-11
CVE-2023-5476 [HIGH] CWE-416 CVE-2023-5476: Use after free in Blink History in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to
Use after free in Blink History in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-5474P3HIGHCVSS 8.8v11.0v12.02023-10-11
CVE-2023-5474 [HIGH] CWE-787 CVE-2023-5474: Heap buffer overflow in PDF in Google Chrome prior to 118.0.5993.70 allowed a remote attacker who co
Heap buffer overflow in PDF in Google Chrome prior to 118.0.5993.70 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Medium)
nvd
CVE-2023-4351P3HIGHCVSS 8.8v11.0v12.02023-08-15
CVE-2023-4351 [HIGH] CWE-416 CVE-2023-4351: Use after free in Network in Google Chrome prior to 116.0.5845.96 allowed a remote attacker who has
Use after free in Network in Google Chrome prior to 116.0.5845.96 allowed a remote attacker who has elicited a browser shutdown to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-4349P3HIGHCVSS 8.8v11.0v12.02023-08-15
CVE-2023-4349 [HIGH] CWE-416 CVE-2023-4349: Use after free in Device Trust Connectors in Google Chrome prior to 116.0.5845.96 allowed a remote a
Use after free in Device Trust Connectors in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd