VendorsDebiandebian_linux11.0
Vulnerabilities

Debian Debian Linux 11.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2060CVEs
CVE-2025-37741
jfs: Prevent copying of nlink with value 0 from disk inode
Published 2025-05-01 · Modified
7.8EPSS 0.002
CVE-2025-39783
PCI: endpoint: Fix configfs group list head handling
Published 2025-09-11 · Modified
7.8EPSS 0.002
CVE-2025-38443
nbd: fix uaf in nbd_genl_connect() error path
Published 2025-07-25 · Analyzed
7.8EPSS 0.002
CVE-2025-38670
arm64/entry: Mask DAIF in cpu_switch_to(), call_on_irq_stack()
Published 2025-08-22 · Modified
7.8EPSS 0.002
CVE-2025-38550
ipv6: mcast: Delay put pmc->idev in mld_del_delrec()
Published 2025-08-16 · Modified
7.8EPSS 0.002
CVE-2025-39873
can: xilinx_can: xcan_write_frame(): fix use-after-free of transmitted SKB
Published 2025-09-23 · Modified
7.8EPSS 0.002
CVE-2025-38499
clone_private_mnt(): make sure that caller has CAP_SYS_ADMIN in the right userns
Published 2025-08-11 · Modified
7.8EPSS 0.002
CVE-2025-38257
s390/pkey: Prevent overflow in size calculation for memdup_user()
Published 2025-07-09 · Modified
7.8EPSS 0.002
CVE-2025-39911
i40e: fix IRQ freeing in i40e_vsi_request_irq_msix error path
Published 2025-10-01 · Analyzed
7.8EPSS 0.002
CVE-2025-23151
bus: mhi: host: Fix race between unprepare and queue_buf
Published 2025-05-01 · Modified
7.8EPSS 0.002
CVE-2025-38239
scsi: megaraid_sas: Fix invalid node index
Published 2025-07-09 · Modified
7.8EPSS 0.002
CVE-2025-39870
dmaengine: idxd: Fix double free in idxd_setup_wqs()
Published 2025-09-23 · Analyzed
7.8EPSS 0.002
CVE-2025-38259
ASoC: codecs: wcd9335: Fix missing free of regulator supplies
Published 2025-07-09 · Analyzed
7.8EPSS 0.002
CVE-2025-38500
xfrm: interface: fix use-after-free after changing collect_md xfrm interface
Published 2025-08-12 · Analyzed
7.8EPSS 0.002
CVE-2025-39697
NFS: Fix a race when updating an existing write
Published 2025-09-05 · Modified
7.8EPSS 0.002
CVE-2025-39800
btrfs: abort transaction on unexpected eb generation at btrfs_copy_root()
Published 2025-09-15 · Modified
7.8EPSS 0.002
CVE-2025-38083
net_sched: prio: fix a race in prio_tune()
Published 2025-06-20 · Modified
7.8EPSS 0.002
CVE-2025-38485
iio: accel: fxls8962af: Fix use after free in fxls8962af_fifo_flush
Published 2025-07-28 · Modified
7.8EPSS 0.002
CVE-2025-38078
ALSA: pcm: Fix race of buffer access at PCM OSS layer
Published 2025-06-18 · Modified
7.8EPSS 0.002
CVE-2025-39877
mm/damon/sysfs: fix use-after-free in state_show()
Published 2025-09-23 · Analyzed
7.8EPSS 0.002
CVE-2025-39881
kernfs: Fix UAF in polling when open file is released
Published 2025-09-23 · Modified
7.8EPSS 0.002
CVE-2025-38102
VMCI: fix race between vmci_host_setup_notify and vmci_ctx_unset_notify
Published 2025-07-03 · Modified
7.8EPSS 0.001
CVE-2025-38108
net_sched: red: fix a race in __red_change()
Published 2025-07-03 · Modified
7.8EPSS 0.001
CVE-2025-39776
mm/debug_vm_pgtable: clear page table entries at destroy_args()
Published 2025-09-11 · Modified
7.8EPSS 0.001
CVE-2025-38107
net_sched: ets: fix a race in ets_qdisc_change()
Published 2025-07-03 · Modified
7.8EPSS 0.001
CVE-2025-38085
mm/hugetlb: fix huge_pmd_unshare() vs GUP-fast race
Published 2025-06-28 · Modified
7.8EPSS 0.001
CVE-2025-38477
net/sched: sch_qfq: Fix race condition on qfq_aggregate
Published 2025-07-28 · Modified
7.8EPSS 0.001
CVE-2025-39825
smb: client: fix race with concurrent opens in rename(2)
Published 2025-09-16 · Modified
7.8EPSS 0.001
CVE-2022-25647
Deserialization of Untrusted Data
Published 2022-05-01 · Modified
7.7EPSS 0.122
CVE-2020-13692
PostgreSQL JDBC Driver (aka PgJDBC) before 42.2.13 allows XXE.
Published 2020-06-04 · Modified
7.7EPSS 0.041
CVE-2022-31090
CURLOPT_HTTPAUTH option not cleared on change of origin in Guzzle
Published 2022-06-27 · Modified
7.7EPSS 0.019
CVE-2022-21682
flatpak-builder can access files outside the build directory.
Published 2022-01-13 · Modified
7.7EPSS 0.017
CVE-2022-31091
Change in port should be considered a change in origin in Guzzle
Published 2022-06-27 · Modified
7.7EPSS 0.015
CVE-2022-0908
Null source pointer passed as an argument to memcpy() function within TIFFFetchNormalTag () in tif_dirread.c in libtiff versions up to 4.3.0 could lead to Denial of Service via crafted TIFF file.
Published 2022-03-11 · Modified
7.7EPSS 0.013
CVE-2022-3570
Multiple heap buffer overflows in tiffcrop.c utility in libtiff library Version 4.4.0 allows attacker to trigger unsafe or out of bounds memory access via crafted TIFF image file which could result into application crash, potential information disclosure or any other context-dependent impact
Published 2022-10-21 · Modified
7.7EPSS 0.005
CVE-2023-6478
Xorg-x11-server: out-of-bounds memory read in rrchangeoutputproperty and rrchangeproviderproperty
Published 2023-12-13 · Modified
7.6EPSS 0.016
CVE-2021-39201
Authenticated cross-site scripting (XSS) in WordPress editor
Published 2021-09-09 · Modified
7.6EPSS 0.015
CVE-2023-44487
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Published 2023-10-10 · Analyzed
7.5KEV1 PoCEPSS 1.000
CVE-2023-50868
The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the "NSEC3" issue. The RFC 5155 specification implies that an algorithm must perform thousands of iterations of a hash function in certain situations.
Published 2024-02-14 · Analyzed
7.5EPSS 0.817
CVE-2022-34169
Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets
Published 2022-07-19 · Modified
7.5EPSS 0.810
← Prev24 / 52Next →