VendorsDebiandebian_linuxall versions
Vulnerabilities

Debian Debian Linux

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10063CVEs
CVE-2024-25189
libjwt 1.15.3 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing side channel.
Published 2024-02-08 · Analyzed
9.8EPSS 0.010
CVE-2023-4056
Memory safety bugs present in Firefox 115, Firefox ESR 115.0, Firefox ESR 102.13, Thunderbird 115.0, and Thunderbird 102.13. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.
Published 2023-08-01 · Modified
9.8EPSS 0.009
CVE-2023-41361
An issue was discovered in FRRouting FRR 9.0. bgpd/bgp_open.c does not check for an overly large length of the rcv software version.
Published 2023-08-29 · Modified
9.8EPSS 0.009
CVE-2022-23479
Buffer Overflow occurs in xrdp
Published 2022-12-09 · Modified
9.8EPSS 0.009
CVE-2022-23477
Buffer Overflow in xrdp
Published 2022-12-09 · Modified
9.8EPSS 0.009
CVE-2022-23480
Buffer Overflow in xrdp
Published 2022-12-09 · Modified
9.8EPSS 0.009
CVE-2022-23478
Out of Bound Write in xrdp
Published 2022-12-09 · Modified
9.8EPSS 0.008
CVE-2024-25714
In Rhonabwy through 1.1.13, HMAC signature verification uses a strcmp function that is vulnerable to side-channel attacks, because it stops the comparison when the first difference is spotted in the two signatures. (The fix uses gnutls_memcmp, which has constant-time execution.)
Published 2024-02-11 · Modified
9.8EPSS 0.008
CVE-2022-23468
Buffer Overflow in xrdp
Published 2022-12-09 · Modified
9.8EPSS 0.008
CVE-2022-23484
Integer Overflow in xrdp
Published 2022-12-09 · Modified
9.8EPSS 0.008
CVE-2024-26877
crypto: xilinx - call finalize with bh disabled
Published 2024-04-17 · Modified
9.8EPSS 0.007
CVE-2025-37879
9p/net: fix improper handling of bogus negative read/write replies
Published 2025-05-09 · Modified
9.8EPSS 0.007
CVE-2024-35884
udp: do not accept non-tunnel GSO skbs landing in a tunnel
Published 2024-05-19 · Modified
9.8EPSS 0.007
CVE-2025-38488
smb: client: fix use-after-free in crypt_message when using async crypto
Published 2025-07-28 · Modified
9.8EPSS 0.007
CVE-2024-41073
nvme: avoid double free special payload
Published 2024-07-29 · Modified
9.8EPSS 0.007
CVE-2025-0838
Heap Buffer overflow in Abseil
Published 2025-02-21 · Analyzed
9.8EPSS 0.006
CVE-2024-0808
Integer underflow in WebUI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via a malicious file. (Chromium security severity: High)
Published 2024-01-23 · Modified
9.8EPSS 0.005
CVE-2025-38430
nfsd: nfsd4_spo_must_allow() must check this is a v4 compound request
Published 2025-07-25 · Modified
9.8EPSS 0.005
CVE-2025-62799
FastDDS's heap buffer overflow in RTPS DATA_FRAG enables unauthenticated DoS (potential RCE)
Published 2026-02-03 · Analyzed
9.8EPSS 0.005
CVE-2025-38439
bnxt_en: Set DMA unmap len correctly for XDP_REDIRECT
Published 2025-07-25 · Modified
9.8EPSS 0.005
CVE-2014-7210
pdns specific as packaged in Debian in version before 3.3.1-1 creates a too privileged MySQL user. It was discovered that the maintainer scripts of pdns-backend-mysql grant too wide database permissions for the pdns user. Other backends are not affected.
Published 2025-06-26 · Analyzed
9.8EPSS 0.005
CVE-2025-39841
scsi: lpfc: Fix buffer free/clear order in deferred receive path
Published 2025-09-19 · Modified
9.8EPSS 0.005
CVE-2025-38075
scsi: target: iscsi: Fix timeout on deleted connection
Published 2025-06-18 · Modified
9.8EPSS 0.005
CVE-2025-39702
ipv6: sr: Fix MAC comparison to be constant-time
Published 2025-09-05 · Modified
9.8EPSS 0.004
CVE-2025-38561
ksmbd: fix Preauh_HashValue race condition
Published 2025-08-19 · Modified
9.8EPSS 0.004
CVE-2025-38527
smb: client: fix use-after-free in cifs_oplock_break
Published 2025-08-16 · Modified
9.8EPSS 0.004
CVE-2025-38471
tls: always refresh the queue when reading sock
Published 2025-07-28 · Modified
9.8EPSS 0.004
CVE-2025-38472
netfilter: nf_conntrack: fix crash due to removal of uninitialised entry
Published 2025-07-28 · Modified
9.8EPSS 0.004
CVE-2025-38724
nfsd: handle get_client_locked() failure in nfsd4_setclientid_confirm()
Published 2025-09-04 · Modified
9.8EPSS 0.004
CVE-2025-38211
RDMA/iwcm: Fix use-after-free of work objects after cm_id destruction
Published 2025-07-04 · Modified
9.8EPSS 0.004
CVE-2025-38708
drbd: add missing kref_get in handle_write_conflicts
Published 2025-09-04 · Modified
9.8EPSS 0.004
CVE-2025-39703
net, hsr: reject HSR frame if skb can't hold tag
Published 2025-09-05 · Modified
9.8EPSS 0.004
CVE-2025-2291
PgBouncer default auth_query does not take Postgres password expiry into account
Published 2025-04-16 · Analyzed
9.8EPSS 0.004
CVE-2025-38476
rpl: Fix use-after-free in rpl_do_srh_inline().
Published 2025-07-28 · Modified
9.8EPSS 0.003
CVE-2024-58240
tls: separate no-async decryption request handling from async
Published 2025-08-28 · Modified
9.8EPSS 0.003
CVE-2025-39880
libceph: fix invalid accesses to ceph_connection_v1_info
Published 2025-09-23 · Modified
9.8EPSS 0.003
CVE-2025-39673
ppp: fix race conditions in ppp_fill_forward_path
Published 2025-09-05 · Modified
9.8EPSS 0.003
CVE-2020-15999
Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published 2020-11-03 · Analyzed
9.6KEVEPSS 0.443
CVE-2023-6345
Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
Published 2023-11-29 · Analyzed
9.6KEVEPSS 0.165
CVE-2021-37973
Use after free in Portals in Google Chrome prior to 94.0.4606.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Published 2021-10-08 · Analyzed
9.6KEVEPSS 0.117
← Prev25 / 252Next →