VendorsDebiandebian_linux11.0
Vulnerabilities

Debian Debian Linux 11.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2060CVEs
CVE-2025-47287
Tornado vulnerable to excessive logging caused by malformed multipart form data
Published 2025-05-15 · Analyzed
7.5EPSS 0.007
CVE-2025-37871
nfsd: decrease sc_count directly if fail to queue dl_recall
Published 2025-05-09 · Modified
7.5EPSS 0.007
CVE-2023-4055
When the number of cookies per domain was exceeded in `document.cookie`, the actual cookie jar sent to the host was no longer consistent with expected cookie jar state. This could have caused requests to be sent with some cookies missing. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.
Published 2023-08-01 · Modified
7.5EPSS 0.007
CVE-2021-25633
Content Manipulation with Double Certificate Attack
Published 2021-10-11 · Modified
7.5EPSS 0.007
CVE-2021-3908
Infinite certificate chain depth results in OctoRPKI running forever
Published 2021-11-11 · Modified
7.5EPSS 0.007
CVE-2021-25634
Timestamp Manipulation with Signature Wrapping
Published 2021-10-12 · Modified
7.5EPSS 0.007
CVE-2024-56644
net/ipv6: release expired exception dst cached in socket
Published 2024-12-27 · Modified
7.5EPSS 0.007
CVE-2023-34058
VMware Tools contains a SAML token signature bypass vulnerability. A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html  in a target virtual machine may be able to elevate their privileges if that target virtual machine has been assigned a more privileged Guest Alias https://vdc-download.vmware.com/vmwb-repository/dcr-public/d1902b0e-d479-46bf-8ac9-cee0e31e8ec0/07ce8dbd-db48-4261-9b8f-c6d3ad8ba472/vim.vm.guest.AliasManager.html .
Published 2023-10-27 · Modified
7.5EPSS 0.007
CVE-2023-3417
File Extension Spoofing using the Text Direction Override Character
Published 2023-07-24 · Modified
7.5EPSS 0.007
CVE-2025-25475
A NULL pointer dereference in the component /libsrc/dcrleccd.cc of DCMTK v3.6.9+ DEV allows attackers to cause a Denial of Service (DoS) via a crafted DICOM file.
Published 2025-02-18 · Analyzed
7.5EPSS 0.006
CVE-2026-25061
tcpflow has TIM Element OOB Write in wifipcap
Published 2026-01-29 · Analyzed
7.5EPSS 0.006
CVE-2025-43965
In MIFF image processing in ImageMagick before 7.1.1-44, image depth is mishandled after SetQuantumFormat is used.
Published 2025-04-23 · Analyzed
7.5EPSS 0.006
CVE-2025-23145
mptcp: fix NULL pointer in can_accept_new_subflow
Published 2025-05-01 · Modified
7.5EPSS 0.006
CVE-2025-38035
nvmet-tcp: don't restore null sk_state_change
Published 2025-06-18 · Modified
7.5EPSS 0.006
CVE-2025-62603
FastDDS has Out-of-memory while parsing GenericMessage when DDS Security is enabled
Published 2026-02-03 · Analyzed
7.5EPSS 0.005
CVE-2025-38181
calipso: Fix null-ptr-deref in calipso_req_{set,del}attr().
Published 2025-07-04 · Modified
7.5EPSS 0.005
CVE-2025-62602
FastDDS has heap buffer overflow in readData via Manipulated DATA Submessage when DDS Security is enabled
Published 2026-02-03 · Analyzed
7.5EPSS 0.005
CVE-2023-46234
browserify-sign vulnerable via an upper bound check issue in `dsaVerify` that leads to a signature forgery attack
Published 2023-10-26 · Analyzed
7.5EPSS 0.005
CVE-2025-37917
net: ethernet: mtk-star-emac: fix spinlock recursion issues on rx/tx poll
Published 2025-05-20 · Modified
7.5EPSS 0.005
CVE-2025-38018
net/tls: fix kernel panic when alloc_page failed
Published 2025-06-18 · Modified
7.5EPSS 0.005
CVE-2025-37757
tipc: fix memory leak in tipc_link_xmit
Published 2025-05-01 · Modified
7.5EPSS 0.004
CVE-2025-38399
scsi: target: Fix NULL pointer dereference in core_scsi3_decode_spec_i_port()
Published 2025-07-25 · Modified
7.5EPSS 0.004
CVE-2025-38124
net: fix udp gso skb_segment after pull from frag_list
Published 2025-07-03 · Modified
7.5EPSS 0.004
CVE-2025-37820
xen-netfront: handle NULL returned by xdp_convert_buff_to_frame()
Published 2025-05-08 · Modified
7.5EPSS 0.004
CVE-2025-38514
rxrpc: Fix oops due to non-existence of prealloc backlog struct
Published 2025-08-16 · Modified
7.5EPSS 0.004
CVE-2025-39770
net: gso: Forbid IPv6 TSO with extensions on devices with only IPV6_CSUM
Published 2025-09-11 · Modified
7.5EPSS 0.004
CVE-2024-47619
tranport: TLS host name wildcard matching too lax
Published 2025-05-07 · Analyzed
7.5EPSS 0.004
CVE-2025-38393
NFSv4/pNFS: Fix a race to wake on NFS_LAYOUT_DRAIN
Published 2025-07-25 · Modified
7.5EPSS 0.004
CVE-2025-39894
netfilter: br_netfilter: do not check confirmed bit in br_nf_local_in() after confirm
Published 2025-10-01 · Modified
7.5EPSS 0.003
CVE-2025-38165
bpf, sockmap: Fix panic when calling skb_linearize
Published 2025-07-03 · Modified
7.5EPSS 0.003
CVE-2025-38331
net: ethernet: cortina: Use TOE/TSO on all TCP
Published 2025-07-10 · Modified
7.5EPSS 0.003
CVE-2025-39857
net/smc: fix one NULL pointer dereference in smc_ib_is_sg_need_sync()
Published 2025-09-19 · Modified
7.5EPSS 0.003
CVE-2026-1940
Gstreamer: incomplete fix of cve-2026-1940
Published 2026-03-23 · Analyzed
7.5EPSS 0.002
CVE-2021-3712
Read buffer overruns processing ASN.1 strings
Published 2021-08-24 · Modified
7.4EPSS 0.504
CVE-2025-3155
Yelp: arbitrary file read
Published 2025-04-03 · Modified
7.4EPSS 0.142
CVE-2020-35662
In SaltStack Salt before 3002.5, when authenticating to services using certain modules, the SSL certificate is not always validated.
Published 2021-02-27 · Modified
7.4EPSS 0.030
CVE-2022-23633
Exposure of sensitive information in Action Pack
Published 2022-02-11 · Modified
7.4EPSS 0.022
CVE-2021-3563
A flaw was found in openstack-keystone. Only the first 72 characters of an application secret are verified allowing attackers bypass some password complexity which administrators may be counting on. The highest threat from this vulnerability is to data confidentiality and integrity.
Published 2022-08-26 · Modified
7.4EPSS 0.017
CVE-2021-37980
Inappropriate implementation in Sandbox in Google Chrome prior to 94.0.4606.81 allowed a remote attacker to potentially bypass site isolation via Windows.
Published 2021-11-02 · Modified
7.4EPSS 0.015
CVE-2023-21930
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6, 20; Oracle GraalVM Enterprise Edition: 20.3.9, 21.3.5 and 22.3.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data as well as unauthorized access to critical data or complete access to all Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
Published 2023-04-18 · Modified
7.4EPSS 0.013
← Prev29 / 52Next →