VendorsDebiandebian_linux11.0
Vulnerabilities

Debian Debian Linux 11.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2060CVEs
CVE-2022-1048
A use-after-free flaw was found in the Linux kernel’s sound subsystem in the way a user triggers concurrent calls of PCM hw_params. The hw_free ioctls or similar race condition happens inside ALSA PCM for other ioctls. This flaw allows a local user to crash or potentially escalate their privileges on the system.
Published 2022-04-29 · Modified
7.0EPSS 0.002
CVE-2025-38460
atm: clip: Fix potential null-ptr-deref in to_atmarpd().
Published 2025-07-25 · Modified
7.0EPSS 0.002
CVE-2025-39749
rcu: Protect ->defer_qs_iw_pending from data race
Published 2025-09-11 · Modified
7.0EPSS 0.002
CVE-2025-38461
vsock: Fix transport_* TOCTOU
Published 2025-07-25 · Modified
7.0EPSS 0.001
CVE-2025-39759
btrfs: qgroup: fix race between quota disable and quota rescan ioctl
Published 2025-09-11 · Modified
7.0EPSS 0.001
CVE-2022-26362
x86 pv: Race condition in typeref acquisition Xen maintains a type reference count for pages, in addition to a regular reference count. This scheme is used to maintain invariants required for Xen's safety, e.g. PV guests may not have direct writeable access to pagetables; updates need auditing by Xen. Unfortunately, the logic for acquiring a type reference has a race condition, whereby a safely TLB flush is issued too early and creates a window where the guest can re-establish the read/write mapping before writeability is prohibited.
Published 2022-06-09 · Modified
6.9EPSS 0.004
CVE-2022-1789
With shadow paging enabled, the INVPCID instruction results in a call to kvm_mmu_invpcid_gva. If INVPCID is executed with CR0.PG=0, the invlpg callback is not set and the result is a NULL pointer dereference.
Published 2022-05-31 · Modified
6.9EPSS 0.003
CVE-2025-6966
Null-pointer dereference in python-apt TagSection.keys()
Published 2025-12-05 · Analyzed
6.9EPSS 0.001
CVE-2025-26465
Openssh: machine-in-the-middle attack if verifyhostkeydns is enabled
Published 2025-02-18 · Modified
6.8EPSS 0.077
CVE-2021-35567
Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via Kerberos to compromise Java SE, Oracle GraalVM Enterprise Edition. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Oracle GraalVM Enterprise Edition, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N).
Published 2021-10-20 · Analyzed
6.8EPSS 0.029
CVE-2021-28700
xen/arm: No memory limit for dom0less domUs The dom0less feature allows an administrator to create multiple unprivileged domains directly from Xen. Unfortunately, the memory limit from them is not set. This allow a domain to allocate memory beyond what an administrator originally configured.
Published 2021-08-27 · Modified
6.8EPSS 0.019
CVE-2023-2002
A vulnerability was found in the HCI sockets implementation due to a missing capability check in net/bluetooth/hci_sock.c in the Linux Kernel. This flaw allows an attacker to unauthorized execution of management commands, compromising the confidentiality, integrity, and availability of Bluetooth communication.
Published 2023-05-26 · Modified
6.8EPSS 0.015
CVE-2024-28102
JWCrypto vulnerable to JWT bomb Attack in `deserialize` function
Published 2024-03-06 · Analyzed
6.8EPSS 0.010
CVE-2021-20316
A flaw was found in the way Samba handled file/directory metadata. This flaw allows an authenticated attacker with permissions to read or modify share metadata, to perform this operation outside of the share.
Published 2022-08-23 · Modified
6.8EPSS 0.010
CVE-2021-28694
IOMMU page mapping issues on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Both AMD and Intel allow ACPI tables to specify regions of memory which should be left untranslated, which typically means these addresses should pass the translation phase unaltered. While these are typically device specific ACPI properties, they can also be specified to apply to a range of devices, or even all devices. On all systems with such regions Xen failed to prevent guests from undoing/replacing such mappings (CVE-2021-28694). On AMD systems, where a discontinuous range is specified by firmware, the supposedly-excluded middle range will also be identity-mapped (CVE-2021-28695). Further, on AMD systems, upon de-assigment of a physical device from a guest, the identity mappings would be left in place, allowing a guest continued access to ranges of memory which it shouldn't have access to anymore (CVE-2021-28696).
Published 2021-08-27 · Modified
6.8EPSS 0.004
CVE-2021-28696
IOMMU page mapping issues on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Both AMD and Intel allow ACPI tables to specify regions of memory which should be left untranslated, which typically means these addresses should pass the translation phase unaltered. While these are typically device specific ACPI properties, they can also be specified to apply to a range of devices, or even all devices. On all systems with such regions Xen failed to prevent guests from undoing/replacing such mappings (CVE-2021-28694). On AMD systems, where a discontinuous range is specified by firmware, the supposedly-excluded middle range will also be identity-mapped (CVE-2021-28695). Further, on AMD systems, upon de-assigment of a physical device from a guest, the identity mappings would be left in place, allowing a guest continued access to ranges of memory which it shouldn't have access to anymore (CVE-2021-28696).
Published 2021-08-27 · Modified
6.8EPSS 0.004
CVE-2023-4273
Kernel: exfat: stack overflow in exfat_get_uniname_from_ext_entry
Published 2023-08-09 · Modified
6.7EPSS 0.007
CVE-2022-21499
KGDB and KDB allow read and write access to kernel memory, and thus should be restricted during lockdown. An attacker with access to a serial port could trigger the debugger so it is important that the debugger respect the lockdown mode when/if it is triggered. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Published 2022-06-09 · Modified
6.7EPSS 0.006
CVE-2024-12426
URL fetching can be used to exfiltrate arbitrary INI file values and environment variables
Published 2025-01-07 · Analyzed
6.7EPSS 0.005
CVE-2022-30783
An invalid return code in fuse_kern_mount enables intercepting of libfuse-lite protocol traffic between NTFS-3G and the kernel in NTFS-3G through 2021.8.22 when using libfuse-lite.
Published 2022-05-26 · Modified
6.7EPSS 0.004
CVE-2022-30787
An integer underflow in fuse_lib_readdir enables arbitrary memory read operations in NTFS-3G through 2021.8.22 when using libfuse-lite.
Published 2022-05-26 · Modified
6.7EPSS 0.004
CVE-2021-33655
When sending malicous data to kernel by ioctl cmd FBIOPUT_VSCREENINFO,kernel will write memory out of bounds.
Published 2022-07-18 · Modified
6.7EPSS 0.003
CVE-2023-21400
In multiple functions of io_uring.c, there is a possible kernel memory corruption due to improper locking. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exploitation.
Published 2023-07-12 · Modified
6.7EPSS 0.003
CVE-2022-32214
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS).
Published 2022-07-14 · Modified
6.5EPSS 0.825
CVE-2023-2650
Possible DoS translating ASN.1 object identifiers
Published 2023-05-30 · Modified
6.5EPSS 0.751
CVE-2022-32215
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding headers. This can lead to HTTP Request Smuggling (HRS).
Published 2022-07-14 · Modified
6.5EPSS 0.688
CVE-2022-31629
$_COOKIE names string replacement (. -> _): cookie integrity vulnerabilities
Published 2022-09-28 · Modified
6.5EPSS 0.493
CVE-2022-32213
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding headers and can lead to HTTP Request Smuggling (HRS).
Published 2022-07-14 · Modified
6.5EPSS 0.441
CVE-2022-32206
curl < 7.84.0 supports "chained" HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with different algorithms. The number of acceptable "links" in this "decompression chain" was unbounded, allowing a malicious server to insert a virtually unlimited number of compression steps.The use of such a decompression chain could result in a "malloc bomb", makingcurl end up spending enormous amounts of allocated heap memory, or trying toand returning out of memory errors.
Published 2022-07-07 · Modified
6.5EPSS 0.331
CVE-2021-37976
Inappropriate implementation in Memory in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
Published 2021-10-08 · Analyzed
6.5KEVEPSS 0.199
CVE-2023-51385
In ssh in OpenSSH before 9.6, OS command injection might occur if a user name or host name has shell metacharacters, and this name is referenced by an expansion token in certain situations. For example, an untrusted Git repository can have a submodule with shell metacharacters in a user name or host name.
Published 2023-12-18 · Modified
6.5EPSS 0.198
CVE-2023-42916
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may disclose sensitive information. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1.
Published 2023-11-30 · Analyzed
6.5KEVEPSS 0.178
CVE-2021-30640
Auth weakness in JNDIRealm
Published 2021-07-12 · Modified
6.5EPSS 0.099
CVE-2023-3338
Crash due to a null pointer dereference in the dn_nsp_send function
Published 2023-06-30 · Modified
6.5EPSS 0.080
CVE-2021-39140
XStream can cause a Denial of Service
Published 2021-08-23 · Analyzed
6.5EPSS 0.059
CVE-2022-29901
Arbitrary Memory Disclosure through CPU Side-Channel Attacks (Retbleed)
Published 2022-07-12 · Modified
6.5EPSS 0.050
CVE-2021-46784
In Squid 3.x through 3.5.28, 4.x through 4.17, and 5.x before 5.6, due to improper buffer management, a Denial of Service can occur when processing long Gopher server responses.
Published 2022-07-17 · Modified
6.5EPSS 0.048
CVE-2021-3634
A flaw has been found in libssh in versions prior to 0.9.6. The SSH protocol keeps track of two shared secrets during the lifetime of the session. One of them is called secret_hash and the other session_id. Initially, both of them are the same, but after key re-exchange, previous session_id is kept and used as an input to new secret_hash. Historically, both of these buffers had shared length variable, which worked as long as these buffers were same. But the key re-exchange operation can also change the key exchange method, which can be based on hash of different size, eventually creating "secret_hash" of different size than the session_id has. This becomes an issue when the session_id memory is zeroed or when it is used again during second key re-exchange.
Published 2021-08-31 · Modified
6.5EPSS 0.047
CVE-2022-29900
Mis-trained branch predictions for return instructions may allow arbitrary speculative code execution under certain microarchitecture-dependent conditions.
Published 2022-07-12 · Modified
6.5EPSS 0.039
CVE-2022-27776
A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.
Published 2022-06-01 · Modified
6.5EPSS 0.038
← Prev32 / 52Next →