VendorsDebiandebian_linux11.0
Vulnerabilities

Debian Debian Linux 11.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2060CVEs
CVE-2025-62799
FastDDS's heap buffer overflow in RTPS DATA_FRAG enables unauthenticated DoS (potential RCE)
Published 2026-02-03 · Analyzed
9.8EPSS 0.005
CVE-2025-38439
bnxt_en: Set DMA unmap len correctly for XDP_REDIRECT
Published 2025-07-25 · Modified
9.8EPSS 0.005
CVE-2025-39841
scsi: lpfc: Fix buffer free/clear order in deferred receive path
Published 2025-09-19 · Modified
9.8EPSS 0.005
CVE-2025-38075
scsi: target: iscsi: Fix timeout on deleted connection
Published 2025-06-18 · Modified
9.8EPSS 0.005
CVE-2025-38561
ksmbd: fix Preauh_HashValue race condition
Published 2025-08-19 · Modified
9.8EPSS 0.004
CVE-2025-39702
ipv6: sr: Fix MAC comparison to be constant-time
Published 2025-09-05 · Modified
9.8EPSS 0.004
CVE-2025-38527
smb: client: fix use-after-free in cifs_oplock_break
Published 2025-08-16 · Modified
9.8EPSS 0.004
CVE-2025-38471
tls: always refresh the queue when reading sock
Published 2025-07-28 · Modified
9.8EPSS 0.004
CVE-2025-38472
netfilter: nf_conntrack: fix crash due to removal of uninitialised entry
Published 2025-07-28 · Modified
9.8EPSS 0.004
CVE-2025-38724
nfsd: handle get_client_locked() failure in nfsd4_setclientid_confirm()
Published 2025-09-04 · Modified
9.8EPSS 0.004
CVE-2025-38211
RDMA/iwcm: Fix use-after-free of work objects after cm_id destruction
Published 2025-07-04 · Modified
9.8EPSS 0.004
CVE-2025-38708
drbd: add missing kref_get in handle_write_conflicts
Published 2025-09-04 · Modified
9.8EPSS 0.004
CVE-2025-39703
net, hsr: reject HSR frame if skb can't hold tag
Published 2025-09-05 · Modified
9.8EPSS 0.004
CVE-2025-2291
PgBouncer default auth_query does not take Postgres password expiry into account
Published 2025-04-16 · Analyzed
9.8EPSS 0.004
CVE-2025-38476
rpl: Fix use-after-free in rpl_do_srh_inline().
Published 2025-07-28 · Modified
9.8EPSS 0.003
CVE-2024-58240
tls: separate no-async decryption request handling from async
Published 2025-08-28 · Modified
9.8EPSS 0.003
CVE-2025-39880
libceph: fix invalid accesses to ceph_connection_v1_info
Published 2025-09-23 · Modified
9.8EPSS 0.003
CVE-2025-39673
ppp: fix race conditions in ppp_fill_forward_path
Published 2025-09-05 · Modified
9.8EPSS 0.003
CVE-2023-6345
Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
Published 2023-11-29 · Analyzed
9.6KEVEPSS 0.165
CVE-2021-37973
Use after free in Portals in Google Chrome prior to 94.0.4606.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Published 2021-10-08 · Analyzed
9.6KEVEPSS 0.117
CVE-2023-2136
Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Published 2023-04-19 · Analyzed
9.6KEVEPSS 0.057
CVE-2021-3693
Cross-site Scripting (XSS) - DOM in ledgersmb/ledgersmb
Published 2021-08-23 · Modified
9.6EPSS 0.032
CVE-2021-3694
Cross-site Scripting (XSS) - Reflected in ledgersmb/ledgersmb
Published 2021-08-23 · Modified
9.6EPSS 0.025
CVE-2021-37981
Heap buffer overflow in Skia in Google Chrome prior to 95.0.4638.54 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Published 2021-11-02 · Modified
9.6EPSS 0.010
CVE-2021-38013
Heap buffer overflow in fingerprint recognition in Google Chrome on ChromeOS prior to 96.0.4664.45 allowed a remote attacker who had compromised a WebUI renderer process to potentially perform a sandbox escape via a crafted HTML page.
Published 2021-12-23 · Modified
9.6EPSS 0.010
CVE-2021-38002
Use after free in Web Transport in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
Published 2021-11-23 · Modified
9.6EPSS 0.010
CVE-2022-3890
Heap buffer overflow in Crashpad in Google Chrome on Android prior to 107.0.5304.106 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Published 2022-11-09 · Modified
9.6EPSS 0.009
CVE-2024-49996
cifs: Fix buffer overflow when parsing NFS reparse points
Published 2024-10-21 · Modified
9.4EPSS 0.008
CVE-2025-38120
netfilter: nf_set_pipapo_avx2: fix initial map fill
Published 2025-07-03 · Modified
9.4EPSS 0.005
CVE-2025-38146
net: openvswitch: Fix the dead loop of MPLS parse
Published 2025-07-03 · Modified
9.4EPSS 0.004
CVE-2025-37959
bpf: Scrub packet on bpf_redirect_peer
Published 2025-05-20 · Modified
9.4EPSS 0.004
CVE-2025-38552
mptcp: plug races between subflow fail and subflow creation
Published 2025-08-16 · Modified
9.4EPSS 0.003
CVE-2025-32463
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.
Published 2025-06-30 · Analyzed
9.3KEV1 PoCEPSS 0.610
CVE-2021-45341
A buffer overflow vulnerability in CDataMoji of the jwwlib component of LibreCAD 2.2.0-rc3 and older allows an attacker to achieve Remote Code Execution using a crafted JWW document.
Published 2022-01-25 · Modified
9.3EPSS 0.066
CVE-2021-30934
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted web content may lead to arbitrary code execution.
Published 2021-08-24 · Modified
9.3EPSS 0.026
CVE-2021-30954
A type confusion issue was addressed with improved memory handling. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted web content may lead to arbitrary code execution.
Published 2021-08-24 · Modified
9.3EPSS 0.014
CVE-2021-3624
There is an integer overflow vulnerability in dcraw. When the victim runs dcraw with a maliciously crafted X3F input image, arbitrary code may be executed in the victim's system.
Published 2022-04-18 · Modified
9.3EPSS 0.009
CVE-2024-36913
Drivers: hv: vmbus: Leak pages if set_memory_encrypted() fails
Published 2024-05-30 · Modified
9.3EPSS 0.007
CVE-2023-45133
Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious code
Published 2023-10-12 · Modified
9.3EPSS 0.005
CVE-2025-38560
x86/sev: Evict cache lines during SNP memory validation
Published 2025-08-19 · Modified
9.3EPSS 0.002
← Prev4 / 52Next →