VendorsDebiandebian_linux12.0
Vulnerabilities

Debian Debian Linux 12.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

292CVEs
CVE-2023-4367
Insufficient policy enforcement in Extensions API in Google Chrome prior to 116.0.5845.96 allowed an attacker who convinced a user to install a malicious extension to bypass an enterprise policy via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-08-15 · Modified
6.5EPSS 0.006
CVE-2023-5479
Inappropriate implementation in Extensions API in Google Chrome prior to 118.0.5993.70 allowed an attacker who convinced a user to install a malicious extension to bypass an enterprise policy via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-10-11 · Modified
6.5EPSS 0.006
CVE-2023-5475
Inappropriate implementation in DevTools in Google Chrome prior to 118.0.5993.70 allowed an attacker who convinced a user to install a malicious extension to bypass discretionary access control via a crafted Chrome Extension. (Chromium security severity: Medium)
Published 2023-10-11 · Modified
6.5EPSS 0.006
CVE-2023-3863
Use-after-free in nfc_llcp_find_loca in net/nfc/llcp_core.c
Published 2023-07-24 · Modified
6.4EPSS 0.002
CVE-2023-5473
Use after free in Cast in Google Chrome prior to 118.0.5993.70 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)
Published 2023-10-11 · Modified
6.3EPSS 0.007
CVE-2024-6706
Open WebUI Stored Cross-Site Scripting
Published 2024-08-07 · Modified
6.3EPSS 0.007
CVE-2023-5631
Stored XSS vulnerability in Roundcube
Published 2023-10-18 · Analyzed
6.1KEVEPSS 0.759
CVE-2023-5480
Inappropriate implementation in Payments in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to bypass XSS preventions via a malicious file. (Chromium security severity: High)
Published 2023-11-01 · Modified
6.1EPSS 0.011
CVE-2023-6867
The timing of a button click causing a popup to disappear was approximately the same length as the anti-clickjacking delay on permission prompts. It was possible to use this fact to surprise users by luring them to click where the permission grant button would be about to appear. This vulnerability affects Firefox ESR < 115.6 and Firefox < 121.
Published 2023-12-19 · Modified
6.1EPSS 0.007
CVE-2023-47272
Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposition header (used for attachment preview or download).
Published 2023-11-05 · Modified
6.1EPSS 0.006
CVE-2023-23908
Improper access control in some 3rd Generation Intel(R) Xeon(R) Scalable processors may allow a privileged user to potentially enable information disclosure via local access.
Published 2023-08-11 · Modified
6.0EPSS 0.002
CVE-2025-26466
Openssh: denial-of-service in openssh
Published 2025-02-28 · Modified
5.9EPSS 0.398
CVE-2022-2127
Samba: out-of-bounds read in winbind auth_crap
Published 2023-07-20 · Modified
5.9EPSS 0.017
CVE-2023-21967
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6, 20; Oracle GraalVM Enterprise Edition: 20.3.9, 21.3.5 and 22.3.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).
Published 2023-04-18 · Modified
5.9EPSS 0.015
CVE-2023-21954
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6; Oracle GraalVM Enterprise Edition: 20.3.9, 21.3.5 and 22.3.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).
Published 2023-04-18 · Modified
5.9EPSS 0.014
CVE-2023-4049
Race conditions in reference counting code were found through code inspection. These could have resulted in potentially exploitable use-after-free vulnerabilities. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.
Published 2023-08-01 · Modified
5.9EPSS 0.006
CVE-2025-64098
FastDDS has Out-of-memory in readOctetVector via Manipulated DATA Submessage when DDS Security is enabled
Published 2026-02-03 · Analyzed
5.9EPSS 0.005
CVE-2023-4875
Undefined Behavior for Input to API in Mutt
Published 2023-09-09 · Modified
5.7EPSS 0.006
CVE-2026-14355
ext/openssl: Memory corruption in openssl_encrypt with AES-WRAP-PAD
Published 2026-07-03 · Analyzed
5.6EPSS 0.003
CVE-2023-20588
Speculative Leaks
Published 2023-08-08 · Modified
5.5EPSS 0.113
CVE-2023-20593
An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may allow an attacker to potentially access sensitive information.
Published 2023-07-24 · Modified
5.5EPSS 0.052
CVE-2023-38633
A directory traversal problem in the URL decoder of librsvg before 2.56.3 could be used by local or remote attackers to disclose files (on the local filesystem outside of the expected area), as demonstrated by href=".?../../../../../../../../../../etc/passwd" in an xi:include element.
Published 2023-07-22 · Modified
5.5EPSS 0.023
CVE-2023-42883
The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, macOS Sonoma 14.2, iOS 17.2 and iPadOS 17.2, watchOS 10.2, tvOS 17.2, iOS 16.7.3 and iPadOS 16.7.3. Processing an image may lead to a denial-of-service.
Published 2023-12-12 · Modified
5.5EPSS 0.007
CVE-2023-3772
Kernel: xfrm: null pointer dereference in xfrm_update_ae_params()
Published 2023-07-25 · Modified
5.5EPSS 0.005
CVE-2023-51384
In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are specified during addition of PKCS#11-hosted private keys, these constraints are only applied to the first key, even if a PKCS#11 token returns multiple keys.
Published 2023-12-18 · Modified
5.5EPSS 0.004
CVE-2023-31084
An issue was discovered in drivers/media/dvb-core/dvb_frontend.c in the Linux kernel 6.2. There is a blocking operation when a task is in !TASK_RUNNING. In dvb_frontend_get_event, wait_event_interruptible is called; the condition is dvb_frontend_test_event(fepriv,events). In dvb_frontend_test_event, down(&fepriv->sem) is called. However, wait_event_interruptible would put the process to sleep, and down(&fepriv->sem) may block the process.
Published 2023-04-24 · Modified
5.5EPSS 0.004
CVE-2023-46316
In buc Traceroute 2.0.12 through 2.1.2 before 2.1.3, the wrapper scripts do not properly parse command lines.
Published 2023-10-24 · Modified
5.5EPSS 0.004
CVE-2024-46955
An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. There is an out-of-bounds read when reading color in Indexed color space.
Published 2024-11-10 · Modified
5.5EPSS 0.003
CVE-2023-4569
Kernel: information leak in nft_set_catchall_flush in net/netfilter/nf_tables_api.c
Published 2023-08-28 · Modified
5.5EPSS 0.003
CVE-2023-4194
Kernel: tap: tap_open(): correctly initialize socket uid next fix of i_uid to current_fsuid
Published 2023-08-07 · Modified
5.5EPSS 0.003
CVE-2023-4132
Kernel: smsusb: use-after-free caused by do_submit_urb()
Published 2023-08-03 · Modified
5.5EPSS 0.003
CVE-2023-3773
Kernel: xfrm: out-of-bounds read of xfrma_mtimer_thresh nlattr
Published 2023-07-25 · Modified
5.5EPSS 0.003
CVE-2023-6206
The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking delay on permission prompts. It was possible to use this fact to surprise users by luring them to click where the permission grant button would be about to appear. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
Published 2023-11-21 · Modified
5.4EPSS 0.006
CVE-2023-34967
Samba: type confusion in mdssvc rpc service for spotlight
Published 2023-07-20 · Modified
5.3EPSS 0.612
CVE-2023-45648
Apache Tomcat: Trailer header parsing too lenient
Published 2023-10-10 · Modified
5.3EPSS 0.058
CVE-2023-21939
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing). Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6, 20; Oracle GraalVM Enterprise Edition: 20.3.9, 21.3.5 and 22.3.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).
Published 2023-04-18 · Modified
5.3EPSS 0.025
CVE-2023-42795
Apache Tomcat: Failure during request clean-up leads to sensitive data leaking to subsequent requests
Published 2023-10-10 · Modified
5.3EPSS 0.022
CVE-2023-34968
Samba: spotlight server-side share path disclosure
Published 2023-07-20 · Modified
5.3EPSS 0.013
CVE-2023-26049
Cookie parsing of quoted values can exfiltrate values from other cookies in Eclipse Jetty
Published 2023-04-18 · Modified
5.3EPSS 0.013
CVE-2023-40167
Jetty accepts "+" prefixed value in Content-Length
Published 2023-09-15 · Modified
5.3EPSS 0.013
← Prev6 / 8Next →