VendorsDebiandebian_linux10.0
Vulnerabilities

Debian Debian Linux 10.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3432CVEs
CVE-2021-36055
XMP Toolkit SDK Use After Free Vulnerability In ReadingXMPNewDOM Could Lead To Arbitrary Code Execution
Published 2021-09-01 · Modified
9.3EPSS 0.028
CVE-2020-6523
Out of bounds write in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published 2020-07-22 · Modified
9.3EPSS 0.027
CVE-2021-36047
XMP Toolkit SDK Improper Input Validation Could Lead To Arbitrary Code Execution
Published 2021-09-01 · Modified
9.3EPSS 0.027
CVE-2021-36064
XMP Toolkit SDK SVG_Adapter ParseFullNS Buffer Underflow
Published 2021-09-01 · Modified
9.3EPSS 0.027
CVE-2021-36048
XMP Toolkit SDK Improper Input Validation Could Lead To Arbitrary Code Execution
Published 2021-09-01 · Modified
9.3EPSS 0.027
CVE-2020-6520
Buffer overflow in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published 2020-07-22 · Modified
9.3EPSS 0.027
CVE-2021-30934
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted web content may lead to arbitrary code execution.
Published 2021-08-24 · Modified
9.3EPSS 0.026
CVE-2020-6548
Heap buffer overflow in Skia in Google Chrome prior to 84.0.4147.125 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
Published 2020-09-21 · Modified
9.3EPSS 0.026
CVE-2020-6518
Use after free in developer tools in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had convinced the user to use developer tools to potentially exploit heap corruption via a crafted HTML page.
Published 2020-07-22 · Modified
9.3EPSS 0.026
CVE-2014-5439
Multiple Stack-based Buffer Overflow vulnerabilities exists in Sniffit prior to 0.3.7 via a crafted configuration file that will bypass Non-eXecutable bit NX, stack smashing protector SSP, and address space layout randomization ASLR protection mechanisms, which could let a malicious user execute arbitrary code.
Published 2019-11-19 · Modified
9.3EPSS 0.025
CVE-2020-6515
Use after free in tab strip in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published 2020-07-22 · Modified
9.3EPSS 0.025
CVE-2021-36046
XMP Toolkit SDK TIFF_MemoryReader::SortIFD function Memory Corruption
Published 2021-09-01 · Modified
9.3EPSS 0.025
CVE-2012-2248
An issue was discovered in dhclient 4.3.1-6 due to an embedded path variable.
Published 2019-11-27 · Modified
9.3EPSS 0.024
CVE-2020-6559
Use after free in presentation API in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published 2020-09-21 · Modified
9.3EPSS 0.023
CVE-2019-18345
A reflected XSS issue was discovered in DAViCal through 1.1.8. It echoes the action parameter without encoding. If a user visits an attacker-supplied link, the attacker can view all data the attacked user can view, as well as perform all actions in the name of the user. If the user is an administrator, the attacker can for example add a new admin user to gain full access to the application.
Published 2019-12-12 · Modified
9.3EPSS 0.022
CVE-2022-1650
Improper Removal of Sensitive Information Before Storage or Transfer in eventsource/eventsource
Published 2022-05-12 · Modified
9.3EPSS 0.019
CVE-2020-6553
Use after free in offline mode in Google Chrome on iOS prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published 2020-09-21 · Modified
9.3EPSS 0.015
CVE-2020-6552
Use after free in Blink in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published 2020-09-21 · Modified
9.3EPSS 0.015
CVE-2021-30954
A type confusion issue was addressed with improved memory handling. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted web content may lead to arbitrary code execution.
Published 2021-08-24 · Modified
9.3EPSS 0.014
CVE-2010-4654
poppler before 0.16.3 has malformed commands that may cause corruption of the internal stack.
Published 2019-11-13 · Modified
9.3EPSS 0.012
CVE-2021-3624
There is an integer overflow vulnerability in dcraw. When the victim runs dcraw with a maliciously crafted X3F input image, arbitrary code may be executed in the victim's system.
Published 2022-04-18 · Modified
9.3EPSS 0.009
CVE-2023-45133
Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious code
Published 2023-10-12 · Modified
9.3EPSS 0.005
CVE-2021-25282
An issue was discovered in through SaltStack Salt before 3002.5. The salt.wheel.pillar_roots.write method is vulnerable to directory traversal.
Published 2021-02-27 · Modified
9.1EPSS 0.924
CVE-2021-21351
XStream is vulnerable to an Arbitrary Code Execution attack
Published 2021-03-22 · Analyzed
9.1EPSS 0.821
CVE-2021-21342
A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host
Published 2021-03-22 · Analyzed
9.1EPSS 0.500
CVE-2019-20445
HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-Encoding header.
Published 2020-01-29 · Modified
9.1EPSS 0.135
CVE-2019-20444
HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header with an incorrect syntax, or might be interpreted as an "invalid fold."
Published 2020-01-29 · Modified
9.1EPSS 0.089
CVE-2022-26499
An SSRF issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it's possible to send arbitrary requests (such as GET) to interfaces such as localhost by using the Identity header. This is fixed in 16.25.2, 18.11.2, and 19.3.2.
Published 2022-04-15 · Modified
9.1EPSS 0.078
CVE-2019-11036
Heap over-read in PHP EXIF extension
Published 2019-05-03 · Modified
9.1EPSS 0.070
CVE-2023-25725
HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently lost in some situations, aka "request smuggling." The HTTP header parsers in HAProxy may accept empty header field names, which could be used to truncate the list of HTTP headers and thus make some headers disappear after being parsed and processed for HTTP/1.0 and HTTP/1.1. For HTTP/2 and HTTP/3, the impact is limited because the headers disappear before being parsed and processed, as if they had not been sent by the client. The fixed versions are 2.7.3, 2.6.9, 2.5.12, 2.4.22, 2.2.29, and 2.0.31.
Published 2023-02-14 · Modified
9.1EPSS 0.054
CVE-2021-3144
In SaltStack Salt before 3002.5, eauth tokens can be used once after expiration. (They might be used to run command against the salt master or minions.)
Published 2021-02-27 · Modified
9.1EPSS 0.052
CVE-2022-21723
Out-of-bounds read in multipart parsing in PJSIP
Published 2022-01-27 · Modified
9.1EPSS 0.045
CVE-2019-12523
An issue was discovered in Squid before 4.9. When handling a URN request, a corresponding HTTP request is made. This HTTP request doesn't go through the access checks that incoming HTTP requests go through. This causes all access checks to be bypassed and allows access to restricted HTTP servers, e.g., an attacker can connect to HTTP servers that only listen on localhost.
Published 2019-11-26 · Modified
9.1EPSS 0.043
CVE-2020-28039
is_protected_meta in wp-includes/meta.php in WordPress before 5.5.2 allows arbitrary file deletion because it does not properly determine whether a meta key is considered protected.
Published 2020-10-31 · Modified
9.1EPSS 0.041
CVE-2019-11040
Heap buffer overflow in EXIF extension
Published 2019-06-18 · Modified
9.1EPSS 0.041
CVE-2021-43845
Prevent out-of-bounds read in PJSIP
Published 2021-12-27 · Modified
9.1EPSS 0.037
CVE-2022-1586
An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.
Published 2022-05-16 · Analyzed
9.1EPSS 0.034
CVE-2019-10197
A flaw was found in samba versions 4.9.x up to 4.9.13, samba 4.10.x up to 4.10.8 and samba 4.11.x up to 4.11.0rc3, when certain parameters were set in the samba configuration file. An unauthenticated attacker could use this flaw to escape the shared directory and access the contents of directories outside the share.
Published 2019-09-03 · Modified
9.1EPSS 0.032
CVE-2019-11039
Out-of-bounds read in iconv.c
Published 2019-06-18 · Modified
9.1EPSS 0.031
CVE-2019-19949
In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer over-read in the function WritePNGImage of coders/png.c, related to Magick_png_write_raw_profile and LocaleNCompare.
Published 2019-12-24 · Modified
9.1EPSS 0.029
← Prev10 / 86Next →