VendorsDebiandebian_linux10.0
Vulnerabilities

Debian Debian Linux 10.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3432CVEs
CVE-2019-19953
In GraphicsMagick 1.4 snapshot-20191208 Q8, there is a heap-based buffer over-read in the function EncodeImage of coders/pict.c.
Published 2019-12-24 · Modified
9.1EPSS 0.028
CVE-2021-45079
In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the case of EAP methods with mutual authentication and EAP-only authentication for IKEv2) even without server authentication.
Published 2022-01-31 · Modified
9.1EPSS 0.028
CVE-2021-35942
The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or read arbitrary memory in parse_param (in posix/wordexp.c) when called with an untrusted, crafted pattern, potentially resulting in a denial of service or disclosure of information. This occurs because atoi was used but strtoul should have been used to ensure correct calculations.
Published 2021-07-22 · Modified
9.1EPSS 0.026
CVE-2022-21722
Potential out-of-bound read during RTP/RTCP parsing in PJSIP
Published 2022-01-27 · Modified
9.1EPSS 0.024
CVE-2020-36331
A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkAssignData. The highest threat from this vulnerability is to data confidentiality and to the service availability.
Published 2021-05-21 · Modified
9.1EPSS 0.023
CVE-2022-35409
An issue was discovered in Mbed TLS before 2.28.1 and 3.x before 3.2.0. In some configurations, an unauthenticated attacker can send an invalid ClientHello message to a DTLS server that causes a heap-based buffer over-read of up to 255 bytes. This can cause a server crash or possibly information disclosure based on error responses. Affected configurations have MBEDTLS_SSL_DTLS_CLIENT_PORT_REUSE enabled and MBEDTLS_SSL_IN_CONTENT_LEN less than a threshold that depends on the configuration: 258 bytes if using mbedtls_ssl_cookie_check, and possibly up to 571 bytes with a custom cookie check function.
Published 2022-07-15 · Modified
9.1EPSS 0.022
CVE-2020-36330
A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkVerifyAndAssign. The highest threat from this vulnerability is to data confidentiality and to the service availability.
Published 2021-05-21 · Modified
9.1EPSS 0.022
CVE-2022-37032
An out-of-bounds read in the BGP daemon of FRRouting FRR before 8.4 may lead to a segmentation fault and denial of service. This occurs in bgp_capability_msg_parse in bgpd/bgp_packet.c.
Published 2022-09-19 · Modified
9.1EPSS 0.022
CVE-2021-46848
GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der.
Published 2022-10-24 · Modified
9.1EPSS 0.022
CVE-2022-24790
HTTP Request Smuggling in puma
Published 2022-03-30 · Modified
9.1EPSS 0.022
CVE-2021-43302
Read out-of-bounds in PJSUA API when calling pjsua_recorder_create. An attacker-controlled 'filename' argument may cause an out-of-bounds read when the filename is shorter than 4 characters.
Published 2022-02-16 · Modified
9.1EPSS 0.022
CVE-2022-23959
In Varnish Cache before 6.6.2 and 7.x before 7.0.2, Varnish Cache 6.0 LTS before 6.0.10, and and Varnish Enterprise (Cache Plus) 4.1.x before 4.1.11r6 and 6.0.x before 6.0.9r4, request smuggling can occur for HTTP/1 connections.
Published 2022-01-26 · Modified
9.1EPSS 0.020
CVE-2023-39356
Missing offset validation leading to Out-of-Bounds Read in FreeRDP
Published 2023-08-31 · Modified
9.1EPSS 0.018
CVE-2023-44981
Apache ZooKeeper: Authorization bypass in SASL Quorum Peer Authentication
Published 2023-10-11 · Modified
9.1EPSS 0.017
CVE-2023-40181
Integer-Underflow leading to Out-Of-Bound Read in FreeRDP
Published 2023-08-31 · Modified
9.1EPSS 0.017
CVE-2021-43400
An issue was discovered in gatt-database.c in BlueZ 5.61. A use-after-free can occur when a client disconnects during D-Bus processing of a WriteValue call.
Published 2021-11-04 · Modified
9.1EPSS 0.017
CVE-2024-27053
wifi: wilc1000: fix RCU usage in connect path
Published 2024-05-01 · Modified
9.1EPSS 0.016
CVE-2020-15472
In nDPI through 3.2, the H.323 dissector is vulnerable to a heap-based buffer over-read in ndpi_search_h323 in lib/protocols/h323.c, as demonstrated by a payload packet length that is too short.
Published 2020-07-01 · Modified
9.1EPSS 0.015
CVE-2023-40188
Out-Of-Bounds Read in FreeRDP
Published 2023-08-31 · Modified
9.1EPSS 0.015
CVE-2023-39353
Missing offset validation leading to Out Of Bound Read in FreeRDP
Published 2023-08-31 · Modified
9.1EPSS 0.015
CVE-2009-5042
python-docutils allows insecure usage of temporary files
Published 2019-10-31 · Modified
9.1EPSS 0.014
CVE-2024-35960
net/mlx5: Properly link new fs rules into the tree
Published 2024-05-20 · Modified
9.1EPSS 0.014
CVE-2024-35845
wifi: iwlwifi: dbg-tlv: ensure NUL termination
Published 2024-05-17 · Modified
9.1EPSS 0.012
CVE-2023-41360
An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c can read the initial byte of the ORF header in an ahead-of-stream situation.
Published 2023-08-29 · Modified
9.1EPSS 0.012
CVE-2024-5197
Integer overflow in libvpx
Published 2024-06-03 · Analyzed
9.1EPSS 0.008
CVE-2024-26665
tunnels: fix out of bounds access when building IPv6 PMTU error
Published 2024-04-02 · Modified
9.1EPSS 0.007
CVE-2021-40438
mod_proxy SSRF
Published 2021-09-16 · Analyzed
9.0KEVEPSS 1.000
CVE-2021-45046
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
Published 2021-12-14 · Analyzed
9.0KEVEPSS 1.000
CVE-2021-44142
The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions prior to 4.13.17, 4.14.12 and 4.15.5 with vfs_fruit configured allow out-of-bounds heap read and write via specially crafted extended file attributes. A remote attacker with write access to extended file attributes can execute arbitrary code with the privileges of smbd, typically root.
Published 2022-02-21 · Modified
9.0EPSS 0.734
CVE-2019-14287
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invoking sudo with a crafted user ID. For example, this allows bypass of !root configuration, and USER= logging, for a "sudo -u \#$((0xffffffff))" command.
Published 2019-10-17 · Modified
9.01 PoCEPSS 0.638
CVE-2020-9273
In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-free in alloc_pool in pool.c, and possible remote code execution.
Published 2020-02-20 · Modified
9.0EPSS 0.120
CVE-2020-15180
A flaw was found in the mysql-wsrep component of mariadb. Lack of input sanitization in `wsrep_sst_method` allows for command injection that can be exploited by a remote attacker to execute arbitrary commands on galera cluster nodes. This threatens the system's confidentiality, integrity, and availability. This flaw affects mariadb versions before 10.1.47, before 10.2.34, before 10.3.25, before 10.4.15 and before 10.5.6.
Published 2021-05-27 · Modified
9.0EPSS 0.055
CVE-2013-2024
OS command injection vulnerability in the "qs" procedure from the "utils" module in Chicken before 4.9.0.
Published 2019-10-31 · Modified
9.0EPSS 0.045
CVE-2021-45960
In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory).
Published 2022-01-01 · Modified
9.0EPSS 0.042
CVE-2019-19920
sa-exim 4.2.1 allows attackers to execute arbitrary code if they can write a .cf file or a rule. This occurs because Greylisting.pm relies on eval (rather than direct parsing and/or use of the taint feature). This issue is similar to CVE-2018-11805.
Published 2019-12-22 · Modified
9.0EPSS 0.032
CVE-2021-32762
Integer overflow that can lead to heap overflow in redis-cli, redis-sentinel on some platforms
Published 2021-10-04 · Modified
9.0EPSS 0.027
CVE-2012-6639
An privilege elevation vulnerability exists in Cloud-init before 0.7.0 when requests to an untrusted system are submitted for EC2 instance data.
Published 2019-11-25 · Modified
9.0EPSS 0.020
CVE-2021-41583
vpn-user-portal (aka eduVPN or Let's Connect!) before 2.3.14, as packaged for Debian 10, Debian 11, and Fedora, allows remote authenticated users to obtain OS filesystem access, because of the interaction of QR codes with an exec that uses the -r option. This can be leveraged to obtain additional VPN access.
Published 2021-09-24 · Modified
9.0EPSS 0.019
CVE-2020-25719
A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could become confused about the user a ticket represents if it did not strictly require a Kerberos PAC and always use the SIDs found within. The result could include total domain compromise.
Published 2022-02-18 · Modified
9.0EPSS 0.017
CVE-2023-3550
Stored XSS leads to privilege escalation in MediaWiki v1.40.0
Published 2023-09-25 · Modified
9.0EPSS 0.012
← Prev11 / 86Next →