VendorsDebiandebian_linux10.0
Vulnerabilities

Debian Debian Linux 10.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3432CVEs
CVE-2021-21349
A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host
Published 2021-03-22 · Analyzed
8.6EPSS 0.468
CVE-2020-8616
BIND does not sufficiently limit the number of fetches performed when processing referrals
Published 2020-05-19 · Modified
8.6EPSS 0.106
CVE-2020-25097
An issue was discovered in Squid through 4.13 and 5.x through 5.0.4. Due to improper input validation, it allows a trusted client to perform HTTP Request Smuggling and access services otherwise forbidden by the security controls. This occurs for certain uri_whitespace configuration settings.
Published 2021-03-19 · Modified
8.6EPSS 0.082
CVE-2020-24606
Squid before 4.13 and 5.x before 5.0.4 allows a trusted peer to perform Denial of Service by consuming all available CPU cycles during handling of a crafted Cache Digest response message. This only occurs when cache_peer is used with the cache digests feature. The problem exists because peerDigestHandleReply() livelocking in peer_digest.cc mishandles EOF.
Published 2020-08-24 · Modified
8.6EPSS 0.052
CVE-2020-27153
In BlueZ before 5.55, a double free was found in the gatttool disconnect_cb() routine from shared/att.c. A remote attacker could potentially cause a denial of service or code execution, during service discovery, due to a redundant disconnect MGMT event.
Published 2020-10-15 · Modified
8.6EPSS 0.043
CVE-2020-8161
A directory traversal vulnerability exists in rack < 2.2.0 that allows an attacker perform directory traversal vulnerability in the Rack::Directory app that is bundled with Rack which could result in information disclosure.
Published 2020-07-02 · Modified
8.6EPSS 0.034
CVE-2021-37701
Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links
Published 2021-08-31 · Modified
8.6EPSS 0.033
CVE-2022-2132
A permissive list of allowed inputs flaw was found in DPDK. This issue allows a remote attacker to cause a denial of service triggered by sending a crafted Vhost header to DPDK.
Published 2022-08-31 · Modified
8.6EPSS 0.022
CVE-2021-23434
Prototype Pollution
Published 2021-08-27 · Modified
8.6EPSS 0.019
CVE-2021-37712
Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links
Published 2021-08-31 · Modified
8.6EPSS 0.019
CVE-2023-3823
Security issue with external entity loading in XML without enabling it
Published 2023-08-11 · Modified
8.6EPSS 0.016
CVE-2021-43860
Permissions granted to applications can be hidden from the user at install time
Published 2022-01-12 · Modified
8.6EPSS 0.013
CVE-2021-21202
Use after free in extensions in Google Chrome prior to 90.0.4430.72 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
Published 2021-04-26 · Modified
8.6EPSS 0.010
CVE-2021-21207
Use after free in IndexedDB in Google Chrome prior to 90.0.4430.72 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
Published 2021-04-26 · Modified
8.6EPSS 0.009
CVE-2024-5696
By manipulating the text in an `&lt;input&gt;` tag, an attacker could have caused corrupt memory leading to a potentially exploitable crash. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
Published 2024-06-11 · Analyzed
8.6EPSS 0.008
CVE-2024-32487
less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation typically requires use with attacker-controlled file names, such as the files extracted from an untrusted archive. Exploitation also requires the LESSOPEN environment variable, but this is set by default in many common cases.
Published 2024-04-13 · Analyzed
8.6EPSS 0.006
CVE-2020-6554
Use after free in extensions in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially perform a sandbox escape via a crafted Chrome Extension.
Published 2020-09-21 · Modified
8.6EPSS 0.006
CVE-2024-26641
ip6_tunnel: make sure to pull inner header in __ip6_tnl_rcv()
Published 2024-03-18 · Modified
8.6EPSS 0.006
CVE-2021-39144
XStream is vulnerable to a Remote Command Execution attack
Published 2021-08-23 · Analyzed
8.5KEVEPSS 0.981
CVE-2021-39141
XStream is vulnerable to an Arbitrary Code Execution attack
Published 2021-08-23 · Analyzed
8.5EPSS 0.161
CVE-2021-39146
XStream is vulnerable to an Arbitrary Code Execution attack
Published 2021-08-23 · Analyzed
8.5EPSS 0.143
CVE-2021-39152
A Server-Side Forgery Request vulnerability in XStream via HashMap unmarshaling
Published 2021-08-23 · Analyzed
8.5EPSS 0.114
CVE-2021-39149
XStream is vulnerable to an Arbitrary Code Execution attack
Published 2021-08-23 · Analyzed
8.5EPSS 0.047
CVE-2021-39154
XStream is vulnerable to an Arbitrary Code Execution attack
Published 2021-08-23 · Analyzed
8.5EPSS 0.047
CVE-2021-39151
XStream is vulnerable to an Arbitrary Code Execution attack
Published 2021-08-23 · Analyzed
8.5EPSS 0.047
CVE-2021-39147
XStream is vulnerable to an Arbitrary Code Execution attack
Published 2021-08-23 · Analyzed
8.5EPSS 0.047
CVE-2021-39148
XStream is vulnerable to an Arbitrary Code Execution attack
Published 2021-08-23 · Analyzed
8.5EPSS 0.047
CVE-2021-39153
XStream is vulnerable to an Arbitrary Code Execution attack
Published 2021-08-23 · Analyzed
8.5EPSS 0.045
CVE-2021-39145
XStream is vulnerable to an Arbitrary Code Execution attack
Published 2021-08-23 · Analyzed
8.5EPSS 0.041
CVE-2021-39150
A Server-Side Forgery Request vulnerability in XStream via PriorityQueue unmarshaling
Published 2021-08-23 · Analyzed
8.5EPSS 0.034
CVE-2021-3682
A flaw was found in the USB redirector device emulation of QEMU in versions prior to 6.1.0-rc2. It occurs when dropping packets during a bulk transfer from a SPICE client due to the packet queue being full. A malicious SPICE client could use this flaw to make QEMU call free() with faked heap chunk metadata, resulting in a crash of QEMU or potential code execution with the privileges of the QEMU process on the host.
Published 2021-08-05 · Modified
8.5EPSS 0.029
CVE-2020-25717
A flaw was found in the way Samba maps domain users to local users. An authenticated attacker could use this flaw to cause possible privilege escalation.
Published 2022-02-18 · Modified
8.5EPSS 0.016
CVE-2021-42097
GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrf_token value is not specific to a single user account. An attacker can obtain a value within the context of an unprivileged user account, and then use that value in a CSRF attack against an admin (e.g., for account takeover).
Published 2021-10-21 · Modified
8.5EPSS 0.013
CVE-2020-5291
Privilege escalation in setuid mode via user namespaces in Bubblewrap
Published 2020-03-31 · Modified
8.5EPSS 0.009
CVE-2022-0572
Heap-based Buffer Overflow in vim/vim
Published 2022-02-13 · Modified
8.4EPSS 0.265
CVE-2022-0714
Heap-based Buffer Overflow in vim/vim
Published 2022-02-22 · Modified
8.4EPSS 0.127
CVE-2024-29944
An attacker was able to inject an event handler into a privileged object that would allow arbitrary JavaScript execution in the parent process. Note: This vulnerability affects Desktop Firefox only, it does not affect mobile versions of Firefox. This vulnerability affects Firefox < 124.0.1 and Firefox ESR < 115.9.1.
Published 2024-03-22 · Analyzed
8.4EPSS 0.047
CVE-2022-0629
Stack-based Buffer Overflow in vim/vim
Published 2022-02-17 · Modified
8.4EPSS 0.019
CVE-2022-0685
Use of Out-of-range Pointer Offset in vim/vim
Published 2022-02-20 · Modified
8.4EPSS 0.017
CVE-2022-0554
Use of Out-of-range Pointer Offset in vim/vim
Published 2022-02-10 · Modified
8.4EPSS 0.017
← Prev22 / 86Next →