VendorsDebiandebian_linux10.0
Vulnerabilities

Debian Debian Linux 10.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3432CVEs
CVE-2019-20421
In Jp2Image::readMetadata() in jp2image.cpp in Exiv2 0.27.2, an input file can result in an infinite loop and hang, with high CPU consumption. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file.
Published 2020-01-27 · Modified
7.8EPSS 0.043
CVE-2019-14744
In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with minimal user interaction. This relates to libKF5ConfigCore.so, and the mishandling of .desktop and .directory files, as demonstrated by a shell command on an Icon line in a .desktop file.
Published 2019-08-07 · Modified
7.8EPSS 0.041
CVE-2019-14811
A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.
Published 2019-09-03 · Modified
7.8EPSS 0.037
CVE-2021-36052
XMPToolkit SDK ImportTIFF_CheckStandardMapping Memory Corruption
Published 2021-09-01 · Modified
7.8EPSS 0.032
CVE-2020-12066
CServer::SendMsg in engine/server/server.cpp in Teeworlds 0.7.x before 0.7.5 allows remote attackers to shut down the server.
Published 2020-04-22 · Modified
7.8EPSS 0.030
CVE-2022-32250
net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local user (able to create user/net namespaces) to escalate privileges to root because an incorrect NFT_STATEFUL_EXPR check leads to a use-after-free.
Published 2022-06-02 · Modified
7.8EPSS 0.029
CVE-2022-1616
Use after free in append_command in vim/vim
Published 2022-05-07 · Modified
7.8EPSS 0.027
CVE-2024-36971
net: fix __dst_negative_advice() race
Published 2024-06-10 · Analyzed
7.8KEVEPSS 0.027
CVE-2020-7919
Go before 1.12.16 and 1.13.x before 1.13.7 (and the crypto/cryptobyte package before 0.0.0-20200124225646-8b5121be2f68 for Go) allows attacks on clients (resulting in a panic) via a malformed X.509 certificate.
Published 2020-03-16 · Modified
7.8EPSS 0.026
CVE-2020-18032
Buffer Overflow in Graphviz Graph Visualization Tools from commit ID f8b9e035 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by loading a crafted file into the "lib/common/shapes.c" component.
Published 2021-04-29 · Modified
7.8EPSS 0.026
CVE-2022-1619
Heap-based Buffer Overflow in function cmdline_erase_chars in vim/vim
Published 2022-05-08 · Modified
7.8EPSS 0.025
CVE-2020-13428
A heap-based buffer overflow in the hxxx_AnnexB_to_xVC function in modules/packetizer/hxxx_nal.c in VideoLAN VLC media player before 3.0.11 for macOS/iOS allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted H.264 Annex-B video (.avi for example) file.
Published 2020-06-08 · Modified
7.8EPSS 0.024
CVE-2022-1621
Heap buffer overflow in vim_strncpy find_word in vim/vim
Published 2022-05-09 · Modified
7.8EPSS 0.024
CVE-2019-12979
ImageMagick 7.0.8-34 has a "use of uninitialized value" vulnerability in the SyncImageSettings function in MagickCore/image.c. This is related to AcquireImage in magick/image.c.
Published 2019-06-26 · Modified
7.8EPSS 0.024
CVE-2017-5510
coders/psd.c in ImageMagick allows remote attackers to have unspecified impact via a crafted PSD file, which triggers an out-of-bounds write.
Published 2017-03-24 · Modified
7.8EPSS 0.023
CVE-2021-32920
Prosody before 0.11.9 allows Uncontrolled CPU Consumption via a flood of SSL/TLS renegotiation requests.
Published 2021-05-13 · Modified
7.8EPSS 0.023
CVE-2017-5333
Integer overflow in the extract_group_icon_cursor_resource function in b/wrestool/extract.c in icoutils before 0.31.1 allows local users to cause a denial of service (process crash) or execute arbitrary code via a crafted executable file.
Published 2019-11-04 · Modified
7.8EPSS 0.022
CVE-2024-26581
netfilter: nft_set_rbtree: skip end interval element from gc
Published 2024-02-20 · Modified
7.8EPSS 0.022
CVE-2019-18397
A buffer overflow in the fribidi_get_par_embedding_levels_ex() function in lib/fribidi-bidi.c of GNU FriBidi through 1.0.7 allows an attacker to cause a denial of service or possibly execute arbitrary code by delivering crafted text content to a user, when this content is then rendered by an application that uses FriBidi for text layout calculations. Examples include any GNOME or GTK+ based application that uses Pango for text layout, as this internally uses FriBidi for bidirectional text layout. For example, the attacker can construct a crafted text file to be opened in GEdit, or a crafted IRC message to be viewed in HexChat.
Published 2019-11-13 · Modified
7.8EPSS 0.022
CVE-2022-1720
Buffer Over-read in function grab_file_name in vim/vim
Published 2022-05-16 · Modified
7.8EPSS 0.022
CVE-2021-29457
Heap buffer overflow in Exiv2::Jp2Image::doWriteMetadata
Published 2021-04-19 · Modified
7.8EPSS 0.022
CVE-2017-5332
The extract_group_icon_cursor_resource in wrestool/extract.c in icoutils before 0.31.1 can access unallocated memory, which allows local users to cause a denial of service (process crash) and execute arbitrary code via a crafted executable.
Published 2019-11-04 · Modified
7.8EPSS 0.021
CVE-2019-13602
An Integer Underflow in MP4_EIA608_Convert() in modules/demux/mp4/mp4.c in VideoLAN VLC media player through 3.0.7.1 allows remote attackers to cause a denial of service (heap-based buffer overflow and crash) or possibly have unspecified other impact via a crafted .mp4 file.
Published 2019-07-14 · Modified
7.8EPSS 0.021
CVE-2019-1010006
Evince 3.26.0 is affected by buffer overflow. The impact is: DOS / Possible code execution. The component is: backend/tiff/tiff-document.c. The attack vector is: Victim must open a crafted PDF file. The issue occurs because of an incorrect integer overflow protection mechanism in tiff_document_render and tiff_document_get_thumbnail.
Published 2019-07-15 · Modified
7.8EPSS 0.021
CVE-2019-13304
ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because of a misplaced assignment.
Published 2019-07-05 · Modified
7.8EPSS 0.021
CVE-2019-13305
ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because of a misplaced strncpy and an off-by-one error.
Published 2019-07-05 · Modified
7.8EPSS 0.021
CVE-2019-13307
ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/statistic.c in EvaluateImages because of mishandling rows.
Published 2019-07-05 · Modified
7.8EPSS 0.021
CVE-2019-14817
A flaw was found in, ghostscript versions prior to 9.50, in the .pdfexectoken and other procedures where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.
Published 2019-09-03 · Modified
7.8EPSS 0.020
CVE-2020-27814
A heap-buffer overflow was found in the way openjpeg2 handled certain PNG format files. An attacker could use this flaw to cause an application crash or in some cases execute arbitrary code with the permission of the user running such an application.
Published 2021-01-25 · Modified
7.8EPSS 0.020
CVE-2021-45444
In zsh before 5.8.1, an attacker can achieve code execution if they control a command output inside the prompt, as demonstrated by a %F argument. This occurs because of recursive PROMPT_SUBST expansion.
Published 2022-02-13 · Modified
7.8EPSS 0.020
CVE-2019-14970
A vulnerability in mkv::event_thread_t in VideoLAN VLC media player 3.0.7.1 allows remote attackers to trigger a heap-based buffer overflow via a crafted .mkv file.
Published 2019-08-29 · Modified
7.8EPSS 0.019
CVE-2020-29394
A buffer overflow in the dlt_filter_load function in dlt_common.c from dlt-daemon through 2.18.5 (GENIVI Diagnostic Log and Trace) allows arbitrary code execution because fscanf is misused (no limit on the number of characters to be read in the format argument).
Published 2020-11-30 · Modified
7.8EPSS 0.019
CVE-2021-45342
A buffer overflow vulnerability in CDataList of the jwwlib component of LibreCAD 2.2.0-rc3 and older allows an attacker to achieve Remote Code Execution using a crafted JWW document.
Published 2022-01-25 · Modified
7.8EPSS 0.019
CVE-2019-9854
Unsafe URL assembly flaw in allowed script location check
Published 2019-09-06 · Modified
7.8EPSS 0.019
CVE-2021-4019
Heap-based Buffer Overflow in vim/vim
Published 2021-12-01 · Analyzed
7.8EPSS 0.019
CVE-2019-9852
Insufficient URL encoding flaw in allowed script location check
Published 2019-08-15 · Modified
7.8EPSS 0.019
CVE-2020-35523
An integer overflow flaw was found in libtiff that exists in the tif_getimage.c file. This flaw allows an attacker to inject and execute arbitrary code when a user opens a crafted TIFF file. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Published 2021-03-09 · Modified
7.8EPSS 0.019
CVE-2020-12762
json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend.
Published 2020-05-09 · Modified
7.8EPSS 0.019
CVE-2020-35524
A heap-based buffer overflow flaw was found in libtiff in the handling of TIFF images in libtiff's TIFF2PDF tool. A specially crafted TIFF file can lead to arbitrary code execution. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Published 2021-03-09 · Modified
7.8EPSS 0.019
CVE-2019-18218
cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a heap-based buffer overflow (4-byte out-of-bounds write).
Published 2019-10-21 · Modified
7.8EPSS 0.019
← Prev26 / 86Next →