VendorsDebiandebian_linux10.0
Vulnerabilities

Debian Debian Linux 10.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3432CVEs
CVE-2022-2129
Out-of-bounds Write in vim/vim
Published 2022-06-19 · Modified
7.8EPSS 0.014
CVE-2022-1968
Use After Free in vim/vim
Published 2022-06-02 · Modified
7.8EPSS 0.014
CVE-2021-3347
An issue was discovered in the Linux kernel through 5.10.11. PI futexes have a kernel stack use-after-free during fault handling, allowing local users to execute code in the kernel, aka CID-34b1a1ce1458.
Published 2021-01-29 · Modified
7.8EPSS 0.014
CVE-2021-3974
Use After Free in vim/vim
Published 2021-11-19 · Modified
7.8EPSS 0.014
CVE-2021-30846
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, Safari 15, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing maliciously crafted web content may lead to arbitrary code execution.
Published 2021-10-19 · Modified
7.8EPSS 0.014
CVE-2022-0359
Heap-based Buffer Overflow in vim/vim
Published 2022-01-26 · Modified
7.8EPSS 0.013
CVE-2021-45078
stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write. NOTE: this issue exists because of an incorrect fix for CVE-2018-12699.
Published 2021-12-15 · Modified
7.8EPSS 0.013
CVE-2021-32277
An issue was discovered in faad2 through 2.10.0. A heap-buffer-overflow exists in the function sbr_qmf_analysis_32 located in sbr_qmf.c. It allows an attacker to cause code Execution.
Published 2021-09-20 · Modified
7.8EPSS 0.013
CVE-2021-4069
Use After Free in vim/vim
Published 2021-12-06 · Modified
7.8EPSS 0.013
CVE-2021-32274
An issue was discovered in faad2 through 2.10.0. A heap-buffer-overflow exists in the function sbr_qmf_synthesis_64 located in sbr_qmf.c. It allows an attacker to cause code Execution.
Published 2021-09-20 · Modified
7.8EPSS 0.013
CVE-2021-32278
An issue was discovered in faad2 through 2.10.0. A heap-buffer-overflow exists in the function lt_prediction located in lt_predict.c. It allows an attacker to cause code Execution.
Published 2021-09-20 · Modified
7.8EPSS 0.013
CVE-2016-10729
An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. The "runtar" setuid root binary does not check for additional arguments supplied after --create, allowing users to manipulate commands and perform command injection as root.
Published 2018-10-24 · Modified
7.8EPSS 0.013
CVE-2021-32272
An issue was discovered in faad2 before 2.10.0. A heap-buffer-overflow exists in the function stszin located in mp4read.c. It allows an attacker to cause Code Execution.
Published 2021-09-20 · Modified
7.8EPSS 0.013
CVE-2018-20196
There is a stack-based buffer overflow in the third instance of the calculate_gain function in libfaad/sbr_hfadj.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. A crafted input will lead to a denial of service or possibly unspecified other impact because the S_M array is mishandled.
Published 2018-12-18 · Modified
7.8EPSS 0.013
CVE-2020-8177
curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for files and other resources that can lead too overwriting a local file when the -J flag is used.
Published 2020-12-14 · Modified
7.8EPSS 0.013
CVE-2022-39377
sysstat Incorrect Buffer Size calculation on 32-bit systems results in RCE via buffer overflow
Published 2022-11-08 · Modified
7.8EPSS 0.012
CVE-2021-3497
GStreamer before 1.18.4 might access already-freed memory in error code paths when demuxing certain malformed Matroska files.
Published 2021-04-19 · Modified
7.8EPSS 0.012
CVE-2022-0546
A missing bounds check in the image loader used in Blender 3.x and 2.93.8 leads to out-of-bounds heap access, allowing an attacker to cause denial of service, memory corruption or potentially code execution.
Published 2022-02-24 · Modified
7.8EPSS 0.012
CVE-2022-1011
A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write(). This flaw allows a local user to gain unauthorized access to data from the FUSE filesystem, resulting in privilege escalation.
Published 2022-03-18 · Analyzed
7.8EPSS 0.012
CVE-2022-0545
An integer overflow in the processing of loaded 2D images leads to a write-what-where vulnerability and an out-of-bounds read vulnerability, allowing an attacker to leak sensitive information or achieve code execution in the context of the Blender process when a specially crafted image file is loaded. This flaw affects Blender versions prior to 2.83.19, 2.93.8 and 3.1.
Published 2022-02-24 · Modified
7.8EPSS 0.012
CVE-2021-32273
An issue was discovered in faad2 through 2.10.0. A stack-buffer-overflow exists in the function ftypin located in mp4read.c. It allows an attacker to cause Code Execution.
Published 2021-09-20 · Modified
7.8EPSS 0.012
CVE-2020-29661
A locking issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_jobctrl.c allows a use-after-free attack against TIOCSPGRP, aka CID-54ffccbf053b.
Published 2020-12-09 · Modified
7.8EPSS 0.011
CVE-2021-45844
Improper sanitization in the invocation of ODA File Converter from FreeCAD 0.19 allows an attacker to inject OS commands via a crafted filename.
Published 2022-01-25 · Modified
7.8EPSS 0.011
CVE-2020-27823
A flaw was found in OpenJPEG’s encoder. This flaw allows an attacker to pass specially crafted x,y offset input to OpenJPEG to use during encoding. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Published 2021-05-13 · Modified
7.8EPSS 0.011
CVE-2011-1588
Thunar before 1.3.1 could crash when copy and pasting a file name with % format characters due to a format string error.
Published 2019-11-14 · Modified
7.8EPSS 0.011
CVE-2023-26604
systemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e.g., plausible sudoers files in which the "systemctl status" command may be executed. Specifically, systemd does not set LESSSECURE to 1, and thus other programs may be launched from the less program. This presents a substantial security risk when running systemctl from Sudo, because less executes as root when the terminal size is too small to show the complete systemctl output.
Published 2023-03-03 · Analyzed
7.8EPSS 0.011
CVE-2021-3472
A flaw was found in xorg-x11-server in versions before 1.20.11. An integer underflow can occur in xserver which can lead to a local privilege escalation. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Published 2021-04-26 · Modified
7.8EPSS 0.011
CVE-2021-32493
A flaw was found in djvulibre-3.5.28 and earlier. A heap buffer overflow in function DJVU::GBitmap::decode() via crafted djvu file may lead to application crash and other consequences.
Published 2021-06-24 · Modified
7.8EPSS 0.010
CVE-2024-32465
Git's protections for cloning untrusted repositories can be bypassed
Published 2024-05-14 · Analyzed
7.8EPSS 0.010
CVE-2022-24765
Uncontrolled search for the Git directory in Git for Windows
Published 2022-04-12 · Modified
7.8EPSS 0.010
CVE-2021-32492
A flaw was found in djvulibre-3.5.28 and earlier. An out of bounds read in function DJVU::DataPool::has_data() via crafted djvu file may lead to application crash and other consequences.
Published 2021-06-24 · Modified
7.8EPSS 0.010
CVE-2021-44731
snapd could be made to escalate privileges and run programs as administrator
Published 2022-02-17 · Modified
7.8EPSS 0.010
CVE-2021-37969
Inappropriate implementation in Google Updater in Google Chrome on Windows prior to 94.0.4606.54 allowed a remote attacker to perform local privilege escalation via a crafted file.
Published 2021-10-08 · Modified
7.8EPSS 0.009
CVE-2021-3500
A flaw was found in djvulibre-3.5.28 and earlier. A Stack overflow in function DJVU::DjVuDocument::get_djvu_file() via crafted djvu file may lead to application crash and other consequences.
Published 2021-06-24 · Modified
7.8EPSS 0.009
CVE-2022-29581
Improper Update of Reference Count vulnerability in net/sched of Linux Kernel allows local attacker to cause privilege escalation to root. This issue affects: Linux Kernel versions prior to 5.18; version 4.14 and later versions.
Published 2022-05-17 · Modified
7.8EPSS 0.009
CVE-2023-4004
Kernel: netfilter: use-after-free due to improper element removal in nft_pipapo_remove()
Published 2023-07-31 · Modified
7.8EPSS 0.009
CVE-2021-32491
A flaw was found in djvulibre-3.5.28 and earlier. An integer overflow in function render() in tools/ddjvu via crafted djvu file may lead to application crash and other consequences.
Published 2021-06-24 · Modified
7.8EPSS 0.009
CVE-2021-32490
A flaw was found in djvulibre-3.5.28 and earlier. An out of bounds write in function DJVU::filter_bv() via crafted djvu file may lead to application crash and other consequences.
Published 2021-06-24 · Modified
7.8EPSS 0.009
CVE-2021-36409
There is an Assertion `scaling_list_pred_matrix_id_delta==1' failed at sps.cc:925 in libde265 v1.0.8 when decoding file, which allows attackers to cause a Denial of Service (DoS) by running the application with a crafted file or possibly have unspecified other impact.
Published 2022-01-10 · Modified
7.8EPSS 0.009
CVE-2022-42720
Various refcounting bugs in the multi-BSS handling in the mac80211 stack in the Linux kernel 5.1 through 5.19.x before 5.19.16 could be used by local attackers (able to inject WLAN frames) to trigger use-after-free conditions to potentially execute code.
Published 2022-10-13 · Modified
7.8EPSS 0.009
← Prev28 / 86Next →