VendorsDebiandebian_linux10.0
Vulnerabilities

Debian Debian Linux 10.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3432CVEs
CVE-2021-45469
In __f2fs_setxattr in fs/f2fs/xattr.c in the Linux kernel through 5.15.11, there is an out-of-bounds memory access when an inode has an invalid last xattr entry.
Published 2021-12-23 · Modified
7.8EPSS 0.005
CVE-2022-1652
Linux Kernel could allow a local attacker to execute arbitrary code on the system, caused by a concurrency use-after-free flaw in the bad_flp_intr function. By executing a specially-crafted program, an attacker could exploit this vulnerability to execute arbitrary code or cause a denial of service condition on the system.
Published 2022-05-31 · Modified
7.8EPSS 0.005
CVE-2022-31676
VMware Tools (12.0.0, 11.x.y and 10.x.y) contains a local privilege escalation vulnerability. A malicious actor with local non-administrative access to the Guest OS can escalate privileges as a root user in the virtual machine.
Published 2022-08-23 · Modified
7.8EPSS 0.005
CVE-2021-4197
An unprivileged write to the file handler flaw in the Linux kernel's control groups and namespaces subsystem was found in the way users have access to some less privileged process that are controlled by cgroups and have higher privileged parent process. It is actually both for cgroup2 and cgroup1 versions of control groups. A local user could use this flaw to crash the system or escalate their privileges on the system.
Published 2022-03-23 · Modified
7.8EPSS 0.005
CVE-2022-3324
Stack-based Buffer Overflow in vim/vim
Published 2022-09-27 · Analyzed
7.8EPSS 0.005
CVE-2022-2946
Use After Free in vim/vim
Published 2022-08-23 · Modified
7.8EPSS 0.005
CVE-2023-35788
An issue was discovered in fl_set_geneve_opt in net/sched/cls_flower.c in the Linux kernel before 6.3.7. It allows an out-of-bounds write in the flower classifier code via TCA_FLOWER_KEY_ENC_OPTS_GENEVE packets. This may result in denial of service or privilege escalation.
Published 2023-06-16 · Modified
7.8EPSS 0.005
CVE-2022-3234
Heap-based Buffer Overflow in vim/vim
Published 2022-09-17 · Modified
7.8EPSS 0.005
CVE-2019-13164
qemu-bridge-helper.c in QEMU 3.1 and 4.0.0 does not ensure that a network interface name (obtained from bridge.conf or a --br=bridge option) is limited to the IFNAMSIZ size, which can lead to an ACL bypass.
Published 2019-07-03 · Modified
7.8EPSS 0.005
CVE-2019-14846
In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG level which lead to a disclosure of credentials if a plugin used a library that logged credentials at the DEBUG level. This flaw does not affect Ansible modules, as those are executed in a separate process.
Published 2019-10-08 · Modified
7.8EPSS 0.005
CVE-2023-3776
Use-after-free in Linux kernel's net/sched: cls_fw component
Published 2023-07-21 · Modified
7.8EPSS 0.005
CVE-2023-42753
Kernel: netfilter: potential slab-out-of-bound access due to integer underflow
Published 2023-09-25 · Modified
7.8EPSS 0.005
CVE-2022-3352
Use After Free in vim/vim
Published 2022-09-29 · Modified
7.8EPSS 0.005
CVE-2022-3235
Use After Free in vim/vim
Published 2022-09-18 · Modified
7.8EPSS 0.005
CVE-2013-2016
A flaw was found in the way qemu v1.3.0 and later (virtio-rng) validates addresses when guest accesses the config space of a virtio device. If the virtio device has zero/small sized config space, such as virtio-rng, a privileged guest user could use this flaw to access the matching host's qemu address space and thus increase their privileges on the host.
Published 2019-12-30 · Modified
7.8EPSS 0.005
CVE-2021-46790
ntfsck in NTFS-3G through 2021.8.22 has a heap-based buffer overflow involving buffer+512*3-2. NOTE: the upstream position is that ntfsck is deprecated; however, it is shipped by some Linux distributions.
Published 2022-05-02 · Modified
7.8EPSS 0.005
CVE-2019-3467
Debian-edu-config all versions < 2.11.10, a set of configuration files used for Debian Edu, and debian-lan-config < 0.26, configured too permissive ACLs for the Kerberos admin server, which allowed password changes for other Kerberos user principals.
Published 2019-12-23 · Modified
7.8EPSS 0.005
CVE-2022-1921
Integer overflow in avidemux element in gst_avi_demux_invert function which allows a heap overwrite while parsing avi files. Potential for arbitrary code execution through heap overwrite.
Published 2022-07-19 · Modified
7.8EPSS 0.005
CVE-2022-1920
Integer overflow in matroskademux element in gst_matroska_demux_add_wvpk_header function which allows a heap overwrite while parsing matroska files. Potential for arbitrary code execution through heap overwrite.
Published 2022-07-19 · Modified
7.8EPSS 0.005
CVE-2020-10936
Sympa before 6.2.56 allows privilege escalation.
Published 2020-05-27 · Modified
7.8EPSS 0.005
CVE-2019-3466
The pg_ctlcluster script in postgresql-common in versions prior to 210 didn't drop privileges when creating socket/statistics temporary directories, which could result in local privilege escalation.
Published 2019-11-20 · Modified
7.8EPSS 0.005
CVE-2022-1785
Out-of-bounds Write in vim/vim
Published 2022-05-19 · Modified
7.8EPSS 0.005
CVE-2021-45417
AIDE before 0.17.4 allows local users to obtain root privileges via crafted file metadata (such as XFS extended attributes or tmpfs ACLs), because of a heap-based buffer overflow.
Published 2022-01-20 · Modified
7.8EPSS 0.005
CVE-2022-3099
Use After Free in vim/vim
Published 2022-09-03 · Modified
7.8EPSS 0.005
CVE-2023-3090
Out-of-bounds write in Linux kernel's ipvlan network driver
Published 2023-06-28 · Modified
7.8EPSS 0.005
CVE-2022-3256
Use After Free in vim/vim
Published 2022-09-22 · Analyzed
7.8EPSS 0.005
CVE-2021-35266
In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS inode pathname is supplied in an NTFS image a heap buffer overflow can occur resulting in memory disclosure, denial of service and even code execution.
Published 2021-09-07 · Modified
7.8EPSS 0.005
CVE-2021-33289
In NTFS-3G versions < 2021.8.22, when a specially crafted MFT section is supplied in an NTFS image a heap buffer overflow can occur and allow for code execution.
Published 2021-09-07 · Modified
7.8EPSS 0.005
CVE-2021-35267
NTFS-3G versions < 2021.8.22, a stack buffer overflow can occur when correcting differences in the MFT and MFTMirror allowing for code execution or escalation of privileges when setuid-root.
Published 2021-09-07 · Modified
7.8EPSS 0.005
CVE-2011-2187
xscreensaver before 5.14 crashes during activation and leaves the screen unlocked when in Blank Only Mode and when DPMS is disabled, which allows local attackers to access resources without authentication.
Published 2019-11-27 · Modified
7.8EPSS 0.005
CVE-2021-35269
NTFS-3G versions < 2021.8.22, when a specially crafted NTFS attribute from the MFT is setup in the function ntfs_attr_setup_flag, a heap buffer overflow can occur allowing for code execution and escalation of privileges.
Published 2021-09-07 · Modified
7.8EPSS 0.005
CVE-2021-35268
In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS inode is loaded in the function ntfs_inode_real_open, a heap buffer overflow can occur allowing for code execution and escalation of privileges.
Published 2021-09-07 · Modified
7.8EPSS 0.005
CVE-2022-41751
Jhead 3.06.0.1 allows attackers to execute arbitrary OS commands by placing them in a JPEG filename and then using the regeneration -rgt50 option.
Published 2022-10-17 · Modified
7.8EPSS 0.005
CVE-2013-4532
Qemu 1.1.2+dfsg to 2.1+dfsg suffers from a buffer overrun which could potentially result in arbitrary code execution on the host with the privileges of the QEMU process.
Published 2020-01-02 · Modified
7.8EPSS 0.005
CVE-2022-1925
DOS / potential heap overwrite in mkv demuxing using HEADERSTRIP decompression. Integer overflow in matroskaparse element in gst_matroska_decompress_data function which causes a heap overflow. Due to restrictions on chunk sizes in the matroskademux element, the overflow can't be triggered, however the matroskaparse element has no size checks.
Published 2022-07-19 · Modified
7.8EPSS 0.005
CVE-2022-1270
In GraphicsMagick, a heap buffer overflow was found when parsing MIFF.
Published 2022-09-28 · Modified
7.8EPSS 0.005
CVE-2021-33286
In NTFS-3G versions < 2021.8.22, when a specially crafted unicode string is supplied in an NTFS image a heap buffer overflow can occur and allow for code execution.
Published 2021-09-07 · Modified
7.8EPSS 0.005
CVE-2022-2122
DOS / potential heap overwrite in qtdemux using zlib decompression. Integer overflow in qtdemux element in qtdemux_inflate function which causes a segfault, or could cause a heap overwrite, depending on libc and OS. Depending on the libc used, and the underlying OS capabilities, it could be just a segfault or a heap overwrite.
Published 2022-07-19 · Modified
7.8EPSS 0.005
CVE-2021-39256
A crafted NTFS image can cause a heap-based buffer overflow in ntfs_inode_lookup_by_name in NTFS-3G < 2021.8.22.
Published 2021-09-07 · Modified
7.8EPSS 0.005
CVE-2022-0367
A heap-based buffer overflow flaw was found in libmodbus in function modbus_reply() in src/modbus.c.
Published 2022-08-29 · Modified
7.8EPSS 0.005
← Prev30 / 86Next →