VendorsDebiandebian_linux10.0
Vulnerabilities

Debian Debian Linux 10.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3432CVEs
CVE-2022-47519
An issue was discovered in the Linux kernel before 6.0.11. Missing validation of IEEE80211_P2P_ATTR_OPER_CHANNEL in drivers/net/wireless/microchip/wilc1000/cfg80211.c in the WILC1000 wireless driver can trigger an out-of-bounds write when parsing the channel list attribute from Wi-Fi management frames.
Published 2022-12-18 · Modified
7.8EPSS 0.003
CVE-2024-27401
firewire: nosy: ensure user_length is taken into account when fetching packet contents
Published 2024-05-13 · Modified
7.8EPSS 0.003
CVE-2024-27008
drm: nv04: Fix out of bounds access
Published 2024-05-01 · Analyzed
7.8EPSS 0.003
CVE-2024-36933
nsh: Restore skb->{protocol,data,mac_header} for outer header in nsh_gso_segment().
Published 2024-05-30 · Modified
7.8EPSS 0.003
CVE-2024-26994
speakup: Avoid crash on very long word
Published 2024-05-01 · Modified
7.8EPSS 0.003
CVE-2024-36934
bna: ensure the copied buf is NUL terminated
Published 2024-05-30 · Analyzed
7.8EPSS 0.003
CVE-2024-26809
netfilter: nft_set_pipapo: release elements in clone only from destroy path
Published 2024-04-04 · Modified
7.8EPSS 0.003
CVE-2024-27073
media: ttpci: fix two memleaks in budget_av_attach
Published 2024-05-01 · Modified
7.8EPSS 0.003
CVE-2023-34319
Linux: buffer overrun in netback due to unusual packet
Published 2023-09-22 · Modified
7.8EPSS 0.003
CVE-2020-15983
Insufficient data validation in webUI in Google Chrome on ChromeOS prior to 86.0.4240.75 allowed a local attacker to bypass content security policy via a crafted HTML page.
Published 2020-11-03 · Modified
7.8EPSS 0.003
CVE-2023-2007
The specific flaw exists within the DPT I2O Controller driver. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this in conjunction with other vulnerabilities to escalate privileges and execute arbitrary code in the context of the kernel.
Published 2023-04-24 · Modified
7.8EPSS 0.003
CVE-2020-11739
An issue was discovered in Xen through 4.13.x, allowing guest OS users to cause a denial of service or possibly gain privileges because of missing memory barriers in read-write unlock paths. The read-write unlock paths don't contain a memory barrier. On Arm, this means a processor is allowed to re-order the memory access with the preceding ones. In other words, the unlock may be seen by another processor before all the memory accesses within the "critical" section. As a consequence, it may be possible to have a writer executing a critical section at the same time as readers or another writer. In other words, many of the assumptions (e.g., a variable cannot be modified after a check) in the critical sections are not safe anymore. The read-write locks are used in hypercalls (such as grant-table ones), so a malicious guest could exploit the race. For instance, there is a small window where Xen can leak memory if XENMAPSPACE_grant_table is used concurrently. A malicious guest may be able to leak memory, or cause a hypervisor crash resulting in a Denial of Service (DoS). Information leak and privilege escalation cannot be excluded.
Published 2020-04-14 · Modified
7.8EPSS 0.003
CVE-2023-4623
Use-after-free in Linux kernel's net/sched: sch_hfsc (HFSC qdisc traffic control) component
Published 2023-09-06 · Analyzed
7.8EPSS 0.003
CVE-2024-35886
ipv6: Fix infinite recursion in fib6_dump_done().
Published 2024-05-19 · Modified
7.8EPSS 0.003
CVE-2024-26988
init/main.c: Fix potential static_command_line memory overflow
Published 2024-05-01 · Modified
7.8EPSS 0.003
CVE-2024-26870
NFSv4.2: fix nfs4_listxattr kernel BUG at mm/usercopy.c:102
Published 2024-04-17 · Modified
7.8EPSS 0.003
CVE-2023-52623
SUNRPC: Fix a suspicious RCU usage warning
Published 2024-03-26 · Modified
7.8EPSS 0.003
CVE-2020-15567
An issue was discovered in Xen through 4.13.x, allowing Intel guest OS users to gain privileges or cause a denial of service because of non-atomic modification of a live EPT PTE. When mapping guest EPT (nested paging) tables, Xen would in some circumstances use a series of non-atomic bitfield writes. Depending on the compiler version and optimisation flags, Xen might expose a dangerous partially written PTE to the hardware, which an attacker might be able to race to exploit. A guest administrator or perhaps even an unprivileged guest user might be able to cause denial of service, data corruption, or privilege escalation. Only systems using Intel CPUs are vulnerable. Systems using AMD CPUs, and Arm systems, are not vulnerable. Only systems using nested paging (hap, aka nested paging, aka in this case Intel EPT) are vulnerable. Only HVM and PVH guests can exploit the vulnerability. The presence and scope of the vulnerability depends on the precise optimisations performed by the compiler used to build Xen. If the compiler generates (a) a single 64-bit write, or (b) a series of read-modify-write operations in the same order as the source code, the hypervisor is not vulnerable. For example, in one test build using GCC 8.3 with normal settings, the compiler generated multiple (unlocked) read-modify-write operations in source-code order, which did not constitute a vulnerability. We have not been able to survey compilers; consequently we cannot say which compiler(s) might produce vulnerable code (with which code-generation options). The source code clearly violates the C rules, and thus should be considered vulnerable.
Published 2020-07-07 · Modified
7.8EPSS 0.003
CVE-2023-3611
Out-of-bounds write in Linux kernel's net/sched: sch_qfq component
Published 2023-07-21 · Modified
7.8EPSS 0.003
CVE-2024-26981
nilfs2: fix OOB in nilfs_set_de_type
Published 2024-05-01 · Modified
7.8EPSS 0.003
CVE-2020-16007
Insufficient data validation in installer in Google Chrome prior to 86.0.4240.183 allowed a local attacker to potentially elevate privilege via a crafted filesystem.
Published 2020-11-03 · Modified
7.8EPSS 0.003
CVE-2022-34670
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an unprivileged regular user can cause truncation errors when casting a primitive to a primitive of smaller size causes data to be lost in the conversion, which may lead to denial of service or information disclosure.
Published 2022-12-30 · Modified
7.8EPSS 0.003
CVE-2023-52612
crypto: scomp - fix req->dst buffer overflow
Published 2024-03-18 · Modified
7.8EPSS 0.003
CVE-2024-26753
crypto: virtio/akcipher - Fix stack overflow on memcpy
Published 2024-04-03 · Analyzed
7.8EPSS 0.003
CVE-2024-26852
net/ipv6: avoid possible UAF in ip6_route_mpath_notify()
Published 2024-04-17 · Modified
7.8EPSS 0.003
CVE-2024-26925
netfilter: nf_tables: release mutex after nft_gc_seq_end from abort path
Published 2024-04-24 · Modified
7.8EPSS 0.003
CVE-2024-26704
ext4: fix double-free of blocks due to wrong extents moved_len
Published 2024-04-03 · Modified
7.8EPSS 0.003
CVE-2024-26766
IB/hfi1: Fix sdma.h tx->num_descs off-by-one error
Published 2024-04-03 · Modified
7.8EPSS 0.003
CVE-2024-26642
netfilter: nf_tables: disallow anonymous set with timeout flag
Published 2024-03-21 · Modified
7.8EPSS 0.003
CVE-2024-26772
ext4: avoid allocating blocks from corrupted group in ext4_mb_find_by_goal()
Published 2024-04-03 · Modified
7.8EPSS 0.003
CVE-2024-27065
netfilter: nf_tables: do not compare internal table flags on updates
Published 2024-05-01 · Modified
7.8EPSS 0.003
CVE-2022-38076
Improper input validation in some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow an authenticated user to potentially enable escalation of privilege via local access.
Published 2023-08-11 · Modified
7.8EPSS 0.003
CVE-2024-26966
clk: qcom: mmcc-apq8084: fix terminating of frequency table arrays
Published 2024-05-01 · Modified
7.8EPSS 0.003
CVE-2024-35910
tcp: properly terminate timers for kernel sockets
Published 2024-05-19 · Modified
7.8EPSS 0.003
CVE-2024-26976
KVM: Always flush async #PF workqueue when vCPU is being destroyed
Published 2024-05-01 · Modified
7.8EPSS 0.003
CVE-2024-35958
net: ena: Fix incorrect descriptor free behavior
Published 2024-05-20 · Modified
7.8EPSS 0.003
CVE-2024-35950
drm/client: Fully protect modes[] with dev->mode_config.mutex
Published 2024-05-20 · Modified
7.8EPSS 0.003
CVE-2019-17341
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges by leveraging a page-writability race condition during addition of a passed-through PCI device.
Published 2019-10-08 · Modified
7.8EPSS 0.003
CVE-2024-26965
clk: qcom: mmcc-msm8974: fix terminating of frequency table arrays
Published 2024-05-01 · Modified
7.8EPSS 0.003
CVE-2023-52482
x86/srso: Add SRSO mitigation for Hygon processors
Published 2024-02-29 · Analyzed
7.8EPSS 0.003
← Prev33 / 86Next →