VendorsDebiandebian_linux10.0
Vulnerabilities

Debian Debian Linux 10.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3432CVEs
CVE-2024-35791
KVM: SVM: Flush pages under kvm->lock to fix UAF in svm_register_enc_region()
Published 2024-05-17 · Modified
7.8EPSS 0.002
CVE-2024-26795
riscv: Sparse-Memory/vmemmap out-of-bounds fix
Published 2024-04-04 · Modified
7.8EPSS 0.002
CVE-2024-35879
of: dynamic: Synchronize of_changeset_destroy() with the devlink removals
Published 2024-05-19 · Modified
7.8EPSS 0.002
CVE-2024-26895
wifi: wilc1000: prevent use-after-free on vif when cleaning up all interfaces
Published 2024-04-17 · Modified
7.8EPSS 0.002
CVE-2023-37208
When opening Diagcab files, Firefox did not warn the user that these files may contain malicious code. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.
Published 2023-07-05 · Modified
7.8EPSS 0.002
CVE-2024-27414
rtnetlink: fix error logic of IFLA_BRIDGE_FLAGS writing back
Published 2024-05-17 · Modified
7.8EPSS 0.002
CVE-2024-26951
wireguard: netlink: check for dangling peer via is_dead instead of empty list
Published 2024-05-01 · Modified
7.8EPSS 0.002
CVE-2024-27431
cpumap: Zero-initialise xdp_rxq_info struct before running XDP program
Published 2024-05-17 · Modified
7.8EPSS 0.002
CVE-2024-35785
tee: optee: Fix kernel panic caused by incorrect error handling
Published 2024-05-17 · Modified
7.8EPSS 0.002
CVE-2023-52637
can: j1939: Fix UAF in j1939_sk_match_filter during setsockopt(SO_J1939_FILTER)
Published 2024-04-03 · Modified
7.8EPSS 0.002
CVE-2024-36007
mlxsw: spectrum_acl_tcam: Fix warning during rehash
Published 2024-05-20 · Modified
7.8EPSS 0.002
CVE-2024-27030
octeontx2-af: Use separate handlers for interrupts
Published 2024-05-01 · Modified
7.8EPSS 0.002
CVE-2024-35905
bpf: Protect against int overflow for stack access size
Published 2024-05-19 · Modified
7.8EPSS 0.002
CVE-2024-26923
af_unix: Fix garbage collector racing against connect()
Published 2024-04-24 · Modified
7.8EPSS 0.002
CVE-2023-52642
media: rc: bpf attach/detach requires write permission
Published 2024-04-17 · Analyzed
7.8EPSS 0.002
CVE-2020-6546
Inappropriate implementation in installer in Google Chrome prior to 84.0.4147.125 allowed a local attacker to potentially elevate privilege via a crafted filesystem.
Published 2020-09-21 · Modified
7.8EPSS 0.002
CVE-2024-26643
netfilter: nf_tables: mark set as dead when unbinding anonymous set with timeout
Published 2024-03-21 · Modified
7.8EPSS 0.002
CVE-2024-26974
crypto: qat - resolve race condition during AER recovery
Published 2024-05-01 · Modified
7.8EPSS 0.002
CVE-2023-21255
In multiple functions of binder.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-07-12 · Modified
7.8EPSS 0.002
CVE-2024-26614
tcp: make sure init the accept_queue's spinlocks once
Published 2024-02-29 · Modified
7.8EPSS 0.002
CVE-2020-26258
Server-Side Forgery Request can be activated unmarshalling with XStream
Published 2020-12-16 · Analyzed
7.7EPSS 0.818
CVE-2022-25647
Deserialization of Untrusted Data
Published 2022-05-01 · Modified
7.7EPSS 0.122
CVE-2019-3900
An infinite loop issue was found in the vhost_net kernel module in Linux Kernel up to and including v5.1-rc6, while handling incoming packets in handle_rx(). It could occur if one end sends packets faster than the other end can process them. A guest user, maybe remote one, could use this flaw to stall the vhost_net kernel thread, resulting in a DoS scenario.
Published 2019-04-25 · Modified
7.7EPSS 0.043
CVE-2020-13692
PostgreSQL JDBC Driver (aka PgJDBC) before 42.2.13 allows XXE.
Published 2020-06-04 · Modified
7.7EPSS 0.041
CVE-2020-14147
An integer overflow in the getnum function in lua_struct.c in Redis before 6.0.3 allows context-dependent attackers with permission to run Lua code in a Redis session to cause a denial of service (memory corruption and application crash) or possibly bypass intended sandbox restrictions via a large number, which triggers a stack-based buffer overflow. NOTE: this issue exists because of a CVE-2015-8080 regression.
Published 2020-06-15 · Modified
7.7EPSS 0.031
CVE-2022-21682
flatpak-builder can access files outside the build directory.
Published 2022-01-13 · Modified
7.7EPSS 0.017
CVE-2023-27538
An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previously used connections to reuse them for subsequent transfers if the configurations match. However, two SSH settings were omitted from the configuration check, allowing them to match easily, potentially leading to the reuse of an inappropriate connection.
Published 2023-03-30 · Modified
7.7EPSS 0.013
CVE-2022-0908
Null source pointer passed as an argument to memcpy() function within TIFFFetchNormalTag () in tif_dirread.c in libtiff versions up to 4.3.0 could lead to Denial of Service via crafted TIFF file.
Published 2022-03-11 · Modified
7.7EPSS 0.013
CVE-2022-3570
Multiple heap buffer overflows in tiffcrop.c utility in libtiff library Version 4.4.0 allows attacker to trigger unsafe or out of bounds memory access via crafted TIFF image file which could result into application crash, potential information disclosure or any other context-dependent impact
Published 2022-10-21 · Modified
7.7EPSS 0.005
CVE-2020-6555
Out of bounds read in WebGL in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
Published 2020-09-21 · Modified
7.6EPSS 0.022
CVE-2023-6478
Xorg-x11-server: out-of-bounds memory read in rrchangeoutputproperty and rrchangeproviderproperty
Published 2023-12-13 · Modified
7.6EPSS 0.016
CVE-2021-39201
Authenticated cross-site scripting (XSS) in WordPress editor
Published 2021-09-09 · Modified
7.6EPSS 0.015
CVE-2023-44487
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Published 2023-10-10 · Analyzed
7.5KEV1 PoCEPSS 1.000
CVE-2022-30333
RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected.
Published 2022-05-09 · Analyzed
7.5KEVEPSS 0.991
CVE-2024-31309
Apache Traffic Server: HTTP/2 CONTINUATION frames can be utilized for DoS attack
Published 2024-04-10 · Modified
7.5EPSS 0.946
CVE-2020-8617
A logic error in code which checks TSIG validity can be used to trigger an assertion failure in tsig.c
Published 2020-05-19 · Modified
7.51 PoCEPSS 0.934
CVE-2020-9490
Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resource afterwards. Configuring the HTTP/2 feature via "H2Push off" will mitigate this vulnerability for unpatched servers.
Published 2020-08-07 · Modified
7.5EPSS 0.888
CVE-2020-13935
The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with invalid payload lengths could lead to a denial of service.
Published 2020-07-14 · Modified
7.5EPSS 0.866
CVE-2020-36221
An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd crashes in the Certificate Exact Assertion processing, resulting in denial of service (schema_init.c serialNumberAndIssuerCheck).
Published 2021-01-25 · Modified
7.5EPSS 0.850
CVE-2020-36228
An integer underflow was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Certificate List Exact Assertion processing, resulting in denial of service.
Published 2021-01-25 · Modified
7.5EPSS 0.850
← Prev35 / 86Next →