VendorsDebiandebian_linux10.0
Vulnerabilities

Debian Debian Linux 10.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3432CVEs
CVE-2023-50868
The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the "NSEC3" issue. The RFC 5155 specification implies that an algorithm must perform thousands of iterations of a hash function in certain situations.
Published 2024-02-14 · Analyzed
7.5EPSS 0.817
CVE-2022-34169
Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets
Published 2022-07-19 · Modified
7.5EPSS 0.810
CVE-2021-21341
XStream can cause a Denial of Service
Published 2021-03-22 · Analyzed
7.5EPSS 0.778
CVE-2020-36222
A flaw was discovered in OpenLDAP before 2.4.57 leading to an assertion failure in slapd in the saslAuthzTo validation, resulting in denial of service.
Published 2021-01-25 · Modified
7.5EPSS 0.772
CVE-2020-36227
A flaw was discovered in OpenLDAP before 2.4.57 leading to an infinite loop in slapd with the cancel_extop Cancel operation, resulting in denial of service.
Published 2021-01-25 · Modified
7.5EPSS 0.772
CVE-2022-29885
EncryptInterceptor does not provide complete protection on insecure networks
Published 2022-05-12 · Modified
7.51 PoCEPSS 0.735
CVE-2022-0778
Infinite loop in BN_mod_sqrt() reachable when parsing certificates
Published 2022-03-15 · Modified
7.5EPSS 0.732
CVE-2020-8450
An issue was discovered in Squid before 4.10. Due to incorrect buffer management, a remote client can cause a buffer overflow in a Squid instance acting as a reverse proxy.
Published 2020-02-04 · Modified
7.5EPSS 0.718
CVE-2020-36193
Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.
Published 2021-01-18 · Analyzed
7.5KEVEPSS 0.706
CVE-2021-26690
mod_session NULL pointer dereference
Published 2021-06-10 · Modified
7.5EPSS 0.653
CVE-2021-34798
NULL pointer dereference in httpd core
Published 2021-09-16 · Modified
7.5EPSS 0.645
CVE-2021-27212
In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in slapd can occur in the issuerAndThisUpdateCheck function via a crafted packet, resulting in a denial of service (daemon exit) via a short timestamp. This is related to schema_init.c and checkTime.
Published 2021-02-14 · Modified
7.5EPSS 0.641
CVE-2020-13934
An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a sufficient number of such requests were made, an OutOfMemoryException could occur leading to a denial of service.
Published 2020-07-14 · Modified
7.5EPSS 0.641
CVE-2021-36160
mod_proxy_uwsgi out of bound read
Published 2021-09-16 · Analyzed
7.5EPSS 0.629
CVE-2023-24580
An issue was discovered in the Multipart Request Parser in Django 3.2 before 3.2.18, 4.0 before 4.0.10, and 4.1 before 4.1.7. Passing certain inputs (e.g., an excessive number of parts) to multipart forms could result in too many open files or memory exhaustion, and provided a potential vector for a denial-of-service attack.
Published 2023-02-15 · Modified
7.5EPSS 0.626
CVE-2022-21449
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 17.0.2 and 18; Oracle GraalVM Enterprise Edition: 21.3.1 and 22.0.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).
Published 2022-04-19 · Modified
7.5EPSS 0.603
CVE-2020-11993
Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong connection, causing concurrent use of memory pools. Configuring the LogLevel of mod_http2 above "info" will mitigate this vulnerability for unpatched servers.
Published 2020-08-07 · Analyzed
7.5EPSS 0.564
CVE-2019-9516
Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service
Published 2019-08-13 · Modified
7.5EPSS 0.563
CVE-2020-1967
Segmentation fault in SSL_check_chain
Published 2020-04-21 · Modified
7.5EPSS 0.533
CVE-2018-25032
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
Published 2022-03-25 · Modified
7.5EPSS 0.517
CVE-2021-31618
NULL pointer dereference on specially crafted HTTP/2 request
Published 2021-06-15 · Modified
7.5EPSS 0.515
CVE-2021-23840
Integer overflow in CipherUpdate
Published 2021-02-16 · Modified
7.5EPSS 0.507
CVE-2020-13950
mod_proxy_http NULL pointer dereference
Published 2021-06-10 · Modified
7.5EPSS 0.494
CVE-2023-23969
In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, the parsed values of Accept-Language headers are cached in order to avoid repetitive parsing. This leads to a potential denial-of-service vector via excessive memory usage if the raw value of Accept-Language headers is very large.
Published 2023-02-01 · Modified
7.5EPSS 0.474
CVE-2021-21343
XStream is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling as long as the executing process has sufficient rights
Published 2021-03-22 · Analyzed
7.5EPSS 0.467
CVE-2021-33193
Request splitting via HTTP/2 method injection and mod_proxy
Published 2021-08-16 · Analyzed
7.5EPSS 0.462
CVE-2024-25126
Rack ReDos in content type parsing (2nd degree polynomial)
Published 2024-02-28 · Analyzed
7.5EPSS 0.354
CVE-2021-32761
Integer overflow issues with *BIT commands on 32-bit systems
Published 2021-07-21 · Modified
7.5EPSS 0.312
CVE-2020-11996
A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 to 10.0.0-M5, 9.0.0.M1 to 9.0.35 and 8.5.0 to 8.5.55 could trigger high CPU usage for several seconds. If a sufficient number of such requests were made on concurrent HTTP/2 connections, the server could become unresponsive.
Published 2020-06-26 · Modified
7.5EPSS 0.267
CVE-2020-17527
Apache Tomcat: Request header mix-up between HTTP/2 streams
Published 2020-12-03 · Modified
7.5EPSS 0.246
CVE-2024-24549
Apache Tomcat: HTTP/2 header handling DoS
Published 2024-03-13 · Modified
7.5EPSS 0.231
CVE-2019-15604
Improper Certificate Validation in Node.js 10, 12, and 13 causes the process to abort when sending a crafted X.509 certificate
Published 2020-02-07 · Modified
7.5EPSS 0.195
CVE-2021-25122
Apache Tomcat h2c request mix-up
Published 2021-03-01 · Modified
7.5EPSS 0.181
CVE-2021-32675
DoS vulnerability in Redis
Published 2021-10-04 · Modified
7.5EPSS 0.169
CVE-2022-26498
An issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it is possible to download files that are not certificates. These files could be much larger than what one would expect to download, leading to Resource Exhaustion. This is fixed in 16.25.2, 18.11.2, and 19.3.2.
Published 2022-04-15 · Modified
7.5EPSS 0.167
CVE-2022-24999
qs before 6.10.3, as used in Express before 4.17.3 and other products, allows attackers to cause a Node process hang for an Express application because an __ proto__ key can be used. In many typical Express use cases, an unauthenticated remote attacker can place the attack payload in the query string of the URL that is used to visit the application, such as a[__proto__]=b&a[__proto__]&a[length]=100000000. The fix was backported to qs 6.9.7, 6.8.3, 6.7.3, 6.6.1, 6.5.3, 6.4.1, 6.3.3, and 6.2.4 (and therefore Express 4.17.3, which has "deps: qs@6.9.7" in its release description, is not vulnerable).
Published 2022-11-26 · Modified
7.5EPSS 0.156
CVE-2019-10081
HTTP/2 (2.4.20 through 2.4.39) very early pushes, for example configured with "H2PushResource", could lead to an overwrite of memory in the pushing request's pool, leading to crashes. The memory copied is that of the configured push link header values, not data supplied by the client.
Published 2019-08-15 · Modified
7.5EPSS 0.146
CVE-2022-24713
Regular expression denial of service in Rust's regex crate
Published 2022-03-08 · Modified
7.5EPSS 0.145
CVE-2022-24785
Path Traversal in Moment.js
Published 2022-04-04 · Modified
7.5EPSS 0.139
CVE-2021-22940
Node.js before 16.6.1, 14.17.5, and 12.22.5 is vulnerable to a use after free attack where an attacker might be able to exploit the memory corruption, to change process behavior.
Published 2021-08-16 · Modified
7.5EPSS 0.139
← Prev36 / 86Next →