VendorsDebiandebian_linux10.0
Vulnerabilities

Debian Debian Linux 10.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3432CVEs
CVE-2012-3543
mono 2.10.x ASP.NET Web Form Hash collision DoS
Published 2019-11-21 · Modified
7.5EPSS 0.026
CVE-2022-2048
In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug that can wind up not properly cleaning up the active connections and associated resources. This can lead to a Denial of Service scenario where there are no enough resources left to process good requests.
Published 2022-07-07 · Modified
7.5EPSS 0.026
CVE-2021-31292
An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata.
Published 2021-07-26 · Modified
7.5EPSS 0.026
CVE-2022-37797
In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer if an invalid HTTP request (websocket handshake) is received. It leads to null pointer dereference which crashes the server. It could be used by an external attacker to cause denial of service condition.
Published 2022-09-12 · Modified
7.5EPSS 0.025
CVE-2022-23094
Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKEv1 packet because pluto/ikev1.c wrongly expects that a state object exists. This is fixed in 4.6.
Published 2022-01-15 · Modified
7.5EPSS 0.025
CVE-2021-37147
Request Smuggling - LF line ending
Published 2021-11-03 · Modified
7.5EPSS 0.025
CVE-2021-32566
Specific sequence of HTTP/2 frames can cause ATS to crash
Published 2021-06-30 · Modified
7.5EPSS 0.025
CVE-2013-1817
MediaWiki before 1.19.4 and 1.20.x before 1.20.3 contains an error in the api.php script which allows remote attackers to obtain sensitive information.
Published 2019-11-20 · Modified
7.5EPSS 0.025
CVE-2022-27387
MariaDB Server v10.7 and below was discovered to contain a global buffer overflow in the component decimal_bin_size, which is exploited via specially crafted SQL statements.
Published 2022-04-12 · Modified
7.5EPSS 0.025
CVE-2021-32567
Reading HTTP/2 frames too many times
Published 2021-06-30 · Modified
7.5EPSS 0.024
CVE-2022-43680
In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.
Published 2022-10-24 · Modified
7.5EPSS 0.024
CVE-2020-6080
An exploitable denial-of-service vulnerability exists in the resource allocation handling of Videolabs libmicrodns 0.1.0. When encountering errors while parsing mDNS messages, some allocated data is not freed, possibly leading to a denial-of-service condition via resource exhaustion. An attacker can send one mDNS message repeatedly to trigger this vulnerability through the function rr_read_RR [5] reads the current resource record, except for the RDATA section. This is read by the loop at in rr_read. For each RR type, a different function is called. When the RR type is 0x10, the function rr_read_TXT is called at [6].
Published 2020-03-24 · Modified
7.5EPSS 0.024
CVE-2022-41704
Apache Batik prior to 1.16 allows RCE when loading untrusted SVG input
Published 2022-10-25 · Modified
7.5EPSS 0.024
CVE-2020-25645
A flaw was found in the Linux kernel in versions before 5.9-rc7. Traffic between two Geneve endpoints may be unencrypted when IPsec is configured to encrypt traffic for the specific UDP port used by the GENEVE tunnel allowing anyone between the two endpoints to read the traffic unencrypted. The main threat from this vulnerability is to data confidentiality.
Published 2020-10-13 · Modified
7.5EPSS 0.024
CVE-2022-27378
An issue in the component Create_tmp_table::finalize of MariaDB Server v10.7 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.
Published 2022-04-12 · Modified
7.5EPSS 0.024
CVE-2021-46669
MariaDB through 10.5.9 allows attackers to trigger a convert_const_to_int use-after-free when the BIGINT data type is used.
Published 2022-02-01 · Modified
7.5EPSS 0.024
CVE-2023-0045
Incorrect indirect branch prediction barrier in the Linux Kernel
Published 2023-04-25 · Modified
7.5EPSS 0.024
CVE-2022-24764
Stack buffer overflow in pjproject
Published 2022-03-22 · Modified
7.5EPSS 0.024
CVE-2020-9481
Apache ATS 6.0.0 to 6.2.3, 7.0.0 to 7.1.9, and 8.0.0 to 8.0.6 is vulnerable to a HTTP/2 slow read attack.
Published 2020-04-27 · Modified
7.5EPSS 0.024
CVE-2019-16236
Dino before 2019-09-10 does not check roster push authorization in module/roster/module.vala.
Published 2019-09-11 · Modified
7.5EPSS 0.024
CVE-2020-12244
An issue has been found in PowerDNS Recursor 4.1.0 through 4.3.0 where records in the answer section of a NXDOMAIN response lacking an SOA were not properly validated in SyncRes::processAnswer, allowing an attacker to bypass DNSSEC validation.
Published 2020-05-19 · Modified
7.5EPSS 0.024
CVE-2022-32091
MariaDB v10.7 was discovered to contain an use-after-poison in in __interceptor_memset at /libsanitizer/sanitizer_common/sanitizer_common_interceptors.inc.
Published 2022-07-01 · Modified
7.5EPSS 0.024
CVE-2018-18898
The email-ingestion feature in Best Practical Request Tracker 4.1.13 through 4.4 allows denial of service by remote attackers via an algorithmic complexity attack on email address parsing.
Published 2019-03-17 · Modified
7.5EPSS 0.024
CVE-2022-27377
MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component Item_func_in::cleanup(), which is exploited via specially crafted SQL statements.
Published 2022-04-12 · Modified
7.5EPSS 0.023
CVE-2013-2600
MiniUPnPd has information disclosure use of snprintf()
Published 2019-11-01 · Modified
7.5EPSS 0.023
CVE-2020-11028
Unauthenticated disclosure of certain private posts in WordPress
Published 2020-04-30 · Modified
7.5EPSS 0.023
CVE-2022-28129
Insufficient Validation of HTTP/1.x Headers
Published 2022-08-10 · Modified
7.5EPSS 0.023
CVE-2021-44420
In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines could bypass upstream access control based on URL paths.
Published 2021-12-07 · Modified
7.5EPSS 0.023
CVE-2022-31780
HTTP/2 framing vulnerabilities
Published 2022-08-10 · Modified
7.5EPSS 0.023
CVE-2016-5285
A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a Denial of Service.
Published 2019-11-15 · Modified
7.5EPSS 0.023
CVE-2022-32084
MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component sub_select.
Published 2022-07-01 · Modified
7.5EPSS 0.023
CVE-2022-35410
mat2 (aka metadata anonymisation toolkit) before 0.13.0 allows ../ directory traversal during the ZIP archive cleaning process. This primarily affects mat2 web instances, in which clients could obtain sensitive information via a crafted archive.
Published 2022-07-08 · Modified
7.5EPSS 0.023
CVE-2022-27379
An issue in the component Arg_comparator::compare_real_fixed of MariaDB Server v10.6.2 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.
Published 2022-04-12 · Modified
7.5EPSS 0.023
CVE-2022-27380
An issue in the component my_decimal::operator= of MariaDB Server v10.6.3 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.
Published 2022-04-12 · Modified
7.5EPSS 0.023
CVE-2022-27386
MariaDB Server v10.7 and below was discovered to contain a segmentation fault via the component sql/sql_class.cc.
Published 2022-04-12 · Modified
7.5EPSS 0.023
CVE-2020-35965
decode_frame in libavcodec/exr.c in FFmpeg 4.3.1 has an out-of-bounds write because of errors in calculations of when to perform memset zero operations.
Published 2021-01-04 · Modified
7.5EPSS 0.023
CVE-2022-27447
MariaDB Server v10.9 and below was discovered to contain a use-after-free via the component Binary_string::free_buffer() at /sql/sql_string.h.
Published 2022-04-14 · Modified
7.5EPSS 0.022
CVE-2022-30293
In WebKitGTK through 2.36.0 (and WPE WebKit), there is a heap-based buffer overflow in WebCore::TextureMapperLayer::setContentsLayer in WebCore/platform/graphics/texmap/TextureMapperLayer.cpp.
Published 2022-05-06 · Modified
7.5EPSS 0.022
CVE-2022-27449
MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_func.cc:148.
Published 2022-04-14 · Modified
7.5EPSS 0.022
CVE-2023-4236
named may terminate unexpectedly under high DNS-over-TLS query load
Published 2023-09-20 · Modified
7.5EPSS 0.022
← Prev41 / 86Next →