VendorsDebiandebian_linux10.0
Vulnerabilities

Debian Debian Linux 10.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3432CVEs
CVE-2021-3803
Inefficient Regular Expression Complexity in fb55/nth-check
Published 2021-09-17 · Modified
7.5EPSS 0.022
CVE-2020-27778
A flaw was found in Poppler in the way certain PDF files were converted into HTML. A remote attacker could exploit this flaw by providing a malicious PDF file that, when processed by the 'pdftohtml' program, would crash the application causing a denial of service.
Published 2020-12-03 · Modified
7.5EPSS 0.022
CVE-2022-27376
MariaDB Server v10.6.5 and below was discovered to contain an use-after-free in the component Item_args::walk_arg, which is exploited via specially crafted SQL statements.
Published 2022-04-12 · Modified
7.5EPSS 0.022
CVE-2022-29970
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files.
Published 2022-05-02 · Modified
7.5EPSS 0.022
CVE-2022-27381
An issue in the component Field::set_default of MariaDB Server v10.6 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.
Published 2022-04-12 · Modified
7.5EPSS 0.022
CVE-2022-27384
An issue in the component Item_subselect::init_expr_cache_tracker of MariaDB Server v10.6 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.
Published 2022-04-12 · Modified
7.5EPSS 0.022
CVE-2022-27452
MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_cmpfunc.cc.
Published 2022-04-14 · Modified
7.5EPSS 0.022
CVE-2022-24793
Potential heap buffer overflow when parsing DNS packets in PJSIP
Published 2022-04-06 · Modified
7.5EPSS 0.022
CVE-2022-27445
MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/sql_window.cc.
Published 2022-04-14 · Modified
7.5EPSS 0.022
CVE-2019-19331
knot-resolver before version 4.3.0 is vulnerable to denial of service through high CPU utilization. DNS replies with very many resource records might be processed very inefficiently, in extreme cases taking even several CPU seconds for each such uncached message. For example, a few thousand A records can be squashed into one DNS message (limit is 64kB).
Published 2019-12-16 · Modified
7.5EPSS 0.022
CVE-2020-11653
An issue was discovered in Varnish Cache before 6.0.6 LTS, 6.1.x and 6.2.x before 6.2.3, and 6.3.x before 6.3.2. It occurs when communication with a TLS termination proxy uses PROXY version 2. There can be an assertion failure and daemon restart, which causes a performance loss.
Published 2020-04-08 · Modified
7.5EPSS 0.022
CVE-2022-40023
Sqlalchemy mako before 1.2.2 is vulnerable to Regular expression Denial of Service when using the Lexer class to parse. This also affects babelplugin and linguaplugin.
Published 2022-09-07 · Modified
7.5EPSS 0.022
CVE-2019-19583
An issue was discovered in Xen through 4.12.x allowing x86 HVM/PVH guest OS users to cause a denial of service (guest OS crash) because VMX VMEntry checks mishandle a certain case. Please see XSA-260 for background on the MovSS shadow. Please see XSA-156 for background on the need for #DB interception. The VMX VMEntry checks do not like the exact combination of state which occurs when #DB in intercepted, Single Stepping is active, and blocked by STI/MovSS is active, despite this being a legitimate state to be in. The resulting VMEntry failure is fatal to the guest. HVM/PVH guest userspace code may be able to crash the guest, resulting in a guest Denial of Service. All versions of Xen are affected. Only systems supporting VMX hardware virtual extensions (Intel, Cyrix, or Zhaoxin CPUs) are affected. Arm and AMD systems are unaffected. Only HVM/PVH guests are affected. PV guests cannot leverage the vulnerability.
Published 2019-12-11 · Modified
7.5EPSS 0.022
CVE-2023-31490
An issue found in Frrouting bgpd v.8.4.2 allows a remote attacker to cause a denial of service via the bgp_attr_psid_sub() function.
Published 2023-05-09 · Modified
7.5EPSS 0.022
CVE-2022-27448
There is an Assertion failure in MariaDB Server v10.9 and below via 'node->pcur->rel_pos == BTR_PCUR_ON' at /row/row0mysql.cc.
Published 2022-04-14 · Modified
7.5EPSS 0.022
CVE-2022-31001
Out-of-bounds Read in Sofia-SIP
Published 2022-05-31 · Modified
7.5EPSS 0.021
CVE-2021-37150
Protocol vs scheme mismatch
Published 2022-08-10 · Modified
7.5EPSS 0.021
CVE-2018-16472
A prototype pollution attack in cached-path-relative versions <=1.0.1 allows an attacker to inject properties on Object.prototype which are then inherited by all the JS objects through the prototype chain causing a DoS attack.
Published 2018-11-06 · Modified
7.5EPSS 0.021
CVE-2021-32565
HTTP Request Smuggling, content length with invalid charters
Published 2021-06-29 · Modified
7.5EPSS 0.021
CVE-2023-27522
Apache HTTP Server: mod_proxy_uwsgi HTTP response splitting
Published 2023-03-07 · Analyzed
7.5EPSS 0.021
CVE-2021-43804
Out-of-bounds read when parsing RTCP BYE message in PJSIP
Published 2021-12-22 · Modified
7.5EPSS 0.021
CVE-2022-27383
MariaDB Server v10.6 and below was discovered to contain an use-after-free in the component my_strcasecmp_8bit, which is exploited via specially crafted SQL statements.
Published 2022-04-12 · Modified
7.5EPSS 0.021
CVE-2022-27456
MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component VDec::VDec at /sql/sql_type.cc.
Published 2022-04-14 · Modified
7.5EPSS 0.021
CVE-2019-19911
There is a DoS vulnerability in Pillow before 6.2.2 caused by FpxImagePlugin.py calling the range function on an unvalidated 32-bit integer if the number of bands is large. On Windows running 32-bit Python, this results in an OverflowError or MemoryError due to the 2 GB limit. However, on Linux running 64-bit Python this results in the process being terminated by the OOM killer.
Published 2020-01-05 · Modified
7.5EPSS 0.021
CVE-2021-32918
An issue was discovered in Prosody before 0.11.9. Default settings are susceptible to remote unauthenticated denial-of-service (DoS) attacks via memory exhaustion when running under Lua 5.2 or Lua 5.3.
Published 2021-05-13 · Modified
7.5EPSS 0.021
CVE-2020-15476
In nDPI through 3.2, the Oracle protocol dissector has a heap-based buffer over-read in ndpi_search_oracle in lib/protocols/oracle.c.
Published 2020-07-01 · Modified
7.5EPSS 0.021
CVE-2022-39028
telnetd in GNU Inetutils through 2.3, MIT krb5-appl through 1.0.3, and derivative works has a NULL pointer dereference via 0xff 0xf7 or 0xff 0xf8. In a typical installation, the telnetd application would crash but the telnet service would remain available through inetd. However, if the telnetd application has many crashes within a short time interval, the telnet service would become unavailable after inetd logs a "telnet/tcp server failing (looping), service terminated" error. NOTE: MIT krb5-appl is not supported upstream but is shipped by a few Linux distributions. The affected code was removed from the supported MIT Kerberos 5 (aka krb5) product many years ago, at version 1.8.
Published 2022-08-30 · Modified
7.5EPSS 0.021
CVE-2021-43666
A Denial of Service vulnerability exists in mbed TLS 3.0.0 and earlier in the mbedtls_pkcs12_derivation function when an input password's length is 0.
Published 2022-03-24 · Modified
7.5EPSS 0.021
CVE-2020-21041
Buffer Overflow vulnerability exists in FFmpeg 4.1 via apng_do_inverse_blend in libavcodec/pngenc.c, which could let a remote malicious user cause a Denial of Service
Published 2021-05-24 · Modified
7.5EPSS 0.021
CVE-2022-24763
Infinite Loop in PJSIP
Published 2022-03-30 · Modified
7.5EPSS 0.021
CVE-2021-20228
A flaw was found in the Ansible Engine 2.9.18, where sensitive info is not masked by default and is not protected by the no_log feature when using the sub-option feature of the basic.py module. This flaw allows an attacker to obtain sensitive information. The highest threat from this vulnerability is to confidentiality.
Published 2021-04-29 · Modified
7.5EPSS 0.021
CVE-2021-35063
Suricata before 5.0.7 and 6.x before 6.0.3 has a "critical evasion."
Published 2021-07-22 · Modified
7.5EPSS 0.021
CVE-2022-24792
Potential infinite loop when parsing WAV format file in PJSIP
Published 2022-04-25 · Modified
7.5EPSS 0.021
CVE-2020-21365
Directory traversal vulnerability in wkhtmltopdf through 0.12.5 allows remote attackers to read local files and disclose sensitive information via a crafted html file running with the default configurations.
Published 2022-08-15 · Modified
7.5EPSS 0.021
CVE-2022-29536
In GNOME Epiphany before 41.4 and 42.x before 42.2, an HTML document can trigger a client buffer overflow (in ephy_string_shorten in the UI process) via a long page title. The issue occurs because the number of bytes for a UTF-8 ellipsis character is not properly considered.
Published 2022-04-20 · Modified
7.5EPSS 0.020
CVE-2021-3805
Prototype Pollution in mariocasciaro/object-path
Published 2021-09-17 · Modified
7.5EPSS 0.020
CVE-2022-32088
MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Exec_time_tracker::get_loops/Filesort_tracker::report_use/filesort.
Published 2022-07-01 · Modified
7.5EPSS 0.020
CVE-2022-32085
MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Item_func_in::cleanup/Item::cleanup_processor.
Published 2022-07-01 · Modified
7.5EPSS 0.020
CVE-2013-1809
Gambas before 3.4.0 allows remote attackers to move or manipulate directory contents or perform symlink attacks due to the creation of insecure temporary directories.
Published 2019-11-07 · Modified
7.5EPSS 0.020
CVE-2022-32083
MariaDB v10.2 to v10.6.1 was discovered to contain a segmentation fault via the component Item_subselect::init_expr_cache_tracker.
Published 2022-07-01 · Modified
7.5EPSS 0.020
← Prev42 / 86Next →