VendorsDebiandebian_linux10.0
Vulnerabilities

Debian Debian Linux 10.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3432CVEs
CVE-2023-5724
Drivers are not always robust to extremely large draw calls and in some cases this scenario could have led to a crash. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
Published 2023-10-24 · Modified
7.5EPSS 0.016
CVE-2021-40516
WeeChat before 3.2.1 allows remote attackers to cause a denial of service (crash) via a crafted WebSocket frame that trigger an out-of-bounds read in plugins/relay/relay-websocket.c in the Relay plugin.
Published 2021-09-05 · Modified
7.5EPSS 0.016
CVE-2020-35475
In MediaWiki before 1.35.1, the messages userrights-expiry-current and userrights-expiry-none can contain raw HTML. XSS can happen when a user visits Special:UserRights but does not have rights to change all userrights, and the table on the left side has unchangeable groups in it. (The right column with the changeable groups is not affected and is escaped correctly.)
Published 2020-12-18 · Modified
7.5EPSS 0.016
CVE-2023-2879
GDSDB infinite loop in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via packet injection or crafted capture file
Published 2023-05-26 · Modified
7.5EPSS 0.016
CVE-2020-11728
An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60. Session management does not use a sufficiently hard-to-guess session key. Anyone who can guess the microsecond time (and the incrementing session_id) can impersonate a session.
Published 2020-04-15 · Modified
7.5EPSS 0.016
CVE-2023-37369
In Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2, there can be an application crash in QXmlStreamReader via a crafted XML string that triggers a situation in which a prefix is greater than a length.
Published 2023-08-20 · Modified
7.5EPSS 0.016
CVE-2021-39923
Large loop in the PNRP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
Published 2021-11-19 · Modified
7.5EPSS 0.016
CVE-2023-39354
FreeRDP Out-Of-Bounds Read in nsc_rle_decompress_data
Published 2023-08-31 · Modified
7.5EPSS 0.016
CVE-2013-2106
webauth before 4.6.1 has authentication credential disclosure
Published 2019-12-03 · Modified
7.5EPSS 0.016
CVE-2020-36476
An issue was discovered in Mbed TLS before 2.24.0 (and before 2.16.8 LTS and before 2.7.17 LTS). There is missing zeroization of plaintext buffers in mbedtls_ssl_read to erase unused application data from memory.
Published 2021-08-23 · Modified
7.5EPSS 0.016
CVE-2023-32067
0-byte UDP payload DoS in c-ares
Published 2023-05-25 · Modified
7.5EPSS 0.016
CVE-2023-39351
FreeRDP Null Pointer Dereference leading denial of service
Published 2023-08-31 · Modified
7.5EPSS 0.016
CVE-2023-6536
Kernel: null pointer dereference in __nvmet_req_complete
Published 2024-02-07 · Modified
7.5EPSS 0.015
CVE-2021-20298
A flaw was found in OpenEXR's B44Compressor. This flaw allows an attacker who can submit a crafted file to be processed by OpenEXR, to exhaust all memory accessible to the application. The highest threat from this vulnerability is to system availability.
Published 2022-08-23 · Modified
7.5EPSS 0.015
CVE-2022-23517
Inefficient Regular Expression Complexity in rails-html-sanitizer
Published 2022-12-14 · Modified
7.5EPSS 0.015
CVE-2022-41881
Netty project is an event-driven asynchronous network application framework. In versions prior to 4.1.86.Final, a StackOverflowError can be raised when parsing a malformed crafted message due to an infinite recursion. This issue is patched in version 4.1.86.Final. There is no workaround, except using a custom HaProxyMessageDecoder.
Published 2022-12-12 · Modified
7.5EPSS 0.015
CVE-2011-4931
gpw generates shorter passwords than required
Published 2019-10-29 · Modified
7.5EPSS 0.015
CVE-2022-1941
Out of Memory issue in ProtocolBuffers for cpp and python
Published 2022-09-22 · Modified
7.5EPSS 0.015
CVE-2022-3109
An issue was discovered in the FFmpeg package, where vp3_decode_frame in libavcodec/vp3.c lacks check of the return value of av_malloc() and will cause a null pointer dereference, impacting availability.
Published 2022-12-16 · Analyzed
7.5EPSS 0.015
CVE-2021-36369
An issue was discovered in Dropbear through 2020.81. Due to a non-RFC-compliant check of the available authentication methods in the client-side SSH code, it is possible for an SSH server to change the login process in its favor. This attack can bypass additional security measures such as FIDO2 tokens or SSH-Askpass. Thus, it allows an attacker to abuse a forwarded agent for logging on to another server unnoticed.
Published 2022-10-12 · Modified
7.5EPSS 0.015
CVE-2022-28203
A denial-of-service issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. When many files exist, requesting Special:NewFiles with actor as a condition can result in a very long running query.
Published 2022-09-19 · Modified
7.5EPSS 0.015
CVE-2023-32324
OpenPrinting CUPS vulnerable to heap buffer overflow
Published 2023-06-01 · Modified
7.5EPSS 0.015
CVE-2021-3842
Inefficient Regular Expression Complexity in nltk/nltk
Published 2022-01-04 · Modified
7.5EPSS 0.015
CVE-2023-6356
Kernel: null pointer dereference in nvmet_tcp_build_iovec
Published 2024-02-07 · Modified
7.5EPSS 0.015
CVE-2022-45693
Jettison before v1.5.2 was discovered to contain a stack overflow via the map parameter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted string.
Published 2022-12-13 · Modified
7.5EPSS 0.014
CVE-2022-45685
A stack overflow in Jettison before v1.5.2 allows attackers to cause a Denial of Service (DoS) via crafted JSON data.
Published 2022-12-13 · Modified
7.5EPSS 0.014
CVE-2024-22201
Jetty connection leaking on idle timeout when TCP congested
Published 2024-02-26 · Modified
7.5EPSS 0.014
CVE-2022-41404
An issue in the fetch() method in the BasicProfile class of org.ini4j through version v0.5.4 allows attackers to cause a Denial of Service (DoS) via unspecified vectors.
Published 2022-10-11 · Modified
7.5EPSS 0.014
CVE-2021-32919
An issue was discovered in Prosody before 0.11.9. The undocumented dialback_without_dialback option in mod_dialback enables an experimental feature for server-to-server authentication. It does not correctly authenticate remote server certificates, allowing a remote server to impersonate another server (when this option is enabled).
Published 2021-05-13 · Modified
7.5EPSS 0.014
CVE-2018-5735
Backport of the fix for CVE-2017-3137 leads to assertion failure in validator.c:1858
Published 2019-10-30 · Modified
7.5EPSS 0.014
CVE-2021-32862
nbconvert vulnerable to cross-site scripting (XSS) via multiple exploit paths
Published 2022-08-18 · Modified
7.5EPSS 0.014
CVE-2019-16235
Dino before 2019-09-10 does not properly check the source of a carbons message in module/xep/0280_message_carbons.vala.
Published 2019-09-11 · Modified
7.5EPSS 0.014
CVE-2022-3705
vim autocmd quickfix.c qf_update_buffer use after free
Published 2022-10-26 · Modified
7.5EPSS 0.013
CVE-2021-28091
Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature.
Published 2021-06-04 · Modified
7.5EPSS 0.013
CVE-2014-1936
rc before 1.7.1-5 insecurely creates temporary files.
Published 2019-11-21 · Modified
7.5EPSS 0.013
CVE-2012-6071
nuSOAP before 0.7.3-5 does not properly check the hostname of a cert.
Published 2019-11-19 · Modified
7.5EPSS 0.013
CVE-2011-0529
Weborf before 0.12.5 is affected by a Denial of Service (DOS) due to malformed fields in HTTP.
Published 2019-11-20 · Modified
7.5EPSS 0.013
CVE-2010-5108
Trac 0.11.6 does not properly check workflow permissions before modifying a ticket. This can be exploited by an attacker to change the status and resolution of tickets without having proper permissions.
Published 2019-11-13 · Modified
7.5EPSS 0.013
CVE-2023-40589
FreeRDP Global-Buffer-Overflow in ncrush_decompress
Published 2023-08-31 · Modified
7.5EPSS 0.013
CVE-2024-27405
usb: gadget: ncm: Avoid dropping datagrams of properly parsed NTBs
Published 2024-05-17 · Analyzed
7.5EPSS 0.013
← Prev44 / 86Next →