VendorsDebiandebian_linux10.0
Vulnerabilities

Debian Debian Linux 10.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3432CVEs
CVE-2019-19728
SchedMD Slurm before 18.08.9 and 19.x before 19.05.5 executes srun --uid with incorrect privileges.
Published 2020-01-13 · Modified
7.5EPSS 0.013
CVE-2012-2350
pam_shield before 0.9.4: Default configuration does not perform protective action
Published 2019-11-21 · Modified
7.5EPSS 0.013
CVE-2023-20900
A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html  in a target virtual machine may be able to elevate their privileges if that target virtual machine has been assigned a more privileged Guest Alias https://vdc-download.vmware.com/vmwb-repository/dcr-public/d1902b0e-d479-46bf-8ac9-cee0e31e8ec0/07ce8dbd-db48-4261-9b8f-c6d3ad8ba472/vim.vm.guest.AliasManager.html .
Published 2023-08-31 · Modified
7.5EPSS 0.013
CVE-2023-41358
An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c processes NLRIs if the attribute length is zero.
Published 2023-08-29 · Modified
7.5EPSS 0.013
CVE-2024-24814
Denial of service when manipulating mod_auth_openidc_session_chunks cookie in mod_auth_openidc
Published 2024-02-13 · Modified
7.5EPSS 0.013
CVE-2021-27803
A vulnerability was discovered in how p2p/p2p_pd.c in wpa_supplicant before 2.10 processes P2P (Wi-Fi Direct) provision discovery requests. It could result in denial of service or other impact (potentially execution of arbitrary code), for an attacker within radio range.
Published 2021-02-26 · Modified
7.5EPSS 0.012
CVE-2009-3723
asterisk allows calls on prohibited networks
Published 2019-10-29 · Modified
7.5EPSS 0.012
CVE-2022-39958
Response body bypass in OWASP ModSecurity Core Rule Set via repeated HTTP Range header submission with a small byte range
Published 2022-09-20 · Modified
7.5EPSS 0.012
CVE-2020-5390
PySAML2 before 5.0.0 does not check that the signature in a SAML document is enveloped and thus signature wrapping is effective, i.e., it is affected by XML Signature Wrapping (XSW). The signature information and the node/object that is signed can be in different places and thus the signature verification will succeed, but the wrong data will be used. This specifically affects the verification of assertion that have been signed.
Published 2020-01-13 · Modified
7.5EPSS 0.012
CVE-2012-1572
OpenStack Keystone: extremely long passwords can crash Keystone by exhausting stack space
Published 2019-11-12 · Modified
7.5EPSS 0.012
CVE-2020-36423
An issue was discovered in Arm Mbed TLS before 2.23.0. A remote attacker can recover plaintext because a certain Lucky 13 countermeasure doesn't properly consider the case of a hardware accelerator.
Published 2021-07-19 · Modified
7.5EPSS 0.012
CVE-2023-5728
During garbage collection extra operations were performed on a object that should not be. This could have led to a potentially exploitable crash. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
Published 2023-10-24 · Modified
7.5EPSS 0.012
CVE-2023-46838
Linux: netback processing of zero-length transmit fragment
Published 2024-01-29 · Modified
7.5EPSS 0.012
CVE-2022-48279
In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart requests were incorrectly parsed and could bypass the Web Application Firewall. NOTE: this is related to CVE-2022-39956 but can be considered independent changes to the ModSecurity (C language) codebase.
Published 2023-01-20 · Modified
7.5EPSS 0.012
CVE-2019-16237
Dino before 2019-09-10 does not properly check the source of an MAM message in module/xep/0313_message_archive_management.vala.
Published 2019-09-11 · Modified
7.5EPSS 0.012
CVE-2020-23804
Uncontrolled Recursion in pdfinfo, and pdftops in poppler 0.89.0 allows remote attackers to cause a denial of service via crafted input.
Published 2023-08-22 · Modified
7.5EPSS 0.012
CVE-2023-31137
MaraDNS Integer Underflow Vulnerability in DNS Packet Decompression
Published 2023-05-09 · Modified
7.5EPSS 0.011
CVE-2023-41909
An issue was discovered in FRRouting FRR through 9.0. bgp_nlri_parse_flowspec in bgpd/bgp_flowspec.c processes malformed requests with no attributes, leading to a NULL pointer dereference.
Published 2023-09-05 · Modified
7.5EPSS 0.011
CVE-2023-24038
The HTML-StripScripts module through 1.06 for Perl allows _hss_attval_style ReDoS because of catastrophic backtracking for HTML content with certain style attributes.
Published 2023-01-21 · Modified
7.5EPSS 0.011
CVE-2020-29260
libvncclient v0.9.13 was discovered to contain a memory leak via the function rfbClientCleanup().
Published 2022-09-02 · Modified
7.5EPSS 0.011
CVE-2019-5094
An exploitable code execution vulnerability exists in the quota file functionality of E2fsprogs 1.45.3. A specially crafted ext4 partition can cause an out-of-bounds write on the heap, resulting in code execution. An attacker can corrupt a partition to trigger this vulnerability.
Published 2019-09-24 · Modified
7.5EPSS 0.011
CVE-2020-36478
An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). A NULL algorithm parameters entry looks identical to an array of REAL (size zero) and thus the certificate is considered valid. However, if the parameters do not match in any way, then the certificate should be considered invalid.
Published 2021-08-23 · Modified
7.5EPSS 0.011
CVE-2007-5743
viewvc 1.0.3 allows improper access control to files in a repository when using the "forbidden" configuration option.
Published 2019-11-07 · Modified
7.5EPSS 0.011
CVE-2022-26306
Execution of Untrusted Macros Due to Improper Certificate Validation
Published 2022-07-25 · Modified
7.5EPSS 0.011
CVE-2023-32307
heap-over-flow and integer-overflow in sofia-sip
Published 2023-05-26 · Modified
7.5EPSS 0.011
CVE-2023-52159
A stack-based buffer overflow vulnerability in gross 0.9.3 through 1.x before 1.0.4 allows remote attackers to trigger a denial of service (grossd daemon crash) or potentially execute arbitrary code in grossd via crafted SMTP transaction parameters that cause an incorrect strncat for a log entry.
Published 2024-03-18 · Modified
7.5EPSS 0.011
CVE-2021-30130
phpseclib before 2.0.31 and 3.x before 3.0.7 mishandles RSA PKCS#1 v1.5 signature verification.
Published 2021-04-06 · Modified
7.5EPSS 0.011
CVE-2022-31291
An issue in dlt_config_file_parser.c of dlt-daemon v2.18.8 allows attackers to cause a double free via crafted TCP packets.
Published 2022-06-16 · Modified
7.5EPSS 0.010
CVE-2022-45060
An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1. An attacker may introduce characters through HTTP/2 pseudo-headers that are invalid in the context of an HTTP/1 request line, causing the Varnish server to produce invalid HTTP/1 requests to the backend. This could, in turn, be used to exploit vulnerabilities in a server behind the Varnish server. Note: the 6.0.x LTS series (before 6.0.11) is affected.
Published 2022-11-09 · Modified
7.5EPSS 0.010
CVE-2021-33054
SOGo 2.x before 2.4.1 and 3.x through 5.x before 5.1.1 does not validate the signatures of any SAML assertions it receives. Any actor with network access to the deployment could impersonate users when SAML is the authentication method. (Only versions after 2.0.5a are affected.)
Published 2021-06-04 · Modified
7.5EPSS 0.010
CVE-2022-39957
Response body bypass in OWASP ModSecurity Core Rule Set via a specialy crafted charset in the HTTP Accept header
Published 2022-09-20 · Modified
7.5EPSS 0.010
CVE-2023-30608
Parser contains an inefficient regular expression in sqlparse
Published 2023-04-18 · Modified
7.5EPSS 0.010
CVE-2022-41916
Read one byte past a buffer when normalizing Unicode
Published 2022-11-15 · Modified
7.5EPSS 0.010
CVE-2014-3495
duplicity 0.6.24 has improper verification of SSL certificates
Published 2019-12-13 · Modified
7.5EPSS 0.009
CVE-2023-4048
An out-of-bounds read could have led to an exploitable crash when parsing HTML with DOMParser in low memory situations. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.
Published 2023-08-01 · Modified
7.5EPSS 0.009
CVE-2023-24021
Incorrect handling of '\0' bytes in file uploads in ModSecurity before 2.9.7 may allow for Web Application Firewall bypasses and buffer over-reads on the Web Application Firewall when executing rules that read the FILES_TMP_CONTENT collection.
Published 2023-01-20 · Modified
7.5EPSS 0.009
CVE-2024-36929
net: core: reject skb_copy(_expand) for fraglist GSO skbs
Published 2024-05-30 · Modified
7.5EPSS 0.009
CVE-2022-2255
A vulnerability was found in mod_wsgi. The X-Client-IP header is not removed from a request from an untrusted proxy, allowing an attacker to pass the X-Client-IP header to the target WSGI application because the condition to remove it is missing.
Published 2022-08-25 · Modified
7.5EPSS 0.009
CVE-2023-40462
Improper input leads to DoS
Published 2023-12-04 · Modified
7.5EPSS 0.009
CVE-2023-52696
powerpc/powernv: Add a null pointer check in opal_powercap_init()
Published 2024-05-17 · Analyzed
7.5EPSS 0.008
← Prev45 / 86Next →