VendorsDebiandebian_linux10.0
Vulnerabilities

Debian Debian Linux 10.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3432CVEs
CVE-2021-4166
Out-of-bounds Read in vim/vim
Published 2021-12-25 · Modified
7.1EPSS 0.016
CVE-2022-0891
A heap buffer overflow in ExtractImageSection function in tiffcrop.c in libtiff library Version 4.3.0 allows attacker to trigger unsafe or out of bounds memory access via crafted TIFF image file which could result into application crash, potential information disclosure or any other context-dependent impact
Published 2022-03-09 · Modified
7.1EPSS 0.015
CVE-2023-34241
CUPS vulnerable to use-after-free in cupsdAcceptClient()
Published 2023-06-22 · Modified
7.1EPSS 0.014
CVE-2022-3564
Linux Kernel Bluetooth l2cap_core.c l2cap_reassemble_sdu use after free
Published 2022-10-17 · Modified
7.1EPSS 0.013
CVE-2022-29458
ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.
Published 2022-04-18 · Modified
7.1EPSS 0.013
CVE-2019-6956
An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. It is a buffer over-read in ps_mix_phase in libfaad/ps_dec.c.
Published 2019-01-25 · Modified
7.1EPSS 0.012
CVE-2022-41742
NGINX ngx_http_mp4_module vulnerability CVE-2022-41742
Published 2022-10-19 · Modified
7.1EPSS 0.011
CVE-2020-0556
Improper access control in subsystem for BlueZ before version 5.54 may allow an unauthenticated user to potentially enable escalation of privilege and denial of service via adjacent access
Published 2020-03-12 · Modified
7.1EPSS 0.010
CVE-2024-32021
Local Git clone may hardlink arbitrary user-readable files into the new repository's "objects/" directory
Published 2024-05-14 · Analyzed
7.1EPSS 0.010
CVE-2019-13220
Use of uninitialized stack variables in the start_decoder function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service or disclose sensitive information by opening a crafted Ogg Vorbis file.
Published 2019-08-15 · Modified
7.1EPSS 0.010
CVE-2019-13222
An out-of-bounds read of a global buffer in the draw_line function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service or disclose sensitive information by opening a crafted Ogg Vorbis file.
Published 2019-08-15 · Modified
7.1EPSS 0.010
CVE-2021-45972
The giftrans function in giftrans 1.12.2 contains a stack-based buffer overflow because a value inside the input file determines the amount of data to write. This allows an attacker to overwrite up to 250 bytes outside of the allocated buffer with arbitrary data.
Published 2022-01-01 · Modified
7.1EPSS 0.010
CVE-2022-44729
Apache XML Graphics Batik: Information disclosure vulnerability
Published 2023-08-22 · Modified
7.1EPSS 0.009
CVE-2021-20302
A flaw was found in OpenEXR's TiledInputFile functionality. This flaw allows an attacker who can submit a crafted single-part non-image to be processed by OpenEXR, to trigger a floating-point exception error. The highest threat from this vulnerability is to system availability.
Published 2022-03-04 · Modified
7.1EPSS 0.009
CVE-2021-20300
A flaw was found in OpenEXR's hufUncompress functionality in OpenEXR/IlmImf/ImfHuf.cpp. This flaw allows an attacker who can submit a crafted file that is processed by OpenEXR, to trigger an integer overflow. The highest threat from this vulnerability is to system availability.
Published 2022-03-04 · Modified
7.1EPSS 0.009
CVE-2023-0412
TIPC dissector crash in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture file
Published 2023-01-24 · Modified
7.1EPSS 0.008
CVE-2024-36916
blk-iocost: avoid out of bounds shift
Published 2024-05-30 · Modified
7.1EPSS 0.007
CVE-2023-36823
Sanitize vulnerable to Cross-site Scripting via insufficient neutralization of `style` element content
Published 2023-07-06 · Modified
7.1EPSS 0.007
CVE-2023-28686
Dino before 0.2.3, 0.3.x before 0.3.2, and 0.4.x before 0.4.2 allows attackers to modify the personal bookmark store via a crafted message. The attacker can change the display of group chats or force a victim to join a group chat; the victim may then be tricked into disclosing sensitive information.
Published 2023-03-24 · Modified
7.1EPSS 0.007
CVE-2023-1161
ISO 15765 and ISO 10681 dissector crash in Wireshark 4.0.0 to 4.0.3 and 3.6.0 to 3.6.11 allows denial of service via packet injection or crafted capture file
Published 2023-03-06 · Modified
7.1EPSS 0.006
CVE-2011-3632
Hardlink before 0.1.2 operates on full file system objects path names which can allow a local attacker to use this flaw to conduct symlink attacks.
Published 2019-11-26 · Modified
7.1EPSS 0.005
CVE-2024-30205
In Emacs before 29.3, Org mode considers contents of remote files to be trusted. This affects Org Mode before 9.6.23.
Published 2024-03-25 · Analyzed
7.1EPSS 0.005
CVE-2023-3268
An out of bounds (OOB) memory access flaw was found in the Linux kernel in relay_file_read_start_pos in kernel/relay.c in the relayfs. This flaw could allow a local attacker to crash the system or leak kernel internal information.
Published 2023-06-16 · Analyzed
7.1EPSS 0.005
CVE-2020-27792
Ghostscript: heap buffer over write vulnerability in ghostscript's lp8000_print_page() in gdevlp8k.c
Published 2022-08-19 · Modified
7.1EPSS 0.005
CVE-2023-3141
A use-after-free flaw was found in r592_remove in drivers/memstick/host/r592.c in media access in the Linux Kernel. This flaw allows a local attacker to crash the system at device disconnect, possibly leading to a kernel information leak.
Published 2023-06-09 · Modified
7.1EPSS 0.004
CVE-2022-1353
A vulnerability was found in the pfkey_register function in net/key/af_key.c in the Linux kernel. This flaw allows a local, unprivileged user to gain access to kernel memory, leading to a system crash or a leak of internal kernel information.
Published 2022-04-29 · Modified
7.1EPSS 0.004
CVE-2023-1989
A use-after-free flaw was found in btsdio_remove in drivers\bluetooth\btsdio.c in the Linux Kernel. In this flaw, a call to btsdio_remove with an unfinished job, may cause a race problem leading to a UAF on hdev devices.
Published 2023-04-11 · Modified
7.1EPSS 0.004
CVE-2019-18390
An out-of-bounds read in the vrend_blit_need_swizzle function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service via VIRGL_CCMD_BLIT commands.
Published 2019-12-23 · Modified
7.1EPSS 0.003
CVE-2022-33742
Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Linux Block and Network PV device frontends don't zero memory regions before sharing them with the backend (CVE-2022-26365, CVE-2022-33740). Additionally the granularity of the grant table doesn't allow sharing less than a 4K page, leading to unrelated data residing in the same 4K page as data shared with a backend being accessible by such backend (CVE-2022-33741, CVE-2022-33742).
Published 2022-07-05 · Modified
7.1EPSS 0.003
CVE-2022-26365
Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Linux Block and Network PV device frontends don't zero memory regions before sharing them with the backend (CVE-2022-26365, CVE-2022-33740). Additionally the granularity of the grant table doesn't allow sharing less than a 4K page, leading to unrelated data residing in the same 4K page as data shared with a backend being accessible by such backend (CVE-2022-33741, CVE-2022-33742).
Published 2022-07-05 · Modified
7.1EPSS 0.003
CVE-2022-33741
Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Linux Block and Network PV device frontends don't zero memory regions before sharing them with the backend (CVE-2022-26365, CVE-2022-33740). Additionally the granularity of the grant table doesn't allow sharing less than a 4K page, leading to unrelated data residing in the same 4K page as data shared with a backend being accessible by such backend (CVE-2022-33741, CVE-2022-33742).
Published 2022-07-05 · Modified
7.1EPSS 0.003
CVE-2022-33740
Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Linux Block and Network PV device frontends don't zero memory regions before sharing them with the backend (CVE-2022-26365, CVE-2022-33740). Additionally the granularity of the grant table doesn't allow sharing less than a 4K page, leading to unrelated data residing in the same 4K page as data shared with a backend being accessible by such backend (CVE-2022-33741, CVE-2022-33742).
Published 2022-07-05 · Modified
7.1EPSS 0.003
CVE-2022-47520
An issue was discovered in the Linux kernel before 6.0.11. Missing offset validation in drivers/net/wireless/microchip/wilc1000/hif.c in the WILC1000 wireless driver can trigger an out-of-bounds read when parsing a Robust Security Network (RSN) information element from a Netlink packet.
Published 2022-12-18 · Modified
7.1EPSS 0.003
CVE-2022-34677
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an unprivileged regular user can cause an integer to be truncated, which may lead to denial of service or data tampering.
Published 2022-12-30 · Modified
7.1EPSS 0.003
CVE-2024-36960
drm/vmwgfx: Fix invalid reads in fence signaled events
Published 2024-06-03 · Modified
7.1EPSS 0.003
CVE-2024-26763
dm-crypt: don't modify the data when using authenticated encryption
Published 2024-04-03 · Modified
7.1EPSS 0.003
CVE-2024-35871
riscv: process: Fix kernel gp leakage
Published 2024-05-19 · Analyzed
7.1EPSS 0.003
CVE-2024-35849
btrfs: fix information leak in btrfs_ioctl_logical_to_ino()
Published 2024-05-17 · Modified
7.1EPSS 0.003
CVE-2024-35967
Bluetooth: SCO: Fix not validating setsockopt user input
Published 2024-05-20 · Modified
7.1EPSS 0.002
CVE-2024-35962
netfilter: complete validation of user input
Published 2024-05-20 · Modified
7.1EPSS 0.002
← Prev48 / 86Next →