VendorsDebiandebian_linux10.0
Vulnerabilities

Debian Debian Linux 10.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3432CVEs
CVE-2020-29565
An issue was discovered in OpenStack Horizon before 15.3.2, 16.x before 16.2.1, 17.x and 18.x before 18.3.3, 18.4.x, and 18.5.x. There is a lack of validation of the "next" parameter, which would allow someone to supply a malicious URL in Horizon that can cause an automatic redirect to the provided malicious URL.
Published 2020-12-04 · Modified
6.1EPSS 0.014
CVE-2013-7370
node-connect before 2.8.1 has XSS in the Sencha Labs Connect middleware
Published 2019-12-11 · Modified
6.1EPSS 0.014
CVE-2021-30157
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. On ChangesList special pages such as Special:RecentChanges and Special:Watchlist, some of the rcfilters-filter-* label messages are output in HTML unescaped, leading to XSS.
Published 2021-04-06 · Modified
6.1EPSS 0.014
CVE-2020-6535
Insufficient data validation in WebUI in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had compromised the renderer process to inject scripts or HTML into a privileged page via a crafted HTML page.
Published 2020-07-22 · Modified
6.1EPSS 0.014
CVE-2021-43543
Documents loaded with the CSP sandbox directive could have escaped the sandbox's script restriction by embedding additional content. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
Published 2021-12-08 · Modified
6.1EPSS 0.014
CVE-2022-42799
The issue was addressed with improved UI handling. This issue is fixed in tvOS 16.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Visiting a malicious website may lead to user interface spoofing.
Published 2022-11-01 · Modified
6.1EPSS 0.013
CVE-2021-30154
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. On Special:NewFiles, all the mediastatistics-header-* messages are output in HTML unescaped, leading to XSS.
Published 2021-04-06 · Modified
6.1EPSS 0.013
CVE-2013-4158
smokeping before 2.6.9 has XSS (incomplete fix for CVE-2012-0790)
Published 2019-12-11 · Modified
6.1EPSS 0.012
CVE-2012-0812
PostfixAdmin 2.3.4 has multiple XSS vulnerabilities
Published 2019-11-22 · Modified
6.1EPSS 0.012
CVE-2021-44025
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to XSS in handling an attachment's filename extension when displaying a MIME type warning message.
Published 2021-11-19 · Modified
6.1EPSS 0.012
CVE-2022-28202
An XSS issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. The widthheight, widthheightpage, and nbytes properties of messages are not escaped when used in galleries or Special:RevisionDelete.
Published 2022-03-30 · Modified
6.1EPSS 0.012
CVE-2019-16392
SPIP before 3.1.11 and 3.2 before 3.2.5 allows prive/formulaires/login.php XSS via error messages.
Published 2019-09-17 · Modified
6.1EPSS 0.012
CVE-2022-23520
rails-html-sanitizer contains an incomplete fix for an XSS vulnerability
Published 2022-12-14 · Modified
6.1EPSS 0.011
CVE-2016-1000108
yaws before 2.0.4 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.
Published 2019-12-10 · Modified
6.1EPSS 0.011
CVE-2019-16393
SPIP before 3.1.11 and 3.2 before 3.2.5 mishandles redirect URLs in ecrire/inc/headers.php with a %0D, %0A, or %20 character.
Published 2019-09-17 · Modified
6.1EPSS 0.011
CVE-2013-4168
Cross-site scripting (XSS) vulnerability in SmokePing 2.6.9 in the start and end time fields.
Published 2019-11-01 · Modified
6.1EPSS 0.011
CVE-2024-27285
YARD's default template vulnerable to Cross-site Scripting in generated frames.html
Published 2024-02-28 · Analyzed
6.1EPSS 0.011
CVE-2021-46144
Roundcube before 1.4.13 and 1.5.x before 1.5.2 allows XSS via an HTML e-mail message with crafted Cascading Style Sheets (CSS) token sequences.
Published 2022-01-06 · Modified
6.1EPSS 0.010
CVE-2020-13964
An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. include/rcmail_output_html.php allows XSS via the username template object.
Published 2020-06-09 · Modified
6.1EPSS 0.010
CVE-2020-6470
Insufficient validation of untrusted input in clipboard in Google Chrome prior to 83.0.4103.61 allowed a local attacker to inject arbitrary scripts or HTML (UXSS) via crafted clipboard contents.
Published 2020-05-21 · Modified
6.1EPSS 0.010
CVE-2021-37999
Insufficient data validation in New Tab Page in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to inject arbitrary scripts or HTML in a new browser tab via a crafted HTML page.
Published 2021-11-23 · Modified
6.1EPSS 0.010
CVE-2022-23527
Open Redirect in oidc_validate_redirect_url()
Published 2022-12-14 · Modified
6.1EPSS 0.009
CVE-2022-23518
Improper neutralization of data URIs allows XSS in rails-html-sanitizer
Published 2022-12-14 · Modified
6.1EPSS 0.009
CVE-2022-23515
Improper neutralization of data URIs may allow XSS in Loofah
Published 2022-12-14 · Modified
6.1EPSS 0.008
CVE-2021-20303
A flaw found in function dataWindowForTile() of IlmImf/ImfTiledMisc.cpp. An attacker who is able to submit a crafted file to be processed by OpenEXR could trigger an integer overflow, leading to an out-of-bounds write on the heap. The greatest impact of this flaw is to application availability, with some potential impact to data integrity as well.
Published 2022-03-04 · Modified
6.1EPSS 0.008
CVE-2024-1551
Set-Cookie response headers were being incorrectly honored in multipart HTTP responses. If an attacker could control the Content-Type response header, as well as control part of the response body, they could inject Set-Cookie response headers that would have been honored by the browser. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.
Published 2024-02-20 · Analyzed
6.1EPSS 0.007
CVE-2023-46734
Symfony potential Cross-site Scripting vulnerabilities in CodeExtension filters
Published 2023-11-10 · Analyzed
6.1EPSS 0.007
CVE-2022-46391
AWStats 7.x through 7.8 allows XSS in the hostinfo plugin due to printing a response from Net::XWhois without proper checks.
Published 2022-12-04 · Modified
6.1EPSS 0.007
CVE-2023-6867
The timing of a button click causing a popup to disappear was approximately the same length as the anti-clickjacking delay on permission prompts. It was possible to use this fact to surprise users by luring them to click where the permission grant button would be about to appear. This vulnerability affects Firefox ESR < 115.6 and Firefox < 121.
Published 2023-12-19 · Modified
6.1EPSS 0.007
CVE-2023-47272
Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposition header (used for attachment preview or download).
Published 2023-11-05 · Modified
6.1EPSS 0.006
CVE-2022-32166
ovs - buffer over-read
Published 2022-09-28 · Modified
6.1EPSS 0.006
CVE-2024-2609
The permission prompt input delay could expire while the window is not in focus. This makes it vulnerable to clickjacking by malicious websites. This vulnerability affects Firefox < 124, Firefox ESR < 115.10, and Thunderbird < 115.10.
Published 2024-03-19 · Analyzed
6.1EPSS 0.006
CVE-2022-39842
An issue was discovered in the Linux kernel before 5.19. In pxa3xx_gcu_write in drivers/video/fbdev/pxa3xx-gcu.c, the count parameter has a type conflict of size_t versus int, causing an integer overflow and bypassing the size check. After that, because it is used as the third argument to copy_from_user(), a heap overflow may occur. NOTE: the original discoverer disputes that the overflow can actually happen.
Published 2022-09-05 · Modified
6.1EPSS 0.006
CVE-2024-1550
A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user's mouse to be re-positioned unexpectedly, which could have led to user confusion and inadvertently granting permissions they did not intend to grant. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.
Published 2024-02-20 · Modified
6.1EPSS 0.006
CVE-2022-1355
A stack buffer overflow flaw was found in Libtiffs' tiffcp.c in main() function. This flaw allows an attacker to pass a crafted TIFF file to the tiffcp tool, triggering a stack buffer overflow issue, possibly corrupting the memory, and causing a crash that leads to a denial of service.
Published 2022-08-31 · Modified
6.1EPSS 0.006
CVE-2024-4768
A bug in popup notifications' interaction with WebAuthn made it easier for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
Published 2024-05-14 · Analyzed
6.1EPSS 0.005
CVE-2024-1549
If a website set a large custom cursor, portions of the cursor could have overlapped with the permission dialog, potentially resulting in user confusion and unexpected granted permissions. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.
Published 2024-02-20 · Analyzed
6.1EPSS 0.005
CVE-2024-37384
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via list columns from user preferences.
Published 2024-06-07 · Analyzed
6.1EPSS 0.005
CVE-2021-3507
A heap buffer overflow was found in the floppy disk emulator of QEMU up to 6.0.0 (including). It could occur in fdctrl_transfer_handler() in hw/block/fdc.c while processing DMA read data transfers from the floppy drive to the guest system. A privileged guest user could use this flaw to crash the QEMU process on the host resulting in DoS scenario, or potential information leakage from the host memory.
Published 2021-05-06 · Modified
6.1EPSS 0.005
CVE-2023-35936
Arbitrary file write is possible in Pandoc when using PDF output or --extract-media with untrusted input
Published 2023-07-05 · Modified
6.1EPSS 0.004
← Prev63 / 86Next →