VendorsDebiandebian_linux10.0
Vulnerabilities

Debian Debian Linux 10.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3432CVEs
CVE-2022-36227
In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the discoverer cites this CWE-476 remark but third parties dispute the code-execution impact: "In rare circumstances, when NULL is equivalent to the 0x0 memory address and privileged code can access it, then writing or reading memory is possible, which may lead to code execution."
Published 2022-11-22 · Modified
9.8EPSS 0.024
CVE-2021-38171
adts_decode_extradata in libavformat/adtsenc.c in FFmpeg 4.4 does not check the init_get_bits return value, which is a necessary step because the second argument to init_get_bits can be crafted.
Published 2021-08-21 · Modified
9.8EPSS 0.024
CVE-2020-17353
scm/define-stencil-commands.scm in LilyPond through 2.20.0, and 2.21.x through 2.21.4, when -dsafe is used, lacks restrictions on embedded-ps and embedded-svg, as demonstrated by including dangerous PostScript code.
Published 2020-08-05 · Modified
9.8EPSS 0.024
CVE-2020-24660
An issue was discovered in LemonLDAP::NG through 2.0.8, when NGINX is used. An attacker may bypass URL-based access control to protected Virtual Hosts by submitting a non-normalized URI. This also affects versions before 0.5.2 of the "Lemonldap::NG handler for Node.js" package.
Published 2020-09-14 · Modified
9.8EPSS 0.024
CVE-2021-43300
Stack overflow in PJSUA API when calling pjsua_recorder_create. An attacker-controlled 'filename' argument may cause a buffer overflow since it is copied to a fixed-size stack buffer without any size validation.
Published 2022-02-16 · Modified
9.8EPSS 0.024
CVE-2021-43301
Stack overflow in PJSUA API when calling pjsua_playlist_create. An attacker-controlled 'file_names' argument may cause a buffer overflow since it is copied to a fixed-size stack buffer without any size validation.
Published 2022-02-16 · Modified
9.8EPSS 0.024
CVE-2021-43303
Buffer overflow in PJSUA API when calling pjsua_call_dump. An attacker-controlled 'buffer' argument may cause a buffer overflow, since supplying an output buffer smaller than 128 characters may overflow the output buffer, regardless of the 'maxlen' argument supplied
Published 2022-02-16 · Modified
9.8EPSS 0.024
CVE-2020-36329
A flaw was found in libwebp in versions before 1.0.1. A use-after-free was found due to a thread being killed too early. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Published 2021-05-21 · Modified
9.8EPSS 0.023
CVE-2019-17542
FFmpeg before 4.2 has a heap-based buffer overflow in vqa_decode_chunk because of an out-of-array access in vqa_decode_init in libavcodec/vqavideo.c.
Published 2019-10-14 · Modified
9.8EPSS 0.023
CVE-2020-27745
Slurm before 19.05.8 and 20.x before 20.02.6 has an RPC Buffer Overflow in the PMIx MPI plugin.
Published 2020-11-27 · Modified
9.8EPSS 0.022
CVE-2007-6745
clamav 0.91.2 suffers from a floating point exception when using ScanOLE2.
Published 2019-11-07 · Modified
9.8EPSS 0.022
CVE-2020-9355
danfruehauf NetworkManager-ssh before 1.2.11 allows privilege escalation because extra options are mishandled.
Published 2020-02-23 · Modified
9.8EPSS 0.022
CVE-2019-15941
OpenID Connect Issuer in LemonLDAP::NG 2.x through 2.0.5 may allow an attacker to bypass access control rules via a crafted OpenID Connect authorization request. To be vulnerable, there must exist an OIDC Relaying party within the LemonLDAP configuration with weaker access control rules than the target RP, and no filtering on redirection URIs.
Published 2019-09-25 · Modified
9.8EPSS 0.022
CVE-2020-28984
prive/formulaires/configurer_preferences.php in SPIP before 3.2.8 does not properly validate the couleur, display, display_navigation, display_outils, imessage, and spip_ecran parameters.
Published 2020-11-23 · Modified
9.8EPSS 0.022
CVE-2013-2166
python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass
Published 2019-12-10 · Modified
9.8EPSS 0.021
CVE-2023-6816
Xorg-x11-server: heap buffer overflow in devicefocusevent and procxiquerypointer
Published 2024-01-18 · Modified
9.8EPSS 0.021
CVE-2019-11766
dhcp6.c in dhcpcd before 6.11.7 and 7.x before 7.2.2 has a buffer over-read in the D6_OPTION_PD_EXCLUDE feature.
Published 2019-05-05 · Modified
9.8EPSS 0.021
CVE-2023-42464
A Type Confusion vulnerability was found in the Spotlight RPC functions in afpd in Netatalk 3.1.x before 3.1.17. When parsing Spotlight RPC packets, one encoded data structure is a key-value style dictionary where the keys are character strings, and the values can be any of the supported types in the underlying protocol. Due to a lack of type checking in callers of the dalloc_value_for_key() function, which returns the object associated with a key, a malicious actor may be able to fully control the value of the pointer and theoretically achieve Remote Code Execution on the host. This issue is similar to CVE-2023-34967.
Published 2023-09-20 · Modified
9.8EPSS 0.021
CVE-2012-6094
cups (Common Unix Printing System) 'Listen localhost:631' option not honored correctly which could provide unauthorized access to the system
Published 2019-12-20 · Modified
9.8EPSS 0.021
CVE-2022-31799
Bottle before 0.12.20 mishandles errors during early request binding.
Published 2022-05-29 · Modified
9.8EPSS 0.021
CVE-2022-0318
Heap-based Buffer Overflow in vim/vim
Published 2022-01-21 · Modified
9.8EPSS 0.020
CVE-2019-17539
In FFmpeg before 4.2, avcodec_open2 in libavcodec/utils.c allows a NULL pointer dereference and possibly unspecified other impact when there is no valid close function pointer.
Published 2019-10-14 · Modified
9.8EPSS 0.020
CVE-2014-0175
mcollective has a default password set at install
Published 2019-12-13 · Modified
9.8EPSS 0.020
CVE-2020-7677
Arbitrary Code Execution
Published 2022-07-25 · Modified
9.8EPSS 0.020
CVE-2011-4120
Yubico PAM Module before 2.10 performed user authentication when 'use_first_pass' PAM configuration option was not used and the module was configured as 'sufficient' in the PAM configuration. A remote attacker could use this flaw to circumvent common authentication process and obtain access to the account in question by providing a NULL value (pressing Ctrl-D keyboard sequence) as the password string.
Published 2019-11-26 · Modified
9.8EPSS 0.020
CVE-2022-31031
Potential stack buffer overflow when parsing message as a STUN client
Published 2022-06-07 · Modified
9.8EPSS 0.020
CVE-2013-2745
An SQL Injection vulnerability exists in MiniDLNA prior to 1.1.0
Published 2019-12-04 · Modified
9.8EPSS 0.020
CVE-2022-24786
Potential out-of-bound read/write in PJSIP
Published 2022-04-06 · Modified
9.8EPSS 0.020
CVE-2013-2167
python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache signing bypass
Published 2019-12-10 · Modified
9.8EPSS 0.020
CVE-2011-2897
gdk-pixbuf through 2.31.1 has GIF loader buffer overflow when initializing decompression tables due to an input validation flaw
Published 2019-11-12 · Modified
9.8EPSS 0.019
CVE-2021-23518
Prototype Pollution
Published 2022-01-21 · Modified
9.8EPSS 0.019
CVE-2022-28044
Irzip v0.640 was discovered to contain a heap memory corruption via the component lrzip.c:initialise_control.
Published 2022-04-15 · Modified
9.8EPSS 0.019
CVE-2021-44538
The olm_session_describe function in Matrix libolm before 3.2.7 is vulnerable to a buffer overflow. The Olm session object represents a cryptographic channel between two parties. Therefore, its state is partially controllable by the remote party of the channel. Attackers can construct a crafted sequence of messages to manipulate the state of the receiver's session in such a way that, for some buffer sizes, a buffer overflow happens on a call to olm_session_describe. Furthermore, safe buffer sizes were undocumented. The overflow content is partially controllable by the attacker and limited to ASCII spaces and digits. The known affected products are Element Web And SchildiChat Web.
Published 2021-12-14 · Modified
9.8EPSS 0.019
CVE-2020-11729
An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60. Long-term session cookies, uses to provide long-term session continuity, are not generated securely, enabling a brute-force attack that may be successful.
Published 2020-04-15 · Modified
9.8EPSS 0.019
CVE-2010-0748
Transmission before 1.92 allows an attacker to cause a denial of service (crash) or possibly have other unspecified impact via a large number of tr arguments in a magnet link.
Published 2019-10-30 · Modified
9.8EPSS 0.019
CVE-2022-37616
A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package before 0.8.3 for Node.js via the p variable. NOTE: the vendor states "we are in the process of marking this report as invalid"; however, some third parties takes the position that "A prototype injection/Prototype pollution is not just when global objects are polluted with recursive merge or deep cloning but also when a target object is polluted."
Published 2022-10-11 · Modified
9.8EPSS 0.017
CVE-2022-24300
Minetest before 5.4.0 allows attackers to add or modify arbitrary meta fields of the same item stack as saved user input, aka ItemStack meta injection.
Published 2022-02-02 · Modified
9.8EPSS 0.017
CVE-2014-6311
generate_doygen.pl in ace before 6.2.7+dfsg-2 creates predictable file names in the /tmp directory which allows attackers to gain elevated privileges.
Published 2019-11-22 · Modified
9.8EPSS 0.017
CVE-2010-3438
libpoe-component-irc-perl before v6.32 does not remove carriage returns and line feeds. This can be used to execute arbitrary IRC commands by passing an argument such as "some text\rQUIT" to the 'privmsg' handler, which would cause the client to disconnect from the server.
Published 2019-11-12 · Modified
9.8EPSS 0.017
CVE-2021-20001
It was discovered, that debian-edu-config, a set of configuration files used for the Debian Edu blend, before 2.12.16 configured insecure permissions for the user web shares (~/public_html), which could result in privilege escalation.
Published 2022-02-11 · Modified
9.8EPSS 0.016
← Prev7 / 86Next →