VendorsDebiandebian_linux10.0
Vulnerabilities

Debian Debian Linux 10.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3432CVEs
CVE-2024-26814
vfio/fsl-mc: Block calling interrupt handler without trigger
Published 2024-04-05 · Analyzed
5.5EPSS 0.002
CVE-2024-26684
net: stmmac: xgmac: fix handling of DPP safety error for DMA channels
Published 2024-04-02 · Analyzed
5.5EPSS 0.002
CVE-2024-26702
iio: magnetometer: rm3100: add boundary check for the value read from RM3100_REG_TMRC
Published 2024-04-03 · Analyzed
5.5EPSS 0.002
CVE-2024-35902
net/rds: fix possible cp null dereference
Published 2024-05-19 · Modified
5.5EPSS 0.002
CVE-2024-35837
net: mvpp2: clear BM pool before initialization
Published 2024-05-17 · Analyzed
5.5EPSS 0.002
CVE-2022-42329
Guests can trigger deadlock in Linux netback driver T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The patch for XSA-392 introduced another issue which might result in a deadlock when trying to free the SKB of a packet dropped due to the XSA-392 handling (CVE-2022-42328). Additionally when dropping packages for other reasons the same deadlock could occur in case of netpoll being active for the interface the xen-netback driver is connected to (CVE-2022-42329).
Published 2022-12-07 · Modified
5.5EPSS 0.002
CVE-2024-36919
scsi: bnx2fc: Remove spin_lock_bh while releasing resources after upload
Published 2024-05-30 · Analyzed
5.5EPSS 0.002
CVE-2024-27004
clk: Get runtime PM before walking tree during disable_unused
Published 2024-05-01 · Modified
5.5EPSS 0.002
CVE-2024-35934
net/smc: reduce rtnl pressure in smc_pnet_create_pnetids_list()
Published 2024-05-19 · Modified
5.5EPSS 0.002
CVE-2024-35940
pstore/zone: Add a null pointer check to the psz_kmsg_read
Published 2024-05-19 · Modified
5.5EPSS 0.002
CVE-2024-35833
dmaengine: fsl-qdma: Fix a memory leak related to the queue command DMA
Published 2024-05-17 · Analyzed
5.5EPSS 0.002
CVE-2024-35829
drm/lima: fix a memleak in lima_heap_alloc
Published 2024-05-17 · Analyzed
5.5EPSS 0.002
CVE-2024-35988
riscv: Fix TASK_SIZE on 64-bit NOMMU
Published 2024-05-20 · Modified
5.5EPSS 0.002
CVE-2024-26984
nouveau: fix instmem race condition around ptr stores
Published 2024-05-01 · Modified
5.5EPSS 0.002
CVE-2023-27932
This issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 16.4, tvOS 16.4, watchOS 9.4. Processing maliciously crafted web content may bypass Same Origin Policy.
Published 2023-05-08 · Modified
5.5EPSS 0.002
CVE-2020-11935
aufs: improperly managed inode reference counts in the vfsub_dentry_open() method
Published 2023-04-07 · Modified
5.5EPSS 0.002
CVE-2024-35809
PCI/PM: Drain runtime-idle callbacks before driver removal
Published 2024-05-17 · Analyzed
5.5EPSS 0.002
CVE-2024-26696
nilfs2: fix hang in nilfs_lookup_dirty_data_buffers()
Published 2024-04-03 · Analyzed
5.5EPSS 0.002
CVE-2024-26679
inet: read sk->sk_family once in inet_recv_error()
Published 2024-04-02 · Analyzed
5.5EPSS 0.002
CVE-2024-26999
serial/pmac_zilog: Remove flawed mitigation for rx irq flood
Published 2024-05-01 · Modified
5.5EPSS 0.002
CVE-2023-52583
ceph: fix deadlock or deadcode of misusing dget()
Published 2024-03-06 · Analyzed
5.5EPSS 0.002
CVE-2024-35895
bpf, sockmap: Prevent lock inversion deadlock in map delete elem
Published 2024-05-19 · Modified
5.5EPSS 0.002
CVE-2024-35806
soc: fsl: qbman: Always disable interrupts when taking cgr_lock
Published 2024-05-17 · Analyzed
5.5EPSS 0.002
CVE-2024-35805
dm snapshot: fix lockup in dm_exception_table_exit
Published 2024-05-17 · Modified
5.5EPSS 0.002
CVE-2024-26781
mptcp: fix possible deadlock in subflow diag
Published 2024-04-04 · Analyzed
5.5EPSS 0.002
CVE-2024-26790
dmaengine: fsl-qdma: fix SoC may hang on 16 byte unaligned read
Published 2024-04-04 · Analyzed
5.5EPSS 0.002
CVE-2019-16223
WordPress before 5.2.3 allows XSS in post previews by authenticated users.
Published 2019-09-11 · Modified
5.41 PoCEPSS 0.052
CVE-2019-17674
WordPress before 5.2.4 is vulnerable to stored XSS (cross-site scripting) via the Customizer.
Published 2019-10-17 · Modified
5.4EPSS 0.016
CVE-2019-15587
In the Loofah gem for Ruby through v2.3.0 unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.
Published 2019-10-22 · Modified
5.4EPSS 0.016
CVE-2022-39348
Twisted vulnerable to NameVirtualHost Host header injection
Published 2022-10-26 · Modified
5.4EPSS 0.012
CVE-2020-4051
XSS in Dijit Editor's LinkDialog plugin
Published 2020-06-15 · Modified
5.4EPSS 0.012
CVE-2018-25047
In Smarty before 3.1.47 and 4.x before 4.2.1, libs/plugins/function.mailto.php allows XSS. A web page that uses smarty_function_mailto, and that could be parameterized using GET or POST input parameters, could allow injection of JavaScript code by a user.
Published 2022-09-14 · Modified
5.4EPSS 0.011
CVE-2022-26874
lib/Horde/Mime/Viewer/Ooo.php in Horde Mime_Viewer before 2.2.4 allows XSS via an OpenOffice document, leading to account takeover in Horde Groupware Webmail Edition. This occurs after XSLT rendering.
Published 2022-03-11 · Modified
5.4EPSS 0.011
CVE-2020-10942
In the Linux kernel before 5.5.8, get_raw_socket in drivers/vhost/net.c lacks validation of an sk_family field, which might allow attackers to trigger kernel stack corruption via crafted system calls.
Published 2020-03-24 · Modified
5.4EPSS 0.010
CVE-2023-6206
The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking delay on permission prompts. It was possible to use this fact to surprise users by luring them to click where the permission grant button would be about to appear. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
Published 2023-11-21 · Modified
5.4EPSS 0.006
CVE-2024-28182
Reading unbounded number of HTTP/2 CONTINUATION frames to cause excessive CPU usage
Published 2024-04-04 · Modified
5.3EPSS 0.850
CVE-2021-28169
For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to access protected resources within the WEB-INF directory. For example a request to `/concat?/%2557EB-INF/web.xml` can retrieve the web.xml file. This can reveal sensitive information regarding the implementation of a web application.
Published 2021-06-09 · Modified
5.3EPSS 0.785
CVE-2020-27223
In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS) state due to high CPU usage processing those quality values, resulting in minutes of CPU time exhausted processing those quality values.
Published 2021-02-26 · Modified
5.3EPSS 0.780
CVE-2021-33037
Incorrect Transfer-Encoding handling with HTTP/1.0
Published 2021-07-12 · Modified
5.3EPSS 0.747
CVE-2021-30641
Unexpected URL matching with 'MergeSlashes OFF'
Published 2021-06-10 · Modified
5.3EPSS 0.526
← Prev76 / 86Next →