VendorsDebiandebian_linux10.0
Vulnerabilities

Debian Debian Linux 10.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3432CVEs
CVE-2011-1028
The $smarty.template variable in Smarty3 allows attackers to possibly execute arbitrary PHP code via the sysplugins/smarty_internal_compile_private_special_variable.php file.
Published 2019-11-20 · Modified
9.8EPSS 0.016
CVE-2012-1577
lib/libc/stdlib/random.c in OpenBSD returns 0 when seeded with 0.
Published 2019-12-10 · Modified
9.8EPSS 0.016
CVE-2022-47629
Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL signature parser.
Published 2022-12-20 · Modified
9.8EPSS 0.016
CVE-2020-8086
The mod_auth_ldap and mod_auth_ldap2 Community Modules through 2020-01-27 for Prosody incompletely verify the XMPP address passed to the is_admin() function. This grants remote entities admin-only functionality if their username matches the username of a local admin.
Published 2020-01-28 · Modified
9.8EPSS 0.015
CVE-2023-39352
Invalid offset validation leading to Out Of Bound Write in FreeRDP
Published 2023-08-31 · Modified
9.8EPSS 0.015
CVE-2007-0899
There is a possible heap overflow in libclamav/fsg.c before 0.100.0.
Published 2019-11-06 · Modified
9.8EPSS 0.015
CVE-2023-40567
Out-Of-Bounds Write in FreeRDP
Published 2023-08-31 · Modified
9.8EPSS 0.015
CVE-2023-5730
Memory safety bugs present in Firefox 118, Firefox ESR 115.3, and Thunderbird 115.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
Published 2023-10-24 · Modified
9.8EPSS 0.015
CVE-2008-7291
gri before 2.12.18 generates temporary files in an insecure way.
Published 2019-11-07 · Modified
9.8EPSS 0.014
CVE-2022-39955
Partial rule set bypass in OWASP ModSecurity Core Rule Set by submitting a specially crafted HTTP Content-Type header
Published 2022-09-20 · Modified
9.8EPSS 0.014
CVE-2023-40186
IntegerOverflow leading to Out-Of-Bound Write Vulnerability in FreeRDP
Published 2023-08-31 · Modified
9.8EPSS 0.014
CVE-2020-22669
Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability. Attackers can use the comment characters and variable assignments in the SQL syntax to bypass Modsecurity WAF protection and implement SQL injection attacks on Web applications.
Published 2022-09-02 · Modified
9.8EPSS 0.013
CVE-2023-40569
Out-Of-Bounds Write in FreeRDP
Published 2023-08-31 · Modified
9.8EPSS 0.013
CVE-2024-36886
tipc: fix UAF in error path
Published 2024-05-30 · Modified
9.8EPSS 0.013
CVE-2022-39353
xmldom allows multiple root nodes in a DOM
Published 2022-11-02 · Modified
9.8EPSS 0.013
CVE-2023-39355
FreeRDP Use-After-Free in RDPGFX_CMDID_RESETGRAPHICS
Published 2023-08-31 · Modified
9.8EPSS 0.013
CVE-2023-5176
Memory safety bugs present in Firefox 117, Firefox ESR 115.2, and Thunderbird 115.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.
Published 2023-09-27 · Modified
9.8EPSS 0.012
CVE-2022-39956
Partial rule set bypass in OWASP ModSecurity Core Rule Set for HTTP multipart requests using character encoding in the Content-Type or Content-Transfer-Encoding header
Published 2022-09-20 · Modified
9.8EPSS 0.012
CVE-2021-40874
An issue was discovered in LemonLDAP::NG (aka lemonldap-ng) 2.0.13. When using the RESTServer plug-in to operate a REST password validation service (for another LemonLDAP::NG instance, for example) and using the Kerberos authentication method combined with another method with the Combination authentication plug-in, any password will be recognized as valid for an existing user.
Published 2022-07-17 · Modified
9.8EPSS 0.011
CVE-2010-4533
offlineimap before 6.3.4 added support for SSL server certificate validation but it is still possible to use SSL v2 protocol, which is a flawed protocol with multiple security deficiencies.
Published 2019-11-13 · Modified
9.8EPSS 0.010
CVE-2022-23537
PJSIP vulnerable to heap buffer overflow when decoding STUN message
Published 2022-12-20 · Modified
9.8EPSS 0.010
CVE-2023-51714
An issue was discovered in the HTTP2 implementation in Qt before 5.15.17, 6.x before 6.2.11, 6.3.x through 6.5.x before 6.5.4, and 6.6.x before 6.6.2. network/access/http2/hpacktable.cpp has an incorrect HPack integer overflow check.
Published 2023-12-24 · Analyzed
9.8EPSS 0.010
CVE-2024-27388
SUNRPC: fix some memleaks in gssx_dec_option_array
Published 2024-05-01 · Modified
9.8EPSS 0.010
CVE-2024-25189
libjwt 1.15.3 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing side channel.
Published 2024-02-08 · Analyzed
9.8EPSS 0.010
CVE-2023-4056
Memory safety bugs present in Firefox 115, Firefox ESR 115.0, Firefox ESR 102.13, Thunderbird 115.0, and Thunderbird 102.13. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.
Published 2023-08-01 · Modified
9.8EPSS 0.009
CVE-2023-41361
An issue was discovered in FRRouting FRR 9.0. bgpd/bgp_open.c does not check for an overly large length of the rcv software version.
Published 2023-08-29 · Modified
9.8EPSS 0.009
CVE-2024-26877
crypto: xilinx - call finalize with bh disabled
Published 2024-04-17 · Modified
9.8EPSS 0.007
CVE-2024-35884
udp: do not accept non-tunnel GSO skbs landing in a tunnel
Published 2024-05-19 · Modified
9.8EPSS 0.007
CVE-2020-15999
Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published 2020-11-03 · Analyzed
9.6KEVEPSS 0.443
CVE-2021-37973
Use after free in Portals in Google Chrome prior to 94.0.4606.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Published 2021-10-08 · Analyzed
9.6KEVEPSS 0.117
CVE-2021-3693
Cross-site Scripting (XSS) - DOM in ledgersmb/ledgersmb
Published 2021-08-23 · Modified
9.6EPSS 0.032
CVE-2021-21110
Use after free in safe browsing in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
Published 2021-01-08 · Modified
9.6EPSS 0.031
CVE-2021-3694
Cross-site Scripting (XSS) - Reflected in ledgersmb/ledgersmb
Published 2021-08-23 · Modified
9.6EPSS 0.025
CVE-2020-16011
Heap buffer overflow in UI in Google Chrome on Windows prior to 86.0.4240.183 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Published 2020-11-03 · Modified
9.6EPSS 0.024
CVE-2021-21106
Use after free in autofill in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Published 2021-01-08 · Modified
9.6EPSS 0.022
CVE-2020-6573
Use after free in video in Google Chrome on Android prior to 85.0.4183.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Published 2020-09-21 · Modified
9.6EPSS 0.018
CVE-2021-21201
Use after free in permissions in Google Chrome prior to 90.0.4430.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Published 2021-04-26 · Modified
9.6EPSS 0.017
CVE-2020-6493
Use after free in WebAuthentication in Google Chrome prior to 83.0.4103.97 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Published 2020-06-03 · Modified
9.6EPSS 0.017
CVE-2020-6522
Inappropriate implementation in external protocol handlers in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
Published 2020-07-22 · Modified
9.6EPSS 0.016
CVE-2020-6465
Use after free in reader mode in Google Chrome on Android prior to 83.0.4103.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Published 2020-05-21 · Modified
9.6EPSS 0.016
← Prev8 / 86Next →