Debian

Debian Linux

10003 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS -
  • Veröffentlicht 20.08.2026 12:42:42
  • Zuletzt bearbeitet 20.08.2026 13:19:07

A heap out-of-bounds write exists in the Photo CD (PCD) decoder of GraphicsMagick. In DecodeImage() (coders/pcd.c), the Huffman delta loop advances its output pointer with q++ after every decoded delta and never checks it against the end of the heap-...

  • EPSS 0.46%
  • Veröffentlicht 30.07.2026 16:38:58
  • Zuletzt bearbeitet 05.08.2026 19:38:07

A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to potentially cause a denial of service or leak memory via crafted packets during TLS session promotion or expiry

Medienbericht
  • EPSS 0.28%
  • Veröffentlicht 03.07.2026 20:57:31
  • Zuletzt bearbeitet 08.07.2026 20:11:16

In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding o...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 23.06.2026 16:18:29
  • Zuletzt bearbeitet 31.07.2026 06:16:30

GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a crafted server.

Medienbericht Exploit
  • EPSS 27.98%
  • Veröffentlicht 08.06.2026 15:26:04
  • Zuletzt bearbeitet 19.08.2026 12:18:28

Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67.

Medienbericht
  • EPSS 9.96%
  • Veröffentlicht 22.05.2026 14:11:41
  • Zuletzt bearbeitet 25.08.2026 13:19:33

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for ex...

Medienbericht Exploit
  • EPSS 1.5%
  • Veröffentlicht 15.05.2026 12:58:44
  • Zuletzt bearbeitet 24.08.2026 13:18:59

In the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner 'get_dumpable()' logic The 'dumpability' of a task is fundamentally about the memory image of the task - the concept comes from whether it can core dump or n...

Warnung Medienbericht Exploit
  • EPSS 99.91%
  • Veröffentlicht 22.04.2026 08:15:10
  • Zuletzt bearbeitet 28.07.2026 14:54:01

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-pl...

  • EPSS 0.21%
  • Veröffentlicht 16.04.2026 17:32:40
  • Zuletzt bearbeitet 15.07.2026 02:21:12

In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.

Exploit
  • EPSS 0.2%
  • Veröffentlicht 09.04.2026 14:41:18
  • Zuletzt bearbeitet 13.05.2026 23:07:51

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.0.9 to before 1.6.57, passing a pointer obtained from png_get_PLTE, png_get_tRNS, or png_get_hIST back ...