Debian

Debian Linux

9142 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.21%
  • Veröffentlicht 31.10.2022 06:15:09
  • Zuletzt bearbeitet 06.05.2025 19:15:56

strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and intermediate CA) certificate that contains a CRL/OCSP URL that points to a server (under the attacker's control...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 29.10.2022 19:15:10
  • Zuletzt bearbeitet 21.11.2024 07:24:11

multipath-tools 0.7.0 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited alone or in conjunction with CVE-2022-41973. Local users able to write to UNIX domain sockets can bypass access controls and manipulate the multip...

Exploit
  • EPSS 0.22%
  • Veröffentlicht 29.10.2022 18:15:12
  • Zuletzt bearbeitet 21.11.2024 07:24:11

multipath-tools 0.7.7 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited in conjunction with CVE-2022-41974. Local users able to access /dev/shm can change symlinks in multipathd due to incorrect symlink handling, which...

  • EPSS 0.42%
  • Veröffentlicht 26.10.2022 20:15:10
  • Zuletzt bearbeitet 21.11.2024 07:17:57

Jupyter Core is a package for the core common functionality of Jupyter projects. Jupyter Core prior to version 4.11.2 contains an arbitrary code execution vulnerability in `jupyter_core` that stems from `jupyter_core` executing untrusted files in CWD...

Exploit
  • EPSS 0.45%
  • Veröffentlicht 26.10.2022 20:15:10
  • Zuletzt bearbeitet 25.11.2024 18:12:24

Twisted is an event-based framework for internet applications. Started with version 0.9.4, when the host header does not match a configured host `twisted.web.vhost.NameVirtualHost` will return a `NoResource` resource which renders the Host header une...

  • EPSS 0.3%
  • Veröffentlicht 26.10.2022 20:15:10
  • Zuletzt bearbeitet 21.11.2024 07:20:04

A vulnerability was found in vim and classified as problematic. Affected by this issue is the function qf_update_buffer of the file quickfix.c of the component autocmd Handler. The manipulation leads to use after free. The attack may be launched remo...

  • EPSS 0.06%
  • Veröffentlicht 26.10.2022 04:15:13
  • Zuletzt bearbeitet 07.05.2025 14:15:37

drivers/usb/mon/mon_bin.c in usbmon in the Linux kernel before 5.19.15 and 6.x before 6.0.1 allows a user-space client to corrupt the monitor's internal memory.

  • EPSS 0.23%
  • Veröffentlicht 25.10.2022 17:15:57
  • Zuletzt bearbeitet 21.11.2024 07:23:41

A vulnerability in Batik of Apache XML Graphics allows an attacker to run untrusted Java code from an SVG. This issue affects Apache XML Graphics prior to 1.16. It is recommended to update to version 1.16.

  • EPSS 0.23%
  • Veröffentlicht 25.10.2022 17:15:57
  • Zuletzt bearbeitet 21.11.2024 07:25:32

A vulnerability in Batik of Apache XML Graphics allows an attacker to run Java code from untrusted SVG via JavaScript. This issue affects Apache XML Graphics prior to 1.16. Users are recommended to upgrade to version 1.16.

Exploit
  • EPSS 0.31%
  • Veröffentlicht 24.10.2022 14:15:53
  • Zuletzt bearbeitet 30.05.2025 20:15:31

In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.