Debian

Debian Linux

9142 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 5.86%
  • Veröffentlicht 12.04.2022 05:15:06
  • Zuletzt bearbeitet 21.11.2024 06:57:11

An issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. QuerySet.annotate(), aggregate(), and extra() methods are subject to SQL injection in column aliases via a crafted dictionary (with dictionary expansion) as...

  • EPSS 1.5%
  • Veröffentlicht 11.04.2022 22:15:07
  • Zuletzt bearbeitet 21.11.2024 06:51:12

Nokogiri is an open source XML and HTML library for Ruby. Nokogiri `< v1.13.4` contains an inefficient regular expression that is susceptible to excessive backtracking when attempting to detect encoding in HTML documents. Users are advised to upgrade...

  • EPSS 0.03%
  • Veröffentlicht 11.04.2022 05:15:07
  • Zuletzt bearbeitet 21.11.2024 06:58:09

The SUNRPC subsystem in the Linux kernel through 5.17.2 can call xs_xprt_free before ensuring that sockets are in the intended state.

  • EPSS 0.39%
  • Veröffentlicht 06.04.2022 14:15:08
  • Zuletzt bearbeitet 21.11.2024 06:51:06

PJSIP is a free and open source multimedia communication library written in C. A buffer overflow vulnerability in versions 2.12 and prior affects applications that use PJSIP DNS resolution. It doesn't affect PJSIP users who utilize an external resolv...

  • EPSS 0.29%
  • Veröffentlicht 06.04.2022 14:15:07
  • Zuletzt bearbeitet 21.11.2024 06:51:05

PJSIP is a free and open source multimedia communication library written in C. PJSIP versions 2.12 and prior do not parse incoming RTCP feedback RPSI (Reference Picture Selection Indication) packet, but any app that directly uses pjmedia_rtcp_fb_pars...

  • EPSS 0.32%
  • Veröffentlicht 06.04.2022 02:15:08
  • Zuletzt bearbeitet 21.11.2024 06:53:26

An issue was discovered in HTCondor 8.8.x before 8.8.16, 9.0.x before 9.0.10, and 9.1.x before 9.6.0. When a user authenticates to an HTCondor daemon via the CLAIMTOBE method, the user can then impersonate any entity when issuing additional commands ...

  • EPSS 0.04%
  • Veröffentlicht 05.04.2022 13:15:07
  • Zuletzt bearbeitet 21.11.2024 06:53:49

Racy interactions between dirty vram tracking and paging log dirty hypercalls Activation of log dirty mode done by XEN_DMOP_track_dirty_vram (was named HVMOP_track_dirty_vram before Xen 4.9) is racy with ongoing log dirty hypercalls. A suitably timed...

  • EPSS 0.01%
  • Veröffentlicht 05.04.2022 13:15:07
  • Zuletzt bearbeitet 21.11.2024 06:53:49

race in VT-d domain ID cleanup Xen domain IDs are up to 15 bits wide. VT-d hardware may allow for only less than 15 bits to hold a domain ID associating a physical device with a particular domain. Therefore internally Xen domain IDs are mapped to the...

  • EPSS 0.09%
  • Veröffentlicht 05.04.2022 13:15:07
  • Zuletzt bearbeitet 21.11.2024 06:53:49

IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Certain PCI devices in a system might be assigned Reserved Memo...

  • EPSS 0.09%
  • Veröffentlicht 05.04.2022 13:15:07
  • Zuletzt bearbeitet 21.11.2024 06:53:49

IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Certain PCI devices in a system might be assigned Reserved Memo...