Debian

Debian Linux

9142 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.17%
  • Veröffentlicht 07.02.2022 22:15:08
  • Zuletzt bearbeitet 25.11.2024 18:12:24

twisted is an event-driven networking engine written in Python. In affected versions twisted exposes cookies and authorization headers when following cross-origin redirects. This issue is present in the `twited.web.RedirectAgent` and `twisted.web. Br...

  • EPSS 45.72%
  • Veröffentlicht 04.02.2022 23:15:15
  • Zuletzt bearbeitet 21.11.2024 06:48:56

Twig is an open source template language for PHP. When in a sandbox mode, the `arrow` parameter of the `sort` filter must be a closure to avoid attackers being able to run arbitrary PHP functions. In affected versions this constraint was not properly...

Exploit
  • EPSS 0.75%
  • Veröffentlicht 04.02.2022 23:15:15
  • Zuletzt bearbeitet 21.11.2024 06:49:30

A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon GCodeNumber parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or excellon file can lead to code execution. An ...

  • EPSS 0.55%
  • Veröffentlicht 04.02.2022 23:15:15
  • Zuletzt bearbeitet 21.11.2024 06:49:30

A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon DCodeNumber parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or excellon file can lead to code execution. An ...

Exploit
  • EPSS 0.94%
  • Veröffentlicht 04.02.2022 23:15:12
  • Zuletzt bearbeitet 21.11.2024 06:36:47

NULL Pointer Dereference in GitHub repository gpac/gpac prior to 1.1.0.

  • EPSS 0.05%
  • Veröffentlicht 04.02.2022 23:15:12
  • Zuletzt bearbeitet 21.11.2024 06:38:45

A use-after-free vulnerability was found in rtsx_usb_ms_drv_remove in drivers/memstick/host/rtsx_usb_ms.c in memstick in the Linux kernel. In this flaw, a local attacker with a user privilege may impact system Confidentiality. This flaw affects kerne...

Exploit
  • EPSS 0.28%
  • Veröffentlicht 04.02.2022 23:15:11
  • Zuletzt bearbeitet 21.11.2024 06:24:03

A use-after-free vulnerability exists in the RS-274X aperture definition tokenization functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and Gerbv forked 2.7.1. A specially-crafted gerber file can lead to code execution. An attacker can provide a...

Exploit
  • EPSS 0.13%
  • Veröffentlicht 04.02.2022 23:15:11
  • Zuletzt bearbeitet 21.11.2024 06:24:03

An information disclosure vulnerability exists in the pick-and-place rotation parsing functionality of Gerbv 2.7.0 and dev (commit b5f1eacd), and Gerbv forked 2.8.0. A specially-crafted pick-and-place file can exploit the missing initialization of a ...

Exploit
  • EPSS 0.12%
  • Veröffentlicht 04.02.2022 21:15:08
  • Zuletzt bearbeitet 21.11.2024 06:34:34

options.c in atftp before 0.7.5 reads past the end of an array, and consequently discloses server-side /etc/group data to a remote client.

  • EPSS 0.01%
  • Veröffentlicht 04.02.2022 20:15:08
  • Zuletzt bearbeitet 21.11.2024 06:50:26

An issue was discovered in fs/nfs/dir.c in the Linux kernel before 5.16.5. If an application sets the O_DIRECTORY flag, and tries to open a regular file, nfs_atomic_open() performs a regular lookup. If a regular file is found, ENOTDIR should occur, b...