Debian

Debian Linux

9144 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.14%
  • Veröffentlicht 21.10.2020 15:15:18
  • Zuletzt bearbeitet 27.05.2025 16:42:14

Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows una...

  • EPSS 0.12%
  • Veröffentlicht 21.10.2020 15:15:18
  • Zuletzt bearbeitet 27.05.2025 16:41:52

Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JNDI). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthentica...

  • EPSS 0.17%
  • Veröffentlicht 21.10.2020 15:15:18
  • Zuletzt bearbeitet 27.05.2025 16:40:51

Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthe...

  • EPSS 1.77%
  • Veröffentlicht 21.10.2020 15:15:17
  • Zuletzt bearbeitet 21.11.2024 05:04:06

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: FTS). Supported versions that are affected are 5.6.49 and prior, 5.7.31 and prior and 8.0.21 and prior. Easily exploitable vulnerability allows low privileged attacker with...

  • EPSS 0.28%
  • Veröffentlicht 16.10.2020 17:15:17
  • Zuletzt bearbeitet 21.11.2024 05:41:34

A type confusion issue was addressed with improved memory handling. This issue is fixed in Safari 14.0. Processing maliciously crafted web content may lead to arbitrary code execution.

  • EPSS 1.15%
  • Veröffentlicht 16.10.2020 17:15:17
  • Zuletzt bearbeitet 21.11.2024 05:41:35

A use after free issue was addressed with improved memory management. This issue is fixed in Safari 14.0. Processing maliciously crafted web content may lead to arbitrary code execution.

  • EPSS 0.65%
  • Veröffentlicht 16.10.2020 17:15:11
  • Zuletzt bearbeitet 21.11.2024 05:04:57

In containerd (an industry-standard container runtime) before version 1.2.14 there is a credential leaking vulnerability. If a container image manifest in the OCI Image format or Docker Image V2 Schema 2 format includes a URL for the location of a sp...

  • EPSS 1.9%
  • Veröffentlicht 15.10.2020 03:15:12
  • Zuletzt bearbeitet 21.11.2024 05:20:47

In BlueZ before 5.55, a double free was found in the gatttool disconnect_cb() routine from shared/att.c. A remote attacker could potentially cause a denial of service or code execution, during service discovery, due to a redundant disconnect MGMT eve...

  • EPSS 0.9%
  • Veröffentlicht 14.10.2020 14:15:17
  • Zuletzt bearbeitet 21.11.2024 04:53:29

In binder_release_work of binder.c, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploita...

Exploit
  • EPSS 0.2%
  • Veröffentlicht 13.10.2020 20:15:12
  • Zuletzt bearbeitet 21.11.2024 05:18:19

A flaw was found in the Linux kernel in versions before 5.9-rc7. Traffic between two Geneve endpoints may be unencrypted when IPsec is configured to encrypt traffic for the specific UDP port used by the GENEVE tunnel allowing anyone between the two e...