Debian

Debian Linux

9144 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.25%
  • Veröffentlicht 11.09.2020 16:15:12
  • Zuletzt bearbeitet 21.11.2024 05:04:59

In Action View before versions 5.2.4.4 and 6.0.3.3 there is a potential Cross-Site Scripting (XSS) vulnerability in Action View's translation helpers. Views that allow the user to control the default (not found) value of the `t` and `translate` helpe...

  • EPSS 0.67%
  • Veröffentlicht 11.09.2020 05:15:12
  • Zuletzt bearbeitet 21.11.2024 04:39:41

An issue was discovered in InspIRCd 2 before 2.0.28 and 3 before 3.3.0. The mysql module contains a NULL pointer dereference when built against mariadb-connector-c 3.0.5 or newer. When combined with the sqlauth or sqloper modules, this vulnerability ...

  • EPSS 0.67%
  • Veröffentlicht 11.09.2020 05:15:12
  • Zuletzt bearbeitet 21.11.2024 05:17:49

An issue was discovered in InspIRCd 2 before 2.0.29 and 3 before 3.6.0. The pgsql module contains a use after free vulnerability. When combined with the sqlauth or sqloper modules, this vulnerability can be used for remote crashing of an InspIRCd ser...

  • EPSS 0.15%
  • Veröffentlicht 10.09.2020 19:15:13
  • Zuletzt bearbeitet 21.11.2024 05:02:09

Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX RMI registry and binds the server to the "jmxrmi" entry. It is possible to connect to the registry without authentication and call the rebind method to rebind jmxrmi to something ...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 10.09.2020 15:15:36
  • Zuletzt bearbeitet 21.11.2024 05:35:05

An exploitable denial of service vulnerability exists in the atftpd daemon functionality of atftp 0.7.git20120829-3.1+b1. A specially crafted sequence of RRQ-Multicast requests trigger an assert() call resulting in denial-of-service. An attacker can ...

Exploit
  • EPSS 0.24%
  • Veröffentlicht 09.09.2020 21:15:11
  • Zuletzt bearbeitet 21.11.2024 05:17:41

url::recvline in url.cpp in libproxy 0.4.x through 0.4.15 allows a remote HTTP server to trigger uncontrolled recursion via a response composed of an infinite stream that lacks a newline character. This leads to stack exhaustion.

Exploit
  • EPSS 1.11%
  • Veröffentlicht 09.09.2020 19:15:21
  • Zuletzt bearbeitet 21.11.2024 05:14:42

WebDAV implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to XXE injection.

Exploit
  • EPSS 44.38%
  • Veröffentlicht 09.09.2020 19:15:21
  • Zuletzt bearbeitet 21.11.2024 05:16:12

CGI implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to OS command injection.

Exploit
  • EPSS 1.16%
  • Veröffentlicht 09.09.2020 18:15:23
  • Zuletzt bearbeitet 21.11.2024 05:36:36

In PHP versions 7.2.x below 7.2.33, 7.3.x below 7.3.21 and 7.4.x below 7.4.9, while processing PHAR files using phar extension, phar_parse_zipfile could be tricked into accessing freed memory, which could lead to a crash or information disclosure.

Exploit
  • EPSS 0.04%
  • Veröffentlicht 09.09.2020 16:15:12
  • Zuletzt bearbeitet 21.11.2024 05:17:39

In the Linux kernel through 5.8.7, local attackers able to inject conntrack netlink configuration could overflow a local buffer, causing crashes or triggering use of incorrect protocol numbers in ctnetlink_parse_tuple_filter in net/netfilter/nf_connt...