Debian

Debian Linux

9140 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.16%
  • Veröffentlicht 11.02.2024 03:15:09
  • Zuletzt bearbeitet 21.11.2024 09:01:15

In Rhonabwy through 1.1.13, HMAC signature verification uses a strcmp function that is vulnerable to side-channel attacks, because it stops the comparison when the first difference is spotted in the two signatures. (The fix uses gnutls_memcmp, which ...

  • EPSS 0.03%
  • Veröffentlicht 07.02.2024 21:15:08
  • Zuletzt bearbeitet 21.11.2024 08:43:41

A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages when using NVMe over TCP, leading the NVMe driver to a NULL pointer dereference in the NVMe driver and c...

  • EPSS 0.03%
  • Veröffentlicht 07.02.2024 21:15:08
  • Zuletzt bearbeitet 21.11.2024 08:44:03

A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages when using NVMe over TCP, leading the NVMe driver to a NULL pointer dereference in the NVMe driver, caus...

  • EPSS 0.03%
  • Veröffentlicht 05.02.2024 08:15:44
  • Zuletzt bearbeitet 13.02.2025 18:17:10

A race condition was found in the Linux kernel's net/bluetooth device driver in conn_info_{min,max}_age_set() function. This can result in integrity overflow issue, possibly leading to bluetooth connection abnormality or denial of service.

  • EPSS 0.02%
  • Veröffentlicht 05.02.2024 08:15:44
  • Zuletzt bearbeitet 13.02.2025 18:17:10

A race condition was found in the Linux kernel's net/bluetooth in {conn,adv}_{min,max}_interval_set() function. This can result in I2cap connection or broadcast abnormality issue, possibly leading to denial of service.

Warnung Exploit
  • EPSS 85.85%
  • Veröffentlicht 31.01.2024 13:15:10
  • Zuletzt bearbeitet 02.04.2025 20:32:33

A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, and hence the n...

  • EPSS 0.16%
  • Veröffentlicht 29.01.2024 11:15:07
  • Zuletzt bearbeitet 02.06.2025 19:15:21

Transmit requests in Xen's virtual network protocol can consist of multiple parts. While not really useful, except for the initial part any of them may be of zero length, i.e. carry no data at all. Besides a certain initial portion of the to be tra...

  • EPSS 0.34%
  • Veröffentlicht 24.01.2024 00:15:07
  • Zuletzt bearbeitet 30.05.2025 15:15:31

Integer underflow in WebUI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via a malicious file. (Chromium security severity: High)

  • EPSS 47.68%
  • Veröffentlicht 23.01.2024 14:15:38
  • Zuletzt bearbeitet 30.05.2025 15:15:29

An out of bounds write in ANGLE could have allowed an attacker to corrupt memory leading to a potentially exploitable crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.

  • EPSS 0.75%
  • Veröffentlicht 23.01.2024 14:15:38
  • Zuletzt bearbeitet 30.05.2025 15:15:29

It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to an incorrect timestamp used to prevent input after page load. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and T...