Debian

Debian Linux

9144 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.16%
  • Veröffentlicht 15.06.2020 22:15:09
  • Zuletzt bearbeitet 21.11.2024 05:32:13

In Dijit before versions 1.11.11, and greater than or equal to 1.12.0 and less than 1.12.9, and greater than or equal to 1.13.0 and less than 1.13.8, and greater than or equal to 1.14.0 and less than 1.14.7, and greater than or equal to 1.15.0 and le...

  • EPSS 1.82%
  • Veröffentlicht 15.06.2020 18:15:15
  • Zuletzt bearbeitet 21.11.2024 05:02:44

The Server-Server protocol implementation in ngIRCd before 26~rc2 allows an out-of-bounds access, as demonstrated by the IRC_NJOIN() function.

  • EPSS 0.27%
  • Veröffentlicht 15.06.2020 18:15:14
  • Zuletzt bearbeitet 21.11.2024 05:02:44

An integer overflow in the getnum function in lua_struct.c in Redis before 6.0.3 allows context-dependent attackers with permission to run Lua code in a Redis session to cause a denial of service (memory corruption and application crash) or possibly ...

  • EPSS 0.51%
  • Veröffentlicht 15.06.2020 17:15:10
  • Zuletzt bearbeitet 21.11.2024 05:02:45

In IJG JPEG (aka libjpeg) before 9d, jpeg_mem_available() in jmemnobs.c in djpeg does not honor the max_memory_to_use setting, possibly causing excessive memory consumption.

  • EPSS 2.12%
  • Veröffentlicht 15.06.2020 05:15:11
  • Zuletzt bearbeitet 21.11.2024 05:02:36

Mutt before 1.14.3 allows an IMAP fcc/postpone man-in-the-middle attack via a PREAUTH response.

  • EPSS 6.31%
  • Veröffentlicht 14.06.2020 20:15:10
  • Zuletzt bearbeitet 27.08.2025 21:15:35

FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oracle.jms.AQjmsQueueConnectionFactory, oracle.jms.AQjmsXATopicConnectionFactory, oracle.jms.AQjmsTopicConnectionFactory, o...

  • EPSS 7.71%
  • Veröffentlicht 14.06.2020 20:15:10
  • Zuletzt bearbeitet 21.11.2024 05:02:28

FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to com.sun.org.apache.xalan.internal.lib.sql.JNDIConnectionPool (aka xalan2).

  • EPSS 6.85%
  • Veröffentlicht 12.06.2020 16:15:10
  • Zuletzt bearbeitet 21.11.2024 05:32:12

In affected versions of WordPress, users with low privileges (like contributors and authors) can use the embed block in a certain way to inject unfiltered HTML in the block editor. When affected posts are viewed by a higher privileged user, this coul...

  • EPSS 5.57%
  • Veröffentlicht 12.06.2020 16:15:10
  • Zuletzt bearbeitet 21.11.2024 05:32:13

In affected versions of WordPress, authenticated users with upload permissions (like authors) are able to inject JavaScript into some media file attachment pages in a certain way. This can lead to script execution in the context of a higher privilege...

  • EPSS 3.5%
  • Veröffentlicht 12.06.2020 16:15:10
  • Zuletzt bearbeitet 21.11.2024 05:32:13

In affected versions of WordPress, due to an issue in wp_validate_redirect() and URL sanitization, an arbitrary external link can be crafted leading to unintended/open redirect when clicked. This has been patched in version 5.4.2, along with all the ...