Debian

Debian Linux

9202 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 1.27%
  • Veröffentlicht 26.11.2019 18:15:15
  • Zuletzt bearbeitet 21.11.2024 04:30:24

Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows code injection if the first argument (aka the "command" argument) to Shell#[] or Shell#test in lib/shell.rb is untrusted data. An attacker can exploit this to call an arbitrary R...

  • EPSS 38.43%
  • Veröffentlicht 26.11.2019 17:15:13
  • Zuletzt bearbeitet 21.11.2024 04:33:31

An issue was discovered in Squid 2.x, 3.x, and 4.x through 4.8. Due to incorrect data management, it is vulnerable to information disclosure when processing HTTP Digest Authentication. Nonce tokens contain the raw byte value of a pointer that sits wi...

  • EPSS 1.37%
  • Veröffentlicht 26.11.2019 17:15:12
  • Zuletzt bearbeitet 21.11.2024 04:33:30

An issue was discovered in Squid 3.x and 4.x through 4.8. Due to incorrect input validation, there is a heap-based buffer overflow that can result in Denial of Service to all clients using the proxy. Severity is high due to this vulnerability occurri...

  • EPSS 9.96%
  • Veröffentlicht 26.11.2019 17:15:12
  • Zuletzt bearbeitet 21.11.2024 04:33:30

An issue was discovered in Squid 3.x and 4.x through 4.8. It allows attackers to smuggle HTTP requests through frontend software to a Squid instance that splits the HTTP Request pipeline differently. The resulting Response messages corrupt caches (be...

  • EPSS 0.56%
  • Veröffentlicht 26.11.2019 17:15:10
  • Zuletzt bearbeitet 21.11.2024 04:23:01

An issue was discovered in Squid before 4.9. When handling a URN request, a corresponding HTTP request is made. This HTTP request doesn't go through the access checks that incoming HTTP requests go through. This causes all access checks to be bypasse...

  • EPSS 33.64%
  • Veröffentlicht 26.11.2019 17:15:10
  • Zuletzt bearbeitet 21.11.2024 04:23:02

An issue was discovered in Squid before 4.9. URN response handling in Squid suffers from a heap-based buffer overflow. When receiving data from a remote server in response to an URN request, Squid fails to ensure that the response can fit within the ...

Exploit
  • EPSS 25.88%
  • Veröffentlicht 26.11.2019 05:15:14
  • Zuletzt bearbeitet 21.11.2024 01:32:17

Yaws 1.91 has a directory traversal vulnerability in the way certain URLs are processed. A remote authenticated user could use this flaw to obtain content of arbitrary local files via specially-crafted URL request.

  • EPSS 1.48%
  • Veröffentlicht 26.11.2019 05:15:13
  • Zuletzt bearbeitet 21.11.2024 01:31:53

Yubico PAM Module before 2.10 performed user authentication when 'use_first_pass' PAM configuration option was not used and the module was configured as 'sufficient' in the PAM configuration. A remote attacker could use this flaw to circumvent common...

  • EPSS 0.92%
  • Veröffentlicht 26.11.2019 05:15:11
  • Zuletzt bearbeitet 21.11.2024 01:31:48

A local file inclusion flaw was found in the way the phpLDAPadmin before 0.9.8 processed certain values of the "Accept-Language" HTTP header. A remote attacker could use this flaw to cause a denial of service via specially-crafted request.

  • EPSS 4.16%
  • Veröffentlicht 26.11.2019 04:15:11
  • Zuletzt bearbeitet 21.11.2024 01:30:53

Hardlink before 0.1.2 has multiple integer overflows leading to heap-based buffer overflows because of the way string lengths concatenation is done in the calculation of the required memory space to be used. A remote attacker could provide a speciall...