Debian

Debian Linux

9212 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 5.44%
  • Veröffentlicht 16.08.2019 16:15:10
  • Zuletzt bearbeitet 21.11.2024 04:45:00

A command injection vulnerability in Nokogiri v1.10.3 and earlier allows commands to be executed in a subprocess via Ruby's `Kernel.open` method. Processes are vulnerable only if the undocumented method `Nokogiri::CSS::Tokenizer#load_file` is being c...

  • EPSS 0.13%
  • Veröffentlicht 16.08.2019 14:15:10
  • Zuletzt bearbeitet 21.11.2024 04:28:05

check_input_term in sound/usb/mixer.c in the Linux kernel through 5.2.9 mishandles recursion, leading to kernel stack exhaustion.

  • EPSS 0.04%
  • Veröffentlicht 16.08.2019 03:15:11
  • Zuletzt bearbeitet 21.11.2024 02:45:00

xtrlock through 2.10 does not block multitouch events. Consequently, an attacker at a locked screen can send input to (and thus control) various programs such as Chromium via events such as pan scrolling, "pinch and zoom" gestures, or even regular mo...

  • EPSS 0.16%
  • Veröffentlicht 16.08.2019 02:15:11
  • Zuletzt bearbeitet 21.11.2024 04:28:02

drivers/net/wireless/ath/ath6kl/usb.c in the Linux kernel through 5.2.9 has a NULL pointer dereference via an incomplete address in an endpoint descriptor.

  • EPSS 2.91%
  • Veröffentlicht 15.08.2019 22:15:22
  • Zuletzt bearbeitet 21.11.2024 04:52:26

LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launched from. LibreOffice also has a feature where documents can specify tha...

  • EPSS 85.78%
  • Veröffentlicht 15.08.2019 22:15:22
  • Zuletzt bearbeitet 21.11.2024 04:52:26

LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launched from. Protection was added, to address CVE-2019-9848, to block calli...

  • EPSS 0.11%
  • Veröffentlicht 15.08.2019 22:15:22
  • Zuletzt bearbeitet 21.11.2024 04:52:26

LibreOffice has a feature where documents can specify that pre-installed macros can be executed on various script events such as mouse-over, document-open etc. Access is intended to be restricted to scripts under the share/Scripts/python, user/Script...

Exploit
  • EPSS 23.33%
  • Veröffentlicht 15.08.2019 22:15:12
  • Zuletzt bearbeitet 21.11.2024 04:18:21

HTTP/2 (2.4.20 through 2.4.39) very early pushes, for example configured with "H2PushResource", could lead to an overwrite of memory in the pushing request's pool, leading to crashes. The memory copied is that of the configured push link header value...

  • EPSS 0.18%
  • Veröffentlicht 15.08.2019 17:15:13
  • Zuletzt bearbeitet 21.11.2024 04:24:28

A NULL pointer dereference in the get_window function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service by opening a crafted Ogg Vorbis file.

  • EPSS 0.14%
  • Veröffentlicht 15.08.2019 17:15:13
  • Zuletzt bearbeitet 21.11.2024 04:24:28

Use of uninitialized stack variables in the start_decoder function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service or disclose sensitive information by opening a crafted Ogg Vorbis file.