Debian

Debian Linux

9212 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.61%
  • Veröffentlicht 01.08.2019 17:15:13
  • Zuletzt bearbeitet 21.11.2024 04:26:51

An issue was discovered in OpenCV before 4.1.1. There is a NULL pointer dereference in the function cv::XMLParser::parse at modules/core/src/persistence.cpp.

Exploit
  • EPSS 1.97%
  • Veröffentlicht 01.08.2019 17:15:13
  • Zuletzt bearbeitet 21.11.2024 04:26:51

An issue was discovered in Poppler through 0.78.0. There is a divide-by-zero error in the function SplashOutputDev::tilingPatternFill at SplashOutputDev.cc.

Warnung
  • EPSS 93.08%
  • Veröffentlicht 01.08.2019 14:15:13
  • Zuletzt bearbeitet 27.10.2025 17:37:56

In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the whole DIH configuration can come from a request's "dataConfig" parameter. The debug mode of the DIH adm...

  • EPSS 0.92%
  • Veröffentlicht 31.07.2019 23:15:11
  • Zuletzt bearbeitet 21.11.2024 04:26:47

An issue was discovered in libmodbus before 3.0.7 and 3.1.x before 3.1.5. There is an out-of-bounds read for the MODBUS_FC_WRITE_MULTIPLE_REGISTERS case, aka VD-1301.

Exploit
  • EPSS 0.41%
  • Veröffentlicht 31.07.2019 23:15:11
  • Zuletzt bearbeitet 21.11.2024 04:26:47

XMFile::read in XMFile.cpp in milkyplay in MilkyTracker 1.02.00 has a heap-based buffer overflow.

  • EPSS 0.33%
  • Veröffentlicht 31.07.2019 23:15:10
  • Zuletzt bearbeitet 21.11.2024 04:18:35

It was found that in icedtea-web up to and including 1.7.2 and 1.8.2 executable code could be injected in a JAR file without compromising the signature verification. An attacker could use this flaw to inject code in a trusted JAR. The code would be e...

  • EPSS 1.56%
  • Veröffentlicht 31.07.2019 23:15:10
  • Zuletzt bearbeitet 21.11.2024 04:18:36

It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attacker could use this flaw to write files to arbitrary locations. This could also be used to replace the ...

  • EPSS 0.92%
  • Veröffentlicht 31.07.2019 23:15:10
  • Zuletzt bearbeitet 21.11.2024 04:26:47

An issue was discovered in libmodbus before 3.0.7 and 3.1.x before 3.1.5. There is an out-of-bounds read for the MODBUS_FC_WRITE_MULTIPLE_COILS case, aka VD-1302.

Exploit
  • EPSS 2.07%
  • Veröffentlicht 31.07.2019 21:15:11
  • Zuletzt bearbeitet 21.11.2024 04:26:47

nfdump 1.6.17 and earlier is affected by an integer overflow in the function Process_ipfix_template_withdraw in ipfix.c that can be abused in order to crash the process remotely (denial of service).

  • EPSS 0.63%
  • Veröffentlicht 30.07.2019 23:15:12
  • Zuletzt bearbeitet 21.11.2024 04:18:32

A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing the possibility of information disclosure through unexpected variable substitution. By taking advantage of unintended variable su...