Debian

Debian Linux

9142 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.03%
  • Published 18.07.2022 15:15:08
  • Last modified 02.04.2025 18:33:53

When setting font with malicous data by ioctl cmd PIO_FONT,kernel will write memory out of bounds.

  • EPSS 0.04%
  • Published 18.07.2022 15:15:07
  • Last modified 21.11.2024 06:09:17

When sending malicous data to kernel by ioctl cmd FBIOPUT_VSCREENINFO,kernel will write memory out of bounds.

Exploit
  • EPSS 0.3%
  • Published 18.07.2022 00:15:08
  • Last modified 21.11.2024 05:06:45

In LemonLDAP::NG (aka lemonldap-ng) through 2.0.8, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used.

Exploit
  • EPSS 0.29%
  • Published 18.07.2022 00:15:08
  • Last modified 21.11.2024 06:24:59

An issue was discovered in LemonLDAP::NG (aka lemonldap-ng) 2.0.13. When using the RESTServer plug-in to operate a REST password validation service (for another LemonLDAP::NG instance, for example) and using the Kerberos authentication method combine...

  • EPSS 9.47%
  • Published 17.07.2022 22:15:08
  • Last modified 21.11.2024 06:34:42

In Squid 3.x through 3.5.28, 4.x through 4.17, and 5.x before 5.6, due to improper buffer management, a Denial of Service can occur when processing long Gopher server responses.

  • EPSS 0.27%
  • Published 17.07.2022 19:15:18
  • Last modified 23.05.2025 16:43:11

An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before 2.3.20. When two passdb configuration entries exist with the same driver and args settings, incorrect username_filter and mechanism settings can be applied to passdb definiti...

Exploit
  • EPSS 0.6%
  • Published 15.07.2022 14:15:09
  • Last modified 21.11.2024 07:11:07

An issue was discovered in Mbed TLS before 2.28.1 and 3.x before 3.2.0. In some configurations, an unauthenticated attacker can send an invalid ClientHello message to a DTLS server that causes a heap-based buffer over-read of up to 255 bytes. This ca...

  • EPSS 0.19%
  • Published 14.07.2022 20:15:08
  • Last modified 21.11.2024 06:49:19

Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure.

  • EPSS 0.08%
  • Published 14.07.2022 15:15:08
  • Last modified 21.11.2024 07:05:56

A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.20.0, <18.5.0 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making D...

Exploit
  • EPSS 89.07%
  • Published 14.07.2022 15:15:08
  • Last modified 21.11.2024 07:05:56

The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding headers and can lead to HTTP Request Smuggling (HRS).