Debian

Debian Linux

9142 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 5.86%
  • Published 12.04.2022 05:15:06
  • Last modified 21.11.2024 06:57:11

An issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. QuerySet.annotate(), aggregate(), and extra() methods are subject to SQL injection in column aliases via a crafted dictionary (with dictionary expansion) as...

  • EPSS 1.5%
  • Published 11.04.2022 22:15:07
  • Last modified 21.11.2024 06:51:12

Nokogiri is an open source XML and HTML library for Ruby. Nokogiri `< v1.13.4` contains an inefficient regular expression that is susceptible to excessive backtracking when attempting to detect encoding in HTML documents. Users are advised to upgrade...

  • EPSS 0.03%
  • Published 11.04.2022 05:15:07
  • Last modified 21.11.2024 06:58:09

The SUNRPC subsystem in the Linux kernel through 5.17.2 can call xs_xprt_free before ensuring that sockets are in the intended state.

  • EPSS 0.39%
  • Published 06.04.2022 14:15:08
  • Last modified 21.11.2024 06:51:06

PJSIP is a free and open source multimedia communication library written in C. A buffer overflow vulnerability in versions 2.12 and prior affects applications that use PJSIP DNS resolution. It doesn't affect PJSIP users who utilize an external resolv...

  • EPSS 0.29%
  • Published 06.04.2022 14:15:07
  • Last modified 21.11.2024 06:51:05

PJSIP is a free and open source multimedia communication library written in C. PJSIP versions 2.12 and prior do not parse incoming RTCP feedback RPSI (Reference Picture Selection Indication) packet, but any app that directly uses pjmedia_rtcp_fb_pars...

  • EPSS 0.32%
  • Published 06.04.2022 02:15:08
  • Last modified 21.11.2024 06:53:26

An issue was discovered in HTCondor 8.8.x before 8.8.16, 9.0.x before 9.0.10, and 9.1.x before 9.6.0. When a user authenticates to an HTCondor daemon via the CLAIMTOBE method, the user can then impersonate any entity when issuing additional commands ...

  • EPSS 0.04%
  • Published 05.04.2022 13:15:07
  • Last modified 21.11.2024 06:53:49

Racy interactions between dirty vram tracking and paging log dirty hypercalls Activation of log dirty mode done by XEN_DMOP_track_dirty_vram (was named HVMOP_track_dirty_vram before Xen 4.9) is racy with ongoing log dirty hypercalls. A suitably timed...

  • EPSS 0.01%
  • Published 05.04.2022 13:15:07
  • Last modified 21.11.2024 06:53:49

race in VT-d domain ID cleanup Xen domain IDs are up to 15 bits wide. VT-d hardware may allow for only less than 15 bits to hold a domain ID associating a physical device with a particular domain. Therefore internally Xen domain IDs are mapped to the...

  • EPSS 0.09%
  • Published 05.04.2022 13:15:07
  • Last modified 21.11.2024 06:53:49

IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Certain PCI devices in a system might be assigned Reserved Memo...

  • EPSS 0.09%
  • Published 05.04.2022 13:15:07
  • Last modified 21.11.2024 06:53:49

IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Certain PCI devices in a system might be assigned Reserved Memo...