Debian

Debian Linux

9144 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.34%
  • Published 26.02.2021 23:15:11
  • Last modified 21.11.2024 05:58:35

A vulnerability was discovered in how p2p/p2p_pd.c in wpa_supplicant before 2.10 processes P2P (Wi-Fi Direct) provision discovery requests. It could result in denial of service or other impact (potentially execution of arbitrary code), for an attacke...

  • EPSS 33.82%
  • Published 26.02.2021 22:15:19
  • Last modified 20.08.2025 10:15:27

In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS) ...

  • EPSS 0.72%
  • Published 26.02.2021 16:15:12
  • Last modified 21.11.2024 05:52:08

Mozilla developers reported memory safety bugs present in Firefox 85 and Firefox ESR 78.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. T...

  • EPSS 0.7%
  • Published 26.02.2021 03:15:13
  • Last modified 21.11.2024 05:52:06

Further techniques that built on the slipstream research combined with a malicious webpage could have exposed both an internal network's hosts as well as services running on the user's local machine. This vulnerability affects Firefox < 85.

  • EPSS 0.49%
  • Published 26.02.2021 03:15:12
  • Last modified 21.11.2024 05:48:02

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In aiohttp before version 3.7.4 there is an open redirect vulnerability. A maliciously crafted link to an aiohttp-based web-server could redirect the browser to a differe...

  • EPSS 0.6%
  • Published 26.02.2021 02:15:13
  • Last modified 21.11.2024 05:52:07

When trying to load a cross-origin resource in an audio/video context a decoding error may have resulted, and the content of that error may have revealed information about the resource. This vulnerability affects Firefox < 86, Thunderbird < 78.8, and...

  • EPSS 0.77%
  • Published 26.02.2021 02:15:12
  • Last modified 21.11.2024 05:52:07

If Content Security Policy blocked frame navigation, the full destination of a redirect served in the frame was reported in the violation report; as opposed to the original frame URI. This could be used to leak sensitive information contained in such...

  • EPSS 0.85%
  • Published 26.02.2021 02:15:12
  • Last modified 21.11.2024 05:52:07

As specified in the W3C Content Security Policy draft, when creating a violation report, "User agents need to ensure that the source file is the URL requested by the page, pre-redirects. If that’s not possible, user agents need to strip the URL down ...

Exploit
  • EPSS 0.03%
  • Published 25.02.2021 20:15:11
  • Last modified 21.11.2024 05:46:07

An integer overflow issue was found in the vmxnet3 NIC emulator of the QEMU for versions up to v5.2.0. It may occur if a guest was to supply invalid values for rx/tx queue size or other NIC parameters. A privileged guest user may use this flaw to cra...

  • EPSS 0.63%
  • Published 24.02.2021 18:15:11
  • Last modified 21.11.2024 04:59:03

Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arb...