Debian

Debian Linux

9144 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.63%
  • Published 04.01.2021 17:15:13
  • Last modified 21.11.2024 05:14:43

An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authenticated attacker can trigger unhibernation via attacker-controlled parameters, leading to access to other users' email messages (and path disclosure).

  • EPSS 6.85%
  • Published 04.01.2021 17:15:13
  • Last modified 21.11.2024 05:17:50

Dovecot before 2.3.13 has Improper Input Validation in lda, lmtp, and imap, leading to an application crash via a crafted email message with certain choices for ten thousand MIME parts.

Exploit
  • EPSS 0.39%
  • Published 04.01.2021 02:15:11
  • Last modified 21.11.2024 05:28:36

decode_frame in libavcodec/exr.c in FFmpeg 4.3.1 has an out-of-bounds write because of errors in calculations of when to perform memset zero operations.

  • EPSS 0.57%
  • Published 31.12.2020 01:15:12
  • Last modified 21.11.2024 05:00:00

gssproxy (aka gss-proxy) before 0.8.3 does not unlock cond_mutex before pthread exit in gp_worker_main() in gp_workers.c. NOTE: An upstream comment states "We are already on a shutdown path when running the code in question, so a DoS there doesn't ma...

  • EPSS 0.67%
  • Published 30.12.2020 21:15:12
  • Last modified 21.11.2024 04:28:55

An issue was discovered in LINBIT csync2 through 2.0. It does not correctly check for the return value GNUTLS_E_WARNING_ALERT_RECEIVED of the gnutls_handshake() function. It neglects to call this function again, as required by the design of the API.

  • EPSS 1.79%
  • Published 30.12.2020 19:15:12
  • Last modified 21.11.2024 05:19:38

Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri before version 1.11.0.rc4 there is an XXE vulnerability. XML Schemas parsed by Nokogiri::XML::Schema are trusted by default, allowing ...

Warning
  • EPSS 64.25%
  • Published 28.12.2020 20:15:13
  • Last modified 22.10.2025 00:17:06

An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in a link reference element that is mishandled by linkref_addindex in rcu...

Exploit
  • EPSS 0.41%
  • Published 28.12.2020 04:15:12
  • Last modified 21.11.2024 05:27:59

WavPack 5.3.0 has an out-of-bounds write in WavpackPackSamples in pack_utils.c because of an integer overflow in a malloc argument. NOTE: some third-parties claim that there are later "unofficial" releases through 5.3.2, which are also affected.

  • EPSS 41.43%
  • Published 27.12.2020 05:15:11
  • Last modified 27.08.2025 21:15:36

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool (aka embedded Xalan in org.glassfish.web/javax.servlet.js...

Exploit
  • EPSS 1.62%
  • Published 24.12.2020 15:15:12
  • Last modified 21.11.2024 05:22:25

The td-agent-builder plugin before 2020-12-18 for Fluentd allows attackers to gain privileges because the bin directory is writable by a user account, but a file in bin is executed as NT AUTHORITY\SYSTEM.