Debian

Debian Linux

9144 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.06%
  • Published 04.12.2020 07:15:10
  • Last modified 21.11.2024 05:23:17

hw/net/e1000e_core.c in QEMU 5.0.0 has an infinite loop via an RX descriptor with a NULL buffer address.

  • EPSS 11.07%
  • Published 03.12.2020 19:15:12
  • Last modified 21.11.2024 05:08:17

While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream received on an HTTP/2 connection for the request asso...

  • EPSS 0.06%
  • Published 03.12.2020 17:15:13
  • Last modified 21.11.2024 05:21:47

In /MagickCore/statistic.c, there are several areas in ApplyEvaluateOperator() where a size_t cast should have been a ssize_t cast, which causes out-of-range values under some circumstances when a crafted input file is processed by ImageMagick. Red H...

Exploit
  • EPSS 0.29%
  • Published 03.12.2020 17:15:13
  • Last modified 21.11.2024 05:21:49

A flaw was found in Poppler in the way certain PDF files were converted into HTML. A remote attacker could exploit this flaw by providing a malicious PDF file that, when processed by the 'pdftohtml' program, would crash the application causing a deni...

Exploit
  • EPSS 1.14%
  • Published 03.12.2020 17:15:13
  • Last modified 21.11.2024 05:21:49

A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A remote attacker could exploit this flaw to run arbit...

  • EPSS 0.1%
  • Published 03.12.2020 17:15:12
  • Last modified 21.11.2024 05:03:04

A flaw was found in the Linux kernel. A use-after-free memory flaw was found in the perf subsystem allowing a local attacker with permission to monitor perf events to corrupt memory and possibly escalate privileges. The highest threat from this vulne...

  • EPSS 0.06%
  • Published 03.12.2020 17:15:12
  • Last modified 21.11.2024 05:21:46

In IntensityCompare() of /MagickCore/quantize.c, a double value was being casted to int and returned, which in some cases caused a value outside the range of type `int` to be returned. The flaw could be triggered by a crafted input file under certain...

  • EPSS 0.12%
  • Published 03.12.2020 17:15:12
  • Last modified 21.11.2024 05:21:46

In `GammaImage()` of /MagickCore/enhance.c, depending on the `gamma` value, it's possible to trigger a divide-by-zero condition when a crafted input file is processed by ImageMagick. This could lead to an impact to application availability. The patch...

  • EPSS 0.09%
  • Published 03.12.2020 17:15:12
  • Last modified 21.11.2024 05:21:46

WritePALMImage() in /coders/palm.c used size_t casts in several areas of a calculation which could lead to values outside the range of representable type `unsigned long` undefined behavior when a crafted input file was processed by ImageMagick. The p...

  • EPSS 0.08%
  • Published 03.12.2020 17:15:12
  • Last modified 21.11.2024 05:21:47

A flaw was found in ImageMagick in coders/hdr.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type `unsigned char`. This would most likely lead to ...