Debian

Debian Linux

9144 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 5.89%
  • Published 12.06.2020 16:15:10
  • Last modified 21.11.2024 05:32:13

In affected versions of WordPress, when uploading themes, the name of the theme folder can be crafted in a way that could lead to JavaScript execution in /wp-admin on the themes page. This does require an admin to upload the theme, and is low severit...

  • EPSS 2.42%
  • Published 12.06.2020 16:15:10
  • Last modified 21.11.2024 05:32:13

In affected versions of WordPress, misuse of the `set-screen-option` filter's return value allows arbitrary user meta fields to be saved. It does require an admin to install a plugin that would misuse the filter. Once installed, it can be leveraged b...

  • EPSS 11.11%
  • Published 11.06.2020 15:15:16
  • Last modified 21.11.2024 04:53:05

In exif_data_load_data_content of exif-data.c, there is a possible UBSAN abort due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product...

  • EPSS 0.48%
  • Published 11.06.2020 15:15:15
  • Last modified 21.11.2024 04:53:03

In exif_entry_get_value of exif-entry.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploita...

Exploit
  • EPSS 0.49%
  • Published 09.06.2020 13:15:10
  • Last modified 21.11.2024 04:56:00

A flaw was found in the Linux Kernel in versions after 4.5-rc1 in the way mremap handled DAX Huge Pages. This flaw allows a local attacker with access to a DAX enabled storage to escalate their privileges on the system.

Exploit
  • EPSS 0.06%
  • Published 09.06.2020 05:15:10
  • Last modified 21.11.2024 05:02:16

An issue was discovered in the Linux kernel 4.4 through 5.7.1. drivers/tty/vt/keyboard.c has an integer overflow if k_ascii is called several times in a row, aka CID-b86dab054059. NOTE: Members in the community argue that the integer overflow does no...

  • EPSS 0.87%
  • Published 09.06.2020 03:15:11
  • Last modified 21.11.2024 05:02:15

An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. include/rcmail_output_html.php allows XSS via the username template object.

Warning Exploit
  • EPSS 85.03%
  • Published 09.06.2020 03:15:11
  • Last modified 22.10.2025 00:16:57

An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview.

  • EPSS 6.92%
  • Published 08.06.2020 19:15:10
  • Last modified 21.11.2024 05:01:14

A heap-based buffer overflow in the hxxx_AnnexB_to_xVC function in modules/packetizer/hxxx_nal.c in VideoLAN VLC media player before 3.0.11 for macOS/iOS allows remote attackers to cause a denial of service (application crash) or execute arbitrary co...

Exploit
  • EPSS 2.74%
  • Published 08.06.2020 17:15:10
  • Last modified 21.11.2024 05:01:37

PHPMailer before 6.1.6 contains an output escaping bug when the name of a file attachment contains a double quote character. This can result in the file type being misinterpreted by the receiver or any mail relay processing the message.