Debian

Debian Linux

9144 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 3.38%
  • Published 27.04.2020 21:15:14
  • Last modified 21.11.2024 05:36:36

In PHP versions 7.2.x below 7.2.30, 7.3.x below 7.3.17 and 7.4.x below 7.4.5, if PHP is compiled with EBCDIC support (uncommon), urldecode() function can be made to access locations past the allocated memory, due to erroneously using signed numbers a...

  • EPSS 5.16%
  • Published 27.04.2020 17:15:13
  • Last modified 21.11.2024 04:59:26

An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. path.c mishandles equivalent filenames that exist because of NTFS Alternate Data Streams. This may allow remote code execution when cloning a repository. This issue is similar t...

  • EPSS 5.58%
  • Published 27.04.2020 17:15:13
  • Last modified 21.11.2024 04:59:26

An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. checkout.c mishandles equivalent filenames that exist because of NTFS short names. This may allow remote code execution when cloning a repository. This issue is similar to CVE-2...

  • EPSS 0.02%
  • Published 27.04.2020 16:15:12
  • Last modified 21.11.2024 05:40:45

Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Lo...

  • EPSS 2.82%
  • Published 27.04.2020 15:15:12
  • Last modified 21.11.2024 04:33:38

HTCondor up to and including stable series 8.8.6 and development series 8.9.4 has Incorrect Access Control. It is possible to use a different authentication method to submit a job than the administrator has specified. If the administrator has configu...

Exploit
  • EPSS 2.37%
  • Published 27.04.2020 15:15:12
  • Last modified 21.11.2024 04:58:40

An issue was discovered in OpenVPN 2.4.x before 2.4.9. An attacker can inject a data channel v2 (P_DATA_V2) packet using a victim's peer-id. Normally such packets are dropped, but if this packet arrives before the data channel crypto parameters have ...

Exploit
  • EPSS 0.81%
  • Published 27.04.2020 02:15:12
  • Last modified 21.11.2024 04:59:24

jbig2_image_compose in jbig2_image.c in Artifex jbig2dec before 0.18 has a heap-based buffer overflow.

  • EPSS 1.24%
  • Published 24.04.2020 13:15:11
  • Last modified 21.11.2024 04:59:19

GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may contribute to XSS attacks against list-archive visitors, because an HTTP reply from an archive web server may lack a MIME type, ...

Exploit
  • EPSS 0.8%
  • Published 23.04.2020 19:15:12
  • Last modified 21.11.2024 04:39:21

libvncclient/cursor.c in LibVNCServer through 0.9.12 has a HandleCursorShape integer overflow and heap-based buffer overflow via a large height or width value. NOTE: this may overlap CVE-2019-15690.

  • EPSS 24.75%
  • Published 23.04.2020 15:15:14
  • Last modified 21.11.2024 04:58:57

An issue was discovered in Squid before 5.0.2. A remote attacker can replay a sniffed Digest Authentication nonce to gain access to resources that are otherwise forbidden. This occurs because the attacker can overflow the nonce reference counter (a s...