Debian

Debian Linux

9177 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 6.74%
  • Published 24.01.2020 19:15:12
  • Last modified 21.11.2024 02:09:38

A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.2, .NET CAS Client before 1.0.2, and phpCAS before 1.3.3 that allow remote attackers to inject arbitr...

Exploit
  • EPSS 70.52%
  • Published 23.01.2020 22:15:10
  • Last modified 21.11.2024 04:32:33

An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) library. A malicious XML-RPC server could target a XML-RPC client causing it to execute arbitrary code. Apa...

  • EPSS 0.08%
  • Published 23.01.2020 17:15:11
  • Last modified 21.11.2024 04:32:52

The ECDSA signature implementation in ecdsa.c in Arm Mbed Crypto 2.1 and Mbed TLS through 2.19.1 does not reduce the blinded scalar before computing the inverse, which allows a local attacker to recover the private key via side-channel attacks.

  • EPSS 0.85%
  • Published 22.01.2020 19:15:11
  • Last modified 21.11.2024 04:31:11

Waitress through version 1.3.1 allows request smuggling by sending the Content-Length header twice. Waitress would header fold a double Content-Length header and due to being unable to cast the now comma separated value to an integer would set the Co...

  • EPSS 0.23%
  • Published 21.01.2020 23:15:13
  • Last modified 21.11.2024 04:38:21

repodata_schema2id in repodata.c in libsolv before 0.7.6 has a heap-based buffer over-read via a last schema whose length is less than the length of the input schema.

  • EPSS 0.56%
  • Published 21.01.2020 23:15:13
  • Last modified 21.11.2024 04:38:21

xmlSchemaPreRun in xmlschemas.c in libxml2 2.9.10 allows an xmlSchemaValidateStream memory leak.

  • EPSS 0.47%
  • Published 21.01.2020 23:15:13
  • Last modified 21.11.2024 05:37:26

xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation.

  • EPSS 5.19%
  • Published 21.01.2020 21:15:16
  • Last modified 21.11.2024 05:36:32

storeBackup.pl in storeBackup through 3.5 relies on the /tmp/storeBackup.lock pathname, which allows symlink attacks that possibly lead to privilege escalation. (Local users can also create a plain file named /tmp/storeBackup.lock to block use of sto...

Exploit
  • EPSS 0.07%
  • Published 21.01.2020 18:15:13
  • Last modified 21.11.2024 05:33:40

apt-cacher-ng through 3.3 allows local users to obtain sensitive information by hijacking the hardcoded TCP port. The /usr/lib/apt-cacher-ng/acngtool program attempts to connect to apt-cacher-ng via TCP on localhost port 3142, even if the explicit So...

  • EPSS 2.93%
  • Published 21.01.2020 18:15:12
  • Last modified 21.11.2024 04:27:39

There is an issue in all samba 4.11.x versions before 4.11.5, all samba 4.10.x versions before 4.10.12 and all samba 4.9.x versions before 4.9.18, where the removal of the right to create or modify a subtree would not automatically be taken away on a...