Debian

Debian Linux

9177 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.69%
  • Published 20.12.2019 15:15:11
  • Last modified 21.11.2024 01:45:48

cups (Common Unix Printing System) 'Listen localhost:631' option not honored correctly which could provide unauthorized access to the system

  • EPSS 0.39%
  • Published 20.12.2019 15:15:11
  • Last modified 21.11.2024 01:45:50

gnome-keyring does not discard stored secrets when using gnome_keyring_lock_all_sync function

  • EPSS 0.08%
  • Published 20.12.2019 14:15:11
  • Last modified 21.11.2024 01:40:48

ecryptfs-utils: suid helper does not restrict mounting filesystems with nosuid,nodev which creates a possible privilege escalation

  • EPSS 0.61%
  • Published 20.12.2019 14:15:11
  • Last modified 21.11.2024 01:45:01

LibreOffice and OpenOffice automatically open embedded content

  • EPSS 1.06%
  • Published 20.12.2019 14:15:11
  • Last modified 21.11.2024 02:38:16

GnuTLS incorrectly validates the first byte of padding in CBC modes

Exploit
  • EPSS 0.4%
  • Published 19.12.2019 18:15:12
  • Last modified 21.11.2024 04:35:37

cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in _sasl_add_string in common.c ...

  • EPSS 4.17%
  • Published 18.12.2019 20:15:15
  • Last modified 04.11.2025 19:15:38

The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external DTDs. This flaw has not been addressed in the maintained version of the library and has no current mitigation other than to disabl...

  • EPSS 8.44%
  • Published 18.12.2019 06:15:12
  • Last modified 21.11.2024 04:35:34

exprListAppendList in window.c in SQLite 3.30.1 allows attackers to trigger an invalid pointer dereference because constant integer values in ORDER BY clauses of window definitions are mishandled.

Exploit
  • EPSS 6.62%
  • Published 17.12.2019 18:15:12
  • Last modified 21.11.2024 01:38:44

Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.4.x before 1.4.3 and 1.5.x before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) javascript innerHTML as used when generating login forms,...

Exploit
  • EPSS 1.62%
  • Published 17.12.2019 06:15:12
  • Last modified 21.11.2024 04:35:26

In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in __mutex_lock in kernel/locking/mutex.c. This is related to mutex_can_spin_on_owner...