Debian

Debian Linux

9212 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.48%
  • Published 26.07.2019 13:15:12
  • Last modified 21.11.2024 04:25:25

GNU patch through 2.7.6 is vulnerable to OS shell command injection that can be exploited by opening a crafted patch file that contains an ed style diff payload with shell metacharacters. The ed editor does not need to be present on the vulnerable sy...

Exploit
  • EPSS 0.12%
  • Published 26.07.2019 04:15:11
  • Last modified 21.11.2024 04:26:21

Xfig fig2dev 3.2.7a has a stack-based buffer overflow in the calc_arrow function in bound.c.

  • EPSS 18.89%
  • Published 25.07.2019 20:15:11
  • Last modified 21.11.2024 04:25:41

Exim 4.85 through 4.92 (fixed in 4.92.1) allows remote code execution as root in some unusual configurations that use the ${sort } expansion for items that can be controlled by an attacker (e.g., $local_part or $domain).

  • EPSS 13.12%
  • Published 25.07.2019 14:15:11
  • Last modified 21.11.2024 04:18:01

CImg The CImg Library v.2.3.3 and earlier is affected by: command injection. The impact is: RCE. The component is: load_network() function. The attack vector is: Loading an image from a user-controllable url can lead to command injection, because no ...

  • EPSS 0.26%
  • Published 23.07.2019 23:15:43
  • Last modified 21.11.2024 04:41:37

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Difficult to exploit vulnerability allo...

  • EPSS 0.65%
  • Published 23.07.2019 23:15:40
  • Last modified 21.11.2024 04:41:31

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Utilities). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Easily exploitable vulnerability allows ...

  • EPSS 0.77%
  • Published 23.07.2019 23:15:39
  • Last modified 21.11.2024 04:41:30

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Utilities). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Easily exploitable vulnerability allows ...

  • EPSS 0.08%
  • Published 23.07.2019 23:15:38
  • Last modified 21.11.2024 04:41:28

Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 7u221, 8u212 and 11.0.3. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrast...

  • EPSS 19.71%
  • Published 23.07.2019 14:15:16
  • Last modified 21.11.2024 04:21:40

A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directories if the names are known or guessed. The Fetch API can then be used to read the contents...

Exploit
  • EPSS 0.87%
  • Published 23.07.2019 14:15:16
  • Last modified 21.11.2024 04:52:21

As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. This vulnerability affects Firefox ESR < 60.8, Firefox < ...