Debian

Debian Linux

9213 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.59%
  • Published 20.02.2019 18:29:00
  • Last modified 21.11.2024 04:09:28

An error within the "parse_sinar_ia()" function (internal/dcraw_common.cpp) within LibRaw versions prior to 0.19.1 can be exploited to exhaust available CPU resources.

Exploit
  • EPSS 92.72%
  • Published 20.02.2019 03:29:00
  • Last modified 21.11.2024 04:50:42

WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an arbitrary string, such as one ending with a .jpg?file.php substring. An attacker with author privileges can exe...

Exploit
  • EPSS 1.98%
  • Published 20.02.2019 00:29:00
  • Last modified 21.11.2024 04:47:41

SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter.

  • EPSS 0.03%
  • Published 19.02.2019 17:29:02
  • Last modified 21.11.2024 04:45:28

Insufficient restrictions on what can be done with Apple Events in Google Chrome on macOS prior to 72.0.3626.81 allowed a local attacker to execute JavaScript via Apple Events.

  • EPSS 0.85%
  • Published 19.02.2019 17:29:02
  • Last modified 21.11.2024 04:45:28

Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.

  • EPSS 79.8%
  • Published 19.02.2019 17:29:02
  • Last modified 21.11.2024 04:45:28

Incorrect optimization assumptions in V8 in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

  • EPSS 0.69%
  • Published 19.02.2019 17:29:02
  • Last modified 21.11.2024 04:45:29

Missing URI encoding of untrusted input in DevTools in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to perform a Dangling Markup Injection attack via a crafted HTML page.

  • EPSS 0.88%
  • Published 19.02.2019 17:29:01
  • Last modified 21.11.2024 04:45:27

Incorrect handling of origin taint checking in Canvas in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • EPSS 0.49%
  • Published 19.02.2019 17:29:01
  • Last modified 21.11.2024 04:45:27

Insufficient protection of permission UI in WebAPKs in Google Chrome on Android prior to 72.0.3626.81 allowed an attacker who convinced the user to install a malicious application to access privacy/security sensitive web APIs via a crafted APK.

  • EPSS 0.49%
  • Published 19.02.2019 17:29:01
  • Last modified 21.11.2024 04:45:27

DevTools API not correctly gating on extension capability in DevTools in Google Chrome prior to 72.0.3626.81 allowed an attacker who convinced a user to install a malicious extension to read local files via a crafted Chrome Extension.