Debian

Debian Linux

9922 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 1.75%
  • Veröffentlicht 16.01.2024 14:15:48
  • Zuletzt bearbeitet 21.11.2024 08:46:53

A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a certificate chain with cockpit-certificate-ensure. This flaw allows an unauthenticated, r...

  • EPSS 0.02%
  • Veröffentlicht 12.01.2024 02:15:44
  • Zuletzt bearbeitet 20.03.2025 16:59:40

An out-of-bounds access vulnerability involving netfilter was reported and fixed as: f1082dd31fe4 (netfilter: nf_tables: Reject tables of unsupported family); While creating a new netfilter table, lack of a safeguard against invalid nf_tables family ...

  • EPSS 0.02%
  • Veröffentlicht 11.01.2024 19:15:12
  • Zuletzt bearbeitet 21.11.2024 08:38:47

An issue was discovered in the Linux kernel before 6.6.8. do_vcc_ioctl in net/atm/ioctl.c has a use-after-free because of a vcc_recvmsg race condition.

  • EPSS 0.02%
  • Veröffentlicht 11.01.2024 19:15:12
  • Zuletzt bearbeitet 21.11.2024 08:38:47

An issue was discovered in the Linux kernel before 6.6.8. atalk_ioctl in net/appletalk/ddp.c has a use-after-free because of an atalk_recvmsg race condition.

  • EPSS 0.02%
  • Veröffentlicht 11.01.2024 19:15:12
  • Zuletzt bearbeitet 21.11.2024 08:38:47

An issue was discovered in the Linux kernel before 6.6.8. rose_ioctl in net/rose/af_rose.c has a use-after-free because of a rose_accept race condition.

Exploit
  • EPSS 1.19%
  • Veröffentlicht 04.01.2024 21:15:10
  • Zuletzt bearbeitet 07.01.2026 19:49:03

httparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulnerability. A remote and unauthenticated attacker can provide a crafted filename parameter during multipart/form-data uploads which could result in attacker controlled file...

  • EPSS 0.02%
  • Veröffentlicht 04.01.2024 17:15:08
  • Zuletzt bearbeitet 30.08.2025 09:15:31

A flaw was found in the ATA over Ethernet (AoE) driver in the Linux kernel. The aoecmd_cfg_pkts() function improperly updates the refcnt on `struct net_device`, and a use-after-free can be triggered by racing between the free on the struct and the ac...

Warnung
  • EPSS 83.31%
  • Veröffentlicht 24.12.2023 22:15:07
  • Zuletzt bearbeitet 24.10.2025 16:39:52

Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execution (ACE) vulnerability due to passing unvalidated input from a file into a string-type “eval”. Speci...

  • EPSS 0.13%
  • Veröffentlicht 24.12.2023 21:15:25
  • Zuletzt bearbeitet 20.03.2025 21:31:13

An issue was discovered in the HTTP2 implementation in Qt before 5.15.17, 6.x before 6.2.11, 6.3.x through 6.5.x before 6.5.4, and 6.6.x before 6.6.2. network/access/http2/hpacktable.cpp has an incorrect HPack integer overflow check.

Exploit
  • EPSS 1.64%
  • Veröffentlicht 24.12.2023 06:15:07
  • Zuletzt bearbeitet 04.11.2025 19:16:21

Exim before 4.97.1 allows SMTP smuggling in certain PIPELINING/CHUNKING configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mecha...