Debian

Debian Linux

9979 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.21%
  • Veröffentlicht 13.02.2024 19:15:11
  • Zuletzt bearbeitet 21.11.2024 08:59:46

mod_auth_openidc is an OpenID Certified™ authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. In affected versions missing input validation on mod_auth_openidc_session_...

  • EPSS 0.01%
  • Veröffentlicht 11.02.2024 15:15:07
  • Zuletzt bearbeitet 21.11.2024 08:49:54

A vulnerability was reported in the Open vSwitch sub-component in the Linux Kernel. The flaw occurs when a recursive operation of code push recursively calls into the code block. The OVS module does not validate the stack depth, pushing too many fram...

  • EPSS 0.19%
  • Veröffentlicht 11.02.2024 03:15:09
  • Zuletzt bearbeitet 21.11.2024 09:01:15

In Rhonabwy through 1.1.13, HMAC signature verification uses a strcmp function that is vulnerable to side-channel attacks, because it stops the comparison when the first difference is spotted in the two signatures. (The fix uses gnutls_memcmp, which ...

Exploit
  • EPSS 0.11%
  • Veröffentlicht 08.02.2024 17:15:10
  • Zuletzt bearbeitet 18.11.2025 17:06:06

libjwt 1.15.3 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing side channel.

  • EPSS 0.02%
  • Veröffentlicht 07.02.2024 21:15:08
  • Zuletzt bearbeitet 04.11.2025 19:16:24

A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages when using NVMe over TCP, leading the NVMe driver to a NULL pointer dereference in the NVMe driver and c...

  • EPSS 0.03%
  • Veröffentlicht 07.02.2024 21:15:08
  • Zuletzt bearbeitet 04.11.2025 19:16:24

A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages when using NVMe over TCP, leading the NVMe driver to a NULL pointer dereference in the NVMe driver, caus...

  • EPSS 0.03%
  • Veröffentlicht 05.02.2024 08:15:44
  • Zuletzt bearbeitet 12.05.2026 12:16:18

A race condition was found in the Linux kernel's net/bluetooth device driver in conn_info_{min,max}_age_set() function. This can result in integrity overflow issue, possibly leading to bluetooth connection abnormality or denial of service.

  • EPSS 0.03%
  • Veröffentlicht 05.02.2024 08:15:44
  • Zuletzt bearbeitet 12.05.2026 12:16:18

A race condition was found in the Linux kernel's net/bluetooth in {conn,adv}_{min,max}_interval_set() function. This can result in I2cap connection or broadcast abnormality issue, possibly leading to denial of service.

Warnung Exploit
  • EPSS 84.55%
  • Veröffentlicht 31.01.2024 13:15:10
  • Zuletzt bearbeitet 27.10.2025 17:06:37

A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, and hence the n...

  • EPSS 0.22%
  • Veröffentlicht 29.01.2024 11:15:07
  • Zuletzt bearbeitet 04.11.2025 19:16:04

Transmit requests in Xen's virtual network protocol can consist of multiple parts. While not really useful, except for the initial part any of them may be of zero length, i.e. carry no data at all. Besides a certain initial portion of the to be tra...