Debian

Debian Linux

9294 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Warnung Medienbericht
  • EPSS 76.68%
  • Veröffentlicht 11.03.2025 13:28:31
  • Zuletzt bearbeitet 27.10.2025 17:06:41

An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vulnerable code assigns a signed...

Warnung Medienbericht Exploit
  • EPSS 94.18%
  • Veröffentlicht 10.03.2025 16:44:03
  • Zuletzt bearbeitet 23.10.2025 14:49:29

Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet in Apache Tomcat. This issue affects Apache Tomcat: from 1...

  • EPSS 1.22%
  • Veröffentlicht 06.03.2025 19:15:27
  • Zuletzt bearbeitet 03.10.2025 00:32:38

An issue was discovered in Django 5.1 before 5.1.7, 5.0 before 5.0.13, and 4.2 before 4.2.20. The django.utils.text.wrap() method and wordwrap template filter are subject to a potential denial-of-service attack when used with very long strings.

  • EPSS 0.26%
  • Veröffentlicht 05.03.2025 21:15:20
  • Zuletzt bearbeitet 03.11.2025 20:18:02

Jinja is an extensible templating engine. Prior to 3.1.6, an oversight in how the Jinja sandboxed environment interacts with the |attr filter allows an attacker that controls the content of a template to execute arbitrary Python code. To exploit the ...

  • EPSS 0.09%
  • Veröffentlicht 04.03.2025 20:15:36
  • Zuletzt bearbeitet 10.12.2025 18:26:24

LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In the affected versions of LibreOffice a link in a brow...

Medienbericht
  • EPSS 45.46%
  • Veröffentlicht 28.02.2025 22:15:40
  • Zuletzt bearbeitet 03.11.2025 22:18:41

A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet is allocated in a memory buffer and stored in a queue of packages. It is only freed when the server/client key exchange has finished. A malicious cli...

Exploit
  • EPSS 0.1%
  • Veröffentlicht 26.02.2025 22:15:14
  • Zuletzt bearbeitet 07.04.2025 18:39:22

When AdaCore Ada Web Server 25.0.0 is linked with GnuTLS, the default behaviour of AWS.Client is vulnerable to a man-in-the-middle attack because of lack of verification of an HTTPS server's certificate (unless the using program specifies a TLS confi...

  • EPSS 0.04%
  • Veröffentlicht 26.02.2025 07:00:43
  • Zuletzt bearbeitet 18.11.2025 15:08:43

In the Linux kernel, the following vulnerability has been resolved: ice: arfs: fix use-after-free when freeing @rx_cpu_rmap The CI testing bots triggered the following splat: [ 718.203054] BUG: KASAN: use-after-free in free_irq_cpu_rmap+0x53/0x80...

  • EPSS 0.23%
  • Veröffentlicht 21.02.2025 15:15:11
  • Zuletzt bearbeitet 30.07.2025 18:10:35

There exists a heap buffer overflow vulnerable in Abseil-cpp. The sized constructors, reserve(), and rehash() methods of absl::{flat,node}hash{set,map} did not impose an upper bound on their size argument. As a result, it was possible for a caller to...

  • EPSS 0.41%
  • Veröffentlicht 18.02.2025 23:15:10
  • Zuletzt bearbeitet 04.11.2025 20:40:26

A NULL pointer dereference in the component /libsrc/dcrleccd.cc of DCMTK v3.6.9+ DEV allows attackers to cause a Denial of Service (DoS) via a crafted DICOM file.