Debian

Debian Linux

9294 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.2%
  • Veröffentlicht 07.01.2025 12:15:24
  • Zuletzt bearbeitet 08.12.2025 18:38:59

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The Document Foundation LibreOffice allows Absolute Path Traversal. An attacker can write to arbitrary locations, albeit suffixed with ".ttf", by supp...

Exploit
  • EPSS 64.8%
  • Veröffentlicht 06.01.2025 22:15:09
  • Zuletzt bearbeitet 05.09.2025 14:20:13

Redis is an open source, in-memory database that persists on disk. An authenticated user may use a specially crafted Lua script to manipulate the garbage collector and potentially lead to remote code execution. The problem is fixed in 7.4.2, 7.2.7, a...

Warnung Medienbericht
  • EPSS 1.8%
  • Veröffentlicht 27.12.2024 14:15:27
  • Zuletzt bearbeitet 04.11.2025 16:47:12

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices A bogus device can provide a bNumConfigurations value that exceeds the initial value used in usb_ge...

Warnung Medienbericht
  • EPSS 1.61%
  • Veröffentlicht 24.12.2024 12:15:23
  • Zuletzt bearbeitet 04.11.2025 16:47:05

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix out of bounds reads when finding clock sources The current USB-audio driver code doesn't check bLength of each descriptor at traversing for clock descriptors. ...

  • EPSS 0.59%
  • Veröffentlicht 12.12.2024 02:03:32
  • Zuletzt bearbeitet 03.11.2025 21:16:24

GStreamer is a library for constructing graphs of media-handling components. An integer underflow has been detected in the function qtdemux_parse_theora_extension within qtdemux.c. The vulnerability occurs due to an underflow of the gint size variabl...

Exploit
  • EPSS 12.5%
  • Veröffentlicht 09.12.2024 10:15:05
  • Zuletzt bearbeitet 15.07.2025 16:35:39

Insufficient validation of filenames against control characters in Apache Subversion repositories served via mod_dav_svn allows authenticated users with commit access to commit a corrupted revision, leading to disruption for users of the repository. ...

Warnung
  • EPSS 12.8%
  • Veröffentlicht 02.12.2024 08:15:08
  • Zuletzt bearbeitet 04.11.2025 14:36:37

In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format This can lead to out of bounds writes since frames of this type were not taken into account when c...

Warnung
  • EPSS 0.36%
  • Veröffentlicht 20.11.2024 00:15:17
  • Zuletzt bearbeitet 04.11.2025 15:21:26

A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, macOS Sequoia 15.1.1, iOS 18.1.1 and iPadOS 18.1.1, visionOS 2.1.1. Processing maliciously crafted web content...

Warnung
  • EPSS 0.52%
  • Veröffentlicht 20.11.2024 00:15:17
  • Zuletzt bearbeitet 04.11.2025 15:22:03

The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, macOS Sequoia 15.1.1, iOS 18.1.1 and iPadOS 18.1.1, visionOS 2.1.1. Processing maliciously crafted web content may lead to arbitrary cod...

Exploit
  • EPSS 0.09%
  • Veröffentlicht 19.11.2024 18:15:19
  • Zuletzt bearbeitet 03.11.2025 22:16:34

Qualys discovered that if unsanitized input was used with the library Modules::ScanDeps, before version 1.36 a local attacker could possibly execute arbitrary shell commands by open()ing a "pesky pipe" (such as passing "commands|" as a filename) or b...