Debian

Debian Linux

9950 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.05%
  • Veröffentlicht 21.03.2023 13:15:12
  • Zuletzt bearbeitet 21.11.2024 07:24:46

x86/HVM pinned cache attributes mis-handling T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To allow cachability control for HVM guests with passed through devices, an ...

  • EPSS 0.05%
  • Veröffentlicht 21.03.2023 13:15:11
  • Zuletzt bearbeitet 21.11.2024 07:24:46

x86 shadow plus log-dirty mode use-after-free In environments where host assisted address translation is necessary but Hardware Assisted Paging (HAP) is unavailable, Xen will run guests in so called shadow mode. Shadow mode maintains a pool of memory...

  • EPSS 0.02%
  • Veröffentlicht 16.03.2023 00:15:11
  • Zuletzt bearbeitet 05.05.2025 16:15:34

do_tls_getsockopt in net/tls/tls_main.c in the Linux kernel through 6.2.6 lacks a lock_sock call, leading to a race condition (with a resultant use-after-free or NULL pointer dereference).

  • EPSS 1.81%
  • Veröffentlicht 10.03.2023 22:15:10
  • Zuletzt bearbeitet 13.02.2025 15:37:40

A DoS vulnerability exists in Rack <v3.0.4.2, <v2.2.6.3, <v2.1.4.3 and <v2.0.9.3 within in the Multipart MIME parsing code in which could allow an attacker to craft requests that can be abuse to cause multipart parsing to take longer than expected.

  • EPSS 0.78%
  • Veröffentlicht 07.03.2023 16:15:09
  • Zuletzt bearbeitet 01.05.2025 15:34:19

HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55. Special characters in the origin response header can truncate/split the response forwarded to the cli...

  • EPSS 0.03%
  • Veröffentlicht 06.03.2023 23:15:11
  • Zuletzt bearbeitet 21.11.2024 07:36:59

A vulnerability in the lsi53c895a device affects the latest version of qemu. A DMA-MMIO reentrancy problem may lead to memory corruption bugs like stack overflow or use-after-free.

  • EPSS 0.2%
  • Veröffentlicht 06.03.2023 21:15:10
  • Zuletzt bearbeitet 03.11.2025 22:16:03

ISO 15765 and ISO 10681 dissector crash in Wireshark 4.0.0 to 4.0.3 and 3.6.0 to 3.6.11 allows denial of service via packet injection or crafted capture file

Exploit
  • EPSS 0.15%
  • Veröffentlicht 03.03.2023 19:15:11
  • Zuletzt bearbeitet 06.12.2024 14:15:19

runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to ru...

Exploit
  • EPSS 5.63%
  • Veröffentlicht 03.03.2023 16:15:10
  • Zuletzt bearbeitet 20.06.2025 19:17:18

systemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e.g., plausible sudoers files in which the "systemctl status" command may be executed. Specifically, systemd does not set LESSSECURE to 1, and thus ...

Exploit
  • EPSS 0.36%
  • Veröffentlicht 01.03.2023 15:15:11
  • Zuletzt bearbeitet 21.11.2024 07:48:21

libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the mc_chroma function at motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.