Debian

Debian Linux

9950 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 6.09%
  • Veröffentlicht 01.02.2023 19:15:08
  • Zuletzt bearbeitet 27.03.2025 15:15:45

In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, the parsed values of Accept-Language headers are cached in order to avoid repetitive parsing. This leads to a potential denial-of-service vector via excessive memory usage if the ra...

Warnung
  • EPSS 0.08%
  • Veröffentlicht 30.01.2023 14:15:10
  • Zuletzt bearbeitet 24.10.2025 13:54:46

A use after free vulnerability exists in the ALSA PCM package in the Linux Kernel. SNDRV_CTL_IOCTL_ELEM_{READ|WRITE}32 is missing locks that can be used in a use-after-free that can result in a priviledge escalation to gain ring0 access from the syst...

  • EPSS 0.28%
  • Veröffentlicht 27.01.2023 05:15:17
  • Zuletzt bearbeitet 03.04.2025 13:15:40

In Apache::Session::Browseable before 1.3.6, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used. NOTE: this can, for example...

  • EPSS 0.18%
  • Veröffentlicht 27.01.2023 05:15:12
  • Zuletzt bearbeitet 28.03.2025 18:15:15

In Apache::Session::LDAP before 0.5, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used. NOTE: this can, for example, be fix...

Exploit
  • EPSS 0.73%
  • Veröffentlicht 26.01.2023 22:15:25
  • Zuletzt bearbeitet 31.03.2025 17:15:39

An issue was discovered in OpenStack Cinder before 19.1.2, 20.x before 20.0.2, and 21.0.0; Glance before 23.0.1, 24.x before 24.1.1, and 25.0.0; and Nova before 24.1.2, 25.x before 25.0.2, and 26.0.0. By supplying a specially created VMDK flat image ...

  • EPSS 0.21%
  • Veröffentlicht 26.01.2023 21:18:07
  • Zuletzt bearbeitet 03.11.2025 22:16:02

TIPC dissector crash in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture file

Exploit
  • EPSS 0.01%
  • Veröffentlicht 23.01.2023 03:15:09
  • Zuletzt bearbeitet 03.04.2025 14:15:23

processCropSelections in tools/tiffcrop.c in LibTIFF through 4.5.0 has a heap-based buffer overflow (e.g., "WRITE of size 307203") via a crafted TIFF image.

Exploit
  • EPSS 0.11%
  • Veröffentlicht 21.01.2023 01:15:15
  • Zuletzt bearbeitet 02.04.2025 16:15:32

The HTML-StripScripts module through 1.06 for Perl allows _hss_attval_style ReDoS because of catastrophic backtracking for HTML content with certain style attributes.

  • EPSS 0.1%
  • Veröffentlicht 20.01.2023 19:15:18
  • Zuletzt bearbeitet 02.04.2025 17:15:34

Incorrect handling of '\0' bytes in file uploads in ModSecurity before 2.9.7 may allow for Web Application Firewall bypasses and buffer over-reads on the Web Application Firewall when executing rules that read the FILES_TMP_CONTENT collection.

  • EPSS 0.65%
  • Veröffentlicht 20.01.2023 19:15:17
  • Zuletzt bearbeitet 03.07.2025 20:59:18

In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart requests were incorrectly parsed and could bypass the Web Application Firewall. NOTE: this is related to CVE-2022-39956 but can be considered independent changes to the ModSecurity (C l...