Debian

Debian Linux

9142 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 1.11%
  • Published 03.02.2022 02:15:07
  • Last modified 21.11.2024 06:47:30

The {% debug %} template tag in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2 does not properly encode the current context. This may lead to XSS.

  • EPSS 0.62%
  • Published 03.02.2022 02:15:07
  • Last modified 21.11.2024 06:49:20

An issue was discovered in MultiPartParser in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2. Passing certain inputs to multipart forms could result in an infinite loop when parsing files.

Exploit
  • EPSS 0.18%
  • Published 02.02.2022 21:15:07
  • Last modified 21.11.2024 06:38:38

Use After Free in GitHub repository vim/vim prior to 8.2.

Exploit
  • EPSS 4.81%
  • Published 02.02.2022 12:15:08
  • Last modified 05.05.2025 17:17:48

pgjdbc is the offical PostgreSQL JDBC Driver. A security hole was found in the jdbc driver for postgresql database while doing security research. The system using the postgresql library will be attacked when attacker control the jdbc url or propertie...

  • EPSS 0.83%
  • Published 02.02.2022 06:15:06
  • Last modified 21.11.2024 06:50:07

Minetest before 5.4.0 allows attackers to add or modify arbitrary meta fields of the same item stack as saved user input, aka ItemStack meta injection.

  • EPSS 0.34%
  • Published 02.02.2022 06:15:06
  • Last modified 21.11.2024 06:50:07

In Minetest before 5.4.0, players can add or subtract items from a different player's inventory.

Exploit
  • EPSS 0.14%
  • Published 01.02.2022 13:15:10
  • Last modified 21.11.2024 06:38:34

Heap-based Buffer Overflow GitHub repository vim/vim prior to 8.2.

Exploit
  • EPSS 2.4%
  • Published 01.02.2022 12:15:08
  • Last modified 23.05.2025 16:53:31

XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resul...

  • EPSS 0.34%
  • Published 01.02.2022 11:15:11
  • Last modified 21.11.2024 06:48:55

treq is an HTTP library inspired by requests but written on top of Twisted's Agents. Treq's request methods (`treq.get`, `treq.post`, etc.) and `treq.client.HTTPClient` constructor accept cookies as a dictionary. Such cookies are not bound to a singl...

Exploit
  • EPSS 0.51%
  • Published 01.02.2022 02:15:07
  • Last modified 21.11.2024 06:34:34

MariaDB through 10.5.9 allows attackers to trigger a convert_const_to_int use-after-free when the BIGINT data type is used.