Debian

Debian Linux

9950 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.34%
  • Veröffentlicht 14.12.2022 18:15:17
  • Zuletzt bearbeitet 03.11.2025 22:15:56

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Prior to version 1.4.4, there is a possible XSS vulnerability with certain configurations of Rails::Html::Sanitizer due to an incomplete fix of CVE-2022-32209. R...

Exploit
  • EPSS 0.14%
  • Veröffentlicht 14.12.2022 17:15:11
  • Zuletzt bearbeitet 03.11.2025 22:15:56

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Prior to version 1.4.4, a possible XSS vulnerability with certain configurations of Rails::Html::Sanitizer may allow an attacker to inject content if the applica...

  • EPSS 0.25%
  • Veröffentlicht 14.12.2022 17:15:10
  • Zuletzt bearbeitet 03.11.2025 22:15:56

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Certain configurations of rails-html-sanitizer < 1.4.4 use an inefficient regular expression that is susceptible to excessive backtracking when attempting to san...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 14.12.2022 17:15:10
  • Zuletzt bearbeitet 03.11.2025 22:15:56

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Versions >= 1.0.3, < 1.4.4 are vulnerable to cross-site scripting via data URIs when used in combination with Loofah >= 2.1.0. This issue is patched in version 1...

  • EPSS 0.26%
  • Veröffentlicht 14.12.2022 14:15:10
  • Zuletzt bearbeitet 03.11.2025 22:15:56

Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah >= 2.1.0, < 2.19.1 is vulnerable to cross-site scripting via the image/svg+xml media type in data URIs. This issue is pat...

Exploit
  • EPSS 0.13%
  • Veröffentlicht 13.12.2022 15:15:11
  • Zuletzt bearbeitet 22.04.2025 04:15:23

A stack overflow in Jettison before v1.5.2 allows attackers to cause a Denial of Service (DoS) via crafted JSON data.

Exploit
  • EPSS 0.13%
  • Veröffentlicht 13.12.2022 15:15:11
  • Zuletzt bearbeitet 22.04.2025 15:16:05

Jettison before v1.5.2 was discovered to contain a stack overflow via the map parameter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted string.

Exploit
  • EPSS 0.52%
  • Veröffentlicht 13.12.2022 07:15:13
  • Zuletzt bearbeitet 21.11.2024 07:24:03

Netty project is an event-driven asynchronous network application framework. Starting in version 4.1.83.Final and prior to 4.1.86.Final, when calling `DefaultHttpHeadesr.set` with an _iterator_ of values, header value validation was not performed, al...

Exploit
  • EPSS 0.12%
  • Veröffentlicht 12.12.2022 18:15:12
  • Zuletzt bearbeitet 21.11.2024 07:23:58

Netty project is an event-driven asynchronous network application framework. In versions prior to 4.1.86.Final, a StackOverflowError can be raised when parsing a malformed crafted message due to an infinite recursion. This issue is patched in version...

  • EPSS 0.25%
  • Veröffentlicht 09.12.2022 18:15:17
  • Zuletzt bearbeitet 21.11.2024 06:48:39

xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Integer Overflow in xrdp_mm_process_rail_update_window_text() function. There are no known work...